EP4635150A1 - Method for monitoring a communication connection between two network nodes that are directly connected to one another - Google Patents
Method for monitoring a communication connection between two network nodes that are directly connected to one anotherInfo
- Publication number
- EP4635150A1 EP4635150A1 EP23828345.1A EP23828345A EP4635150A1 EP 4635150 A1 EP4635150 A1 EP 4635150A1 EP 23828345 A EP23828345 A EP 23828345A EP 4635150 A1 EP4635150 A1 EP 4635150A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- signal propagation
- propagation time
- delay
- message
- value
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
- H04L43/50—Testing arrangements
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
- H04L43/08—Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
- H04L43/0852—Delays
- H04L43/0858—One way delays
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
- H04L43/10—Active monitoring, e.g. heartbeat, ping or trace-route
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
- H04L43/10—Active monitoring, e.g. heartbeat, ping or trace-route
- H04L43/106—Active monitoring, e.g. heartbeat, ping or trace-route using time related information in packets, e.g. by adding timestamps
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
- H04L43/16—Threshold monitoring
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/12—Discovery or management of network topologies
Definitions
- the present invention relates to communication networks with network nodes that are synchronized with one another in time.
- the invention relates to a method for monitoring an Ethernet-based communication network, for example a communication network in a motor vehicle, and a network node set up to carry out the method, for example in the form of a control unit.
- the method can be used, among other things, to monitor for errors in the communication network and/or for changes in the network topology. For this purpose, monitoring of a direct communication connection between two network nodes, for example designed as electronic control units, is provided.
- Ethernet-based communication is based on the so-called OSI layer model, in which each layer is assigned certain tasks that must be performed by the entities (devices and software) of the respective layer for the communication to function.
- OSI layer model in which each layer is assigned certain tasks that must be performed by the entities (devices and software) of the respective layer for the communication to function.
- Each instance of a layer provides services in accordance with the standardized network protocol that an entity above it can use without having to worry about how and with what technical means the entity below it solves its tasks. Corresponding interfaces are defined between the various layers.
- Fig. 1 schematically shows the known Ethernet-based communication, which is also used in the present invention, between two network nodes 1, 2 of a wired communication network 3, which are designed as control units, for example, and which operates in a network protocol according to the OSI layer model with a total of 7 layers I to VII.
- the tasks to be performed by the individual layers are implemented in computing units of the network nodes 1, 2 (not shown separately) and are shown schematically in Fig. 1.
- Layer I Physical Layer
- Layer II Data Link Layer
- Layer III Network Layer
- Layer IV Transport Layer
- Layer V Session Layer
- Layer VI Presentation Layer
- Layer VII Application Layer.
- Layers III to VII are used to prepare the physically transmitted data and assign it to special applications that access the transmitted data via the Application layer (layer VII). These layers are of an organizational nature and have nothing to do with the physical transmission of data or data packets. Since these layers are not affected by the present invention, a description of the content of these layers known to the person skilled in the art is omitted.
- Layer I PHY - Physical Layer
- Layer I directly contains the tools for activating or deactivating the physical connection. This includes in particular devices and network components such as amplifiers, plugs, sockets for the network cable, repeaters, hubs, transceivers and the like.
- This layer I is therefore used to physically address the transmission channel using suitable electrical, optical, electromagnetic or sound signals; in the case of wired Ethernet communication networks, these are usually electrical or electromagnetic signals.
- the network interfaces required for physical communication are assigned to each network node and form layer I according to the OSI layer model.
- Layer II of the OSI layer model is used to organize and control a largely error-free transmission and to regulate access to the transmission medium. This also includes data flow control between sender and receiver.
- the data link layer is often divided into a media access control MAC (Medium Access Control) and a logical link control LLC (Logical Link Control).
- the media access control MAC regulates how several computers share the shared physical transmission medium. To do this, it uses, among other things, the so-called MAC addresses of the communication participants, which are assigned to each network node as a participant in the communication network 3 as a unique identification.
- the media access control MAC is managed by the logical link control LLC, which distributes incoming data in each transmission direction and coordinates access to the higher-level layers of the network control.
- the tasks of the media access control MAC and the logical link control LLC define the so-called data link layer. (Layer II) is formed in which the various network participants can be identified in order to organize the network communication in a regulated manner.
- This logical management is schematically integrated in Fig. 1 between the network nodes 1 and 2 in the line of the communication network 3 representing the physical connection.
- the only control of the network nodes 1, 2 as participants in the communication network is therefore in the security view (layer II), for example through the unique MAC addresses for identifying the individual network participants, which is necessary for media access control.
- layer II the security view
- a network node 1, 2 has no knowledge of the other network nodes 2, 1 in the communication network 3, but only controls the physical communication at its interface to the communication network 3.
- a large number of systems that are communicatively connected to one another via Ethernet connections can place particularly high demands on the reliability of the transmission and the temporal coordination of data packets.
- safety-critical applications in vehicles e.g. the transmission of sensor and control information for driver assistance systems or autonomous driving, place high demands on the temporal coordination of data packets.
- Even relatively small changes in signal propagation times can lead to a change in system behavior, e.g. because signals that are to be processed together or that must be present in a certain, closely coordinated time frame with other signals no longer match one another due to the change in signal propagation time. If the system behavior changes or is unpredictable, the reliability of the system can no longer be guaranteed.
- time-synchronized network nodes will continue to increase in the future, partly because an increasing number of control units transmit sensor data from different sensors that are used to provide safety and Comfort functions are linked and evaluated.
- a particularly important aspect of the fusion of sensor data is the temporal coherence of the sensor data. Depending on the application, it may be necessary to fuse sensor data that belong together to within milliseconds or microseconds, while in other applications a larger time interval between the recording times may be permissible. It is also conceivable that the recording times must belong together exactly in the range of nanoseconds.
- data that was recorded when monitoring the operation of the vehicle and is only used for maintenance purposes or to document that the vehicle is operating correctly and in accordance with the regulations may also be subject to strict requirements for their correct recording and storage at the correct time.
- Time synchronization of network nodes within an Ethernet network can be carried out using appropriate protocols so that a globally valid time base is available within the network.
- Time synchronization in Ethernet networks is, for example, agreed in the IEEE 802.1 AS standard, which uses the Precision Time Protocol (PTP).
- PTP Precision Time Protocol
- PTP defines a master-slave clock hierarchy with a best clock within a network, also known as the grandmaster clock.
- the time base of the other network nodes in this network is derived from this best clock, the grandmaster, which is determined using the Best Master Clock Algorithm (BMCA).
- BMCA Best Master Clock Algorithm
- Time synchronization messages are distributed across the network from the grandmaster.
- PTP also defines a mechanism for measuring the signal propagation time on a connection, as well as a method for exchanging time information.
- IEEE 802.1AS-capable network nodes cyclically send Announce messages with information about their internal clock to other directly connected network nodes.
- the information about the internal clocks provides information about the accuracy of the respective clock, its reference or time reference, and other properties that can be used to determine the best clock in the network.
- Such an Announce message is shown in Figure 2 a). shown as an example.
- a recipient of such an announce message compares the information received with the characteristics of its own internal clock and possibly messages already received from another port with information on clocks at other network nodes, and accepts a clock in another network node if it has better clock parameters.
- Each port of a network node is assigned one of four port states.
- the master port state is assigned to the port that has a shorter path to the grandmaster than its link partner.
- the slave state is assigned if no other port on this node has this state. Disabled is selected by the port that cannot fully support the PTP protocol.
- the passive state is selected if none of the other three states apply.
- the generalized Precision Time Protocol In a variant of PTP, the generalized Precision Time Protocol (gPTP), two network nodes always communicate directly with each other for time synchronization, and neither of the two network nodes simply forwards a received time synchronization message to another network node in the network. Instead, the network node corrects the time information before forwarding it by the previously determined signal propagation time on the connection over which it receives time synchronization messages from a directly connected network node, as well as by the internal processing time before it creates and forwards a new time synchronization message with the corrected time information.
- Network nodes that support gPTP are also known as "time-aware systems".
- the signal runtime on a connection between two network nodes can be determined using the Sync_Follow_Up mechanism, which is shown schematically in Figure 2 b).
- the master ports cyclically send Sync and Follow_Up messages to the neighboring link partner, i.e. their slave ports.
- a time stamp is generated, which is immediately transmitted in a subsequent FollowJJP message. This time stamp corresponds to the current time of the Grandmaster at the time the sync message was sent. From the difference in the reception time of the two messages, the receiver can determine the signal propagation time of the connection, and with this and the time of the Grandmaster Clock transmitted in the sync message, the receiver can then set its clock.
- the so-called “peer delay mechanism” is used to determine the delay between two connected ports independently of time synchronization messages from the grandmaster clock. This is shown as an example in Figure 2 c).
- a port the initiator, starts the measurement of the line delay by sending a Delay_Request message to the port of a network node directly connected to it, the responder.
- a transmission time stamp with the time t1 is generated and inserted into the message so that this transmission time stamp t1 defines the actual transmission time to a good approximation.
- the responder When the message arrives, the responder generates a reception time stamp t2. In response, the responder sends a Delay_Response message to the initiator.
- this message transmits the reception time stamp t2 of the Delay_Request message. If this message leaves the responder, it generates a transmission time stamp t3, which is sent to the initiator in an immediately following Delay_Response_Follow-Up message.
- the initiator receives the Delay_Response message, it generates a reception time stamp t4.
- the initiator can calculate the average runtime on the communication link from the four time stamps t1 to t4. Since the runtime on a connection link can vary depending on the direction, Delay_Request messages are sent independently by both communication partners.
- These measurements can be carried out cyclically, ie at predetermined time intervals of, for example, 100 ms up to several seconds or minutes. Even with a time interval of around one second, the network is not heavily loaded, so that even a measurement at these relatively short time intervals is not a problem for the operation of the network. It may be useful to carry out such signal propagation time measurements between all network nodes 1, 2 of the communication network 3 that are in communication connection with one another, preferably as a direct signal propagation time between two network nodes 1, 2.
- test access point or a switch or bridge is usually inserted into the network connection between the two devices.
- a tap 4 e.g. a TAP
- PHY physical interfaces
- Such a TAP 4 is simply looped into the existing line connection, copies the data information or data packets bit by bit as the data stream passes through, without analyzing their content, and outputs the copied data information via another interface.
- the physical data stream is simply forwarded unchanged.
- the network analyzer 4 therefore does not appear in the communication network 3.
- the Data link layer (layer II of the OSI layer model) of network nodes 1 and 2 have no knowledge of the existence of this network analyzer 4.
- switches or bridges in a connection between network nodes to monitor communication has an even greater impact on communication than a TAP. Even if a switch or bridge, like a TAP, does not have a direct address, it causes a large delay, among other things because of the possibility of storing data before forwarding it, and also takes part in Layer 2 communication.
- a disrupted or failed time synchronization can lead to one or more network nodes switching from the original operating mode to another operating mode, e.g. an error operating mode, and the intended permissible interception of the communication of the original operating mode of the network node or system cannot take place. This may no longer ensure safe operation and also makes troubleshooting considerably more difficult.
- Inserting TAPs or switches or bridges into a network connection can also be done for reasons other than troubleshooting, for example to eavesdrop on communication in the network without authorization and to identify vulnerabilities that can be used to deliberately change the system behavior without authorization.
- This approach can be used in particular in systems that are used in large numbers in identical fashion. An attacker only needs to gain access to one of the systems and, after analyzing and finding a vulnerability, can specifically attack any of the other systems.
- a static communication network e.g. that of a motor vehicle, in which the network topology does not change unless the network is modified by a permissible or impermissible intervention
- One option that can be used in this context to measure the signal propagation times between network nodes is the method described with reference to Figure 2 c).
- the use of average runtimes determined in a system before any intervention on connections between two network nodes requires that these runtimes are stored in each network node for each direct connection to other network nodes.
- the measurement of the runtimes must be repeated cyclically at intervals that are not too short in order to be able to detect even short-term interventions. This can lead to an increased communication load on the network connection on a cyclic basis, which means that particularly time-critical messages may reach their destination with a delay.
- a first part of this object is achieved according to the invention by a method having the features of claim 1.
- a further part of the object is achieved by the method of claim 8.
- Yet another part is achieved by the network node specified in claim 11. Further developments and embodiments of the method are specified in the respective dependent claims.
- a limit value of a parameter of the direct connection between the two network nodes must first be determined, which is exceeded when the direct connection is intruded upon and which can be used as a reliable indication of the presence of an intrusion.
- One such parameter is, for example, the signal propagation time on the direct connection, since the signal propagation time is increased when a TAP or a switch or a bridge is inserted, as is required for active intrusion into the direct connection.
- This parameter cannot be queried from a network node, nor is it available for retrieval in a database or the like.
- the parameter can be different for each link and each link type.
- the term "direct connection" refers to a direct physical connection between two network nodes, i.e. without any other network nodes in between.
- a method for determining a limit value of the signal propagation time of a direct connection between two network nodes firstly comprises determining the signal propagation time on the direct connection at a time when there is no interference with the direct connection between two directly connected network nodes of a system. This can be done, for example, using the peer-delay-X/ method known from the IEEE 802.1 AS standard, whereby the measurement can be carried out in one or both directions.
- the signal propagation time can also be determined by reading from a database or a configuration memory if the signal propagation time was previously determined and does not change over time. Other methods for determining the signal propagation time are conceivable and known to those skilled in the art.
- a sending time stamp is added or assigned at least in the sender.
- a receiving time stamp can be added or assigned to the first type of message in the receiver.
- the time stamp(s) in the first type of message can be used to check the signal propagation time at the physical level.
- the first type of message can also trigger a response from the receiver, so that a check of the signal propagation time is also possible in the sender of the message.
- the first type of message can be a message from the class of event messages specified in the IEEE 8201 .AS standard, eg also a peer-cfe/ay message.
- the message Before the previously initiated message of the first type provided with the transmission time stamp is sent via the physical layer, it is delayed by a first transmission delay value. Additionally or alternatively, the message can be delayed by a first reception delay value after being received on the physical layer and before the reception time stamp is set. The first reception delay value can be dependent on or independent of the first transmission delay value.
- At least some messages from the event message class specify that if the signal propagation time on the direct connection exceeds a predetermined value, a variable that previously signaled that the signal propagation time on the direct connection was not exceeded is changed.
- the predetermined value is, for example, a value specified in the IEEE 802.1 AS standard via the meanLinkDelayThresh variable.
- the variable is, for example, the asCapableAcrossDomains or asCapable flag from the IEEE 802.1AS standard, which is used during the time synchronization of the system's network nodes and indicates the ability of a network port to perform time synchronization in accordance with the standard.
- the status of the port is communicated, among other things, during time synchronization, so that the change is made known to all other network nodes within a short time due to the cyclical transmission of time synchronization messages.
- the method includes checking whether the signal propagation time has exceeded a predetermined value. This can be done, for example, by comparing the transmission time specified in the transmission time stamp with the synchronized system time of the receiver, by comparing the transmission time with the reception time sent back by the receiver to the transmitter in a response message, by evaluating the asCapableAcrossDomains or asCapable flags of the IEEE 802.1 AS standard, by evaluating the port states or other methods known to those skilled in the art.
- the sending of another message of a first type is initiated via the direct connection, whereby the delay after setting the time stamp and before the actual transmission on the physical layer is increased compared to the previously set value. It is then checked again whether the signal propagation time has exceeded the predetermined value. The initiation and delayed sending is repeated with a delay that is increased compared to the previous sending process until the signal propagation time has exceeded the predetermined value. The last delay value is then output and/or saved as the determined limit value for the direct connection at which the signal propagation time has not yet exceeded the predetermined value. If delay values are set separately for both sending and receiving, the last delay values are saved as the determined limit values. Storage can take place locally or in an external database.
- the determination of the limit between the two directly connected network nodes can be done in both directions.
- the transmission is repeated with the previously set delay for a previously set number of attempts or repetitions. If the signal propagation time has exceeded the predetermined value in all attempts or repetitions in succession, the method proceeds to the next step. If the signal propagation time exceeds the predetermined value before reaching the previously set delay, the transmission is repeated with the previously set delay for a previously set number of attempts or repetitions. If the signal delay falls below the predetermined value after the specified number of attempts or repetitions, this repetition phase is restarted, with the sending and checking taking place with a longer delay than the previously set value.
- a delay value which, due to the smallest deviations occurring in normal operation, leads to the predetermined signal delay time either being exceeded or not being reached can be reliably detected.
- a value which is at the limit can be specifically used or omitted when the limit value for the signal delay time is used later, depending on the application, particularly if the delay can only be set in discrete steps which have a certain minimum size.
- the value or values for the delay can be reduced again and the test for exceeding the signal propagation time can be carried out again. The reduction and test are repeated if necessary until the signal propagation time is below the predetermined value.
- a repetition phase with the previously set delay can be used to check whether the signal propagation time is below the predetermined value in a previously defined number of attempts or repetitions in a row and if necessary the repetition phase can be restarted with a further reduced delay.
- a message of the first type to which a transmission time stamp is added or assigned in the transmitter and/or a reception time stamp in the receiver, can be sent without delay.
- the methods for time synchronization according to The IEEE 802.1AS standard can compensate for the failure of up to two consecutive synchronization messages. Only if three consecutive synchronization messages are missing would the system's time synchronization be disrupted or re-initiated, network nodes would go into error mode or show other effects that result in a change in the operation of the system.
- the delay for delayed sending can be added, for example, by encrypting at least the messages of the first type on the physical layer, i.e. on the physical connection, after setting the time stamp and before the then encrypted data bits are actually transmitted over the communication medium.
- the MACsec mechanism known from IEEE 802.1AE can be used, for example.
- the MACsec mechanism supports a method for securing the integrity of the transmitted data and, on the other hand, encrypting the data.
- the sender appends an 8-byte header and a 16-byte tail, which are checked by the receiver to ensure the integrity of the data.
- a delay which depends among other things on the number of data bits encrypted in each block, occurs before the message is actually transmitted to the receiver.
- the number of bits or octets of the message to be transmitted can be increased considerably, so that the increased amount of data to be transmitted through encryption also leads to an additional delay.
- different delays can be set by using different encryption parameters. For example, the use of GCM-AES-128 encryption can result in a shorter delay than the use of GCM-AES-256 encryption. If only a short delay is required, the method can be used to ensure integrity without encrypting the data.
- any other message can be sent encrypted and/or with additional bytes to ensure integrity. Since in both cases the amount of data to be sent is increased and the corresponding processing may require additional time, the sending of the subsequent message of the first type is delayed accordingly after the send time stamp has been set in the sender's flow control buffer. In the same way, the received message of the first type is stored in the receiver buffer until the message sent before it has been decrypted, so that the use of the MACsec mechanism also delays the setting of the receive time stamp and the signal propagation time visible to the network nodes is extended. Since a response to an encrypted message is also encrypted, the signal propagation time can be significantly extended when the peer delay method described with reference to Figure 2 c) is used.
- the determination of the limit value for the signal propagation time does not have to be repeated at short intervals. In order to take account of the aging of electronic components in the system of network nodes, it is sufficient to repeat the determination of the limit value at longer intervals.
- messages of the first type are initiated cyclically or at irregular intervals, to which the transmission time is added or assigned in the transmitter, for example a transmission time stamp, and/or for which the receiver logs the reception time, for example by means of a reception time stamp.
- the transmission time stamp is added or assigned in the transmitter
- the receiver logs the reception time, for example by means of a reception time stamp.
- the messages of the first type are delayed by a time specified in the previously described The delay is then delayed by a limit value determined by the method or by limit values determined in the previously described method for the signal propagation time on the direct connection.
- the signal propagation time is checked whether the signal propagation time has exceeded a predetermined value. If the signal propagation time has exceeded the predetermined value, the exceedance is signaled. This makes it possible to detect interventions in the direct connection between the two network nodes and to take action accordingly.
- the extension of the signal propagation time set by the delay is expediently selected so that on the one hand the predetermined value of the signal propagation time is reliably not exceeded, but even a small additional extension of the signal propagation time leads to an exceedance.
- the role of the sending and receiving network node can also change repeatedly in this aspect of the invention, since the messages of the first type can be sent cyclically and bidirectionally, i.e. in every direction of communication between the two network nodes. Monitoring is expediently carried out cyclically, i.e. at predetermined or predeterminable time intervals, so that changes can be reliably detected.
- the network node executing the procedure can communicate this to the affected system components at a higher communication level in the OSI layer model. This means that, if necessary after a further check to see if the intervention is permissible, an adjustment can be triggered to enable the system to continue operating without exceeding the predetermined value of the signal propagation time.
- the system or at least one of the network nodes in response to the signaling of the exceedance of the limit value, is put into an error mode in which, for example, safety-relevant functions are carried out in a particularly secure manner or are switched off.
- a network node operating in an error mode can notify other network nodes of the system of its operation in an error mode via the network.
- the delay of at least the messages of the first type can be reduced to a reduced value at which the signal propagation time does not exceed a predetermined value.
