Ethernet Device Physical Layer Safety Features
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing automotive ethernet connectivity systems face challenges in ensuring reliable communication links for safety-critical applications, as they fail to detect and handle faults within a low fault detection time interval and cannot differentiate between random and intentional errors, leading to potential data loss and communication failures.
Innovation Solution
An ethernet device with safety features at the physical layer, comprising dual PCS/PMA units and media independent interface switches, which detects safety problems in one ethernet channel and reroutes safety-critical data to a redundant channel, ensuring continuous communication by switching between two independent ethernet channels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If end-to-end protection is provided on the application layer with checksum verification, then data integrity can be detected, but the receiving node cannot determine the cause of corruption and safety mechanisms for event-based messages are not possible
Solution Approach 1:
The patent applies preliminary action by generating and attaching a cyclic redundancy check (CRC) value to each Ethernet frame at the physical layer before transmission. This allows the receiving node to verify data integrity immediately upon receipt by recalculating the CRC and comparing it with the transmitted value, enabling rapid detection of corruption without complex application-layer verification.
Solution Approach 2:
The patent introduces an intermediary mechanism by using a dedicated CRC calculation and verification process at the physical layer. This intermediary layer provides a simple, standardized method for detecting data corruption that works independently of the application layer, enabling safety mechanisms for event-based messages while maintaining compatibility with standard Ethernet protocols.
2Reliability
If connected transport protocols like TCP are used for data protection, then message acknowledge and resend features are available, but connection establishment is complex and message resends can lead to bus congestion
Solution Approach 1:
The patent extracts the reliability verification function from the transport layer and implements it at the physical layer using CRC checks. This removes the need for complex connection establishment protocols, message acknowledgments, and retry mechanisms, thereby eliminating bus congestion risks while maintaining data integrity verification.
3Device complexity
If a single ethernet channel is used for safety-critical data transfer, then communication is simple, but any fault in the channel causes communication failure
Solution Approach 1:
The patent applies preliminary action by implementing a health check mechanism that continuously monitors the Ethernet channel status before and during data transmission. The system detects faults such as link loss, signal quality degradation, or errors in received frames and switches to a backup channel proactively, ensuring continuous reliable communication without complex reconfiguration.
4Loss of time
If fault detection time interval is reduced for safety-critical applications, then safety is improved, but the system cannot differentiate between random and intentional errors
Solution Approach 1:
The patent implements feedback by continuously monitoring multiple error indicators including CRC errors, frame alignment errors, and signal quality metrics. By analyzing the pattern and frequency of these errors over time, the system can differentiate between random transient errors and systematic intentional errors, enabling rapid fault detection while maintaining measurement precision for error classification.
Data Source
AI summary
An ethernet device with safety features at the physical layer and a method for a bi-directional data transfer between two ethernet devices, includes at least one of two ethernet devices with safety features at the physical layer. The ethernet device can switch safety critical traffic from a first ethernet channel to a second ethernet channel if a safety problem has been detected for the first ethernet channel.


