Method for securing transmission of payload, transmitter device configured for same, and motor vehicle
By calculating user data and a test value in parallel within a transmitter and combining them for transmission, the method addresses the complexity of existing data transmission methods, enhancing security and reducing costs through simplified error detection and reduced hardware redundancy.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-07-02
- Publication Date
- 2026-03-26
AI Technical Summary
Current data transmission methods in vehicles require significant effort and complexity, including hardware redundancy and separate data connections, which is undesirable for cost-effective and secure data transfer.
A method where user data is calculated by a primary and secondary module within a transmitter, with a test value generated by the secondary module, combined into a single data set, and transmitted to a receiver, allowing error detection without redundant connections.
This approach simplifies error detection and reduces system complexity by eliminating the need for redundant connections and comparators, maintaining security and integrity while reducing processing load and costs.
Smart Images

Figure EP2025068838_26032026_PF_FP_ABST
Abstract
Description
[0001] 24-1388
[0002] 1
[0003] Method for securing the transmission of user data, as well as a transmitter device and motor vehicle set up for this purpose.
[0004] The present invention relates to a method for securing the transmission of user data and to a control unit configured for this purpose, for example for a motor vehicle. The invention further relates to a correspondingly configured motor vehicle.
[0005] Nowadays, data needs to be transferred for a wide variety of applications and functions, for example, between different control units, computers, or similar devices. In principle, errors can occur during the calculation and / or transmission of this data. Since this can have undesirable consequences, safeguards against undetected errors or the further processing of faulty data are desirable. Depending on the application, there may be different requirements, and thus various solutions already exist.
[0006] One approach described in CN 115 / 085 867 A is a method for E2E (end-to-end) verification of CAN bus messages. In this method, E2E-protected messages are received and verified using a pre-generated configuration file.
[0007] US 6222-28 B1 describes a method for providing selective redundancy in a network between two end users. It establishes a primary connection via a first route and a redundant connection via a second route between the end users. If a failure of the primary connection occurs, 24-1388
[0008] If connection 2 is detected, data traffic is switched from this connection to the redundant connection.
[0009] CN 216 / 122138U describes a control system for vehicle lights with two microcontrollers and a comparator for comparing the outputs of the microcontrollers. The microcontrollers are connected to modules for voltage monitoring, data verification, operating program monitoring, LED diagnostics, communication protection, and logic validation.
[0010] CN 113 341 906 A describes a method for error handling in a vehicle's LIN bus, via which a main node is connected to at least one slave node. In this method, a first E2E message is sent to the first slave node, containing a CRC signal and a message counter signal. A second E2E message, correspondingly sent by the first slave node, is received, indicating whether a check of the CRC signal of the first E2E message failed and / or whether the message counter signal of the first E2E message is abnormal. Based on the second E2E message, it is then determined whether the first slave node has a communication error via the LIN bus. If so, an error code and so-called freeze frame information are stored, indicating communication error information detected by the first slave node.
[0011] However, current approaches often require significant effort, for example, for calculations and / or necessary hardware and / or data transmission via separate or redundant data connections, or similar measures. A reduction in effort and complexity would be desirable here, without compromising security.
[0012] The object of the present invention is to enable secure data transmission in a particularly cost-effective manner.
[0013] This problem is solved by the subject matter of the main claim and the dependent claims or independent claims. Further possible embodiments of the invention are disclosed in the dependent claims, the description, and the figures. Features, advantages, and possible embodiments set forth in the description for one of the subject matter of the independent claims are shown in Figure 24-1388.
[0014] 3 are to be regarded at least analogously as features, advantages and possible embodiments of the respective subject matter of the other independent claims as well as any possible combination of the subject matter of the independent claims, possibly in conjunction with one or more of the dependent claims.
