Method and masterclock for providing fail-silent synchronisation messages
12 claims: 1 independent, 11 dependent
- 1Verfahren zur Erstellung von fail-silent Synchronisationsnachrichten in einem verteilten Echtzeitsystem, wobei das Verfahren folgenden Funktionseinheiten verwendet:einen Satellitenempfänger ( 1 10) zum Empfang eines Zeitsignals von einem Navigationssatellitensystem, eine präzise Referenzuhr (130), die ein im Folgenden als R-Signal bezeichnetes periodisches Zeitsignal generiert, einen zentralen Rechner (140), einen Monitor (120) mit einer periodischen Zeitquelle, und einen Datenblock (210) zur Speicherung von Konfigurationsparametern, wobei der Satellitenempfänger (110) periodisch ein S-Signal generiert, wobei die Frequenz und Phase des nominalen R-Signals identisch ist mit der Frequenz und Phase des S-Signals, und wobei die Differenz zwischen dem nominalen und tatsächlichen R-Signal verwendet wird, um diese Differenz in Zukunft zu minimieren, und wobei • im Normalfall des Satellitenempfängers (110) eine periodische Synchronisationsnachricht (220), die entsprechend den Konfigurationsparametern (210) von dem zentralen Rechner (140) zu generieren ist, auf der Grundlage des S-Signals generiert wird und die Differenz zwischen dem nominalen und tatsächlichen R-Signal verwendet wird, um den Stand und den Gang der Referenzuhr (130) an das S-Signal anzupassen, und wobei • im Anomaliefall des Satellitenempfängers (110) die Ganganpassung der Referenzuhr (120) ausgesetzt wird, und wobei • im Fehlerfall des Satellitenempfängers (110) die periodische Synchronisationsnachricht (220), welche entsprechend den Konfigurationsparametern (210) vom zentralen Rechner (140) zu generieren ist, auf der Grundlage des tatsächlichen R-Signals generiert wird;und wobei mit der periodischen Zeitquelle des Monitors (120) der zeitliche Abstand zweier aufeinander folgender Synchronisationsnachrichten (220) gemessen wird und der Monitor (120) überprüft, ob der in der Synchronisationsnachricht enthaltene Sendezeitpunkt mit dem tatsächlichen Sendezeitpunkt übereinstimmt und der Abstand zwischen zwei aufeinanderfolgenden Synchronisationsnachrichten (220) innerhalb eines a priori festgelegten Toleranzintervalls liegt, und, falls dies nicht der Fall ist, die Synchronisationsnachricht (220) derart modifiziert, dass jeder Empfänger die Synchronisationsnachricht (220) als fehlerhaft erkennt.
- 2Verfahren nach Anspruch 1, dadurch gekennzeichnet, dass der Monitor (120) nach Start-up in eine Initialphase eintritt, während welcher der Abstand zwischen aufeinanderfolgenden Synchronisationsnachrichten (220) vermessen wird und in der folgenden Betriebsphase den gemessen Abstand verwendet, um einen fehlerhaften Abstand von zwei aufeinanderfolgenden Synchronisationsnachrichten (220) zu erkennen.
- 3Verfahren nach Anspruch 1, dadurch gekennzeichnet, dass der zentralen Rechner (140) periodisch eine Diagnosenachricht generiert, in welcher der Betriebszustand und eventuelle Anomalien oder Fehler des Gesamtsystems während der vorangegangen Periode enthalten sind.
- 4Verfahren nach einem der Ansprüche 1 bis 3, dadurch gekennzeichnet, dass die in Konfigurationsdatenblock (210) gespeicherten Daten mit fehlererkennenden Codes gesichert sind.
- 5Verfahren nach einem der Ansprüche 1 bis 4, dadurch gekennzeichnet, dass die im Konfigurationsdatenblock (210) gespeicherten Daten mit fehlerkorrigierenden Codes gesichert sind.