- the method according to the first aspect of the invention can optionally be used to determine this reduced value.
- a system behavior can be restored that is no different from the system behavior before the signaling of the exceedance of the limit value.
- a network node comprises one or more processors, volatile and non-volatile memory associated with it or these, and a physical network interface communicatively connected to the one or more processors and set up to send and/or receive data via a communication medium shared by several network nodes.
- the elements of the network node are communicatively connected to one another by means of one or more data lines or buses.
- the non-volatile memory stores computer program instructions which, when executed by the at least one processor, set up the network node to carry out one or more embodiments of the method according to the invention.
- a system in particular a vehicle system, comprises one or more network nodes, each networked via a direct connection.
- at least one of the network nodes is set up to carry out at least one embodiment of the method according to the invention described above.
- a computer program product contains instructions which, when executed by a computer, cause the computer to carry out one or more embodiments and further developments of the method described above.
- the computer program product can be stored on a computer-readable medium or data carrier.
- the medium or data carrier can be physically embodied, for example as a hard disk, CD, DVD, flash memory or the like, but the medium or data carrier can also comprise a modulated electrical, electromagnetic or optical signal that can be received by a computer by means of a corresponding receiver and stored in the computer's memory.
- the methods described above and the network nodes executing the method can advantageously be implemented without changes to existing hardware and can be integrated into existing networks accordingly, since the protocols already used do not have to be changed and the function of the network in normal operation, ie without inadmissible interference with at least one direct connection between two network nodes, is not impaired by inadmissible exceedances of the signal propagation time. Since the integrity of the direct connections is monitored during operation, the operational reliability of systems, e.g. sensor networks and control units that control and execute actions based on sensor data, can be increased, e.g. in vehicles with a high degree of driver assistance or autonomous vehicles. Unauthorized interventions in one or more direct connections between two network nodes can be quickly detected and appropriate measures can be taken more quickly to restore safe operation or to switch to a safe operating mode.
- a signal propagation time map of the communication network can be created in which the time reserves of the respective connections between two network nodes are entered. This information cannot normally be easily queried from a network node, either because no query is implemented for this purpose or the implementation is not disclosed. Nevertheless, the method according to the invention can be used to identify, among other things, connections into which network analyzers or diagnostic devices can be looped. In the case of such permissible intervention in one or more direct connections between two network nodes, a signal propagation time increased by the intervention, which is then above a predetermined value, can be brought back into a range that is below the predetermined value by reducing the delay at the transmitter and/or receiver accordingly.
- the method described above and the network nodes executing the method can be used platform-independently and therefore flexibly due to the simple and lean implementation and the use of resources already available in standards.
- the type of monitoring proposed in accordance with the invention also helps to eliminate additional complex and/or computationally intensive security protocols. This reduces the load on the communications network as a whole.
- Fig. 1 schematically shows the communication process between two network nodes of an Ethernet-based communication network according to the OSI layer model
- Fig. 2 Swim-lane diagrams of exemplary messages used for time synchronization and measurement of signal propagation times
- Fig. 3 schematically shows the physical and logical communication paths between two network nodes before and after the interposition of a TAP
- Fig. 4 is a schematic flow diagram of a method for determining a limit value for the signal propagation time of two directly connected network nodes
- Fig. 5 is an exemplary schematic flow diagram of a method for determining a limit value for the signal propagation time of two directly connected network nodes during operation of a system in a first operating mode, without the operation of the system or the network nodes in the first operating mode being disrupted in an uncorrectable or uncompensable manner when determining the upper limit value of the signal propagation time or one of the network nodes of the system being placed in a second operating mode,
- Fig. 6 shows an exemplary block diagram of a network node with a microprocessor pP and a typical physical Ethernet interface PHY
- Fig. 7 is a schematic flow diagram of a method according to the invention for monitoring the operation of a system with two or more network nodes that are directly connected to each other,
- Fig. 8 is a schematic flow diagram of an exemplary application of an aspect of the invention in a system with two or more network nodes that are directly interconnected, and
- Fig. 9 is an exemplary block diagram of a network node configured to carry out one or more aspects of the method according to the invention.
- FIG 4 shows a schematic flow diagram of a basic method 100 for determining a limit value for the signal propagation time of two directly connected network nodes.
- the signal propagation time is first measured in a first operating mode.
- the first operating mode is, for example, normal operation of the two network nodes in their system context. The measurement can be carried out several times in succession in order to filter out smaller fluctuations or deviations that can occur during normal operation by averaging or the like.
- the sending of a message of a first type from a first of the two network nodes to the second of the two network nodes is initiated.
- step 106 Before the message is actually sent via the communication medium, it is delayed by a delay value in step 106.
- step 108 it is then checked whether the signal propagation time of the message is below a predetermined value despite the delay, so that the message can be processed by the receiving network node without changing an operating mode or an operating parameter of the receiving network node. If this is the case, "yes" branch of step 108, the sending of further messages of the first type is initiated from the first of the two network nodes to the second of the two network nodes, wherein these further messages of the first type are delayed by a delay value that is greater than the respective previous delay value of the previous message.
- a limit value for the signal propagation time is determined, or at least a limited range within which the limit value lies.
- the limit value lies in a range, the lower end of which is determined by the sum of the first in step 102 Signal propagation time and the last set delay value at which the signal propagation time of the message is below a predetermined value despite the delay, so that the message can be processed by the recipient network node without changing an operating mode or an operating parameter of the recipient network node.
- the upper end of the range is marked by the sum of the signal propagation time first determined in step 102 and the delay value at which the signal propagation time of the message is above a predetermined value for the first time due to the delay, so that the message cannot be processed by the recipient network node without changing an operating mode or an operating parameter of the recipient network node.
- the limit value or range determined according to the method described above, or a value selected from this range, can then be stored locally and/or output in step 114.
- Figure 5 shows an exemplary schematic flow diagram of a method 500 for determining a limit value for the signal propagation time of two network nodes that are directly connected to one another during operation of a system in a first operating mode, without the operation of the system or the network nodes in the first operating mode being disrupted in an uncorrectable or uncompensable manner when determining the upper limit value of the signal propagation time or one of the network nodes of the system being put into a second operating mode.
- the method according to the invention uses the knowledge that certain messages of the first type do not lead to a disruption of operation if a predetermined value for the signal propagation time is exceeded by no more than a predetermined number of consecutive messages.
- step 104 the sending of a message of a first type from a first of the two network nodes to the second of the two network nodes. Before the message is actually sent over the communication medium, it is delayed by a delay value in step 106. In step 108, it is then checked whether the signal propagation time of the message is below a predetermined value despite the delay, so that the message can be processed by the receiving network node without changing an operating mode or an operating parameter of the receiving network node.
- step 110 a check is made in step 110 to see whether a longer delay can be set for messages to be sent. If this is possible (“yes” branch of step 110), a longer delay is selected in step 112 and the process is repeated starting with step 104. The setting of a modified delay is indicated by the dashed arrow from step 112 to step 106. If a longer delay cannot be set for messages to be sent (“no” branch of step 110), this greatest possible delay is assumed as the limit value and stored and/or output in step 114.
- step 108 If the test in step 108 shows that the signal propagation time is above the predetermined value (“no” branch of step 108), the signal propagation time of the direct connection is determined for this delay in step 116, and the delay is deactivated again in step 118. Then, in step 120, another message of the first type is sent so that an error counter that may have been incremented previously due to the signal propagation time being exceeded is reset or so that the system can compensate for or correct this exceeding of the signal propagation time in another way. Then, in step 122, a check is made as to whether a reduced delay can be set that is below the last delay set but above a delay set before this. If this is not the case (“no” branch of step 122), the delay value that led to the predetermined value being exceeded is assumed to be the limit value and stored and/or output in step 114.
- step 122 If the check in step 122 shows that a reduced delay can be set, but which is higher than the delay set before last, “yes” - branch of step 122, it is selected in step 112 and the process is repeated starting with step 104.
- Figure 6 shows an example block diagram of a network node 600 with a microprocessor pP and a typical physical Ethernet interface PHY.
- the figure shows in particular at which point within the PHY a transmission time stamp is added or assigned to a message, and at which points the message can subsequently be delayed.
- the microprocessor pP communicates with the PHY via an interface, the implementation of which can be parallel or serial, and which is usually different from the Ethernet transmission medium.
- a media-independent interface Mil Media Independent Interface
- the media-independent interface Mil receives messages from the MAC of the data link level, layer II of the OSI layer model, for transmission via the transmission medium, or forwards received messages to the MAC.
- a message to be sent which was received at the media-independent interface Mil and is essentially available as raw data, is subjected to channel coding in a physical coding sublayer PCS before it is actually sent.
- Channel coding is used to protect digital data against transmission errors when transmitted over faulty channels by adding redundancy.
- Channel coding adds redundancy to the data at the input of a transmission channel and decodes the data at its output. If the additional information only indicates an error and requires the data to be retransmitted, this is referred to as backward error correction. If the redundancy information is sufficient to correct the error, this is forward error correction.
- Efficient channel coding increases the signal-to-noise ratio without changing the bit error rate. Depending on the channel coding method, the code gain can be several dB.
- a small rate, ie, the larger n at the same k means a higher proportion of code symbols in the transmitted symbols, thus a lower data transmission rate.
- a channel code with a lower code rate can correct more errors than a comparable channel code with a high code rate - so a trade-off between data transmission rate and error correction capability is possible.
- Received data is processed accordingly in reverse order by the blocks mentioned above.
- TSU time stamp unit
- the protocols defined in IEEE 802.1AE for confidential and secure data transmission also known as MACsec, make it possible to encrypt or decrypt data before sending or after receiving via the communication medium. Encryption takes place between setting the time stamp and before channel coding, among other things so that the time stamp is also protected by encryption and no conclusions can be drawn from the analysis of time stamps.
- the adjustable delay of the messages required for the method according to the invention after setting the respective time stamp can therefore only take place in one or more of the MACsec, PCS or PMA blocks. Due to the predominantly analog structure of this block, setting a delay in the PMA block does not appear to be possible or only possible to an extremely limited extent, which would not be sufficient for the purposes of the invention.
- setting a delay in the PCS block appears to be entirely possible, for example by selecting a suitable code rate for channel coding, by means of which the amount of data transmitted on the communication medium can be varied, so that a longer transmission time for a data packet of fixed size, i.e. an additional delay, can be achieved simply by the increased amount of data at a small code rate R compared to a large code rate R.
- a particularly suitable block for setting a delay after setting the time stamp and before sending over the communication medium is the MACsec block.
- either the message itself can be encrypted and/or a message of any type sent immediately before the message of the first type can be encrypted. Since the encryption of a message sent before the message of the first type increases its data volume, subsequently sent messages must be delayed accordingly in the flow control buffer of the PHY. Thus, by appropriately selecting the message to be encrypted, if necessary its length, and the encryption method, a delay of at least Messages of the first type can be set in a range from a few hundred nanoseconds to a few microseconds.
- the appropriate method in each case i.e. encryption of a message sent immediately before a message of the first type, choice of encryption method, choice of key length, choice of the length of the message to be encrypted, encryption (also) of the message of the first type as well as the key to be used in each case, its length and the encryption method to be used may depend on the transmission speed of the connection.
- FIG. 7 shows a schematic flow diagram of a method 700 according to the invention for monitoring the operation of a system with two or more network nodes that are each directly connected to one another.
- a limit value for the signal propagation time on a direct connection between two network nodes to be monitored is determined.
- the limit value can be read from a memory.
- the sending is delayed by a delay value at which the predetermined value for the signal propagation time is reliably just not exceeded.
- step 104 the sending of a message of the first type from a first of the two network nodes to the second of the two network nodes is initiated during operation of the system.
- the message Before the message is actually sent via the communication medium, it is delayed by a delay value in step 106.
- step 108 it is then checked whether the signal propagation time of the message is below the predetermined value for the signal propagation time despite the delay, so that the message can be processed by the receiving network node without changing an operating mode or an operating parameter of the receiving network node. If this is the case, "yes" branch of step 108, the method is repeated starting with step 104 without changing the delay value set in step 702, whereby the repetition can take place cyclically or at irregular intervals.
- the control required for this in each case is provided by the between steps 108 and 104.
- the control can be of a conventional type and use a timer or a (pseudo-)random generator, or an external trigger that reacts to a change in an environmental or system variable or the like.
- step 108 If the check in step 108 shows that the signal propagation time of the message is above the predetermined value due to the delay, so that the message cannot be processed by the receiving network node without changing an operating mode or an operating parameter of the receiving network node, "no" branch of step 108, an additional delay in the signal propagation time must have been inserted into the direct connection between the two network nodes, or there is another change or disturbance.
- the exceedance of the predetermined value of the signal propagation time is signaled in step 704, whereupon at least the network node carrying out the method can initiate further steps or measures.
- the monitoring described above can therefore detect an intervention in a direct connection between two network nodes, which results in an extension of the signal propagation time.
- FIG. 8 shows a schematic flow diagram of a method 800 of an exemplary application of an aspect of the invention in a system with two or more network nodes that are directly interconnected.
- it is to be determined on which direct connections between two network nodes the communication between these network nodes can be recorded and evaluated without the necessary insertion of a TAP or Switches or a bridge result in the operation of the system or the network nodes being disrupted in a way that cannot be corrected or compensated for, or one of the network nodes of the system being put into a second operating mode.
- step 802 the extension of the signal propagation time caused by the inserted TAP or switch or the bridge is determined.
- step 804 a method is determined by means of which a corresponding delay of messages to be sent can be set in the PHY of a network node of the system. It is then verified whether, even with the added delay in the connection between two network nodes, the operation of the system in the previously set operating mode is still possible, or whether none of the network nodes changes to an operating mode other than the previously used operating mode. If this is the case, i.e. operation is possible without changes, a measuring device, TAP or switch or a bridge with a corresponding delay can be looped into this connection. The verification can be carried out, for example, using the method described with reference to Figure 5. This method can therefore be used to identify those connections in a system where a signal propagation time extended by an intervention can be compensated for without actually having to carry out the intervention.
- a monitoring method is carried out in the network nodes of the system as described with reference to Figure 7, the method described above can also be used.
- a minimal further extension of the signal propagation time will result in the predetermined value for the signal propagation time being exceeded.
- this can be compensated by a corresponding reduction in the delay set for normal operation.
- FIG. 9 shows an exemplary block diagram of a network device 900 configured to carry out one or more aspects of the method according to the invention.
- the network device 900 comprises a microprocessor 902, volatile and non-volatile memory 904, 906 and one or more communication interfaces 908.
- the elements of the network device are communicatively connected to one another via one or more data links or buses 910.
- the non-volatile memory 906 contains computer program instructions which, when executed by the microprocessor 902, configure the network device to carry out at least one embodiment of the method according to the invention.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Health & Medical Sciences (AREA)
- Cardiology (AREA)
- General Health & Medical Sciences (AREA)
- Environmental & Geological Engineering (AREA)
- Small-Scale Networks (AREA)
Abstract
Description
BESCHREIBUNG DESCRIPTION
VERFAHREN ZUM ÜBERWACHEN EINER KOMMUNIKATIONSVERBINDUNG ZWEIER DIREKT MITEINANDER VERBUNDENER NETZWERKKNOTEN METHOD FOR MONITORING A COMMUNICATIONS CONNECTION BETWEEN TWO DIRECTLY CONNECTED NETWORK NODES
FELD FIELD
Die vorliegende Erfindung betrifft Kommunikationsnetzwerke mit miteinander zeitsynchronisierten Netzwerkknoten. Insbesondere betrifft die Erfindung ein Verfahren zur Überwachung eines Ethernet-basierten Kommunikationsnetzwerks, bspw. eines Kommunikationsnetzwerkes in einem Kraftfahrzeug, sowie einen zur Durchführung des Verfahrens eingerichteten Netzwerkknoten, beispielsweise in Form eines Steuergeräts. Das Verfahren kann u.a. zur Überwachung auf Fehler in dem Kommunikationsnetzwerk und/oder auf Änderungen der Netzwerktopologie genutzt werden. Dazu ist eine Überwachung einer direkten Kommunikationsverbindung zwischen zwei bspw. als elektronische Steuergeräte ausgebildeten Netzwerkknoten vorgesehen. The present invention relates to communication networks with network nodes that are synchronized with one another in time. In particular, the invention relates to a method for monitoring an Ethernet-based communication network, for example a communication network in a motor vehicle, and a network node set up to carry out the method, for example in the form of a control unit. The method can be used, among other things, to monitor for errors in the communication network and/or for changes in the network topology. For this purpose, monitoring of a direct communication connection between two network nodes, for example designed as electronic control units, is provided.
HINTERGRUND BACKGROUND
In vielen Bereichen der Technik kommuniziert eine Vielzahl von Steuergeräten oder Computern über Netzwerke miteinander. In bestimmten Anwendungsfällen ist es erforderlich, diese Netzwerkknoten miteinander zeitlich zu synchronisieren, bspw. in vernetzen Multimediasystemen, die Medieninhalte zeitlich synchronisiert wiedergeben sollen, oder in Systemen, in denen eine Vielzahl miteinander vernetzter Sensoren Sensordaten an eine Verarbeitungseinheit senden, welche zeitlich zueinander passende Sensordaten auswertet und daraus Steuersignale für das System generiert. In many areas of technology, a large number of control devices or computers communicate with each other via networks. In certain applications, it is necessary to synchronize these network nodes with each other in time, for example in networked multimedia systems that are to play media content in a synchronized manner, or in systems in which a large number of networked sensors send sensor data to a processing unit, which evaluates sensor data that match each other in time and generates control signals for the system from this.
Ein Anwendungsbeispiel für letzteren Anwendungsfall ist das teilautomatisierte bzw. hochautomatisierte Fahren, bei dem die Fahrzeugumgebung sowie Fahrzeugzustände repräsentierende Sensorsignale in Echtzeit oder Quasi-Echtzeit ausgewertet werden, um daraus u.a. Steuersignale für den sicheren Betrieb des Fahrzeugs abzuleiten. Die Verarbeitung von Sensorsignalen einer Vielzahl von Sensoren auch unterschiedlicher Art wird auch als Sensorfusion bezeichnet. Auch in Fahrzeugen werden zunehmend Ethernet-Technologien eingesetzt und ersetzen dort ältere bzw. proprietäre Datenverbindungen und -busse. Die Ethernet-basierte Kommunikation erfolgt nach dem sogenannten OSI-Schichtenmodell, in dem jeder Schicht bestimmte Aufgaben zugewiesen werden, die durch die Instanzen (Geräte und Software) der jeweiligen Schicht für das Funktionieren der Kommunikationen geleistet werden müssen. Dabei stellt jede Instanz einer Schicht entsprechend dem normierten Netzwerkprotokoll Dienste zur Verfügung, die eine darüber liegende Instanz nutzen kann, ohne sich darum kümmern zu müssen, auf welche Weise und mit welchen technischen Mitteln die darunterliegende Instanz die ihr obliegenden Aufgaben löst. Zwischen den verschiedenen Schichten sind als entsprechende Schnittstellen definiert. An example of the latter application is partially automated or highly automated driving, in which sensor signals representing the vehicle environment and vehicle conditions are evaluated in real time or quasi-real time in order to derive control signals for the safe operation of the vehicle, among other things. The processing of sensor signals from a large number of sensors, including those of different types, is also referred to as sensor fusion. Ethernet technologies are also increasingly being used in vehicles, replacing older or proprietary data connections and buses. Ethernet-based communication is based on the so-called OSI layer model, in which each layer is assigned certain tasks that must be performed by the entities (devices and software) of the respective layer for the communication to function. Each instance of a layer provides services in accordance with the standardized network protocol that an entity above it can use without having to worry about how and with what technical means the entity below it solves its tasks. Corresponding interfaces are defined between the various layers.
In Fig. 1 ist schematisch die bekannte, aber auch bei der vorliegenden Erfindung angewendete Ethernet-basierte Kommunikation zwischen zwei beispielsweise als Steuergeräte ausgebildeten Netzwerkknoten 1 , 2 eines kabelgebundenen Kommunikationsnetzwerks 3 dargestellt, die in einem Netzwerkprotokoll nach dem OSI- Schichtenmodell mit insgesamt 7 Schichten I bis VII arbeitet. Die von den einzelnen Schichten zu übernehmenden Aufgaben sind in nicht gesondert dargestellten Recheneinheiten der Netzwerkknoten 1 , 2 implementiert und in Fig. 1 schematisch dargestellt. Fig. 1 schematically shows the known Ethernet-based communication, which is also used in the present invention, between two network nodes 1, 2 of a wired communication network 3, which are designed as control units, for example, and which operates in a network protocol according to the OSI layer model with a total of 7 layers I to VII. The tasks to be performed by the individual layers are implemented in computing units of the network nodes 1, 2 (not shown separately) and are shown schematically in Fig. 1.