[0015] The method according to the invention serves to secure the transmission of user data from a transmitter to a receiver. The transmitter and receiver can be, for example, control units, computers, or other data processing devices. In particular, they can be control units, computing units, or the like for a motor vehicle. However, the invention can also be used for other applications. In one step of the method according to the invention, the user data to be transmitted is calculated within the transmitter from the respective input data, once in a main or primary path or by a main or primary module of the transmitter, and in parallel or redundantly a second time in a redundant path or secondary path or by a redundancy or secondary module. These modules can, for example, be separate computing units within the transmitter.In particular, the primary and secondary modules can use or comprise at least partially different, i.e., separate or dedicated, computing hardware. The input data can, for example, be data previously received by the transmitter, data sent by an upstream device, or sensor data acquired or received by the transmitter. Similarly, the input data can be data resulting from a previous calculation or data processing by the transmitter, or similar information. The exact type and / or origin of the input data can therefore vary depending on the specific application.
[0016] In a further step of the method according to the invention, a test value is calculated in the redundant path or by the secondary module for the user data calculated by it, according to a predefined method. Since this test value is calculated within the transmitter device, it is also referred to here as the transmitter test value. For example, the transmitter test value can be a CRC sum, a hash value, or the like. 24-1388
[0017] 4
[0018] In a further step of the inventive process, the user data calculated by the primary module and the test value calculated by the secondary module are combined within the transmitter device to form a single overall data set. This can be performed, for example, by a merging or combining module of the transmitter device. Since the test value is calculated from the user data calculated by the secondary module, but the overall data set contains not this user data but instead the user data calculated by the primary module, it may still be unclear at this point whether the user data calculated by the primary module and the user data calculated by the secondary module correspond, i.e., whether the test value calculated by the secondary module matches the user data calculated by the primary module. This can therefore save the corresponding verification effort on the part of the transmitter device.
[0019] In a further step of the inventive process, the entire data set is then sent from the sending device to the receiving device via a data connection. In particular, the entire data set, i.e., all parts of the data set together, can be sent to the receiving device via a single data connection. This eliminates the need for a second or redundant data connection, thus saving the associated effort.
[0020] In a further step of the inventive process, the receiver device checks whether the test value contained in the received data set matches the user data contained in the received data set. If this is not the case, an error is detected. In this way, the receiver device can, for example, detect whether an error has occurred in one of the modules of the transmitter device, such as during the calculation of the user data or the calculation of the test value, or during the transmission of the data set from the transmitter device to the receiver device. If an error is detected, a predefined, automatic response can be initiated, which may depend on the specific application or requirements.If, however, the test value matches the user data, this can demonstrate that the entire dataset was transmitted correctly and that no error occurred during the previous combination of the user data with the test value. Furthermore, it can also demonstrate that the previous calculation of the user data in the primary module was performed correctly, and thus that the entire corresponding data processing function was performed correctly (24-1388).
[0021] The execution was successful because the result of the computational redundancy inherent in the primary module was implicitly transferred and checked. These assumptions regarding error-free operation can therefore be justified, since in practice it is not to be expected that several errors will occur simultaneously at different points, their effects canceling each other out or corresponding with each other in such a way that no error is detected.
[0022] The methodology proposed here allows a single message transmitted from the sender to the receiver—that is, the entire data set—to be sufficient for checking for potential errors during calculation and / or transmission, thus enabling the detection of such errors without the need for separate transmission paths for the user data or error information. This results in improved communication integrity between the devices compared to unsecured transmission, while simultaneously reducing the complexity of the necessary security technology compared to conventional methods. For example, the present invention can reduce system complexity by eliminating a comparator, which in turn leads to less susceptibility to errors and a simpler system design, while, for example, compared to correspondingly more complex systems, a security or...A certain level of safety, such as a specific ASIL (Automotive Safety Integrity Level), can be maintained. By combining the user data and the test value in the overall data set, verification or validation can be simplified, thereby reducing or keeping the processing load on the devices, especially the receiving device, to a minimum, while simultaneously enabling comparatively simple implementation. Overall, the present invention can thus enable increased robustness in data transmission or distributed data use by facilitating the detection, i.e., the recognition, of various errors, particularly when combining user data and test values, as well as during transmission, without requiring additional safety mechanisms on the receiving device.