- 6Verfahren nach einem der Ansprüche 1 bis 5, dadurch gekennzeichnet, dass die im Konfigurationsdatenblock (210) gespeicherten Parameter nur geändert werden können, wenn eine physikalische Verbindung zwischen einem externen Eingabegerät und dem zentralen Rechner (140) existiert.
- 7Verfahren nach einem der Ansprüche 1 bis 6, dadurch gekennzeichnet, dass die im Konfigurationsdatenblock (210) gespeicherten Parameter über das Internet mit einem kryptographisch gesicherten Protokoll änderbar sind.
- 8Verfahren nach einem der Ansprüche 1 bis 7, dadurch gekennzeichnet, dass der Satellitenempfänger (110) die Feldstärke der Satellitensignale misst und dem zentralen Rechner (140) mitteilt, um Anomalien in den Satellitensignalen erkennen zu können.
- 9Verfahren nach einem der Ansprüche 1 bis 8, dadurch gekennzeichnet, dass die Synchronisationsnachricht (220) durch eine elektronische Unterschrift gesichert ist.
- 10Verfahren nach einem der Ansprüche 1 bis 9, dadurch gekennzeichnet, dass der syntaktische Aufbau der Synchronisationsnachricht (220) dem SAE Standard AS6802 entspricht und/oder der syntaktische Aufbau der Synchronisationsnachricht (220) dem IEEE Standard 1588 entspricht.
- 11Verfahren nach einem der Ansprüche 1 bis 10, dadurch gekennzeichnet, dass die S-Signale auf der Basis der Satellitensignale des GPS Systems und/oder des Galileo Systems und/oder des GLANOSS Systems generiert werden.
- 12Verfahren nach einem der Ansprüche 1 bis 11, dadurch gekennzeichnet, dass nach dem Ende des Ausfalls des Satellitenempfängers (110) das von der Referenzuhr (130) generierte R-Signal mit einer maximalen vordefinierten Gangdifferenz an das wieder vorhandene S-Signal geführt wird, um die während des Ausfalls akkumulierte Uhrenstanddifferenz zwischen dem R-Signal und dem S-Signal abzubauen.
Independent claims12
29 paragraphs, as filed
0001The invention relates to a method for creating fail-silent synchronization messages in a distributed real-time system.
0002Such procedures are known from the following documents:<patcit id="pcit0001" dnum="WO2004066530A1"><text>WO 2004/066530 A1</text></patcit>, <patcit id="pcit0002" dnum="US2009225743A1"><text>US 2009/225743 A1</text></patcit>, and from the publication by <nplcit id="ncit0001" npl-type="s"><text>Kopetz et al .: "Integration of Internal and External Clock Synchronization by the Combination of Clock-State and Clock-Rate Correction in Fault-Tolerant Distributed Systems", published in Real-Time Systems Symposium, 2004. Proceedings. 25th IEEE International Lisbon, Portugal 05-08 Dec. 2004</text></nplcit>.
0003The present invention is in the field of computer technology. It describes an innovative method of how reliable synchronization messages, which correspond to the SAE standard AS6802 from TT Ethernet and the IEEE standard 1588, can be generated from satellite signals using a master clock.
0004In a distributed, fault-tolerant real-time system in which a number of computers control a physical process, it is advantageous if all computers have a fault-tolerant physical time base according to the TAI standard [7]. Such a time base can be established by receiving periodic synchronization messages that are sent from a fault-tolerant master clock. A synchronization message contains the time it was sent by the master clock in its data field.
0005In the following, a method is described how such a fault-tolerant master clock, which generates reliable synchronization messages according to the SAE standard AS6802 from TT Ethernet [8] and the IEEE standard 1588 [9], can be set up.
0006The terms used in this document are explained below: An Ethernet message contains a <i>Header,</i> a <i>Data field</i> and a redundant one <i>CRC field.</i> In a real one <i>closed</i> Message is the CRC field with the content of the message <i>consistent.</i> A message is <i>open,</i> if not <i>consistent CRC field</i> exists. If a modification is to be made in the data field of a message, the message must first be opened. When a message is opened, it is checked whether the content of the closed message is consistent with the CRC field. If this is not the case, the message is discarded. After making the modification in the data field of the<i>open</i> Message must be the message again <i>closed</i> ie a new consistent CRC field must be calculated before the message can be sent further. If a modification is made in an open message, a transient error (e.g. a SEU (<i>single event upset</i>) due to the natural cosmic radiation) cause an error in the message, which remains even after the message is closed.