Nach dem an sich bekannten OSI-Schichtmodell werden die Schichten wie folgt bezeichnet: According to the well-known OSI layer model, the layers are named as follows:
Schicht I: Bitübertragungssicht (Physical Layer), Schicht II: Sicherungsschicht (Data Link Layer), Schicht III: Vermittlungsschicht (Network Layer), Schicht IV: Transportschicht (Transport Layer) Schicht V: Sitzungsschicht (Session Layer), Schicht VI: Darstellungsschicht (Presentation Layer), Schicht VII: Anwendungsschicht (Application Layer). Layer I: Physical Layer, Layer II: Data Link Layer, Layer III: Network Layer, Layer IV: Transport Layer, Layer V: Session Layer, Layer VI: Presentation Layer, Layer VII: Application Layer.
Die Schichten III bis VII dienen der Aufbereitung der physisch übertragenen Daten und ihrer Zuordnung zu speziellen Anwendungen, die auf die übertragenen Daten über die Anwendungsschicht (Schicht VII) zugreifen. Diese Schichten sind organisatorischer Art und haben mit der physischen Übertragung der Daten bzw. Datenpakete nichts zu tun. Da diese Schichten von der vorliegenden Erfindung nicht betroffen sind, wird auf eine Beschreibung des dem Fachmann bekannten Inhalts dieser Schichten verzichtet. Layers III to VII are used to prepare the physically transmitted data and assign it to special applications that access the transmitted data via the Application layer (layer VII). These layers are of an organizational nature and have nothing to do with the physical transmission of data or data packets. Since these layers are not affected by the present invention, a description of the content of these layers known to the person skilled in the art is omitted.
Die eigentliche Datenübertragung findet in den Schichten I und II statt. Die Schicht I (PHY - Physical Layer; Bitübertragungsschicht) beinhaltet direkt die Hilfsmittel zur Aktivierung bzw. Deaktivierung der physischen Verbindung. Hierzu zählen insbesondere Geräte und Netzkomponenten wie Verstärker, Stecker, Buchsen für das Netzwerkkabel, Repeater, Hub, Transceiver und dergleichen. Diese Schicht I dient also dem physikalischen Ansprechen des Übertragungskanals durch geeignete elektrische, optische, elektromagnetische oder Schallsignale, im Falle der leitungsgebundenen Ethernet- Kommunikationsnetzwerke handelt es sich üblicherweise um elektrische bzw. elektromagnetische Signale. Die für die physische Kommunikation notwendigen Netzwerkschnittstellen sind jedem Netzwerkknoten zugeordnet und bilden die Schicht I gemäß dem OSI-Schichtenmodell. The actual data transmission takes place in layers I and II. Layer I (PHY - Physical Layer) directly contains the tools for activating or deactivating the physical connection. This includes in particular devices and network components such as amplifiers, plugs, sockets for the network cable, repeaters, hubs, transceivers and the like. This layer I is therefore used to physically address the transmission channel using suitable electrical, optical, electromagnetic or sound signals; in the case of wired Ethernet communication networks, these are usually electrical or electromagnetic signals. The network interfaces required for physical communication are assigned to each network node and form layer I according to the OSI layer model.
Die als Sicherungs- oder auch Verbindungsschicht bezeichnete Schicht II des OSI- Schichtmodells dient der Organisation und Steuerung einer weitestgehend fehlerfreien Übertragung und der Regelung des Zugriffs auf das Übertragungsmedium. Hierbei wird auch eine Datenflusskontrolle zwischen Sender und Empfänger realisiert. Logisch wird die Sicherungsschicht häufig in eine Medienzugriffssteuerung MAC (Medium Access Control) und eine logische Verbindungssteuerung LLC (Logical Link Control) unterteilt. Die Medienzugriffssteuerung MAC regelt, wie sich mehrere Rechner das gemeinsam genutzte physikalische Übertragungsmedium teilen. Hierzu verwendet sie u. a. die sogenannten MAC-Adressen der Kommunikationsteilnehmer, die als eindeutige Identifikation jedem Netzwerkknoten als Teilnehmer an dem Kommunikationsnetzwerk 3 zugeordnet sind. Die Medienzugriffssteuerung MAC wird von der logischen Verbindungssteuerung LLC verwaltet, welche eingehende Daten in jede Übertragungsrichtung verteilt und den Zugriff auf die übergeordneten Schichten der Netzwerksteuerung koordiniert. Durch die Aufgaben der Medienzugriffssteuerung MAC und der logischen Verbindungssteuerung LLC wird die sogenannte Sicherungsschicht (Schicht II) gebildet, in der die verschiedenen Netzwerkteilnehmer identifizierbar sind, um die Netzwerkkommunikation geregelt zu organisieren. Diese logische Verwaltung ist in Fig. 1 zwischen den Netzwerkknoten 1 und 2 in der die physische Verbindung repräsentierenden Linie des Kommunikationsnetzwerks 3 schematisch eingebunden. Layer II of the OSI layer model, known as the data link layer, is used to organize and control a largely error-free transmission and to regulate access to the transmission medium. This also includes data flow control between sender and receiver. Logically, the data link layer is often divided into a media access control MAC (Medium Access Control) and a logical link control LLC (Logical Link Control). The media access control MAC regulates how several computers share the shared physical transmission medium. To do this, it uses, among other things, the so-called MAC addresses of the communication participants, which are assigned to each network node as a participant in the communication network 3 as a unique identification. The media access control MAC is managed by the logical link control LLC, which distributes incoming data in each transmission direction and coordinates access to the higher-level layers of the network control. The tasks of the media access control MAC and the logical link control LLC define the so-called data link layer. (Layer II) is formed in which the various network participants can be identified in order to organize the network communication in a regulated manner. This logical management is schematically integrated in Fig. 1 between the network nodes 1 and 2 in the line of the communication network 3 representing the physical connection.
Die einzige Kontrolle der Netzwerkknoten 1 , 2 als Teilnehmer an dem Kommunikationsnetzwerk ergibt sich also in der Sicherungssicht (Schicht II), beispielsweise durch die eindeutigen MAC-Ad ressen zur Identifikation der einzelnen Netzwerkteilnehmer, die für die Medienzugriffssteuerung notwendig ist. In der Bitübertragungsschicht (Schicht I) hat ein Netzwerkknoten 1 , 2 keine Kenntnis von den jeweils anderen Netzwerkknoten 2, 1 in dem Kommunikationsnetzwerk 3, sondern steuert nur die physische Kommunikation an seiner Schnittstelle zu dem Kommunikationsnetzwerk 3. The only control of the network nodes 1, 2 as participants in the communication network is therefore in the security view (layer II), for example through the unique MAC addresses for identifying the individual network participants, which is necessary for media access control. In the physical layer (layer I), a network node 1, 2 has no knowledge of the other network nodes 2, 1 in the communication network 3, but only controls the physical communication at its interface to the communication network 3.
Eine Vielzahl von Systemen die über Ethernet-Verbindungen miteinander kommunikativ verbunden sind, u.a. Systeme in Fahrzeugen oder Systeme zur synchronisierten Übertragung von Audio- und Videosignalen, können besonders hohe Anforderungen an die Zuverlässigkeit der Übertragung und an die zeitliche Koordination von Datenpaketen stellen. Insbesondere für sicherheitskritische Anwendungen, in Fahrzeugen bspw. die Übertragung von Sensor- und Steuerinformationen für Fahrerunterstützungssysteme oder das autonome Fahren, werden hohe Anforderungen an die zeitliche Koordination von Datenpaketen gestellt. Selbst vergleichsweise kleine Veränderungen der Signallaufzeiten können zu einem veränderten Systemverhalten führen, z.B. weil Signale, die gemeinsam verarbeitet werden sollen oder die zu anderen Signalen in einem bestimmten, eng aufeinander abgestimmten Zeitrahmen vorliegen müssen, aufgrund der Veränderung der Signallaufzeit nicht mehr passend zueinander vorliegen. Bei einem veränderten oder nicht vorhersehbaren Systemverhalten kann die Zuverlässigkeit des Systems nicht mehr gewährleistet werden. A large number of systems that are communicatively connected to one another via Ethernet connections, including systems in vehicles or systems for the synchronized transmission of audio and video signals, can place particularly high demands on the reliability of the transmission and the temporal coordination of data packets. In particular, safety-critical applications in vehicles, e.g. the transmission of sensor and control information for driver assistance systems or autonomous driving, place high demands on the temporal coordination of data packets. Even relatively small changes in signal propagation times can lead to a change in system behavior, e.g. because signals that are to be processed together or that must be present in a certain, closely coordinated time frame with other signals no longer match one another due to the change in signal propagation time. If the system behavior changes or is unpredictable, the reliability of the system can no longer be guaranteed.
Der Verbreitungsgrad zeitlich synchronisierter Netzwerkknoten wird in Zukunft weiter zunehmen, u.a. weil eine immer größere Zahl von Steuergeräten Sensordaten unterschiedlicher Sensoren übertragen, die zur Bereitstellung von Sicherheits- und Komfortfunktionen verknüpft und ausgewertet werden. Ein besonders wichtiger Aspekt bei der Fusion von Sensordaten ist die zeitliche Zusammengehörigkeit der Sensordaten. Je nach Anwendung kann es erforderlich sein, auf Milli- oder Mikrosekunden genau zusammengehörende Sensordaten zu fusionieren, während bei anderen Anwendungen unter Umständen ein größerer zeitlicher Abstand der Erfassungszeitpunkte zulässig sein kann. Es ist auch vorstellbar, dass die Erfassungszeitpunkte im Bereich von Nanosekunden genau zusammengehören müssen. Außer den für die Sensorfusion benötigten Daten können aber bspw. auch Daten, die bei der Überwachung des Betriebs des Fahrzeugs erfasst wurden und lediglich für Wartungszwecke oder zur Dokumentation des zulassungsgemäßen und ordnungsgemäßen Betriebs genutzt werden strengen Anforderungen für deren zeitlich korrekte Erfassung und Speicherung unterliegen. The prevalence of time-synchronized network nodes will continue to increase in the future, partly because an increasing number of control units transmit sensor data from different sensors that are used to provide safety and Comfort functions are linked and evaluated. A particularly important aspect of the fusion of sensor data is the temporal coherence of the sensor data. Depending on the application, it may be necessary to fuse sensor data that belong together to within milliseconds or microseconds, while in other applications a larger time interval between the recording times may be permissible. It is also conceivable that the recording times must belong together exactly in the range of nanoseconds. In addition to the data required for sensor fusion, data that was recorded when monitoring the operation of the vehicle and is only used for maintenance purposes or to document that the vehicle is operating correctly and in accordance with the regulations may also be subject to strict requirements for their correct recording and storage at the correct time.
Die Zeitsynchronisation von Netzwerkknoten innerhalb eines Ethernet-Netzwerks kann mittels entsprechender Protokolle erfolgen, so dass innerhalb des Netzwerks eine global gültige Zeitbasis vorliegt. Die Zeitsynchronisierung in Ethernet-Netzwerken ist bspw. in dem IEEE 802.1 AS-Standard vereinbart, der das Precision Time Protocol (PTP) nutzt. The time synchronization of network nodes within an Ethernet network can be carried out using appropriate protocols so that a globally valid time base is available within the network. Time synchronization in Ethernet networks is, for example, agreed in the IEEE 802.1 AS standard, which uses the Precision Time Protocol (PTP).
PTP definiert eine Master-Slave-Uhrenhierarchie mit einer besten Uhr innerhalb eines Netzwerks, die auch als Grandmaster Clock bezeichnet wird. Von dieser besten Uhr, dem Grandmaster, die mittels des Best Master Clock Algorithm (BMCA) ermittelt wird, leitet sich die Zeitbasis der übrigen in diesem Netzwerk befindlichen Netzwerkknoten ab. Ausgehend von dem Grandmaster werden Nachrichten zur Zeitsynchronisation über das Netzwerk verbreitet. Außerdem definiert PTP einen Mechanismus zur Messung der Signallaufzeit auf einer Verbindung, sowie ein Verfahren zum Austausch von Zeitinformationen. PTP defines a master-slave clock hierarchy with a best clock within a network, also known as the grandmaster clock. The time base of the other network nodes in this network is derived from this best clock, the grandmaster, which is determined using the Best Master Clock Algorithm (BMCA). Time synchronization messages are distributed across the network from the grandmaster. PTP also defines a mechanism for measuring the signal propagation time on a connection, as well as a method for exchanging time information.
Für die Ermittlung der Grandmaster Clock gemäß dem BMCA senden IEEE 802.1AS- fähige Netzwerkknoten zyklisch Announce-Nachrichten mit Informationen über ihre interne Uhr an unmittelbar angeschlossene weitere Netzwerkknoten. Die Informationen über die internen Uhren geben Aufschluss auf die Genauigkeit der jeweiligen Uhr, deren Bezug oder Zeitreferenz sowie andere Eigenschaften, anhand derer die beste Uhr in dem Netzwerk bestimmt werden kann. Eine solche Announce-Nachricht ist in Figur 2 a) beispielhaft dargestellt. Ein Empfänger einer solchen Announce-Nachricht vergleicht die empfangenen Informationen mit den Merkmalen seiner eigenen internen Uhr und evtl, bereits von einem anderen Port empfangenen Nachrichten mit Informationen zu Uhren anderer Netzwerkknoten, und akzeptiert eine in einem anderen Netzwerkknoten befindliche Uhr, wenn diese bessere Uhrenparameter hat. Nach kurzer Zeit ist die beste Uhr in dem Netzwerk ermittelt, die dann der Grandmaster in dem Netzwerk wird, und ein Zeitsynchronisations-Spannbaum wurde aufgestellt. Jedem Port eines Netzwerkknotens wird in diesem Zuge einer von vier Port-Zuständen zugewiesen. Der Zustand Master Port wird dem Port zugewiesen, der einen kürzeren Weg zum Grandmaster hat als sein Linkpartner. Der Zustand Slave wird dann zugeordnet, wenn an diesem Knoten noch kein anderer Port diesen Zustand besitzt. Disabled wählt derjenige Port, welcher dass PTP- Protokoll nicht vollständig unterstützen kann. Der Zustand passiv wird gewählt, wenn keiner der anderen drei Zustände zutrifft. To determine the Grandmaster Clock according to the BMCA, IEEE 802.1AS-capable network nodes cyclically send Announce messages with information about their internal clock to other directly connected network nodes. The information about the internal clocks provides information about the accuracy of the respective clock, its reference or time reference, and other properties that can be used to determine the best clock in the network. Such an Announce message is shown in Figure 2 a). shown as an example. A recipient of such an announce message compares the information received with the characteristics of its own internal clock and possibly messages already received from another port with information on clocks at other network nodes, and accepts a clock in another network node if it has better clock parameters. After a short time, the best clock in the network is determined, which then becomes the grandmaster in the network, and a time synchronization spanning tree has been set up. Each port of a network node is assigned one of four port states. The master port state is assigned to the port that has a shorter path to the grandmaster than its link partner. The slave state is assigned if no other port on this node has this state. Disabled is selected by the port that cannot fully support the PTP protocol. The passive state is selected if none of the other three states apply.
Bei einer Variante des PTP, dem generalized Precision Time Protocol (gPTP), kommunizieren jeweils zwei Netzwerkknoten zur Zeitsynchronisation stets direkt miteinander, und keiner der zwei Netzwerkknoten leitet eine empfangene Nachricht zur Zeitsynchronisation einfach nur an einen weiteren Netzwerkknoten im Netzwerk weiter. Vielmehr wird die Zeitinformation von dem Netzwerkknoten vor dem Weiterleiten um die zuvor ermittelte Signallaufzeit auf der Verbindung, über die es Nachrichten zur Zeitsynchronisation von einem direkt verbundenen Netzwerkknoten empfängt, sowie um die interne Bearbeitungsdauer korrigiert, bevor es eine neue Nachricht zur Zeitsynchronisation mit der korrigierten Zeitinformation erstellt und weitersendet. Netzwerkknoten, die das gPTP unterstützen werden auch als „time-aware systems“ bezeichnet. In a variant of PTP, the generalized Precision Time Protocol (gPTP), two network nodes always communicate directly with each other for time synchronization, and neither of the two network nodes simply forwards a received time synchronization message to another network node in the network. Instead, the network node corrects the time information before forwarding it by the previously determined signal propagation time on the connection over which it receives time synchronization messages from a directly connected network node, as well as by the internal processing time before it creates and forwards a new time synchronization message with the corrected time information. Network nodes that support gPTP are also known as "time-aware systems".
Die Signallaufzeit auf einer Verbindung zwischen zwei Netzwerkknoten kann mittels des Sync_Follow_Up-Mechanismus bestimmt werden, der in Figur 2 b) schematisch dargestellt ist. Die Master Ports senden zyklisch Sync- und Follow_Up- Nachrichten an den jeweils benachbarten Linkpartner, also deren Slave-Ports. Wenn die Sync-Nachricht den Master Port verlässt, wird ein Zeitstempel generiert, welcher unmittelbar in einer darauffolgenden FollowJJp-Nachricht übertragen wird. Dieser Zeitstempel entspricht der aktuellen Uhrzeit des Grandmasters zum Sendezeitpunkt der Sync-Nachricht. Aus der Differenz der Empfangszeit der beiden Nachrichten kann der Empfänger die Signallaufzeit der Verbindung bestimmen, und damit sowie anhand der in der Sync-Nachricht übertragenen Uhrzeit der Grandmaster Clock kann der Empfänger dann seine Uhr einstellen. The signal runtime on a connection between two network nodes can be determined using the Sync_Follow_Up mechanism, which is shown schematically in Figure 2 b). The master ports cyclically send Sync and Follow_Up messages to the neighboring link partner, i.e. their slave ports. When the Sync message leaves the master port, a time stamp is generated, which is immediately transmitted in a subsequent FollowJJP message. This time stamp corresponds to the current time of the Grandmaster at the time the sync message was sent. From the difference in the reception time of the two messages, the receiver can determine the signal propagation time of the connection, and with this and the time of the Grandmaster Clock transmitted in the sync message, the receiver can then set its clock.
Zur Bestimmung der die Verzögerung zwischen zwei verbundenen Ports unabhängig von Zeitsynchronisationsnachrichten der Grandmaster Clock dient der sogenannte „Peer Delay Mechanismus“, der beispielhaft in Figur 2 c) gezeigt ist. Ein Port, der Initiator, startet die Messung der Leitungsverzögerung, indem er eine Delay_Request-Nachricht an den mit ihm direkt verbundenen Port eines Netzwerkknotens, den Responder, sendet. Dabei wird so spät wie möglich vor dem tatsächlichen Absenden der Nachricht über den Ethernet-Transceiver ein Sendezeitstempel mit der Zeit t1 generiert und in die Nachricht eingefügt, so dass dieser Sendezeitstempel t1 in guter Näherung die tatsächliche Sendezeit definiert. Der Responder generiert beim Eintreffen der Nachricht einen Empfangszeitstempel t2. Als Antwort sendet der Responder eine Delay_Response- Nachricht an den Initiator. In dieser Nachricht überträgt er den Empfangszeitstempel t2 der Delay_Request-Nachricht. Verlässt diese Nachricht den Responder, so erzeugt dieser wiederum einen Sendezeitstempel t3, welcher in einer unmittelbar darauffolgenden Delay_Response_Follow-Up-Nachricht an den Initiator versendet wird. Beim Empfang der Delay_Response-Nachricht beim Initiator generiert dieser einen Empfangszeitstempel t4. Der Initiator kann aus den vier Zeitstempeln t1 bis t4 die durchschnittliche Laufzeit auf der Kommunikationsstrecke errechnen. Da die Laufzeit auf einer Verbindungsstrecke richtungsabhängig unterschiedlich sein kann, werden Delay_Request-Nachrichten von beiden Kommunikationspartnern unabhängig voneinander versendet. The so-called "peer delay mechanism" is used to determine the delay between two connected ports independently of time synchronization messages from the grandmaster clock. This is shown as an example in Figure 2 c). A port, the initiator, starts the measurement of the line delay by sending a Delay_Request message to the port of a network node directly connected to it, the responder. As late as possible before the message is actually sent via the Ethernet transceiver, a transmission time stamp with the time t1 is generated and inserted into the message so that this transmission time stamp t1 defines the actual transmission time to a good approximation. When the message arrives, the responder generates a reception time stamp t2. In response, the responder sends a Delay_Response message to the initiator. In this message, it transmits the reception time stamp t2 of the Delay_Request message. If this message leaves the responder, it generates a transmission time stamp t3, which is sent to the initiator in an immediately following Delay_Response_Follow-Up message. When the initiator receives the Delay_Response message, it generates a reception time stamp t4. The initiator can calculate the average runtime on the communication link from the four time stamps t1 to t4. Since the runtime on a connection link can vary depending on the direction, Delay_Request messages are sent independently by both communication partners.