[0023] The present invention can, for example, be used in applications that are generally less safety-critical and / or enable a particularly simple achievement of a certain level of safety or security. For example, according to the invention, individual components or steps, such as 24-1388
[0024] 6. For example, combining the user data calculated by the primary module with the test value calculated by the secondary module, or a corresponding combination module, each implemented in or with ASIL QM, and thus achieving a higher ASIL overall, i.e., in a more comprehensive system. Within the framework of the method according to the invention, it is not necessary, for example, for the receiver device to recognize which message or data should have been sent by the transmitter device, or at what point a detected error occurred in detail. This allows the described savings and simplifications to be used practically and without problems.
[0025] In a possible further development of the present invention, the test value is calculated only by the secondary module. The primary module, on the other hand, does not calculate a test value. In other words, the test value is calculated only once in the transmitter. Redundancy in the test value calculation is therefore unnecessary. This saves considerable effort and complexity on the transmitter side. Because the test value and the user data ultimately used in the receiver are calculated by different modules within the transmitter, a certain degree of redundancy and protection against calculation errors of the user data or the test value is implicitly provided. Thus, while maintaining this protection on the transmitter side, manufacturing effort, data processing effort, implementation effort, and costs can be reduced.
[0026] In a further possible embodiment of the present invention, the primary module and the secondary module also output respective identification data and / or predefined keepalive signals or keepalive data. The identification data identifies the respective output data, i.e., the user data calculated by the primary module or the test value calculated by the secondary module, and / or a respective data source from which the respective data originates, i.e., the primary module or the secondary module. Such identification data can, for example, be DIDs (Decentralized Identifiers). The keepalive signals can, for example, comprise a counter value or a counter signal and / or a timestamp. Such a counter value or such a counter signal can be automatically incremented according to a predefined time schedule, so that at any time and at any point in the system it is clear which keepalive signal is being used under normal operating conditions.
[0027] 7
[0028] The number of keepalive signals can be incremented with each intended or actual output or transmission of data or signals. The identification data and / or the keepalive signals can be output by the primary module along with the respective usage data, or by the secondary module along with the respective test value. Similarly, at least the keepalive signals can be output regularly by the primary and secondary modules in a predefined manner, regardless of whether new usage data or a new test value is available.This enables monitoring of the corresponding functionality of the modules and their data connection, for example, to the combination module mentioned elsewhere. This allows potential errors to be detected particularly early and reliably. Furthermore, the identification data and / or the keep-alive signals can support the combination of the respective user data with the corresponding test value, thus making the process particularly secure, reliable, and robust. The identification data can, for example, uniquely identify the respective data source or communication channel, such as at the level of a motor vehicle in which the invention is applied.
[0029] In a further possible embodiment of the present invention, to check whether the test value corresponds to the user data, a test value is also calculated in or by the receiver device for the user data contained in the respective received total data set. This test value calculated on the receiver device side is also referred to here as the receiver test value. This receiver test value is then compared in or by the receiver device with the transmitter test value contained in the received total data set. In particular, the transmitter test value and the receiver test value can be calculated using the same function or methodology, i.e., according to the same calculation procedure. If the receiver test value and the transmitter test value are identical, it can be assumed that the calculation and transmission of the data was error-free. If, on the other hand, the receiver test value deviates from the transmitter test value, an error can be detected.The calculation of the receiver test value can be performed relatively easily and with minimal effort. Furthermore, such test values can provide robust detection of random errors (24-1388).
[0030] 8 or unintentional data changes and thus enable appropriate protection.