0007In the field of computer reliability, the term has one <i>Fault containment unit</i> (FCU) is of central importance [7, p. 136]. Under one<i>FCU</i> is understood to be an encapsulated subsystem, with the direct effects of a cause of error on this subsystem being limited.
0008The quality of a real-time clock is characterized by its accuracy [7]. If two real-time clocks are compared, a distinction is made between the level difference and the rate difference. If the status of a real-time clock regularly deviates from a reference clock, this indicates a rate difference that can be corrected using a digital micro / macro tick transformation logic.
0009It is an object of the invention to provide a solution for how reliable synchronization messages, in particular in accordance with the SAE standard AS6802 from TT Ethernet [8] and the IEEE standard 1588 [9], can be generated.
0010This object is achieved with a method according to the invention in that the method uses the following functional units: a satellite receiver for receiving a time signal (S-signal) from a navigation satellite system, a precise reference clock that generates an actual time signal (R-signal), a central computer, a monitor, and a data block for storing configuration parameters, the satellite receiver periodically activating S-signal generated and the reference clock periodically producing an R-signal, wherein the nominal frequency and phase of the R-signal is identical to the frequency and phase of the S-signal, and wherein the difference between the nominal and actual R-signals is used to minimize this difference in the future, and in the normal case the Satellite receiver the periodic synchronization message that is to be generated by the central computer according to the configuration parameters, is generated on the basis of the S-signal and the difference between the nominal and actual R-signal is used to - preferably short-term - the status and - preferably long-term - the rate of the reference clock to adapt to the S-signal, and in the event of anomaly of the satellite receiver the rate adjustment of the reference clock is suspended, and in the event of an error in the satellite receiver the periodic synchronization message, which is to be generated by the central computer in accordance with the configuration parameters, is generated on the basis of the R signal, and the monitor checks whether the transmission time contained in the synchronization message matches the actual transmission time and the distance between two successive synchronization messages is within an a priori specified tolerance interval and, if this is not the case, Modifies the synchronization message in such a way that each recipient recognizes the synchronization message as incorrect.
0011The essence of the present invention is that a master clock has three independent time sources that check and complement each other: (1) a periodic time signal from a satellite receiver, (2) a periodic time signal from a local reference clock and (3) a periodic time source an independent monitor. Normally, the time signal of the satellite receiver is used by a central computer of the master clock as the basis for generating the periodic synchronization message and the rate of the local reference clock is adapted to the rate of the satellite receiver. If an anomaly occurs, for example the field strength of the satellite signals changes outside of the normal interval, the reference clock is not corrected. If the central computer detects an error or failure of the satellite signal, the reference clock forms the basis for generating the periodic synchronization message. In parallel with the central computer, an independent monitor checks the content of each synchronization message and the time interval between successive synchronization messages without opening the synchronization message in order to detect errors that occurred before the synchronization message was closed. If the monitor detects an error, the expiring synchronization message is aborted or changed in such a way that every recipient can recognize the modified synchronization message as defective. This ensures with a high degree of probability that a syntactically correct synchronization message is also correct in terms of content. If two independent master clocks are used in a system, the failure of one master clock is tolerated in the system.
0012The main innovation of the present method concerns the construction of a master clock for generating periodic <i>fail-silent</i> Ethernet-compatible synchronization messages that provide the physical time, as defined by the GPS system, in a distributed real-time system and recognize and partially tolerate errors caused by hardware failure or security attacks. When using two or more such independent master clocks, a fault-tolerant synchronization system can be set up.
0013The methods described in the prior art for creating synchronization messages [3, 4] on the basis of satellite signals do not address problems of security and fault tolerance of a master clock.