Diese Messungen können zyklisch, d. h. in vorgegebenen Zeitabständen von beispielsweise 100ms bis hin zu mehreren Sekunden oder Minuten stattfinden. Schon bei einem Zeitabstand in der Größenordnung von etwa einer Sekunde wird das Netzwerk nicht stark belastet, so dass auch eine Messung in diesen relativ kurzen Zeitabständen unproblematisch für den Betrieb des Netzwerks ist. Es kann sinnvoll sein, derartige Signallaufzeitmessungen zwischen allen miteinander in Kommunikationsverbindung stehenden Netzwerkknoten 1 , 2 des Kommunikationsnetzwerkes 3 durchzuführen, vorzugweise jeweils als direkte Signallaufzeit zwischen zwei Netzwerkknoten 1 , 2. These measurements can be carried out cyclically, ie at predetermined time intervals of, for example, 100 ms up to several seconds or minutes. Even with a time interval of around one second, the network is not heavily loaded, so that even a measurement at these relatively short time intervals is not a problem for the operation of the network. It may be useful to carry out such signal propagation time measurements between all network nodes 1, 2 of the communication network 3 that are in communication connection with one another, preferably as a direct signal propagation time between two network nodes 1, 2.
Während der Entwicklung oder bei der Analyse vernetzter Systeme kann es erforderlich sein, den über die Netzwerkverbindungen gesendeten Datenverkehr abzuhören, bspw. um in dem System auftretende Fehler aufzufinden. Um die Kommunikation zwischen zwei direkt miteinander verbundenen Netzwerkknoten mithören zu können, ohne dass die Software der Netzwerkknoten dazu speziell angepasst oder geändert werden muss, was zu einem veränderten Systemverhalten führen könnte, bei dem der Fehler nicht auftritt oder bei dem andere Fehler auftreten, wird üblicherweise in die Netzwerkverbindung zwischen den zwei Geräten ein sogenannter Test Access Point (TAP) oder ein Switch bzw. eine Bridge eingefügt. During the development or analysis of networked systems, it may be necessary to listen to the data traffic sent over the network connections, for example to find errors that occur in the system. In order to be able to listen to the communication between two directly connected network nodes without having to specifically adapt or change the software of the network nodes, which could lead to a changed system behavior in which the error does not occur or in which other errors occur, a so-called test access point (TAP) or a switch or bridge is usually inserted into the network connection between the two devices.
Aus der schematischen Darstellung der physikalischen Verbindung des in Figur 3 a) gezeigten Kommunikationsnetzwerks 3, entsprechend den durchgezogen dargestellten Pfeilen, ist zu erkennen, dass die physische Verbindung durchaus aufgetrennt werden kann, ohne dass die durch die gestrichelt dargestellten Pfeile dargestellte Zugriffssteuerung (MAC gemäß der Sicherungsschicht bzw. Schicht II) dies wahrnehmen muss und kann. Hierzu ist, wie in der Figur 3 b) dargestellt, an jeweils zwei physischen Schnittstellen PHY ein Abgriff 4 zwischengeschaltet, bspw. ein TAP, und an den bspw. ein Netzwerkanalysator angeschlossen sein kann, der den Datenverkehr zwischen den beiden Netzwerkknoten 1 , 2 analysiert (nicht in der Figur gezeigt). From the schematic representation of the physical connection of the communication network 3 shown in Figure 3 a), according to the solid arrows, it can be seen that the physical connection can certainly be broken without the access control (MAC according to the data link layer or layer II) shown by the dashed arrows having to or being able to notice this. For this purpose, as shown in Figure 3 b), a tap 4, e.g. a TAP, is interposed at each of two physical interfaces PHY, and to which, for example, a network analyzer can be connected, which analyzes the data traffic between the two network nodes 1, 2 (not shown in the figure).
Ein derartiger TAP 4 wird einfach in die bestehende Leitungsverbindung eingeschleift, kopiert beim Durchleiten des Datenstroms bitweise die Dateninformationen bzw. Datenpakte, ohne deren Inhalt zu analysieren, und gibt die kopierten Dateninformationen über eine weitere Schnittstelle aus. Der physikalische Datenstrom wird einfach unverändert weitergeleitet. Somit tritt der Netzwerkanalysator 4 in dem Kommunikationsnetzwerk 3 nicht in Erscheinung. Insbesondere erhält die Sicherungsschicht (Schicht II des OSI-Schichtmodells) der Netzwerkknoten 1 und 2 keine Kenntnis von der Existenz dieses Netzwerkanalysators 4. Such a TAP 4 is simply looped into the existing line connection, copies the data information or data packets bit by bit as the data stream passes through, without analyzing their content, and outputs the copied data information via another interface. The physical data stream is simply forwarded unchanged. The network analyzer 4 therefore does not appear in the communication network 3. In particular, the Data link layer (layer II of the OSI layer model) of network nodes 1 and 2 have no knowledge of the existence of this network analyzer 4.
Gegenüber einer direkten Leitungsverbindung zwischen den Netzwerkknoten 1 und 2 führt das Durchschleifen des Datenstroms durch den TAP 4 aber zu einer verlängerten Signallaufzeit der Signale (Datenpakete), die zwischen den Netzwerkknoten 1 und 2 übertragen werden. Diese Verlängerung der Signallaufzeit kann einige hundert Nanosekunden betragen. Compared to a direct line connection between network nodes 1 and 2, looping the data stream through TAP 4 leads to an extended signal propagation time for the signals (data packets) transmitted between network nodes 1 and 2. This extension of the signal propagation time can amount to several hundred nanoseconds.
Der Einsatz von Switches bzw. Bridges in einer Verbindung zwischen bei Netzwerkknoten zum Mitlesen der Kommunikation hat gegenüber einem TAP einen noch größeren Einfluss auf die Kommunikation. Selbst wenn ein Switch bzw. eine Bridge, ähnlich wie ein TAP, keine direkte Adresse hat, so verursacht er, u.a. wegen einer möglichen Speicherung der Daten vor dem Weiterleiten, eine große Verzögerung und nimmt zudem an der Layer-2 Kommunikation teil. The use of switches or bridges in a connection between network nodes to monitor communication has an even greater impact on communication than a TAP. Even if a switch or bridge, like a TAP, does not have a direct address, it causes a large delay, among other things because of the possibility of storing data before forwarding it, and also takes part in Layer 2 communication.
Wie bereits weiter oben beschrieben wurde, kann das Einfügen eines TAPs oder Switches bzw. einer Bridge zu einer Verlängerung der Signallaufzeit führen, welche die Genauigkeit der Zeitsynchronisation verringert oder diese sogar stört bzw. verhindert. Insbesondere in Systemen, in denen eine korrekte und zuverlässige Zeitsynchronisation für das Funktionieren einer Vielzahl von vernetzte Netzwerkknoten umfassenden Systemen unerlässlich ist, kann eine gestörte oder ausgefallene Zeitsynchronisation dazu führen, dass ein oder mehrere Netzwerkknoten daraufhin von der ursprünglichen Betriebsart in eine andere Betriebsart wechseln, bspw. einen Fehlerbetriebsmodus, und das beabsichtigte zulässige Abhören der Kommunikation der ursprünglichen Betriebsart des Netzwerkknotens oder des Systems nicht erfolgen kann. Damit ist ein sicherer Betrieb u.U. nicht mehr gegeben, und auch eine Fehlersuche wird erheblich erschwert. Es ist leicht zu erkennen, dass die Störung der Zeitsynchronisation mit der Anzahl der zwischen zwei Netzwerkknoten eingefügten TAPs oder Switches bzw. Bridges zunimmt, sofern nicht die Signallaufzeit neu bestimmt und bei der Weiterleitung von Zeitsynchronisationsnachrichten entsprechend korrigiert wird. Das Einfügen von TAPs oder Switches bzw. Bridges in eine Netzwerkverbindung kann auch aus anderen Gründen als zur Fehlersuche erfolgen, bspw. um unbefugt die Kommunikation im Netzwerk abzuhören und Schwachstellen zu erkennen, die zur gezielten unerlaubten Veränderung des Systemverhaltens genutzt werden können. Ein solches Vorgehen kann insbesondere in Systemen genutzt werden, welche identisch in großer Zahl eingesetzt werden. Ein Angreifer braucht sich nur Zugriff auf eines der Systeme zu verschaffen und kann nach erfolgter Analyse und Auffinden einer Schwachstelle jedes andere der Systeme gezielt angreifen. As already described above, the insertion of a TAP or switch or bridge can lead to an increase in the signal propagation time, which reduces the accuracy of the time synchronization or even disrupts or prevents it. Particularly in systems in which correct and reliable time synchronization is essential for the functioning of a large number of networked network nodes, a disrupted or failed time synchronization can lead to one or more network nodes switching from the original operating mode to another operating mode, e.g. an error operating mode, and the intended permissible interception of the communication of the original operating mode of the network node or system cannot take place. This may no longer ensure safe operation and also makes troubleshooting considerably more difficult. It is easy to see that the disruption of the time synchronization increases with the number of TAPs or switches or bridges inserted between two network nodes, unless the signal propagation time is re-determined and corrected accordingly when forwarding time synchronization messages. Inserting TAPs or switches or bridges into a network connection can also be done for reasons other than troubleshooting, for example to eavesdrop on communication in the network without authorization and to identify vulnerabilities that can be used to deliberately change the system behavior without authorization. This approach can be used in particular in systems that are used in large numbers in identical fashion. An attacker only needs to gain access to one of the systems and, after analyzing and finding a vulnerability, can specifically attack any of the other systems.
Dies birgt gerade bei sicherheitsrelevanten Anwendungen, wie sie im Kraftfahrzeug vorliegen, ein gewisses Gefahrenpotential. Wenn beispielsweise durch Fahrerassistenzsysteme ausgewertete Informationen übertragen werden, ist es notwendig festzustellen, ob diese Informationen mitgelesen werden. Ein derartiges Mitlesen kann einen gezielten Angriff auf das Kommunikationssystem des Kraftfahrzeugs vorbereiten, beispielsweise durch Bekanntwerden benutzter Schlüssel oder Netzwerkadressen. This poses a certain risk potential, particularly in safety-relevant applications such as those found in motor vehicles. For example, if information evaluated by driver assistance systems is transmitted, it is necessary to determine whether this information is being read. Such reading can pave the way for a targeted attack on the vehicle's communication system, for example by revealing the keys or network addresses used.
Da eine Überwachung der Teilnehmer an dem Kommunikationsnetzwerk grundsätzlich erst in Kenntnis deren Adressierung, d. h. deren MAC-Adressen oder anderen eindeutigen Identifikationsmerkmalen, in dem Netzwerk möglich ist, bildet das Einfügen eines TAPs oder Switches bzw. einer Bridge eine Angriffsmöglichkeit bei einem Ethernetbasierten Kommunikationssystem, welche nicht auf dem Layer II oder auf höheren Layern des OSI-Schichtenmodells erkennbar ist. Since monitoring the participants in the communication network is only possible if their addressing, i.e. their MAC addresses or other unique identification features, is known in the network, the insertion of a TAP or switch or a bridge represents an attack opportunity in an Ethernet-based communication system that cannot be detected on Layer II or higher layers of the OSI layer model.
In einem statischen Kommunikationsnetzwerk, bspw. dem eines Kraftfahrzeuges, in dem sich die Netzwerktopologie nicht ändert, wenn das Netzwerk nicht durch einen zulässigen oder unzulässigen Eingriff geändert wird, ist es möglich, einen Eingriff durch Erkennen von Änderungen in der Signallaufzeit festzustellen. Eine in diesem Zusammenhang nutzbare Möglichkeit zur Messung der Signallaufzeiten zwischen Netzwerkknoten ist das mit Bezug auf Figur 2 c) beschriebene Verfahren. Die Nutzung von in einem System vor jeglichem Eingriff ermittelten mittleren Laufzeiten auf Verbindungen zwischen zwei Netzwerkknoten setzt voraus, dass diese Laufzeiten in jedem Netzwerkknoten für jede direkte Verbindung zu anderen Netzwerkknoten gespeichert sind. Außerdem muss die Messung der Laufzeiten zyklisch in nicht zu kurzen Abständen wiederholt werden, um auch kurzzeitige Eingriffe erkennen zu können. Dies kann entsprechend zyklisch zu einer erhöhten Kommunikationslast auf der Netzwerkverbindung führen, wodurch besonders zeitkritische Nachrichten möglicherweise verzögert ihr Ziel erreichen. In a static communication network, e.g. that of a motor vehicle, in which the network topology does not change unless the network is modified by a permissible or impermissible intervention, it is possible to detect an intervention by detecting changes in the signal propagation time. One option that can be used in this context to measure the signal propagation times between network nodes is the method described with reference to Figure 2 c). The use of average runtimes determined in a system before any intervention on connections between two network nodes requires that these runtimes are stored in each network node for each direct connection to other network nodes. In addition, the measurement of the runtimes must be repeated cyclically at intervals that are not too short in order to be able to detect even short-term interventions. This can lead to an increased communication load on the network connection on a cyclic basis, which means that particularly time-critical messages may reach their destination with a delay.
BESCHREIBUNG DER ERFINDUNG DESCRIPTION OF THE INVENTION
Es ist daher wünschenswert ein Verfahren zum Überwachen einer Kommunikationsverbindung zweier direkt miteinander verbundener Netzwerkknoten eines Systems anzugeben, mittels dessen ein Eingriff in die direkte Verbindung auch auf der technischen Bitübertragungsschicht erkannt werden kann, auf der lediglich der physische Datenverkehr abgewickelt wird, ohne dazu eine zyklische Messung der Signallaufzeit und einen Vergleich mit einem zuvor ermittelten Wert der Signallaufzeit ausführen zu müssen. Es ist außerdem wünschenswert, durch einen Eingriff veränderte Parameter der Verbindung der beiden Netzwerkknoten so anpassen zu können, dass das Betriebsverhalten des Systems sich nicht von dem Betriebsverhalten vor dem Eingriff unterscheidet. Es ist außerdem wünschenswert, einen Netzwerkknoten anzugeben, insbesondere ein Steuergerät eines Kraftfahrzeugs, der mit anderen Netzwerkknoten verbindbar oder verbunden ist, und der zur Ausführung einer oder mehrerer Ausgestaltungen des erfindungsgemäßen Überwachungsverfahrens oder Teilen davon eingerichtet ist. It is therefore desirable to provide a method for monitoring a communication connection between two directly connected network nodes of a system, by means of which an intervention in the direct connection can also be detected on the technical bit transmission layer, on which only the physical data traffic is processed, without having to carry out a cyclic measurement of the signal propagation time and a comparison with a previously determined value of the signal propagation time. It is also desirable to be able to adapt parameters of the connection between the two network nodes that have been changed by an intervention so that the operating behavior of the system does not differ from the operating behavior before the intervention. It is also desirable to provide a network node, in particular a control unit of a motor vehicle, which can be connected or is connected to other network nodes and which is set up to carry out one or more embodiments of the monitoring method according to the invention or parts thereof.
Ein erster Teil dieser Aufgabe wird erfindungsgemäß durch ein Verfahren mit den Merkmalen des Anspruchs 1 gelöst. Ein weiterer Teil der Aufgabe wird durch das Verfahren des Anspruchs 8 gelöst. Wiederum ein anderer Teil wird durch den in Anspruch 11 angegebenen Netzwerkknoten gelöst. Weiterentwicklungen und Ausgestaltungen des Verfahrens sind in den jeweiligen abhängigen Ansprüchen angegeben. Gemäß einem ersten Aspekt der Erfindung ist für die Erkennung eines Eingriffs in die direkte Verbindung zweier Netzwerkknoten (Netzwerkknoten) zunächst ein Grenzwert eines Parameters der direkten Verbindung der beiden Netzwerkknoten zu bestimmen, der bei einem Eingriff in die direkte Verbindung überschritten wird und der als sicheres Anzeichen für das Vorliegen eines Eingriffs genutzt werden kann. Ein solcher Parameter ist bspw. die Signallaufzeit auf der direkten Verbindung, da die Signallaufzeit bei Einfügen eines TAPs oder eines Switches bzw. einer Bridge, wie es für einen aktiven Eingriff in die direkte Verbindung erforderlich ist, vergrößert wird. Dieser Parameter kann nicht aus einem Netzwerkknoten abgefragt werden, und er steht auch nicht in einer Datenbank oder dergleichen abrufbar zur Verfügung. Zudem kann der Parameter für jeden Link und jeden Link-Typ unterschiedlich sein. Im Kontext dieser Beschreibung steht der Ausdruck „direkte Verbindung“ für eine direkte physikalische Verbindung zweier Netzwerkknoten, d.h. , ohne dazwischen geschaltete andere Netzwerkknoten. A first part of this object is achieved according to the invention by a method having the features of claim 1. A further part of the object is achieved by the method of claim 8. Yet another part is achieved by the network node specified in claim 11. Further developments and embodiments of the method are specified in the respective dependent claims. According to a first aspect of the invention, in order to detect an intrusion into the direct connection between two network nodes (network nodes), a limit value of a parameter of the direct connection between the two network nodes must first be determined, which is exceeded when the direct connection is intruded upon and which can be used as a reliable indication of the presence of an intrusion. One such parameter is, for example, the signal propagation time on the direct connection, since the signal propagation time is increased when a TAP or a switch or a bridge is inserted, as is required for active intrusion into the direct connection. This parameter cannot be queried from a network node, nor is it available for retrieval in a database or the like. In addition, the parameter can be different for each link and each link type. In the context of this description, the term "direct connection" refers to a direct physical connection between two network nodes, i.e. without any other network nodes in between.
Ein erfindungsgemäßes Verfahren zur Ermittlung eines Grenzwerts der Signallaufzeit einer direkten Verbindung zweier Netzwerkknoten umfasst zunächst das Ermitteln der Signallaufzeit auf der direkten Verbindung zu einem Zeitpunkt, an dem kein Eingriff in die direkte Verbindung zweier direkt miteinander verbundener Netzwerkknoten eines Systems vorliegt. Dies kann bspw. mittels des aus dem IEEE 802.1 AS Standard bekannten peer-delay-X/ erfahrens erfolgen, wobei die Messung in einer oder beiden Richtungen ausgeführt werden kann. Das Ermitteln der Signallaufzeit kann jedoch auch das Auslesen aus einer Datenbank oder einem Konfigurationsspeicher erfolgen, wenn die Signallaufzeit zuvor bestimmt wurde und sich über die Zeit nicht ändert. Andere Verfahren zur Bestimmung der Signallaufzeit sind denkbar und dem Fachmann bekannt. A method according to the invention for determining a limit value of the signal propagation time of a direct connection between two network nodes firstly comprises determining the signal propagation time on the direct connection at a time when there is no interference with the direct connection between two directly connected network nodes of a system. This can be done, for example, using the peer-delay-X/ method known from the IEEE 802.1 AS standard, whereby the measurement can be carried out in one or both directions. However, the signal propagation time can also be determined by reading from a database or a configuration memory if the signal propagation time was previously determined and does not change over time. Other methods for determining the signal propagation time are conceivable and known to those skilled in the art.
In einem nächsten Schritt wird das Senden einer Nachricht eines ersten Typs über die direkte Verbindung initiiert, welchem ersten Typ Nachricht zumindest im Sender ein Sendezeitstempel hinzugefügt bzw. zugeordnet wird. Zusätzlich kann dem ersten Typ Nachricht im Empfänger ein Empfangszeitstempel hinzugefügt bzw. zugeordnet werden. In a next step, the sending of a message of a first type is initiated via the direct connection, to which first type of message a sending time stamp is added or assigned at least in the sender. In addition, a receiving time stamp can be added or assigned to the first type of message in the receiver.
Anhand des oder der Zeitstempel in dem ersten Typ Nachricht kann eine Überprüfung der Signallaufzeit auf der Bitübertragungsebene erfolgen. Der erste Typ Nachricht kann auch eine Antwort des Empfängers auslösen, so dass das eine Überprüfung der Signallaufzeit auch im Sender der Nachricht möglich ist. Der erste Typ Nachricht kann eine im IEEE 8201 .AS Standard spezifizierte Nachricht aus der Klasse der event messages sein, z.B. ebenfalls eine peer-cfe/ay-Nachricht. The time stamp(s) in the first type of message can be used to check the signal propagation time at the physical level. The first type of message can also trigger a response from the receiver, so that a check of the signal propagation time is also possible in the sender of the message. The first type of message can be a message from the class of event messages specified in the IEEE 8201 .AS standard, eg also a peer-cfe/ay message.
Vor dem Senden der zuvor initiierten und mit dem Sendezeitstempel versehenen Nachricht des ersten Typs über die Bitübertragungsschicht wird diese um einen ersten Sendeverzögerungswert verzögert. Zusätzlich oder alternativ kann die Nachricht nach dem Empfangen auf der Bitübertragungsschicht und vor dem Setzen des Empfangszeitstempels um einen ersten Empfangsverzögerungswert verzögert werden. Der erste Empfangsverzögerungswert kann vom ersten Sendeverzögerungswert abhängig oder unabhängig sein. Before the previously initiated message of the first type provided with the transmission time stamp is sent via the physical layer, it is delayed by a first transmission delay value. Additionally or alternatively, the message can be delayed by a first reception delay value after being received on the physical layer and before the reception time stamp is set. The first reception delay value can be dependent on or independent of the first transmission delay value.