[0031] In another possible embodiment of the present invention, the transmitter sends a keep-alive signal or keep-alive data to the receiver at predetermined intervals, regardless of whether new user data (i.e., data not yet transmitted to the receiver) is available. The receiver then detects an error if an expected keep-alive signal from the transmitter is not received. Thus, the receiver can, for example, detect a complete failure of the transmitter if no data or signals are received from it. Similarly, an error can be detected, for example, in the case of a temporary interruption of the data connection, such as when an expected keep-alive signal is skipped.The latter can mean, for example, that a keepalive signal received by the receiver, originating from the transmitter, is increased or modified by two units compared to the last received keepalive signal, even though an increase or modification of one unit is predetermined for each of two consecutive keepalive signals. The embodiment of the present invention proposed here allows for protection against a wider range of possible error scenarios.
[0032] In a further possible embodiment of the present invention, a predefined error response is executed or initiated when an error is detected in or by the receiver. An error can be detected at least when the test value does not match the usage data or when an expected signal from the transmitter is missing, i.e., not received by the receiver. Depending on the application, different error responses can be predefined. For example, the detected error can simply be logged as an error response. Similarly, an error response can be, for example, a request for retransmission of the data, i.e., sent from the receiver to the transmitter.Similarly, as a fault response, for example, a function affected by the fault or dependent on the affected user data, such as in a motor vehicle in which the method according to the invention is applied, can be deactivated. Likewise, as a fault response, a warning can be issued to a user or the issuance of such a warning can be initiated. (See 24-1388.)
[0033] 9. Several different possible error responses can also be predefined, whereby the specific error response executed or initiated can then be automatically selected depending on the detected error or its type. Automatic execution or initiation of a predefined error response enables needs-based error handling. Depending on the application, this can, for example, improve robustness, reliability, or safety, and / or allow for the improvement or further development of a given system.
[0034] In a further possible embodiment of the present invention, the user data received as part of the overall data set is only processed further in or by the receiving device if no error is detected in or by the receiving device. For example, a predefined calculation can then be performed using the user data, or a control operation can be carried out or initiated according to the user data, or the user data can be forwarded from the receiving device or a receiving and testing module of the receiving device, for example to a calculation module of the receiving device or the like. Conversely, if an error is detected, the further use of the received user data can be stopped or omitted.The proposed embodiment of the present invention prevents the propagation of errors, for example, into subsequent calculations or control processes. This avoids unforeseen consequences, which, depending on the application, can improve robustness, reliability, or safety.
[0035] The present invention also relates to a transmitter device configured for use as a transmitter in the method according to the invention. The transmitter device according to the invention comprises a primary module, a secondary module, a combination module, and an output interface. The primary module is configured to process input data into respective user data and to output the user data to the combination module. The secondary module is configured to process the input data into respective user data, to calculate a test value for the user data, and to output the test value to the combination module. The combination module is configured to combine the user data output by the primary module and the test value output by the secondary module to produce the desired result.
[0036] 10 or in a respective complete data set and configured to send the respective complete data set via the output interface to a receiver device. The transmitter device according to the invention can, in particular, be the transmitter device mentioned in connection with the method according to the invention or correspond to it. For this purpose, the transmitter device can include corresponding computing hardware, for example, microchips or microprocessors or microcontrollers or the like, and computer-readable data storage devices coupled thereto. Corresponding operating or computer programs can then be stored in these data storage devices, which encode or implement the process steps, measures, or sequences described in connection with the method according to the invention or corresponding control instructions and can be executed by means of the process device in order to carry out the corresponding method overall or to effect its execution.Similarly, the transmitter may, for example, have an input interface for acquiring or receiving the respective input data. The input and output interfaces may be separate or combined or integrated in a common bidirectional interface. The transmitter may be specifically designed for a motor vehicle and thus configured accordingly. For example, the transmitter may be or include an engine control unit, a battery control unit, a cell supervision circuit (CSC), a sensor, or the like. Likewise, a variety of other configurations or applications are possible.
[0037] The present invention also relates to a motor vehicle comprising at least one transmitter device according to the invention and at least one receiver device connected thereto via at least one data connection. According to the invention, the motor vehicle is equipped for the execution of the method according to the invention, in particular automatically. The motor vehicle according to the invention may, in particular, be the motor vehicle mentioned in connection with the method according to the invention and / or in connection with the transmitter device according to the invention, or correspond to it.
