Vehicle Network Time Sync Validation with Central Validator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing time synchronization methods in communication networks of automated vehicles do not adequately ensure compliance with predefined safety integrity levels, such as ASIL B or higher, which is crucial for safe operation of vehicles at SAE Levels 3, 4, and 5.

Innovation Solution

A method involving a master clock sending synchronization messages to control units and central validators, with local time synchronization and comparison across different communication networks, and error messaging if time differences exceed predefined thresholds, ensuring synchronization integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If time synchronization is performed using standard protocols (IEEE 802.1AS or IEEE 1588) in communication networks of automated vehicles, then time synchronization functionality is achieved, but the integrity and safety compliance (ASIL B or higher) of the synchronization process cannot be ensured

Engineering Contradiction:
Improvesafety integrity level complianceVSAvoidsynchronization validation system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A central validator is introduced as an intermediary component that receives synchronized local times from multiple control units and validates them against safety criteria. This mediator ensures ASIL B or higher compliance by independently verifying time synchronization integrity without requiring changes to the existing IEEE 802.1AS or IEEE 1588 protocols, thus resolving the contradiction between maintaining standard compatibility and achieving safety certification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a feedback mechanism where control units send their synchronized local times to the central validator, which then validates these times and can trigger error messages or alarms if validation fails. This closed-loop feedback ensures continuous monitoring and verification of time synchronization integrity, maintaining ASIL B or higher safety levels while using established synchronization protocols.

Inventive Principle:
Principle #23Feedback

2Reliability

If multiple communication busses are used to ensure safety requirements for autonomous driving functions, then functional safety is improved, but time synchronization validation across different networks becomes insufficient

Engineering Contradiction:
Improvefunctional safetyVSAvoidtime synchronization validation accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The central validator is designed with multi-functionality to handle time synchronization validation across multiple different communication networks and standards (e.g., Ethernet, CAN, FlexRay). It can receive and validate synchronized local times from control units belonging to different communication busses, ensuring consistent time synchronization validation and ASIL B or higher compliance across the entire multi-network automotive system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If time synchronization is implemented across multiple control units in automated vehicles, then coordinated operation is achieved, but validation of synchronization integrity across different communication standards is lacking

Engineering Contradiction:
Improvecoordinated operation efficiencyVSAvoidsynchronization integrity validation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements a feedback mechanism where control units send their synchronized local times to the central validator, which then validates these times and can trigger error messages or alarms if validation fails. This closed-loop feedback ensures continuous monitoring and verification of time synchronization integrity, maintaining ASIL B or higher safety levels while using established synchronization protocols.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

A central validator is introduced as an intermediary component that receives synchronized local times from multiple control units and validates them against safety criteria. This mediator ensures ASIL B or higher compliance by independently verifying time synchronization integrity without requiring changes to the existing IEEE 802.1AS or IEEE 1588 protocols, thus resolving the contradiction between maintaining standard compatibility and achieving safety certification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4324123B1Validation of time synchronization
Publication Date: 2025.12.03 BAYERISCHE MOTOREN WERKE AG
  • EP4324123B1 patent drawingFigure 1
  • EP4324123B1 patent drawingFigure 2

AI summary

Provided is a method for validating a time synchronization in a communication network of an automated vehicle. The communication network comprises a master clock, and a first communication network of a first communication standard. The first communication network comprises at least two control units and a central validator. The method comprises sending a time synchronization message from the master clock to the two control units of the first communication network, respectively, wherein the time synchronization message includes a master time; synchronizing a local time of the two control units of the first communication network to the received master time, respectively; sending the synchronized local times of the two control units of the first communication network to the central validator of the first communication network, respectively; comparing, at the central validator of the first communication network, the received synchronized local times of the two control units of the first communication network to each other; and, if a difference between the received synchronized local times is bigger than a predefined first threshold, outputting an error message from the central validator of the first communication network to the automated vehicle.