Gemäß dem Standard IEEE 802.1 AS ist für zumindest für einige Nachrichten aus der Klasse der event messages vorgesehen dass, wenn die Signallaufzeit auf der direkten Verbindung einen vorbestimmten Wert überschreitet, eine Variable geändert wird, die zuvor das Nicht-Überschreiten der Signallaufzeit auf der direkten Verbindung signalisiert hat. Der vorbestimmte Wert ist bspw. ein in dem IEEE 802.1 AS Standard über die Variable meanLinkDelayThresh festgelegter Wert. Die Variable ist bspw. das Flag asCapableAcrossDomains oder asCapable aus dem IEEE 802.1AS Standard, welches im Zuge der Zeitsynchronisation der Netzwerkknoten des Systems genutzt wird und die Fähigkeit eines Netzwerk-Ports anzeigt, die Zeitsynchronisation entsprechend dem Standard durchzuführen. Änderungen des Werts von asCapableAcrossDomains oder asCapable, die als Boolesche Variable die Werte true oder false annehmen können, werden an eine Zustandsmaschine in der PHY kommuniziert, welche daraufhin den Zustand des betreffenden Ports auf reenabled Ext oder disabledExt setzt. According to the IEEE 802.1 AS standard, at least some messages from the event message class specify that if the signal propagation time on the direct connection exceeds a predetermined value, a variable that previously signaled that the signal propagation time on the direct connection was not exceeded is changed. The predetermined value is, for example, a value specified in the IEEE 802.1 AS standard via the meanLinkDelayThresh variable. The variable is, for example, the asCapableAcrossDomains or asCapable flag from the IEEE 802.1AS standard, which is used during the time synchronization of the system's network nodes and indicates the ability of a network port to perform time synchronization in accordance with the standard. Changes to the value of asCapableAcrossDomains or asCapable, which as a Boolean variable can assume the values true or false, are communicated to a state machine in the PHY, which then sets the state of the port in question to reenabled Ext or disabledExt.
Der Zustand des Ports wird u.a. im Zuge der Zeitsynchronisation kommuniziert, so dass die Änderung wegen der zyklischen Übertragung von Zeitsynchronisationsnachrichten innerhalb kurzer Zeit allen anderen Netzwerkknoten zur Kenntnis gebracht wird. Entsprechend umfasst das Verfahren das Prüfen, ob die Signallaufzeit einen vorbestimmten Wert überschritten hat. Dies kann bspw. durch vergleichen der im Sendezeitstempel angegebenen Sendezeit mit der synchronisierten Systemzeit des Empfängers, durch vergleichen der Sendezeit mit der vom Empfänger in einer Antwortnachricht an den Sender zurückgesendeten Empfangszeit, durch Auswerten der asCapableAcrossDomains oder asCapable Flags des IEEE 802.1 AS Standards, durch Auswerten der Portzustände oder andere dem Fachmann bekannte Verfahren erfolgen. The status of the port is communicated, among other things, during time synchronization, so that the change is made known to all other network nodes within a short time due to the cyclical transmission of time synchronization messages. Accordingly, the method includes checking whether the signal propagation time has exceeded a predetermined value. This can be done, for example, by comparing the transmission time specified in the transmission time stamp with the synchronized system time of the receiver, by comparing the transmission time with the reception time sent back by the receiver to the transmitter in a response message, by evaluating the asCapableAcrossDomains or asCapable flags of the IEEE 802.1 AS standard, by evaluating the port states or other methods known to those skilled in the art.
Wenn die Prüfung ergibt, dass die Signallaufzeit den vorbestimmten Wert nicht überschritten hat, wird das Senden einer weiteren Nachricht eines ersten Typs über die direkte Verbindung initiiert, wobei die Verzögerung nach dem Setzen des Zeitstempels und vor der tatsächlichen Übertragung auf der Bitübertragungsschicht gegenüber dem zuvor eingestellten Wert vergrößert wird. Anschließend wird erneut geprüft, ob die Signallaufzeit den vorbestimmten Wert überschritten hat. Das Initiieren und verzögerte Senden wird solange mit jeweils gegenüber dem vorigen Sendevorgang vergrößerter Verzögerung wiederholt, bis die Signallaufzeit den vorbestimmten Wert überschritten hat. Anschließend wird der letzte Verzögerungswert als ermittelter Grenzwert für die direkte Verbindung ausgegeben und/oder gespeichert, bei dem die Signallaufzeit den vorbestimmten Wert noch nicht überschritten hat. Wenn Verzögerungswerte sowohl beim Senden als auch beim Empfangen separat eingestellt sind, werden entsprechend die letzten Verzögerungswerte als ermittelte Grenzwerte gespeichert. Die Speicherung kann lokal erfolgen oder in einer externen Datenbank. If the test shows that the signal propagation time has not exceeded the predetermined value, the sending of another message of a first type is initiated via the direct connection, whereby the delay after setting the time stamp and before the actual transmission on the physical layer is increased compared to the previously set value. It is then checked again whether the signal propagation time has exceeded the predetermined value. The initiation and delayed sending is repeated with a delay that is increased compared to the previous sending process until the signal propagation time has exceeded the predetermined value. The last delay value is then output and/or saved as the determined limit value for the direct connection at which the signal propagation time has not yet exceeded the predetermined value. If delay values are set separately for both sending and receiving, the last delay values are saved as the determined limit values. Storage can take place locally or in an external database.
Die Ermittlung des Grenzwerts zwischen den beiden direkt miteinander verbundenen Netzwerkknoten kann in beide Richtungen erfolgen. The determination of the limit between the two directly connected network nodes can be done in both directions.
Bei einer oder mehreren Ausgestaltungen des Verfahrens wird, nachdem die Signallaufzeit den vorbestimmten Wert erstmals überschritten hat, das Senden mit der zuvor eingestellten Verzögerung für eine zuvor festgelegte Anzahl an Versuchen oder Wiederholungen wiederholt. Wenn die Signallaufzeit in allen Versuchen oder Wiederholungen den vorbestimmten Wert in Folge überschritten hat, wird zum nächsten Schritt des Verfahrens übergegangen. Falls die Signallaufzeit vor Erreichen der zuvor festgelegten Anzahl an Versuchen oder Wiederholungen wieder unterhalb des vorbestimmten Werts liegt, wird diese Wiederholungsphase neu gestartet, wobei das Senden und Überprüfen mit einer gegenüber dem zuvor eingestellten Wert vergrößerten Verzögerung erfolgt. So kann ein Wert für die Verzögerung, der aufgrund von kleinsten, im Normalbetrieb vorkommenden Abweichungen entweder zu einer Überschreitung oder einer Unterschreitung des vorbestimmten Werts der Signallaufzeit führt, sicher erkannt werden. Ein solcher an der Grenze liegender Wert kann bei einer späteren Nutzung des Grenzwerts für die Signallaufzeit je nach Anwendung gezielt genutzt oder ausgelassen werden, insbesondere wenn die Verzögerung sich nur in diskreten Schritten einstellen lässt, die eine bestimmte Mindestgröße haben. In one or more embodiments of the method, after the signal propagation time has exceeded the predetermined value for the first time, the transmission is repeated with the previously set delay for a previously set number of attempts or repetitions. If the signal propagation time has exceeded the predetermined value in all attempts or repetitions in succession, the method proceeds to the next step. If the signal propagation time exceeds the predetermined value before reaching the previously set delay, the transmission is repeated with the previously set delay for a previously set number of attempts or repetitions. If the signal delay falls below the predetermined value after the specified number of attempts or repetitions, this repetition phase is restarted, with the sending and checking taking place with a longer delay than the previously set value. In this way, a delay value which, due to the smallest deviations occurring in normal operation, leads to the predetermined signal delay time either being exceeded or not being reached can be reliably detected. Such a value which is at the limit can be specifically used or omitted when the limit value for the signal delay time is used later, depending on the application, particularly if the delay can only be set in discrete steps which have a certain minimum size.
Bei einer oder mehreren Ausgestaltungen des Verfahrens kann bzw. können, nachdem die Signallaufzeit den vorbestimmten Wert bei einer eingestellten Verzögerung ein- oder ggf. mehrmals überschritten hat, der Wert bzw. die Werte für die Verzögerung wieder verringert werden und die Prüfung auf Überschreitung der Signallaufzeit erneut durchgeführt. Die Verringerung und Prüfung wird ggf. solange wiederholt, bis die Signallaufzeit unter dem vorbestimmten Wert liegt. Bei einer oder mehreren Ausgestaltungen dieses Verfahrens kann in einer Wiederholungsphase mit der zuvor eingestellten Verzögerung geprüft werden, ob die Signallaufzeit in einer zuvor festgelegten Anzahl an Versuchen oder Wiederholungen in Folge unterhalb des vorbestimmten Werts liegt und ggf. die Wiederholungsphase mit einer erneut verringerten Verzögerung neu gestartet werden. In one or more embodiments of the method, after the signal propagation time has exceeded the predetermined value at a set delay once or possibly several times, the value or values for the delay can be reduced again and the test for exceeding the signal propagation time can be carried out again. The reduction and test are repeated if necessary until the signal propagation time is below the predetermined value. In one or more embodiments of this method, a repetition phase with the previously set delay can be used to check whether the signal propagation time is below the predetermined value in a previously defined number of attempts or repetitions in a row and if necessary the repetition phase can be restarted with a further reduced delay.
Um den laufenden Betrieb des Systems nicht zu stören kann bei einer oder mehreren Ausgestaltungen des Verfahrens nach jeder Nachricht, deren Signallaufzeit den vorbestimmten Wert überschritten hat, eine Nachricht des ersten Typs, dem im Sender ein Sendezeitstempel und/oder im Empfänger ein Empfangszeitstempel hinzugefügt bzw. zugeordnet wird, unverzögert gesendet werden. Dadurch kann ein ggf. vorhandener Mechanismus zurückgesetzt werden, der erst bei einer zuvor festgelegten Anzahl an Versuchen das System oder einen oder mehrere Netzwerkknoten in einen Fehlerbetriebsmodus oder einen anderen, vom ursprünglichen Betriebsmodus abweichenden Modus bringt. Insbesondere die Verfahren zur Zeitsynchronisation nach dem IEEE 802.1AS Standard können den Ausfall von bis zu zwei aufeinanderfolgenden Synchronisationsnachrichten kompensieren. Erst bei Ausbleiben von drei aufeinanderfolgenden Synchronisationsnachrichten würde die Zeitsynchronisation des Systems gestört oder neu initiiert werden, würden Netzwerkknoten in einen Fehlermodus gehen oder andere Auswirkungen zeigen, welche einen veränderten Betrieb des System nach sich ziehen. In order not to disrupt the ongoing operation of the system, in one or more embodiments of the method, after each message whose signal propagation time has exceeded the predetermined value, a message of the first type, to which a transmission time stamp is added or assigned in the transmitter and/or a reception time stamp in the receiver, can be sent without delay. This makes it possible to reset any existing mechanism that only puts the system or one or more network nodes into an error operating mode or another mode that differs from the original operating mode after a previously defined number of attempts. In particular, the methods for time synchronization according to The IEEE 802.1AS standard can compensate for the failure of up to two consecutive synchronization messages. Only if three consecutive synchronization messages are missing would the system's time synchronization be disrupted or re-initiated, network nodes would go into error mode or show other effects that result in a change in the operation of the system.
Bei einer oder mehreren Ausgestaltungen des Verfahrens kann das Hinzufügen der Verzögerung für das verzögerte Senden bspw. durch Verschlüsseln zumindest der Nachrichten des ersten Typs auf der Bitübertragungsschicht, d.h. auf der physischen Verbindung, nach dem Setzen des Zeitstempels und vor dem tatsächlichen Übertragen der dann verschlüsselten Datenbits über das Kommunikationsmedium erfolgen. Dazu kann bspw. der aus der IEEE 802.1AE bekannte MACsec-Mechanismus genutzt werden. Der MACsec Mechanismus unterstützt zum einen ein Verfahren zur Sicherung der Integrität der übertragenen Daten, zum anderen das Verschlüsseln der Daten. Bei ersterem wird vom Sender ein 8 Byte lange Header und ein 16 Byte langer Tail angehängt, die von dem Empfänger überprüft werden, um die Integrität der Daten sicherzustellen. Alleine diese 24 zusätzlichen Byte bewirken eine Vergrößerung der Signallaufzeit. Da das Verschlüsseln zumindest das Speichern einer gewissen Anzahl von Datenbits erfordert bedeutet das, dass sich eine u.a. auch von der Anzahl der jeweils in einem Block verschlüsselten Datenbits abhängige Verzögerung ergibt, bevor die Nachricht tatsächlich zum Empfänger übertragen wird. Zudem kann je nach gewähltem Verschlüsselungsverfahren und Schlüssel die Anzahl der Bits oder Oktette der zu übertragenden Nachricht erheblich vergrößert werden, so dass auch die durch das Verschlüsseln vergrößerte zu übertragende Datenmenge zu einer zusätzlichen Verzögerung führt. Entsprechend können bei einer oder mehreren Ausgestaltungen des Verfahrens unterschiedliche Verzögerungen durch Verwendung unterschiedlicher Verschlüsselungsparameter eingestellt werden. Bspw. kann die Nutzung der GCM-AES- 128 Verschlüsselung eine kürzere Verzögerung als die Nutzung der GCM-AES-256 Verschlüsselung bewirken. Ist eine nur kurze Verzögerung nötig kann das Verfahren zur Sicherung der Integrität ohne Verschlüsselung der Daten genutzt werden. Alternativ oder zusätzlich zum Verschlüsseln der Nachrichten des ersten Typs kann unmittelbar vor dem Senden der Nachricht des ersten Typs eine beliebige andere Nachricht verschlüsselt und/oder oder mit zusätzlichen Bytes zur Sicherung der Integrität gesendet werden. Da in beiden Fällen die zu sendende Datenmenge erhöht wird und die entsprechende Bearbeitung ggf. zusätzliche Zeit benötigt, wird das Senden der darauffolgenden Nachricht des ersten Typs nach dem Setzen des Sendezeitstempels im Flow-Control- Buffer des Senders entsprechend verzögert. Genauso wird die empfangene Nachricht des ersten Typs im Empfängerpuffer gespeichert, bis die davor gesendete Nachricht entschlüsselt ist, so dass auch vor das Setzen des Empfangszeitstempels durch die Verwendung des MACsec-Mechanismus verzögert wird, und sich die für die Netzwerkknoten sichtbare Signallaufzeit verlängert. Da auch eine Antwort auf eine verschlüsselte Nachricht verschlüsselt wird, kann sich bei Anwendung des mit Bezug auf Figur 2 c) beschriebenen Peer-Delay-Verfahren eine erhebliche Verlängerung der Signallaufzeit ergeben. In one or more embodiments of the method, the delay for delayed sending can be added, for example, by encrypting at least the messages of the first type on the physical layer, i.e. on the physical connection, after setting the time stamp and before the then encrypted data bits are actually transmitted over the communication medium. For this purpose, the MACsec mechanism known from IEEE 802.1AE can be used, for example. The MACsec mechanism supports a method for securing the integrity of the transmitted data and, on the other hand, encrypting the data. In the former, the sender appends an 8-byte header and a 16-byte tail, which are checked by the receiver to ensure the integrity of the data. These 24 additional bytes alone increase the signal propagation time. Since encryption requires at least a certain number of data bits to be stored, this means that a delay, which depends among other things on the number of data bits encrypted in each block, occurs before the message is actually transmitted to the receiver. In addition, depending on the encryption method and key selected, the number of bits or octets of the message to be transmitted can be increased considerably, so that the increased amount of data to be transmitted through encryption also leads to an additional delay. Accordingly, in one or more embodiments of the method, different delays can be set by using different encryption parameters. For example, the use of GCM-AES-128 encryption can result in a shorter delay than the use of GCM-AES-256 encryption. If only a short delay is required, the method can be used to ensure integrity without encrypting the data. Alternatively or in addition to encrypting the messages of the first type, immediately before the After sending the message of the first type, any other message can be sent encrypted and/or with additional bytes to ensure integrity. Since in both cases the amount of data to be sent is increased and the corresponding processing may require additional time, the sending of the subsequent message of the first type is delayed accordingly after the send time stamp has been set in the sender's flow control buffer. In the same way, the received message of the first type is stored in the receiver buffer until the message sent before it has been decrypted, so that the use of the MACsec mechanism also delays the setting of the receive time stamp and the signal propagation time visible to the network nodes is extended. Since a response to an encrypted message is also encrypted, the signal propagation time can be significantly extended when the peer delay method described with reference to Figure 2 c) is used.
Da sich die Signallaufzeiten in einem statischen Kommunikationsnetzwerk, wie es bspw. in einem Kraftfahrzeug vorliegt, abgesehen von kleineren, nicht signifikanten Abweichungen beispielsweise aufgrund eines üblichen Jitters oder temperaturbedingten Laufzeitunterschieden nicht wesentlich ändern, muss die Ermittlung des Grenzwerts für die Signallaufzeit nicht in kurzen Zeitabständen wiederholt werden. Um einer Alterung von Elektronikkomponenten in dem System von Netzwerkknoten Rechnung zu tragen, genügt eine Wiederholung der Ermittlung des Grenzwerts in größeren zeitlichen Abständen. Since the signal propagation times in a static communications network, such as in a motor vehicle, do not change significantly apart from small, insignificant deviations, for example due to normal jitter or temperature-related propagation time differences, the determination of the limit value for the signal propagation time does not have to be repeated at short intervals. In order to take account of the aging of electronic components in the system of network nodes, it is sufficient to repeat the determination of the limit value at longer intervals.
Gemäß einem zweiten Aspekt der Erfindung werden bei einem Verfahren zur Erkennung eines Eingriffs in eine direkte Verbindung zweier Netzwerkknoten eines Systems während des Betriebs in einer ersten Betriebsart zyklisch oder in unregelmäßigen Abständen wiederholt Nachrichten des ersten Typs initiiert, denen im Sender die Sendezeit hinzugefügt bzw. zugeordnet wird, bspw. ein Sendezeitstempel, und/oder bei welchen der Empfänger die Empfangszeit protokolliert, bspw. mittels eines Empfangszeitstempels. Nach dem Setzen des Sendezeitstempels und vor dem Senden über die Bitübertragungsschicht und/oder nach dem Empfangen der Nachricht über die Bitübertragungsschicht und vor dem Setzen des Empfangszeitstempels werden zumindest die Nachrichten des ersten Typs um einen in dem zuvor beschriebenen Verfahren ermittelten Grenzwert bzw. um in dem zuvor beschriebenen Verfahren ermittelte Grenzwerte für die Signallaufzeit auf der direkten Verbindung verzögert. Anschließend wird geprüft, ob die Signallaufzeit einen vorbestimmten Wert überschritten hat. Wenn die Signallaufzeit den vorbestimmten Wert überschritten hat wird die Überschreitung signalisiert. Dadurch wird es möglich, Eingriffe in die direkte Verbindung der beiden Netzwerkknoten zu erkennen und daraufhin Maßnahmen zu ergreifen. Die durch die Verzögerung eingestellte Verlängerung der Signallaufzeit wird zweckmäßigerweise so gewählt, dass einerseits der vorbestimmte Wert der Signallaufzeit zuverlässig nicht überschritten wird, aber bereits eine kleine zusätzliche Verlängerung der Signallaufzeit zu einer Überschreitung führt. According to a second aspect of the invention, in a method for detecting an intervention in a direct connection between two network nodes of a system during operation in a first operating mode, messages of the first type are initiated cyclically or at irregular intervals, to which the transmission time is added or assigned in the transmitter, for example a transmission time stamp, and/or for which the receiver logs the reception time, for example by means of a reception time stamp. After setting the transmission time stamp and before sending via the physical layer and/or after receiving the message via the physical layer and before setting the reception time stamp, at least the messages of the first type are delayed by a time specified in the previously described The delay is then delayed by a limit value determined by the method or by limit values determined in the previously described method for the signal propagation time on the direct connection. It is then checked whether the signal propagation time has exceeded a predetermined value. If the signal propagation time has exceeded the predetermined value, the exceedance is signaled. This makes it possible to detect interventions in the direct connection between the two network nodes and to take action accordingly. The extension of the signal propagation time set by the delay is expediently selected so that on the one hand the predetermined value of the signal propagation time is reliably not exceeded, but even a small additional extension of the signal propagation time leads to an exceedance.
