Dual Master Clock Synchronization for In-Vehicle Network Fault Tolerance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In in-vehicle time- and safety-critical networks, establishing a common time base is challenging due to differing clock characteristics among communicating devices, leading to intolerable clock deviations that can cause dangerous vehicle behavior, especially in autonomous or semi-automated driving applications.

Innovation Solution

An enhanced fault-tolerant clock synchronization mechanism using two master clocks that operate simultaneously, where the second master clock is independent of the first and does not receive failure information, allowing for reduced recovery time and improved fault tolerance by exchanging synchronization messages to maintain clock accuracy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single master clock is used for time synchronization in an in-vehicle network, then the device complexity is reduced, but the reliability deteriorates because the system cannot tolerate clock failures or deviations

Engineering Contradiction:
Improvefault toleranceVSAvoidnumber of master clocks
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the time synchronization function into multiple independent master clocks (first master clock and second master clock) that operate autonomously. Each master clock independently provides time synchronization to slave devices, eliminating the single point of failure and improving fault tolerance without requiring complex inter-master coordination protocols.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each master clock maintains independent local timekeeping characteristics and operates autonomously without being influenced by the other master clock. This local independence allows each master to provide reliable time synchronization even when the other fails, while the overall system benefits from having multiple independent time sources.

Inventive Principle:
Principle #3Local quality

2Reliability

If the second master clock monitors failure information from the first master clock, then the clock synchronization reliability improves through failover capability, but the recovery time increases due to synchronization checks required before resuming operation

Engineering Contradiction:
Improvefailover capabilityVSAvoidrecovery time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The second master clock is pre-configured and maintains readiness to provide time synchronization without waiting for failure confirmation or performing synchronization checks with the first master clock. This preliminary preparation enables immediate failover when the first master clock fails, minimizing recovery time while maintaining reliability through the standby capability.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If multiple master clocks operate simultaneously without inter-synchronization, then the recovery time is reduced and fault tolerance is improved, but the manufacturing precision of time synchronization deteriorates due to potential clock deviations

Engineering Contradiction:
Improverecovery speedVSAvoidtime synchronization accuracy
Core Design Contradiction:
ProductivityVSManufacturing precision

Solution Approach 1:

The system uses multiple independent master clocks that can be quickly replaced or taken offline if they deviate from accurate timekeeping. Each master clock operates independently without expensive complex synchronization mechanisms between masters, and slave devices can switch between masters based on their operational status, achieving fast recovery and fault tolerance with acceptable time synchronization accuracy.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentEP3206315B1Clock synchronization monitoring in an ethernet-based network
Publication Date: 2021.08.25 ROBERT BOSCH GMBH
  • EP3206315B1 patent drawingFigure 1~2
  • EP3206315B1 patent drawingFigure 3
  • EP3206315B1 patent drawingFigure 4

AI summary

Method and corresponding system for clock synchronization in a network (100), the method comprises the steps of - sending, by a first clock master (101), a first message (203, 610) addressed to at least one clock slave node (111, 112, 113, 114, 141, 142, 143, 144) in the network (100); - sending, by a second clock master (102) a second message (204, 620) addressed to the at least one clock slave node (111, 112, 113, 114, 141, 142, 143, 144) in the network (100); wherein the first message (203, 610) and the second message (204, 620) contain synchronized time information for synchronizing a clock of the at least one clock slave node (111, 112, 113, 114, 141, 142, 143, 144).