[0038] In one possible embodiment of the present invention, the transmitter and receiver are connected to the receiver only via a single data connection for the transmission of data signals, i.e., for example, the total data sets associated with the method according to the invention, from the transmitter to the receiver 24-1388
[0039] 11 interconnected. Such a data connection can be, for example, a data line, a data cable, or a wireless data connection. Depending on the configuration, it may also be possible to transmit data signals, i.e., data and / or signals, from the receiver to the transmitter, either via the same data connection or a different one. The configuration proposed here of the present invention, by using only one data connection from the transmitter to the receiver—thus eliminating the need for a second or redundant data connection—enables a particularly simple, cost-effective, and robust vehicle design.
[0040] Further features of the invention may become apparent from the claims, the figures, and the description of the figures. The features and combinations of features mentioned above in the description, as well as the features and combinations of features shown below in the description of the figures and / or in the figures themselves, can be used not only in the combinations specified, but also in other combinations or on their own, without departing from the scope of the invention.
[0041] The drawing shows in:
[0042] Fig. 1 shows a partial schematic representation of a motor vehicle equipped for secure data transmission between two control units; and
[0043] Fig. 2 is a schematic representation to further illustrate the secure data transmission.
[0044] In the figures, identical and functionally equivalent elements are provided with the same reference symbols.
[0045] Currently, vehicle communication systems often use two paths for safety-relevant functions to create redundancy. Such redundancy may be necessary to achieve a required ASIL (Automatic Safety Integrity Level). For example, if the result of a redundant calculation is to be sent to another control unit, end-to-end (E2E) protection of the transmission or a transmitted message can be implemented. In this approach, the message can be calculated in both a primary path and a redundant path, and E2E protection measures can be performed independently to ensure data integrity. The calculated and verified messages can then each be forwarded to a comparator that checks the consistency of both messages.However, typically only the main path is responsible for actually sending the verified message to the other control unit via a communication channel. In case of a calculation error, the comparator can inform the other control unit that an error has occurred via a second logical communication channel. This duplicated calculation and verification strategy can increase transmission security and reliability, which can be particularly important in safety-critical applications. However, this also entails considerable complexity, arising in particular from the use of a comparator and the need for a second communication channel.
[0046] However, at least for certain applications, some of this complexity can initially be reduced. To illustrate this, Fig. 1 shows a partial schematic representation of a motor vehicle 1. The components of this motor vehicle 1 are schematically represented here as a data source 2, a transmitter 3, a receiver 4, and a vehicle control unit 5. The data source 2 can be, for example, a sensor, a control unit, or the like, and sends data signals to the transmitter 3. From the transmitter 3's perspective, this data is input, which the transmitter 3 can receive and process. The corresponding processing result can then be sent from the transmitter 3 to the receiver 4. Based on this, the receiver 4 can then, for example, control the vehicle control unit 5 or, in turn, send its own processing results to the vehicle control unit 5.
[0047] The primary focus here is on the processing of input data in and from the transmitter 3, the data transmission from the transmitter 3 to the receiver 4, and further data processing in and from the receiver 4. In this sense, the main concern is improved data transmission between the transmitter 3 and the receiver 4, which could, for example, be control units. 13
[0048] The transmitter 3 is schematically represented here by a transmitter input interface 6, through which the transmitter 3 can receive the input data from the data source 2, a primary module 7, a secondary module 8, a combination module 9, and a transmitter output interface 10. The primary module 7 and the secondary module 8 can process the respective input data in parallel and independently of each other and each output corresponding processing results to the combination module 9. The combination module 9 can combine the processing results output by the primary module 7 and the secondary module 8 and send a corresponding combined data set to the receiver 4 via the transmitter output interface 10.