Die Rolle von sendendem und empfangendem Netzwerkknoten kann auch bei diesem Aspekt der Erfindung immer wieder wechseln, da die Nachrichten des ersten Typs zyklisch und bidirektional ausgesendet werden können, d. h. in jede Kommunikationsrichtung zwischen den beiden Netzwerkknoten. Die Überwachung erfolgt zweckmäßigerweise zyklisch, d. h. in vorgegebenen bzw. vorgebbaren Zeitabständen, so dass Veränderungen zuverlässig festgestellt werden können. The role of the sending and receiving network node can also change repeatedly in this aspect of the invention, since the messages of the first type can be sent cyclically and bidirectionally, i.e. in every direction of communication between the two network nodes. Monitoring is expediently carried out cyclically, i.e. at predetermined or predeterminable time intervals, so that changes can be reliably detected.
Sobald ein Eingriff in eine direkte Verbindung zweier Netzwerkknoten festgestellt wurde, kann der das Verfahren ausführende Netzwerkknoten dies auf einer höheren Kommunikationsebene im OSI-Schichtenmodell den betroffenen Systemkomponenten mitgeteilt werden. So kann, ggf. nach einer weiteren Prüfung auf Zulässigkeit des Eingriffs, eine Anpassung ausgelöst werden, um den Weiterbetrieb des Systems ohne Überschreitungen des vorbestimmten Werts der Signallaufzeit wieder zu ermöglichen. As soon as an intervention in a direct connection between two network nodes is detected, the network node executing the procedure can communicate this to the affected system components at a higher communication level in the OSI layer model. This means that, if necessary after a further check to see if the intervention is permissible, an adjustment can be triggered to enable the system to continue operating without exceeding the predetermined value of the signal propagation time.
Um nur einmalige Überschreitungen des vorbestimmten Werts der Signallaufzeit in unregelmäßigen Abständen zu erkennen und ignorieren zu können kann vorgesehen sein, dass erst eine mehrmalige Überschreitung des vorbestimmten Werts der Signallaufzeit zu einer Signalisierung führt. Dadurch können bspw. vorübergehende Überlastungen von Netzwerkknoten, welche die Signalannahme bzw. die dabei ausgeführten Rechenoperationen etwas verzögern, die aber keinen Eingriff in die Struktur des Netzwerks darstellen, abgefangen werden. Gemäß einer oder mehreren Ausgestaltungen des Verfahrens nach dem zweiten Aspekt der Erfindung wird in Antwort auf das Signalisieren der Überschreitung des Grenzwerts das System bzw. mindestens einer der Netzwerkknoten in eine Fehlerbetriebsart versetzt, bei der z.B. sicherheitsrelevante Funktionen besonders gesichert ausgeführt oder abgeschaltet sind. Ein in einer Fehlerbetriebsart betriebener Netzwerkknoten kann anderen Netzwerkknoten des Systems den Betrieb in einer Fehlerbetriebsart über das Netzwerk bekanntgeben. In order to be able to detect and ignore only one-off exceedances of the predetermined value of the signal propagation time at irregular intervals, it can be provided that only if the predetermined value of the signal propagation time is exceeded several times does a signaling occur. This makes it possible, for example, to intercept temporary overloads of network nodes, which slightly delay the signal acceptance or the calculation operations carried out during it, but which do not represent an intervention in the structure of the network. According to one or more embodiments of the method according to the second aspect of the invention, in response to the signaling of the exceedance of the limit value, the system or at least one of the network nodes is put into an error mode in which, for example, safety-relevant functions are carried out in a particularly secure manner or are switched off. A network node operating in an error mode can notify other network nodes of the system of its operation in an error mode via the network.
Alternativ kann das Verzögern zumindest der Nachrichten des ersten Typs auf einen verringerten Wert reduziert werden, bei dem die Signallaufzeit einen vorbestimmten Wert nicht überschreitet. Zur Bestimmung dieses verringerten Werts kann ggf. das Verfahren nach dem ersten Aspekt der Erfindung genutzt werden. Alternatively, the delay of at least the messages of the first type can be reduced to a reduced value at which the signal propagation time does not exceed a predetermined value. The method according to the first aspect of the invention can optionally be used to determine this reduced value.
Wenn die Verzögerung auf einen Wert reduziert wird, bei dem die Signallaufzeit den vorbestimmten Wert nicht überschreitet kann ein Systemverhalten wiederhergestellt werden, welches sich von dem Systemverhalten vor der Signalisierung der Überschreitung des Grenzwerts nicht unterscheidet. Dadurch kann bspw. ein durch das zulässige Einfügen eines TAPs in eine direkte Verbindung zweier Netzwerkknoten geänderte Systemverhalten wieder in einen Zustand wie vor dem Einfügen des TAPs gebracht werden, so dass bspw. bei einer Fehlersuche keine zusätzlichen, durch das Einfügen des TAPs verursachten Fehler auftreten, oder ein unverändertes Betriebsverhalten des Systems gegenüber dem Betrieb vor dem Einfügen von TAPs vorliegt. If the delay is reduced to a value at which the signal propagation time does not exceed the predetermined value, a system behavior can be restored that is no different from the system behavior before the signaling of the exceedance of the limit value. This means, for example, that a system behavior that has been changed by the permissible insertion of a TAP in a direct connection between two network nodes can be brought back to the state it was in before the TAP was inserted, so that, for example, no additional errors caused by the insertion of the TAP occur during troubleshooting, or the system's operating behavior is unchanged compared to before the TAPs were inserted.
Gemäß einem dritten Aspekt der Erfindung umfasst ein Netzwerkknoten einen oder mehrere Prozessoren, diesem bzw. diesen zugeordneten flüchtigen und nichtflüchtigen Speicher sowie eine mit dem einen oder den mehreren Prozessoren kommunikativ verbundene, zum Senden und/oder Empfangen von über ein von mehreren Netzwerkknoten gemeinsam genutztes Kommunikationsmedium eingerichtete physikalische Netzwerkschnittstelle. Die Elemente des Netzwerkknotens sind mittels einer oder mehreren Datenleitungen oder -bussen kommunikativ miteinander verbunden. In dem nichtflüchtigen Speicher sind Computerprogramminstruktionen gespeichert welche, wenn sie von dem mindestens einen Prozessor ausgeführt werden, den Netzwerkknoten zur Ausführung einer oder mehrerer Ausführungsformen des erfindungsgemäßen Verfahrens einrichten. According to a third aspect of the invention, a network node comprises one or more processors, volatile and non-volatile memory associated with it or these, and a physical network interface communicatively connected to the one or more processors and set up to send and/or receive data via a communication medium shared by several network nodes. The elements of the network node are communicatively connected to one another by means of one or more data lines or buses. In The non-volatile memory stores computer program instructions which, when executed by the at least one processor, set up the network node to carry out one or more embodiments of the method according to the invention.
Gemäß einem vierten Aspekt der Erfindung umfasst ein System, insbesondere ein Fahrzeugsystem, einen oder mehrere jeweils über eine direkte Verbindung vernetzte Netzwerkknoten. Erfindungsgemäß ist mindestens einer der Netzwerkknoten dazu eingerichtet, zumindest eine Ausführungsform des weiter oben beschriebenen erfindungsgemäßen Verfahrens auszuführen. According to a fourth aspect of the invention, a system, in particular a vehicle system, comprises one or more network nodes, each networked via a direct connection. According to the invention, at least one of the network nodes is set up to carry out at least one embodiment of the method according to the invention described above.
Ein Computerprogrammprodukt gemäß einem fünften Aspekt der Erfindung enthält Befehle, die bei der Ausführung durch einen Computer diesen dazu veranlassen, eine oder mehrere Ausgestaltungen und Weiterentwicklungen des vorstehend beschriebenen Verfahrens ausführen. A computer program product according to a fifth aspect of the invention contains instructions which, when executed by a computer, cause the computer to carry out one or more embodiments and further developments of the method described above.
Das Computerprogrammprodukt kann auf einem computerlesbaren Medium bzw. Datenträger gespeichert sein. Das Medium bzw. der Datenträger kann physisch verkörpert sein, bspw. als Festplatte, CD, DVD, Flash-Speicher oder dergleichen, das Medium bzw. der Datenträger kann aber auch ein moduliertes elektrisches, elektromagnetisches oder optisches Signal umfassen, das von einem Computer mittels eines entsprechenden Empfängers empfangen und in dem Speicher des Computers gespeichert werden kann. The computer program product can be stored on a computer-readable medium or data carrier. The medium or data carrier can be physically embodied, for example as a hard disk, CD, DVD, flash memory or the like, but the medium or data carrier can also comprise a modulated electrical, electromagnetic or optical signal that can be received by a computer by means of a corresponding receiver and stored in the computer's memory.
Die vorstehend beschriebenen Verfahren und die das Verfahren ausführenden Netzwerkknoten können in vorteilhafter Weise ohne Änderungen an bereits existierender Hardware implementiert werden, und entsprechend in bereits bestehende Netzwerke integriert werden, da die bereits genutzten Protokolle nicht geändert werden müssen und die Funktion des Netzwerks im normalen Betrieb, d.h. ohne unzulässigen Eingriff in zumindest eine direkte Verbindung zweier Netzwerkknoten nicht durch unzulässige Überschreitungen der Signallaufzeit beeinträchtigt wird. Da die Integrität der direkten Verbindungen im laufenden Betrieb überwacht wird, kann die Betriebssicherheit von Systemen, bspw. von Sensornetzwerken und von Steuergeräten, welche basierend auf Sensordaten Aktionen steuern und ausführen gesteigert werden, bspw. in Fahrzeugen mit einem hohen Grad an Fahrerunterstützung oder autonom fahrenden Fahrzeugen. Unzulässige Eingriffe in eine oder mehrere direkte Verbindungen zweier Netzwerkknoten können schnell erkannt werden und geeignete Maßnahmen können schneller getroffen werden, um den sicheren Betrieb wiederherzustellen oder in einen sicheren Betriebsmodus überzugehen. The methods described above and the network nodes executing the method can advantageously be implemented without changes to existing hardware and can be integrated into existing networks accordingly, since the protocols already used do not have to be changed and the function of the network in normal operation, ie without inadmissible interference with at least one direct connection between two network nodes, is not impaired by inadmissible exceedances of the signal propagation time. Since the integrity of the direct connections is monitored during operation, the operational reliability of systems, e.g. sensor networks and control units that control and execute actions based on sensor data, can be increased, e.g. in vehicles with a high degree of driver assistance or autonomous vehicles. Unauthorized interventions in one or more direct connections between two network nodes can be quickly detected and appropriate measures can be taken more quickly to restore safe operation or to switch to a safe operating mode.
Anhand des Verfahrens zur Bestimmung des Grenzwerts der Signallaufzeit nach dem ersten Aspekt kann eine Signallaufzeitkarte des Kommunikationsnetzwerks angelegt werden, in der die zeitlichen Reserven der jeweiligen Verbindungen zweier Netzwerkknoten eingetragen sind. Diese Information kann normalerweise nicht einfach von einem Netzwerkknoten abgefragt werden, entweder weil dazu keine Abfrage implementiert ist, oder die Implementierung nicht offengelegt ist. Dennoch können mit dem erfindungsgemäßen Verfahren u.a. Verbindungen identifiziert werden, in denen Netzwerkanalysatoren oder Diagnosegeräte eingeschleift werden können. Bei einem solchen zulässigen Eingriff in eine oder mehrere direkte Verbindungen zweier Netzwerkknoten kann eine durch den Eingriff erhöhte Signallaufzeit, welche dann über einem vorbestimmten Wert liegt, durch entsprechende Verringerung der Verzögerung beim Sender und/oder beim Empfänger wieder in einen Bereich gebracht werden, der unterhalb des vorbestimmten Werts liegt. Dadurch kann ein aufgrund des Eingriffs verändertes Systemverhalten wieder zurück in einen mit dem vor dem Eingriff vergleichbaren Zustand gebracht werden. Im Gegensatz zu früheren Verfahren muss keine Restbussimulation oder dergleichen verwendet werden, um Netzwerkknoten separat im simulierten Systemkontext testen zu können. Auf vergleichbare Weise kann bereits vorab festgestellt werden, ob Übertragungsprotokolle, die beim Versenden zusätzliche Zeitverzögerungen hervorrufen, in einem System genutzt werden können. Using the method for determining the limit value of the signal propagation time according to the first aspect, a signal propagation time map of the communication network can be created in which the time reserves of the respective connections between two network nodes are entered. This information cannot normally be easily queried from a network node, either because no query is implemented for this purpose or the implementation is not disclosed. Nevertheless, the method according to the invention can be used to identify, among other things, connections into which network analyzers or diagnostic devices can be looped. In the case of such permissible intervention in one or more direct connections between two network nodes, a signal propagation time increased by the intervention, which is then above a predetermined value, can be brought back into a range that is below the predetermined value by reducing the delay at the transmitter and/or receiver accordingly. In this way, a system behavior that has changed due to the intervention can be brought back to a state comparable to that before the intervention. In contrast to previous methods, no residual bus simulation or the like needs to be used in order to be able to test network nodes separately in the simulated system context. In a similar way, it can be determined in advance whether transmission protocols that cause additional time delays when sending can be used in a system.
Auch bei einem Austausch von Netzwerkknoten oder dem Austausch oder der Reparatur der Kommunikationsleitungen zwischen Netzwerkknoten können die erfindungsgemäßen Verfahren ohne großen Aufwand erneut durchgeführt werden, um ggf. geänderte Parameter zu ermitteln und den Betrieb des Systems ggf. mit geänderten Verzögerungen auf einzelnen Verbindungen wie zuvor fortzusetzen. Even if network nodes are replaced or communication lines between network nodes are replaced or repaired, the methods according to the invention can be carried out again without great effort in order to implement any changes parameters and to continue the operation of the system as before, if necessary with modified delays on individual connections.
Das vorstehend beschriebene Verfahren und die das Verfahren ausführenden Netzwerkknoten können wegen der einfachen und schlanken Implementierung und des Einsatzes von in Standards bereits vorhandenen Mitteln plattformunabhängig und daher flexibel eingesetzt werden. The method described above and the network nodes executing the method can be used platform-independently and therefore flexibly due to the simple and lean implementation and the use of resources already available in standards.
Die Art der insgesamt erfindungsgemäß vorgeschlagenen Überwachung hilft auch, zusätzliche komplexe und/oder rechenintensive Sicherheitsprotokolle einzusparen. Hierdurch wird das Kommunikationsnetzwerk insgesamt entlastet. The type of monitoring proposed in accordance with the invention also helps to eliminate additional complex and/or computationally intensive security protocols. This reduces the load on the communications network as a whole.
Wenngleich die Erfindung vorstehend mit Bezug auf Ethernet-basierte Kommunikation und einem starken Fokus auf das Automotive-Umfeld beschrieben wurde ist das Prinzip auf alle Systeme anwendbar, in denen direkt miteinander verbundene Netzwerkknoten Verfahren des IEEE 802.1AS Standards oder zu den darin beschriebenen vergleichbare Verfahren zur Zeitsynchronisierung nutzen, und in denen Netzwerkknoten zwischen dem Setzen eines Zeitstempels und dem tatsächlichen Übertragen auf der Bitübertragungsschicht durch diverse Maßnahmen gezielt Verzögerungen herbeiführen können. Although the invention has been described above with reference to Ethernet-based communication and a strong focus on the automotive environment, the principle is applicable to all systems in which directly connected network nodes use methods of the IEEE 802.1AS standard or comparable methods to those described therein for time synchronization, and in which network nodes can deliberately cause delays between the setting of a time stamp and the actual transmission on the physical layer by various measures.
KURZE BESCHREIBUNG DER ZEICHNUNG SHORT DESCRIPTION OF THE DRAWING
Im Folgenden wird die Erfindung mit Bezug auf die Zeichnung exemplarisch erläutert, aus der sich auch weitere Vorteile, Merkmale oder Anwendungsmöglichkeiten der Erfindung ergeben. Dabei bilden alle beschriebenen und/oder bildlich dargestellte Merkmale für sich oder in beliebiger Kombination den Gegenstand der vorliegenden Erfindung, auch unabhängig von ihrer Zusammenfassung in den Ansprüchen oder deren Rückbezügen. In the following, the invention is explained by way of example with reference to the drawing, from which further advantages, features or possible applications of the invention also emerge. All described and/or illustrated features form the subject matter of the present invention, either individually or in any combination, regardless of their summary in the claims or their references.
In der Zeichnung zeigt: Fig. 1 schematisch den Ablauf einer Kommunikation zwischen zwei Netzwerkknoten eines Ethernet-basierten Kommunikationsnetzwerks nach dem OSI- Schichtenmodell, In the drawing shows: Fig. 1 schematically shows the communication process between two network nodes of an Ethernet-based communication network according to the OSI layer model,
Fig. 2 Swim-Lane-Diagramme beispielhafter zur Zeitsynchronisation und Messung von Signallaufzeiten genutzter Nachrichten, Fig. 2 Swim-lane diagrams of exemplary messages used for time synchronization and measurement of signal propagation times,
Fig. 3 schematisch die physikalischen und logischen Kommunikationspfade zwischen zwei Netzwerkknoten vor und nach der Zwischenschaltung eines TAPs,Fig. 3 schematically shows the physical and logical communication paths between two network nodes before and after the interposition of a TAP,
Fig. 4 ein schematisches Flussdiagramm eines Verfahrens zur Ermittlung eines Grenzwerts für die Signallaufzeit zweier direkt miteinander verbundener Netzwerkknoten, Fig. 4 is a schematic flow diagram of a method for determining a limit value for the signal propagation time of two directly connected network nodes,
Fig. 5 ein beispielhaftes schematisches Flussdiagramm eines Verfahrens zur Ermittlung eines Grenzwerts für die Signallaufzeit zweier direkt miteinander verbundener Netzwerkknoten im laufenden Betrieb eines Systems in einem ersten Betriebsmodus, ohne dass der Betrieb des Systems bzw. der Netzwerkknoten in dem ersten Betriebsmodus bei der Bestimmung des oberen Grenzwerts der Signallaufzeit unkorrigierbar oder unkompensierbar gestört wird bzw. einer der Netzwerkknoten des Systems in einen zweiten Betriebsmodus versetzt wird, Fig. 5 is an exemplary schematic flow diagram of a method for determining a limit value for the signal propagation time of two directly connected network nodes during operation of a system in a first operating mode, without the operation of the system or the network nodes in the first operating mode being disrupted in an uncorrectable or uncompensable manner when determining the upper limit value of the signal propagation time or one of the network nodes of the system being placed in a second operating mode,
Fig. 6 ein beispielhaftes Blockschaltbild eines Netzwerkknoten mit einem Mikroprozessor pP und einer typischen physikalischen Ethernet-Schnittstelle PHY, Fig. 6 shows an exemplary block diagram of a network node with a microprocessor pP and a typical physical Ethernet interface PHY,
Fig. 7 ein schematisches Flussdiagramm eines erfindungsgemäßen Verfahrens zur Überwachung des Betriebs eines Systems mit zwei oder mehr jeweils direkt miteinander verbundenen Netzwerkknoten, Fig. 7 is a schematic flow diagram of a method according to the invention for monitoring the operation of a system with two or more network nodes that are directly connected to each other,
Fig. 8 ein schematisches Flussdiagramm einer beispielhaften Anwendung eines Aspekts der Erfindung in einem System mit zwei oder mehr jeweils direkt miteinander vernetzten Netzwerkknoten, und Fig. 8 is a schematic flow diagram of an exemplary application of an aspect of the invention in a system with two or more network nodes that are directly interconnected, and
Fig. 9 ein exemplarisches Blockdiagramm eines zur Ausführung eines oder mehrerer Aspekte des erfindungsgemäßen Verfahrens eingerichteten Netzwerkknotens. Fig. 9 is an exemplary block diagram of a network node configured to carry out one or more aspects of the method according to the invention.
Gleiche oder ähnliche Elemente können in den Figuren mit denselben Bezugszeichen referenziert sein. Die Figuren 1 bis 3 wurden bereits weiter oben beschrieben und werden daher im Folgenden nicht erneut diskutiert. Identical or similar elements may be referenced in the figures with the same reference numerals. Figures 1 to 3 have already been described above and will therefore not be discussed again below.
