Ethernet Sensor Timestamp Validation via Transit Time Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current automotive Ethernet systems lack effective mechanisms to validate timestamps, which is crucial for reliable sensor data fusion and synchronization, especially in safety-critical applications like ADAS, where incorrect timestamps can lead to data loss and operational safety issues.
Innovation Solution
A method is introduced to determine the transit time, maximum speed, and type of transmission medium of signal paths within the Ethernet on-board network, allowing for the detection of timestamp validity and potential attacks, using existing IEEE 802.1AS and PTP protocols without requiring additional hardware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If time synchronization is implemented using IEEE 802.1AS and PTP protocols in automotive Ethernet networks, then synchronization accuracy is improved, but the system becomes vulnerable to timestamp manipulation attacks and lacks timestamp validity detection capability
Solution Approach 1:
The patent performs preliminary validation of timestamp validity by checking whether the time difference between synchronized clocks falls within an expected range before using the synchronized time for critical operations. This preliminary check prevents manipulation attacks by rejecting timestamps that show unrealistic time deviations, thus resolving the contradiction between achieving synchronization accuracy and ensuring timestamp reliability.
2Reliability
If additional hardware or proprietary protocols are deployed to detect timestamp manipulation, then security is improved, but device complexity and cost increase
Solution Approach 1:
The patent enables existing Ethernet network devices to perform self-validation of timestamp authenticity using standard IEEE 802.1AS and PTP protocols already deployed in the network. Each device independently checks whether received timestamps fall within expected time ranges based on its local clock and synchronization interval, eliminating the need for additional security hardware or proprietary protocols while maintaining high security standards.
3Reliability
If comprehensive timestamp validation and attack detection mechanisms are implemented, then data fusion reliability is improved, but processing load on network devices increases
Solution Approach 1:
The patent implements a lightweight validation mechanism that performs only the essential check of whether timestamp differences fall within a predefined acceptable range. This partial validation approach provides sufficient protection against manipulation attacks and ensures data fusion reliability without implementing overly complex validation algorithms, thus maintaining low processing load on network devices while achieving the desired level of security and reliability.
Data Source
Figure 1a~1b
Figure 2
Figure 3
AI summary
The invention relates to a method for verifying the validity of sensor data of an Ethernet on-board network of a motor vehicle, in which method the following steps are carried out: - determining a runtime of a first signal on a first connection path between a first control unit of the Ethernet on-board network and a second control unit of the Ethernet on-board network; - determining a maximum velocity of the first connection path on the basis of the runtime; and - determining a type of transmission medium of the first connection path (6) on the basis of the maximum velocity, wherein the following steps are carried out: identifying at least one first control unit of the Ethernet on-board network, synchronizing at least one first control unit of the Ethernet on-board network, determining the synchronization interval, determining a drift of a timer of the first control unit, determining a time stamp of the first control unit, outputting a time stamp or querying the time of the first control unit, comparing the time stamp to a reference clock of the Ethernet on-board network, carrying out a runtime measurement, determining the velocity of the associated clock generator, determining the time difference of the synchronization interval, determining the last synchronization.