[0049] The receiver device 4 is schematically represented here by a receiver input interface 11, a processor 12, a computer-readable data storage device 13 coupled to it, and a receiver output interface 14. The receiver device 4 can receive the data set transmitted by the transmitter device 3 via the receiver input interface 11. The receiver device 4 can then process this data set using the processor 12 and the data storage device 13 and, if necessary, output corresponding processing results or control signals, or the like, to the vehicle direction 5 via the receiver output interface 14.
[0050] Figure 2 shows a schematic representation to further illustrate the functionality and data processing. It depicts that the primary module 7 outputs a primary data set 15 to the combination module 9 as a processing result, containing primary metadata 16 and primary user data 17. The primary metadata 16 can, for example, be or include identification data and / or keepalive data. The primary user data 17 can be calculated by the primary module 7 from the input data.
[0051] In parallel, the secondary module 8 can also process the input data and output a secondary data record 18 to the combination module 9 as a processing result. This secondary data record 18 contains secondary metadata 19 and a check value 20. Analogous to the primary metadata 16, the secondary metadata 19 can be used to identify the source of the respective data record, in this case, the secondary module 8, and / or to indicate the ongoing activity of the respective module, in this case, the secondary module 8, or the data connection between the respective module and the combination module 9.
[0052] Secondary module 8 can be configured or designated to calculate the same user data as primary module 7, based on the respective input data. However, secondary module 8 additionally calculates the test value 20 for the user data and outputs it as part of secondary data set 18. In particular, unlike primary data set 15, secondary data set 18 does not contain any user data.
[0053] The combination module 9 combines the primary data set 15 and the secondary data set 18 into a combined data set 21. This combined data set 21 can contain or include sender metadata 22, the check value 20, and the primary payload 17. The sender metadata 22 can, for example, identify the combined data set 21 as originating from the sender device 3 and / or be or include keepalive data for the data link between the sender device 3 and the receiver device 4. When combining the primary data sets 15 and secondary data sets 18, the combination module 9 can take into account the primary metadata 16 and secondary metadata 19 contained therein to ensure correct assignment. This ensures that the check value 20 integrated into the respective combined data set 21 is calculated for payload data that was calculated from the same input data as the primary payload 17 ultimately integrated into the same combined data set 21.
[0054] The receiver 4 can, in turn, receive the complete data set 21 and, analogous to the test value 20, calculate a receiver test value for the primary user data 17 contained therein and compare this with the test value 20 contained in the respective complete data set 21 in order to detect any errors. Depending on the result of the comparison, the receiver 4 can then, for example, control the vehicle equipment 5 or execute or initiate a predefined error response.
[0055] Primary module 7 can represent a main path that outputs the payload without a checksum, while secondary module 8 can represent a redundant path that outputs the checksum 20 but no payload. A merging process performed in or by combination module 9 can be 24-1388
[0056] 15. Both the primary data set 15 and the secondary data set 18 are combined into a secure message in the form of the complete data set 21. Based on this, errors can be detected in the receiving device 4 without an additional communication channel or additional logic. This reduces system complexity and ensures efficient error detection.
[0057] It can be assumed here that the calculation of the user data, as well as the calculation or provision of the input data, takes place in a secure environment. Combination module 9, on the other hand, can represent a non-safety-critical quality level, for which, for example, only ASIL QM might be required.
[0058] Overall, the described examples show how efficient and fault-tolerant sending of E2E-secured messages can be implemented from a redundantly calculated ASIL function.