BESCHREIBUNG VON AUSFÜHRUNGSBEISPIELEN DESCRIPTION OF EXAMPLES OF IMPLEMENTATION
Figur 4 zeigt ein schematisches Flussdiagramm eines grundlegenden Verfahrens 100 zur Ermittlung eines Grenzwerts für die Signallaufzeit zweier direkt miteinander verbundener Netzwerkknoten. In Schritt 102 wird zunächst die Signallaufzeit in einem ersten Betriebsmodus gemessen. Dazu kann bspw. das mit Bezug auf Figur 2 c) beschriebene Verfahren genutzt werden. Der erste Betriebsmodus ist bspw. ein normaler Betrieb der beiden Netzwerkknoten in ihrem System kontext. Die Messung kann mehrfach aufeinanderfolgend ausgeführt werden, um kleinere Schwankungen oder Abweichungen, die im normalen Betrieb auftreten können, durch Mittelung oder dgl. herauszufiltern. In Schritt 104 wird nun das Senden einer Nachricht eines ersten Typs von einem ersten der beiden Netzwerkknoten zu dem zweiten der beiden Netzwerkknoten initiiert. Bevor die Nachricht tatsächlich über das Kommunikationsmedium gesendet wird, wird sie in Schritt 106 um einen Verzögerungswert verzögert. In Schritt 108 wird sodann überprüft, ob die Signallaufzeit der Nachricht trotz der Verzögerung unterhalb eines vorbestimmten Werts liegt, so dass die Nachricht vom Empfänger-Netzwerkknoten ohne Änderung eines Betriebsmodus oder eines Betriebsparameters des Empfänger-Netzwerkknoten verarbeitet werden kann. Ist dies der Fall, „ja“-Zweig von Schritt 108, wird das Senden von weiteren Nachrichten des ersten Typs von dem ersten der beiden Netzwerkknoten zu dem zweiten der beiden Netzwerkknoten initiiert, wobei diese weiteren Nachrichten des ersten Typs um einen gegenüber dem jeweils vorherigen Verzögerungswert der vorherigen Nachricht vergrößerten Verzögerungswert verzögert werden. Wenn die Überprüfung in Schritt 108 ergibt, dass die Signallaufzeit der Nachricht aufgrund der Verzögerung oberhalb eines vorbestimmten Werts liegt, so dass die Nachricht vom Empfänger-Netzwerkknoten nicht ohne Änderung eines Betriebsmodus oder eines Betriebsparameters des Empfänger-Netzwerkknoten verarbeitet werden kann, „nein“- Zweig von Schritt 108, ist ein Grenzwert für die Signallaufzeit ermittelt, oder zumindest ein eingegrenzter Bereich innerhalb dessen der Grenzwert liegt. Der Grenzwert liegt in einem Bereich, dessen unteres Ende von der Summe aus der zuerst in Schritt 102 bestimmten Signallaufzeit und dem zuletzt eingestellten Verzögerungswert, bei dem die Signallaufzeit der Nachricht trotz der Verzögerung unterhalb eines vorbestimmten Werts liegt, so dass die Nachricht vom Empfänger-Netzwerkknoten ohne Änderung eines Betriebsmodus oder eines Betriebsparameters des Empfänger-Netzwerkknoten verarbeitet werden kann, markiert wird. Das obere Ende des Bereichs wird von der Summe aus der zuerst in Schritt 102 bestimmten Signallaufzeit und demjenigen Verzögerungswert, bei dem die Signallaufzeit der Nachricht aufgrund der Verzögerung erstmals oberhalb eines vorbestimmten Werts liegt, so dass die Nachricht vom Empfänger-Netzwerkknoten nicht ohne Änderung eines Betriebsmodus oder eines Betriebsparameters des Empfänger- Netzwerkknoten verarbeitet werden kann, markiert. Der gemäß dem vorstehend beschriebenen Verfahren ermittelte Grenzwert bzw. Bereich, oder ein aus diesem Bereich ausgewählter Wert kann dann in Schritt 114 lokal gespeichert und oder ausgegeben werden. Figure 4 shows a schematic flow diagram of a basic method 100 for determining a limit value for the signal propagation time of two directly connected network nodes. In step 102, the signal propagation time is first measured in a first operating mode. For this purpose, the method described with reference to Figure 2 c) can be used, for example. The first operating mode is, for example, normal operation of the two network nodes in their system context. The measurement can be carried out several times in succession in order to filter out smaller fluctuations or deviations that can occur during normal operation by averaging or the like. In step 104, the sending of a message of a first type from a first of the two network nodes to the second of the two network nodes is initiated. Before the message is actually sent via the communication medium, it is delayed by a delay value in step 106. In step 108, it is then checked whether the signal propagation time of the message is below a predetermined value despite the delay, so that the message can be processed by the receiving network node without changing an operating mode or an operating parameter of the receiving network node. If this is the case, "yes" branch of step 108, the sending of further messages of the first type is initiated from the first of the two network nodes to the second of the two network nodes, wherein these further messages of the first type are delayed by a delay value that is greater than the respective previous delay value of the previous message. If the check in step 108 shows that the signal propagation time of the message is above a predetermined value due to the delay, so that the message cannot be processed by the receiving network node without changing an operating mode or an operating parameter of the receiving network node, "no" branch of step 108, a limit value for the signal propagation time is determined, or at least a limited range within which the limit value lies. The limit value lies in a range, the lower end of which is determined by the sum of the first in step 102 Signal propagation time and the last set delay value at which the signal propagation time of the message is below a predetermined value despite the delay, so that the message can be processed by the recipient network node without changing an operating mode or an operating parameter of the recipient network node. The upper end of the range is marked by the sum of the signal propagation time first determined in step 102 and the delay value at which the signal propagation time of the message is above a predetermined value for the first time due to the delay, so that the message cannot be processed by the recipient network node without changing an operating mode or an operating parameter of the recipient network node. The limit value or range determined according to the method described above, or a value selected from this range, can then be stored locally and/or output in step 114.
Figur 5 zeigt ein beispielhaftes schematisches Flussdiagramm eines Verfahrens 500 zur Ermittlung eines Grenzwerts für die Signallaufzeit zweier direkt miteinander verbundener Netzwerkknoten im laufenden Betrieb eines Systems in einem ersten Betriebsmodus, ohne dass der Betrieb des Systems bzw. der Netzwerkknoten in dem ersten Betriebsmodus bei der Bestimmung des oberen Grenzwerts der Signallaufzeit unkorrigierbar oder unkompensierbar gestört wird bzw. einer der Netzwerkknoten des Systems in einen zweiten Betriebsmodus versetzt wird. Das erfindungsgemäße Verfahren nutzt dabei die Erkenntnis, dass bestimmte Nachrichten des ersten Typs bei einer Überschreitung eines vorgegebenen Werts für die Signallaufzeit durch nicht mehr als eine vorbestimmte Anzahl aufeinanderfolgender Nachrichten noch nicht zu einer Störung des Betriebs führen. Einzelne Nachrichten, deren Signallaufzeit oberhalb des Grenzwerts liegt, können zwar einen Fehlerzähler inkrementieren, der jedoch durch die nächste Nachricht, deren Signallaufzeit unterhalb des vorgegebenen Werts liegt, wieder zurückgesetzt wird. So kann eine Beeinflussung des Betriebsverhaltens des Systems durch sporadische Fehler verhindert werden. Figure 5 shows an exemplary schematic flow diagram of a method 500 for determining a limit value for the signal propagation time of two network nodes that are directly connected to one another during operation of a system in a first operating mode, without the operation of the system or the network nodes in the first operating mode being disrupted in an uncorrectable or uncompensable manner when determining the upper limit value of the signal propagation time or one of the network nodes of the system being put into a second operating mode. The method according to the invention uses the knowledge that certain messages of the first type do not lead to a disruption of operation if a predetermined value for the signal propagation time is exceeded by no more than a predetermined number of consecutive messages. Individual messages whose signal propagation time is above the limit value can increment an error counter, but this is reset again by the next message whose signal propagation time is below the predetermined value. In this way, the operating behavior of the system can be prevented from being influenced by sporadic errors.
Die Schritte 104, 106 und 108 entsprechen denen, welche bereits mit Bezug auf Figur 4 beschreiben wurden. In Schritt 104 wird das Senden einer Nachricht eines ersten Typs von einem ersten der beiden Netzwerkknoten zu dem zweiten der beiden Netzwerkknoten initiiert. Bevor die Nachricht tatsächlich über das Kommunikationsmedium gesendet wird, wird sie in Schritt 106 um einen Verzögerungswert verzögert. In Schritt 108 wird sodann überprüft, ob die Signallaufzeit der Nachricht trotz der Verzögerung unterhalb eines vorbestimmten Werts liegt, so dass die Nachricht vom Empfänger-Netzwerkknoten ohne Änderung eines Betriebsmodus oder eines Betriebsparameters des Empfänger- Netzwerkknoten verarbeitet werden kann. The steps 104, 106 and 108 correspond to those already described with reference to Figure 4. In step 104, the sending of a message of a first type from a first of the two network nodes to the second of the two network nodes. Before the message is actually sent over the communication medium, it is delayed by a delay value in step 106. In step 108, it is then checked whether the signal propagation time of the message is below a predetermined value despite the delay, so that the message can be processed by the receiving network node without changing an operating mode or an operating parameter of the receiving network node.
Ist dies der Fall, „ja“-Zweig von Schritt 108, wird in Schritt 110 geprüft, ob eine größere Verzögerung für zu sendende Nachrichten einstellbar ist. Ist das möglich, „ja“-Zweig von Schritt 110, wird in Schritt 112 eine größere Verzögerung gewählt, und das Verfahren wird beginnend mit Schritt 104 wiederholt. Das Einstellen einer geänderten Verzögerung ist durch den gestrichelt dargestellten Pfeil von Schritt 112 zu Schritt 106 angedeutet. Wenn keine größere Verzögerung für zu sendende Nachrichten einstellbar ist, „nein“-Zweig von Schritt 110, wird diese größtmögliche Verzögerung als Grenzwert angenommen und in Schritt 114 gespeichert und/oder ausgegeben. If this is the case (“yes” branch of step 108), a check is made in step 110 to see whether a longer delay can be set for messages to be sent. If this is possible (“yes” branch of step 110), a longer delay is selected in step 112 and the process is repeated starting with step 104. The setting of a modified delay is indicated by the dashed arrow from step 112 to step 106. If a longer delay cannot be set for messages to be sent (“no” branch of step 110), this greatest possible delay is assumed as the limit value and stored and/or output in step 114.
Wenn die Prüfung in Schritt 108 ergibt, dass die Signallaufzeit oberhalb des vorbestimmten Werts liegt, „nein“-Zweig von Schritt 108, wird in Schritt 116 für diese Verzögerung die Signallaufzeit der direkten Verbindung bestimmt, und die Verzögerung in Schritt 118 wieder deaktiviert. Anschließend wird in Schritt 120 eine weitere Nachricht des ersten Typs gesendet, damit ein möglicherweise durch das Überschreiten der Signallaufzeit zuvor inkrementierter Fehlerzähler wieder zurückgesetzt wird bzw. das System diese Überschreitung der Signallaufzeit auf andere Weise kompensieren oder korrigieren kann. Sodann wird in Schritt 122 geprüft, ob eine verringerte Verzögerung eingestellt werden kann, welche unterhalb der zuletzt eingestellten, aber oberhalb einer vor dieser eingestellten Verzögerung liegt. Ist dies nicht der Fall, „nein“-Zweig von Schritt 122, wird der Verzögerungswert, welcher zum Überschreiten des vorbestimmten Werts führte, als Grenzwert angenommen und in Schritt 114 gespeichert und/oder ausgegeben. If the test in step 108 shows that the signal propagation time is above the predetermined value (“no” branch of step 108), the signal propagation time of the direct connection is determined for this delay in step 116, and the delay is deactivated again in step 118. Then, in step 120, another message of the first type is sent so that an error counter that may have been incremented previously due to the signal propagation time being exceeded is reset or so that the system can compensate for or correct this exceeding of the signal propagation time in another way. Then, in step 122, a check is made as to whether a reduced delay can be set that is below the last delay set but above a delay set before this. If this is not the case (“no” branch of step 122), the delay value that led to the predetermined value being exceeded is assumed to be the limit value and stored and/or output in step 114.
Wenn die Prüfung in Schritt 122 ergibt, dass eine verringerte Verzögerung eingestellt werden kann, welche jedoch oberhalb der zu vorletzt eingestellten Verzögerung liegt, „ja“- Zweig von Schritt 122, wird diese in Schritt 112 gewählt, und das Verfahren wird beginnend mit Schritt 104 wiederholt. If the check in step 122 shows that a reduced delay can be set, but which is higher than the delay set before last, “yes” - branch of step 122, it is selected in step 112 and the process is repeated starting with step 104.
Figur 6 zeigt ein beispielhaftes Blockschaltbild eines Netzwerkknoten 600 mit einem Mikroprozessor pP und einer typischen physikalischen Ethernet-Schnittstelle PHY. In der Figur ist insbesondere dargestellt, an welcher Stelle innerhalb der PHY einer Nachricht ein Sendezeitstempel hinzugefügt bzw. zugeordnet wird, und an welchen Stellen die Nachricht anschließend verzögert werden kann. Der Mikroprozessor pP kommuniziert mit dem PHY über eine Schnittstelle, deren Implementierung parallel oder seriell sein kann, und die sich von dem Ethernet-Übertragungsmedium in der Regel unterscheidet. Entsprechend ist auf der Prozessorseite der PHY eine medienunabhängige Schnittstelle Mil (Media Independent Interface) vorgesehen. Die medienunabhängige Schnittstelle Mil nimmt Nachrichten vom MAC der Sicherungsebene, der Schicht II des OSI- Schichtenmodells, zum Senden über das Übertragungsmedium entgegen, bzw. leitet empfangene Nachrichten an den MAC weiter. Eine zu sendende Nachricht, die an der medienunabhängigen Schnittstelle Mil empfangen wurde und quasi als Rohdaten vorliegt, wird vor dem tatsächlichen Senden in einem Physical Coding Sublayer PCS einer Kanalkodierung unterworfen. Die Kanalkodierung dient dazu, digitale Daten bei der Übertragung über gestörte Kanäle durch Hinzufügen von Redundanz gegen Übertragungsfehler zu schützen. Die Kanalkodierung fügt den Daten am Eingang eines Übertragungskanals Redundanz hinzu und dekodiert die Daten an seinem Ausgang. Wenn die Zusatzinformationen lediglich auf einen Fehler hindeuten und eine Neuübertragung der Daten erfordern, spricht man von Rückwärtsfehlerkorrektur. Genügt die Redundanzinformation, den Fehler zu korrigieren, handelt es sich um eine Vorwärtsfehlerkorrektur. Eine effiziente Kanalkodierung erhöht das Signal-Rausch- Verhältnis bei unveränderter Bitfehlerhäufigkeit. Je nach Kanalkodierungsverfahren kann der Codegewinn mehrere dB betragen. Figure 6 shows an example block diagram of a network node 600 with a microprocessor pP and a typical physical Ethernet interface PHY. The figure shows in particular at which point within the PHY a transmission time stamp is added or assigned to a message, and at which points the message can subsequently be delayed. The microprocessor pP communicates with the PHY via an interface, the implementation of which can be parallel or serial, and which is usually different from the Ethernet transmission medium. Accordingly, a media-independent interface Mil (Media Independent Interface) is provided on the processor side of the PHY. The media-independent interface Mil receives messages from the MAC of the data link level, layer II of the OSI layer model, for transmission via the transmission medium, or forwards received messages to the MAC. A message to be sent, which was received at the media-independent interface Mil and is essentially available as raw data, is subjected to channel coding in a physical coding sublayer PCS before it is actually sent. Channel coding is used to protect digital data against transmission errors when transmitted over faulty channels by adding redundancy. Channel coding adds redundancy to the data at the input of a transmission channel and decodes the data at its output. If the additional information only indicates an error and requires the data to be retransmitted, this is referred to as backward error correction. If the redundancy information is sufficient to correct the error, this is forward error correction. Efficient channel coding increases the signal-to-noise ratio without changing the bit error rate. Depending on the channel coding method, the code gain can be several dB.
Eine wesentliche Eigenschaft eines Kanalkodes ist seine Coderate R = k/n, wobei k die Anzahl der Symbole am Eingang des Kodierers, die Informationssymbole, und n die Anzahl der Symbole am Ausgang, die Codesymbole, bezeichnet. Es werden also k Informationssymbole auf n Codesymbole abgebildet. Eine kleine Rate, d.h. , je größer n bei gleichem k ist, bedeutet einen höheren Anteil der Codesymbole an den übertragenden Symbolen, also eine kleinere Datenübertragungsrate. Üblicherweise kann ein Kanalcode mit einer niedrigeren Coderate mehr Fehler korrigieren als ein vergleichbarer Kanalkode mit einer hohen Coderate - es ist also ein Abtausch zwischen Datenübertragungsrate und Fehlerkorrekturfähigkeit möglich. An essential property of a channel code is its code rate R = k/n, where k is the number of symbols at the input of the encoder, the information symbols, and n is the number of symbols at the output, the code symbols. Thus, k information symbols are mapped to n code symbols. A small rate, ie, the larger n at the same k means a higher proportion of code symbols in the transmitted symbols, thus a lower data transmission rate. Usually, a channel code with a lower code rate can correct more errors than a comparable channel code with a high code rate - so a trade-off between data transmission rate and error correction capability is possible.
Erst die kanalkodierten Daten werden von einer an das physikalische Übertragungsmedium angepassten Schnittstelle PMA in das Übertragungsmedium gesendet. Only the channel-coded data are sent into the transmission medium from a PMA interface adapted to the physical transmission medium.
Empfangene Daten werden entsprechend in umgekehrter Reihenfolge von den vorstehend genannten Blöcken bearbeitet. Received data is processed accordingly in reverse order by the blocks mentioned above.
Wenn einer Nachricht vor dem Senden oder nach dem Empfang ein Sendezeitstempel hinzugefügt bzw. zugeordnet wird, kann dies in einer zwischen der Mil und dem PCS angeordneten Zeitstempeleinheit TSU erfolgen, damit auch die Zeitstempel von der Kanalcodierung erfasst werden. If a transmission time stamp is added or assigned to a message before transmission or after reception, this can be done in a time stamp unit (TSU) located between the MIL and the PCS so that the time stamps are also captured by the channel coding.
Die in der IEEE 802.1AE definierten Protokolle zur vertraulichen und sicheren Übertragung von Daten, auch unter dem Begriff MACsec bekannt, ermöglichen es, Daten vor dem Senden bzw. nach dem Empfangen über das Kommunikationsmedium zu verschlüsseln bzw. zu entschlüsseln. Die Verschlüsselung erfolgt zwischen dem Setzen des Zeitstempels und vor der Kanalkodierung, u.a. damit auch der Zeitstempel durch die Verschlüsselung geschützt ist und auch aus der Analyse von Zeitstempeln keine Erkenntnisse gezogen werden können. The protocols defined in IEEE 802.1AE for confidential and secure data transmission, also known as MACsec, make it possible to encrypt or decrypt data before sending or after receiving via the communication medium. Encryption takes place between setting the time stamp and before channel coding, among other things so that the time stamp is also protected by encryption and no conclusions can be drawn from the analysis of time stamps.
Ausgehend von der vorstehend beschriebenen Anordnung der Funktionsblöcke und der dadurch vorgegebenen Reihenfolge der Bearbeitung zu sendender bzw. empfangener Daten kann die für das erfindungsgemäße Verfahren benötigte einstellbare Verzögerung der Nachrichten nach dem Setzen des jeweiligen Zeitstempels kann also nur in einem oder mehreren der Blöcke MACsec, PCS oder PMA erfolgen. Das Einstellen einer Verzögerung in dem Block PMA erscheint wegen der überwiegend analogen Struktur dieses Blocks nicht oder nur in einem äußerst geringen Rahmen möglich, der für die Zwecke der Erfindung nicht ausreichend wäre. Based on the arrangement of the functional blocks described above and the resulting predetermined sequence of processing of data to be sent or received, the adjustable delay of the messages required for the method according to the invention after setting the respective time stamp can therefore only take place in one or more of the MACsec, PCS or PMA blocks. Due to the predominantly analog structure of this block, setting a delay in the PMA block does not appear to be possible or only possible to an extremely limited extent, which would not be sufficient for the purposes of the invention.
Demgegenüber erscheint das Einstellen einer Verzögerung in dem Block PCS durchaus möglich, bspw. durch Auswahl einer geeigneten Coderate bei der Kanalkodierung, mittels derer die auf dem Kommunikationsmedium übertragene Datenmenge variiert werden kann, so dass allein durch die bei einer kleinen Coderate R gegenüber einer großen Coderate R vergrößerte Datenmenge eine längere Übertragungsdauer für ein Datenpaket fester Größe, d.h. eine zusätzliche Verzögerung erzielt werden kann. In contrast, setting a delay in the PCS block appears to be entirely possible, for example by selecting a suitable code rate for channel coding, by means of which the amount of data transmitted on the communication medium can be varied, so that a longer transmission time for a data packet of fixed size, i.e. an additional delay, can be achieved simply by the increased amount of data at a small code rate R compared to a large code rate R.