[0059] 24-1388
[0060] 16
[0061] Reference symbol list
[0062] 1 motor vehicle
[0063] 2 Data source
[0064] 3 transmitters
[0065] 4 Receiver device
[0066] 5 Vehicle equipment
[0067] 6 Transmitter input interface
[0068] 7 Primary Module
[0069] 8 Secondary Module
[0070] 9 Combination module
[0071] 10 Transmitter output interface
[0072] 11 Receiver input interface
[0073] 12 processor
[0074] 13 Data storage
[0075] 14 Receiver output interface
[0076] 15 Primary data set
[0077] 16 Primary Metadata
[0078] 17 Primary user data
[0079] 18 Secondary data set
[0080] 19 Secondary Metadata
[0081] 20 test value
[0082] 21 Total data set
[0083] 22 Transmitter metadata
Claims
24-1388 17 Patent claims 1. Method for securing a transmission of user data (17) from a sending device (3) to a receiving device (4), wherein automatically - within the transmitter (3) the user data (17) to be transmitted is calculated from input data once by a primary module (7) of the transmitter (3) and in parallel a second time by a secondary module (8), - a test value (20) is calculated by the secondary module (8) for the user data calculated by the secondary module (8) according to a predefined method, - within the transmitter (3) the user data (17) calculated by the primary module (7) and the test value (20) calculated by the secondary module (8) are combined together in a total data set (21), - the complete data set (21) is sent from the sender device (3) to the receiver device (4) via a data connection, - in the receiver device (4) it is checked whether the check value (20) contained in the received total data set (21) matches the user data (17) contained in the received total data set (21) and if this is not the case, an error is detected.
2. Method according to claim 1, characterized in that the test value (20) is calculated only by the secondary module (8) and the primary module (7) does not calculate a test value.
3. Method according to one of the preceding claims, characterized in that the primary module (7) and the secondary module (8) also output respective identification data (16, 19) which identify the respective output data (15, 18) and / or a respective data source (7, 8), and / or predefined keepalive signals (16, 19) and these are taken into account for combining the user data (17) output by the primary module (7) with the associated test value (20) output by the secondary module (8). 24-1388 18 4. Method according to one of the preceding claims, characterized in that, in order to check whether the test value (20) matches the user data (17), a test value is calculated by the receiver device (4) for the user data (17) contained in the received total data set (21) and compared with the test value (20) contained in the received total data set (21).
5. Method according to one of the preceding claims, characterized in that the transmitter (3) sends a keepalive signal (22) to the receiver (4) at predetermined regularity, irrespective of the availability of new user data (17), and the receiver (4) detects an error if an expected keepalive signal (22) from the transmitter (3) is not received.
6. Method according to one of the preceding claims, characterized in that when an error is detected by the receiver device (4), a predetermined error response is initiated.
7. Method according to one of the preceding claims, characterized in that only if no error is detected by the receiver device (4), the user data (17) received as part of the total data set (21) is further processed by the receiver device (4) in a predetermined manner.
8. Transmitter device (3), in particular for a motor vehicle (1), which is configured for use as a transmitter device (3) in the method according to one of claims 1 to 7 and which for this purpose has a primary module (7), a secondary module (8), a combination module (9) and an output interface (10), wherein - the primary module (7) for processing input data to respective user data (17) and is set up to output the user data (17) to the combination module (9), 24-1388 19 - the secondary module (8) is set up to process the input data into respective user data, to calculate a test value (20) for this user data and to output the test value (20) to the combination module (9), - the combination module (9) is set up to combine the user data (17) output by the primary module (7) and the test value (20) output by the secondary module (8) into a respective total data set (21) and to send the respective total data set (21) via the output interface (10) to a receiver device (4).
9. Motor vehicle (1) comprising a transmitter (3) according to claim 8 and at least one receiver (4) connected thereto via a data connection, wherein the motor vehicle (1) is equipped to carry out the method according to one of claims 1 to 7.
10. Motor vehicle (1) according to claim 9, characterized in that the transmitter (3) and the receiver (4) are connected to each other only via a single data connection for transmitting data signals from the transmitter (3) to the receiver (4).
Citation Information
Patent Citations
Fault processing method, device and apparatus and automobile
CN113341906A
E2E verification method and device for CAN bus message
CN115085867A
Rotor magnetic steel mounting tool
CN216122138U
Test interconnect for semiconductor components having bumped and planar contacts
US6222280B1
System and procedure for data transmission
DE102021127310A1