Ein besonders geeigneter Block für das Einstellen einer Verzögerung nach dem Setzen des Zeitstempels und vor dem Versenden über das Kommunikationsmedium ist der Block MACsec. Durch Auswahl eines der in der IEEE 802.1AE vereinbarten unterschiedlichen Verschlüsselungsverfahren, sofern in einem PHY eines Netzwerkknoten implementiert, wird aus einer gegebenen Menge an Daten nach der Verschlüsselung eine jeweils andere, stets größere Menge an verschlüsselten Daten erzeugt. Auch die Wahl des Schlüssels, bspw. dessen Länge, kann die Menge der durch die Verschlüsselung hinzukommenden Daten beeinflussen. Alleine der Vorgang der Verschlüsselung selbst erfordert eine Speicherung von Daten, wodurch sich eine gewisse zusätzliche Verzögerung ergibt. Die durch die Verschlüsselung vergrößerte Menge Daten, die ja mit der gleichen Geschwindigkeit wie unverschlüsselte Daten über das Kommunikationsmedium gesendet werden müssen, ergibt eine weitere Verzögerung. A particularly suitable block for setting a delay after setting the time stamp and before sending over the communication medium is the MACsec block. By selecting one of the different encryption methods agreed in IEEE 802.1AE, provided it is implemented in a PHY of a network node, a different, always larger amount of encrypted data is generated from a given amount of data after encryption. The choice of key, e.g. its length, can also influence the amount of data added by encryption. The encryption process itself requires data to be stored, which results in a certain additional delay. The increased amount of data caused by encryption, which has to be sent over the communication medium at the same speed as unencrypted data, results in a further delay.
Für die Verzögerung von Nachrichten des ersten Typs kann die Nachricht entweder selbst verschlüsselt werden, und/oder es kann eine unmittelbar vor der Nachricht des ersten Typs gesendete Nachricht beliebigen Typs verschlüsselt werden. Da sich durch die Verschlüsselung einer vor der Nachricht des ersten Typs gesendeten Nachricht deren Datenmenge vergrößert müssen nachfolgend gesendete Nachrichten im Flow-Control- Buffer der PHY entsprechend verzögert werden. So kann durch geeignete Auswahl der zu verschlüsselnden Nachricht, ggf. deren Länge, sowie des Verschlüsselungsverfahrens eine für Teile des erfindungsgemäßen Verfahrens eine Verzögerung zumindest der Nachrichten des ersten Typs in einem Bereich von einigen hundert Nanosekunden bis hin zu einigen Mikrosekunden eingestellt werden. To delay messages of the first type, either the message itself can be encrypted and/or a message of any type sent immediately before the message of the first type can be encrypted. Since the encryption of a message sent before the message of the first type increases its data volume, subsequently sent messages must be delayed accordingly in the flow control buffer of the PHY. Thus, by appropriately selecting the message to be encrypted, if necessary its length, and the encryption method, a delay of at least Messages of the first type can be set in a range from a few hundred nanoseconds to a few microseconds.
Das jeweils geeignete Verfahren, also Verschlüsselung von unmittelbar vor einer Nachricht des ersten Typs gesendeten Nachricht, Wahl des Verschlüsselungsverfahrens, Wahl der Schlüssellänge, Wahl der Länge der zu verschlüsselnden Nachricht, Verschlüsselung (auch) der Nachricht des ersten Typs sowie des dabei jeweils zu verwendenden Schlüssels, dessen Länge und das zu nutzende Verschlüsselungsverfahren können von der Übertragungsgeschwindigkeit der Verbindung abhängen. The appropriate method in each case, i.e. encryption of a message sent immediately before a message of the first type, choice of encryption method, choice of key length, choice of the length of the message to be encrypted, encryption (also) of the message of the first type as well as the key to be used in each case, its length and the encryption method to be used may depend on the transmission speed of the connection.
Figur 7 zeigt ein schematisches Flussdiagramm eines erfindungsgemäßen Verfahrens 700 zur Überwachung des Betriebs eines Systems mit zwei oder mehr jeweils direkt miteinander verbundenen Netzwerkknoten. Zunächst wird ein Grenzwert für die Signallaufzeit auf einer zu überwachenden direkten Verbindung zweier Netzwerkknoten ermittelt. Dazu kann bspw. eines der mit Bezug auf Figur 4 oder 5 beschriebenen Verfahren genutzt werden. Alternativ kann der Grenzwert aus einem Speicher ausgelesen werden. Erfindungsgemäß wird in Schritt 702 für das Versenden zumindest von Nachrichten des ersten Typs das Senden um eine einen Verzögerungswert verzögert, bei dem der vorbestimmte Wert für die Signallaufzeit zuverlässig gerade noch nicht überschritten wird. Anschließend wird in Schritt 104 während des Betriebs des Systems das Senden einer Nachricht des ersten Typs von einem ersten der beiden Netzwerkknoten zu dem zweiten der beiden Netzwerkknoten initiiert. Bevor die Nachricht tatsächlich über das Kommunikationsmedium gesendet wird, wird sie in Schritt 106 um einen Verzögerungswert verzögert. In Schritt 108 wird sodann überprüft, ob die Signallaufzeit der Nachricht trotz der Verzögerung unterhalb des vorbestimmten Werts für die Signallaufzeit liegt, so dass die Nachricht vom Empfänger-Netzwerkknoten ohne Änderung eines Betriebsmodus oder eines Betriebsparameters des Empfänger- Netzwerkknoten verarbeitet werden kann. Ist dies der Fall, „ja“-Zweig von Schritt 108, wird das Verfahren beginnend mit Schritt 104 wiederholt, ohne den in Schritt 702 eingestellten Verzögerungswert zu ändern, wobei die Wiederholung zyklisch oder in unregelmäßigen Abständen erfolgen kann. Die dazu jeweils erforderliche Steuerung ist durch den zwischen den Schritten 108 und 104 liegenden Verfahrensschritt 109 angedeutet. Die Steuerung kann konventioneller Art sein und einen Timer oder einen (Pseudo-)Zufallsgenerator nutzen, oder einen externen Auslöser, der auf eine Veränderung einer Umwelt-, Systemvariable oder dergleichen reagiert. Figure 7 shows a schematic flow diagram of a method 700 according to the invention for monitoring the operation of a system with two or more network nodes that are each directly connected to one another. First, a limit value for the signal propagation time on a direct connection between two network nodes to be monitored is determined. For this purpose, one of the methods described with reference to Figure 4 or 5 can be used, for example. Alternatively, the limit value can be read from a memory. According to the invention, in step 702, for sending at least messages of the first type, the sending is delayed by a delay value at which the predetermined value for the signal propagation time is reliably just not exceeded. Then, in step 104, the sending of a message of the first type from a first of the two network nodes to the second of the two network nodes is initiated during operation of the system. Before the message is actually sent via the communication medium, it is delayed by a delay value in step 106. In step 108, it is then checked whether the signal propagation time of the message is below the predetermined value for the signal propagation time despite the delay, so that the message can be processed by the receiving network node without changing an operating mode or an operating parameter of the receiving network node. If this is the case, "yes" branch of step 108, the method is repeated starting with step 104 without changing the delay value set in step 702, whereby the repetition can take place cyclically or at irregular intervals. The control required for this in each case is provided by the between steps 108 and 104. The control can be of a conventional type and use a timer or a (pseudo-)random generator, or an external trigger that reacts to a change in an environmental or system variable or the like.
Wenn die Überprüfung in Schritt 108 ergibt, dass die Signallaufzeit der Nachricht aufgrund der Verzögerung oberhalb des vorbestimmten Werts liegt, so dass die Nachricht vom Empfänger-Netzwerkknoten nicht ohne Änderung eines Betriebsmodus oder eines Betriebsparameters des Empfänger-Netzwerkknoten verarbeitet werden kann, „nein“- Zweig von Schritt 108, muss eine zusätzliche Verzögerung der Signallaufzeit in die direkte Verbindung der beiden Netzwerkknoten eingefügt worden sein, oder es liegt eine anderweitige Veränderung oder Störung vor. In jedem Fall wird die Überschreitung des vorbestimmten Werts der Signallaufzeit in Schritt 704 signalisiert, worauf zumindest der das Verfahren durchführende Netzwerkknoten weitere Schritte oder Maßnahmen einleiten kann. If the check in step 108 shows that the signal propagation time of the message is above the predetermined value due to the delay, so that the message cannot be processed by the receiving network node without changing an operating mode or an operating parameter of the receiving network node, "no" branch of step 108, an additional delay in the signal propagation time must have been inserted into the direct connection between the two network nodes, or there is another change or disturbance. In any case, the exceedance of the predetermined value of the signal propagation time is signaled in step 704, whereupon at least the network node carrying out the method can initiate further steps or measures.
Die durch das vorstehend beschriebene Überwachung kann also einen Eingriff in eine direkte Verbindung zweier Netzwerkknoten erkennen, der eine Verlängerung der Signallaufzeit mit sich bringt. The monitoring described above can therefore detect an intervention in a direct connection between two network nodes, which results in an extension of the signal propagation time.
Wenn die Veränderung der Signallaufzeit durch einen zulässigen Eingriff in das System hervorgerufen wurde, bspw. durch das vorübergehende Einfügen eines Messgerätes über einen TAP oder einen Switch bzw. einer Bridge, kann ein Systemverhalten, wie es vor dem Eingriff vorlag, z.B. mit dem mit Bezug auf Figur 8 beschriebene Verfahren wiederhergestellt werden. If the change in signal propagation time was caused by a permissible intervention in the system, e.g. by temporarily inserting a measuring device via a TAP or a switch or bridge, the system behavior as it existed before the intervention can be restored, e.g. using the procedure described with reference to Figure 8.
Figur 8 zeigt ein schematisches Flussdiagramm eines Verfahrens 800 einer beispielhaften Anwendung eines Aspekts der Erfindung in einem System mit zwei oder mehr jeweils direkt miteinander vernetzten Netzwerkknoten. Bei der beispielhaften Anwendung soll ermittelt werden, auf welchen direkten Verbindungen jeweils zweier Netzwerkknoten die Kommunikation zwischen diesen Netzwerkknoten mitgeschnitten und ausgewertet werden kann, ohne dass die durch das dazu erforderliche Einfügen eines TAPs oder Switches bzw. einer Bridge hervorgerufene zusätzliche Verlängerung der Signallaufzeit dazu führt, dass der Betrieb des Systems bzw. der Netzwerkknoten unkorrigierbar oder unkompensierbar gestört wird bzw. einer der Netzwerkknoten des Systems in einen zweiten Betriebsmodus versetzt wird. Erfindungsgemäß wird in Schritt 802 die durch den eingefügten TAP oder Switch bzw. die Bridge hervorgerufene Verlängerung der Signallaufzeit bestimmt. Dies kann bspw. durch geeignete Messungen erfolgen, anhand von Angaben in einem Datenblatt oder dgl. Anschließend wird in Schritt 804 ein Verfahren bestimmt, mittels dessen eine entsprechende Verzögerung von zu sendenden Nachrichten in der PHY eines Netzwerkknotens des Systems eingestellt werden kann. Anschließend wird verifiziert, ob auch mit der hinzugefügten Verzögerung in der Verbindung zweier Netzwerkknoten der Betrieb des Systems in dem zuvor eingestellten Betriebsmodus weiter möglich ist, bzw. ob keiner der Netzwerkknoten in einen gegenüber dem zuvor genutzten Betriebsmodus anderen Betriebsmodus wechselt. Ist dies der Fall, ist der Betrieb also unverändert möglich, kann ein Messgerät, TAP oder Switch bzw. eine Bridge mit einer entsprechenden Verzögerung in diese Verbindung eingeschleift werden. Die Verifizierung kann bspw. mit dem mit Bezug auf Figur 5 beschriebenen Verfahren erfolgen. Mit diesem Verfahren können also diejenigen Verbindungen in einem System identifiziert werden, bei denen eine durch einen Eingriff verlängerte Signallaufzeit kompensierbar ist, ohne den Eingriff tatsächlich vornehmen zu müssen. Figure 8 shows a schematic flow diagram of a method 800 of an exemplary application of an aspect of the invention in a system with two or more network nodes that are directly interconnected. In the exemplary application, it is to be determined on which direct connections between two network nodes the communication between these network nodes can be recorded and evaluated without the necessary insertion of a TAP or Switches or a bridge result in the operation of the system or the network nodes being disrupted in a way that cannot be corrected or compensated for, or one of the network nodes of the system being put into a second operating mode. According to the invention, in step 802 the extension of the signal propagation time caused by the inserted TAP or switch or the bridge is determined. This can be done, for example, by suitable measurements, based on information in a data sheet or the like. Then, in step 804, a method is determined by means of which a corresponding delay of messages to be sent can be set in the PHY of a network node of the system. It is then verified whether, even with the added delay in the connection between two network nodes, the operation of the system in the previously set operating mode is still possible, or whether none of the network nodes changes to an operating mode other than the previously used operating mode. If this is the case, i.e. operation is possible without changes, a measuring device, TAP or switch or a bridge with a corresponding delay can be looped into this connection. The verification can be carried out, for example, using the method described with reference to Figure 5. This method can therefore be used to identify those connections in a system where a signal propagation time extended by an intervention can be compensated for without actually having to carry out the intervention.
Falls in den Netzwerkknoten des Systems ein Verfahren zur Überwachung ausgeführt wird, wie es mit Bezug auf Figur 7 beschrieben wurde, kann das vorstehend beschriebene Verfahren ebenfalls genutzt werden. In der Regel wird dabei bereits bei vielen Verbindungen zweier Netzwerkknoten bereits eine minimale weitere Verlängerung der Signallaufzeit dazu führen, dass der vorbestimmte Wert für die Signallaufzeit überschritten wird. Dies kann jedoch durch eine entsprechende Verringerung der für den normalen Betrieb eingestellten Verzögerung kompensiert werden. If a monitoring method is carried out in the network nodes of the system as described with reference to Figure 7, the method described above can also be used. As a rule, even with many connections between two network nodes, a minimal further extension of the signal propagation time will result in the predetermined value for the signal propagation time being exceeded. However, this can be compensated by a corresponding reduction in the delay set for normal operation.
Figur 9 zeigt ein exemplarisches Blockdiagramm eines zur Ausführung eines oder mehrerer Aspekte des erfindungsgemäßen Verfahrens eingerichteten Netzwerkgeräts 900. Das Netzwerkgerät 900 umfasst neben einem Mikroprozessor 902 flüchtigen und nichtflüchtigen Speicher 904, 906 sowie eine oder mehrere Kommunikationsschnittstellen 908. Die Elemente des Netzwerkgeräts sind über eine oder mehrere Datenverbindungen oder -busse 910 kommunikativ miteinander verbunden. Der nichtflüchtige Speicher 906 enthält Computerprogramminstruktionen die, wenn sie von dem Mikroprozessor 902 ausgeführt werden, das Netzwerkgerät zur Ausführung zumindest einer Ausgestaltung des erfindungsgemäßen Verfahrens einrichten. Figure 9 shows an exemplary block diagram of a network device 900 configured to carry out one or more aspects of the method according to the invention. The network device 900 comprises a microprocessor 902, volatile and non-volatile memory 904, 906 and one or more communication interfaces 908. The elements of the network device are communicatively connected to one another via one or more data links or buses 910. The non-volatile memory 906 contains computer program instructions which, when executed by the microprocessor 902, configure the network device to carry out at least one embodiment of the method according to the invention.
BEZUGSZEICHENLISTE LIST OF REFERENCE SYMBOLS
1 , 2 Netzwerkknoten 900 Netzwerkknoten 1 , 2 network nodes 900 network nodes
3 Netzwerk/Verbindung 902 Mikroprozessor 3 Network/Connection 902 Microprocessor
904 flüchtiger Speicher 904 volatile memory
100 Verfahren 906 nichtflüchtiger Speicher100 Procedure 906 non-volatile memory
102 Signallaufzeit messen 908 Kommunikationsschnittstelle102 Measuring signal propagation time 908 Communication interface
104 Senden initiieren 910 Datenverbindungen /-busse104 Initiate sending 910 Data connections / buses
106 Senden verzögern 106 Delay sending
108 vorb. Wert unterschritten? 108 pre-determined value exceeded?
109 Wiederholungssteuerung 109 Repetition Control
110 größere Verzögerung einstellbar? 110 larger delay adjustable?
112 größere/kleinere Verz. wählen 112 select larger/smaller directory
114 Grenzwert ausgeben 114 Output limit value
116 Signallaufzeit bestimmen 116 Determine signal propagation time
118 Verzögerung deaktivieren 118 Disable delay
120 Nachricht unverzögert senden 120 Send message without delay
122 kleinere Verzögerung einstellbar? 122 smaller delay adjustable?
500 Verfahren 500 procedures
600 Netzwerkknoten 600 network nodes
700 Verfahren 700 procedures
702 Senden verzögern 702 Delay sending
704 Überschreitung signalisieren 704 Signal exceedance
800 Verfahren 800 procedures
802 Signallaufzeit bestimmen 802 Determine signal propagation time
804 Verzögerungsverfahren bestimmen 804 Determine delay procedure
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102022213581.4A DE102022213581A1 (en) | 2022-12-13 | 2022-12-13 | METHOD FOR MONITORING A COMMUNICATION CONNECTION BETWEEN TWO DIRECTLY CONNECTED NETWORK NODES |
| PCT/DE2023/200242 WO2024125733A1 (en) | 2022-12-13 | 2023-12-01 | Method for monitoring a communication connection between two network nodes that are directly connected to one another |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP4635150A1 true EP4635150A1 (en) | 2025-10-22 |
Family
ID=89321676
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP23828345.1A Pending EP4635150A1 (en) | 2022-12-13 | 2023-12-01 | Method for monitoring a communication connection between two network nodes that are directly connected to one another |
Country Status (4)
| Country | Link |
|---|---|
| EP (1) | EP4635150A1 (en) |
| CN (1) | CN120303917A (en) |
| DE (1) | DE102022213581A1 (en) |
| WO (1) | WO2024125733A1 (en) |
Family Cites Families (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE102012216689B4 (en) * | 2012-09-18 | 2017-05-04 | Continental Automotive Gmbh | Method for monitoring an Ethernet-based communication network in a motor vehicle |
| EP2736194B1 (en) * | 2012-11-27 | 2017-09-27 | ADVA Optical Networking SE | Latency monitoring point |
| DE102018213898B4 (en) * | 2018-08-17 | 2020-03-19 | Continental Automotive Gmbh | Monitoring a network connection for eavesdropping |
-
2022
- 2022-12-13 DE DE102022213581.4A patent/DE102022213581A1/en active Pending
-
2023
- 2023-12-01 WO PCT/DE2023/200242 patent/WO2024125733A1/en not_active Ceased
- 2023-12-01 EP EP23828345.1A patent/EP4635150A1/en active Pending
- 2023-12-01 CN CN202380083473.XA patent/CN120303917A/en active Pending
Also Published As
| Publication number | Publication date |
|---|---|
| CN120303917A (en) | 2025-07-11 |
| DE102022213581A1 (en) | 2024-06-13 |
| WO2024125733A1 (en) | 2024-06-20 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP3501154B1 (en) | Provision of secure communication in a communications network capable of operating in real time | |
| DE102019220096B4 (en) | Method for safeguarding the time synchronization of an Ethernet on-board network | |
| DE102012216689B4 (en) | Method for monitoring an Ethernet-based communication network in a motor vehicle | |
| EP3794751B1 (en) | Method for determining synchronisation accuracy, computer program, communication unit and motor vehicle | |
| DE112016003907T5 (en) | Forwarding device | |
| EP4078863B1 (en) | Method of checking the validity of sensordata of an ethernet-network of a vehicle | |
| EP3295645B1 (en) | Method and arrangement for decoupled transmission of data between networks | |
| DE102019220498B4 (en) | Method for safeguarding the time synchronization in a server ECU | |
| WO2018077528A1 (en) | Detection of manipulations in a can network by checking can identifiers | |
| DE102020125262A1 (en) | Warning system for controller area networks | |
| EP3177973A1 (en) | Method for operating security control and automation network having such security control | |
| DE102017219661A1 (en) | Method for operating a control device | |
| EP2829011A1 (en) | Method and device for generating cryptographically protected redundant data packets | |
| EP2695324B1 (en) | Method for sending messages with integrity protection | |
| EP3688951B1 (en) | Method for detecting an attack on a control device of a vehicle | |
| EP4635150A1 (en) | Method for monitoring a communication connection between two network nodes that are directly connected to one another | |
| EP2839601B1 (en) | Field bus data transmission | |
| DE102019217037A1 (en) | Procedure for safeguarding the time synchronization in a network | |
| EP4635133A1 (en) | Authentication device for a vehicle | |
| DE102013204371B4 (en) | Method and bus system for protocol-independent transmission of standard data packets with security data | |
| DE102017208735A1 (en) | Method and device for protecting a communication between at least one first communication device and at least one second communication device, in particular within a communication network of an industrial manufacturing and / or automation | |
| DE102023112245B3 (en) | Method for data transmission, transmission system for data transmission and vehicle | |
| EP2446599A1 (en) | Data transmission between automation devices protected against manipulation | |
| DE102023202226A1 (en) | Method for forwarding data from a plurality of data sources to a data sink | |
| DE102020209043A1 (en) | Method of operating a network and bypass connection unit |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20250714 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC ME MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| RAP3 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: AUMOVIO GERMANY GMBH |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) |