0014The present invention discloses an innovative method and an apparatus for the reliable generation of synchronization messages in accordance with the SAE standard AS6802 from TT Ethernet and the IEEE standard 1588 for establishing a reliable physical time base in a distributed real-time system. According to the invention, a fail-silent master clock is constructed from three fault containment units, a satellite receiver, a central computer with a reference clock and an independent monitor with its own clock generator. Normally, the synchronization message is generated on the basis of the time signal from the satellite receiver and the rate of the reference clock is adapted to the rate of the satellite signal. In addition, the exact time interval between the periodic synchronization messages is monitored by an independent monitor. If the monitor detects an error, the outgoing synchronization message is modified in such a way that each recipient can recognize the modified synchronization message as being incorrect. If the time signal generated by the satellite receiver fails, the time signal from the reference clock is used as the basis for generating the synchronization message. If in a distributed real-time system a second<i>fail-silent</i> Master clock is used, the total failure of one of the two master clocks can be tolerated.
0015Further advantageous embodiments of the method according to the invention are described as follows, which can be implemented additionally, alternatively or in any combination with one another. It can be provided that<ul id="ul0001" list-style="none"><li>-) the monitor enters an initial phase after start-up, during which the distance between successive synchronization messages is measured and in the following operating phase uses the measured distance in order to detect an incorrect distance between two successive synchronization messages;</li><li>-) the central computer periodically generates a diagnostic message in which the operating status and any anomalies or errors of the overall system during the previous period are included;</li><li>-) the data stored in the configuration data block are secured with error-detecting codes;</li><li>-) the data stored in the configuration data block are secured with error-correcting codes;</li><li>-) the parameters stored in the configuration data block can only be changed if there is a physical connection between an external input device and the central computer;</li><li>-) the parameters stored in the configuration data block can be changed via the Internet with a cryptographically secured protocol;</li><li>-) the satellite receiver measures the field strength of the satellite signals and communicates this to the central computer in order to be able to detect anomalies in the satellite signals;</li><li>-) the synchronization message is secured by an electronic signature;</li><li>-) the syntactic structure of the synchronization message corresponds to the SAE standard AS6802;</li><li>-) the syntactic structure of the synchronization message corresponds to the IEEE Standard 1588;</li><li>-) the S signals are generated on the basis of the satellite signals from the GPS system, and / or the S signals are generated on the basis of the satellite signals from the Galileo system, and / or the S signals are generated on the basis of the satellite signals from the GLANOSS system to be generated;</li><li>-) After the end of the failure of the satellite receiver, the R signal generated by the reference clock is routed to the existing S signal with a maximum predefined rate difference in order to reduce the clock status difference between the R signal and the S signal that was accumulated during the failure .</li></ul>
0016Furthermore, the invention is achieved with an apparatus mentioned at the beginning, in particular a master clock, for performing the method according to the invention.
0017Preferably, the apparatus derives the R signal of the reference clock derived from a temperature compensated quartz, or the R signal of the reference clock is derived from an atomic clock.
0018The present invention is explained by way of example with reference to the following drawing. It shows the only one<figref idref="f0001">Figure 1</figref> the internal structure of a fail-silent master clock.
0019<figref idref="f0001">Fig. 1</figref> FIG. 13 shows a structural diagram of FIG <i>fail-silent</i> Master clock. The master clock consists of three fault containment units (FCUs), (1) the satellite receiver<b>110,</b> (2) the central computer <b>140</b> with the reference clock <b>130,</b> and (3) the monitor <b>120.</b> The parameters that define the exact function of the master clock are in the configuration data block <b>210</b> saved. The one in the configuration data block<b>210</b> Stored data can be secured with error-detecting or error-correcting codes. Loading the parameters into the configuration data block<b>210</b> takes place via a physical connection between an input device and the master clock in order to prevent a security attack via the Internet. Alternatively, the configuration data block can be loaded via the Internet using a cryptographically secured protocol.
0020The satellite receiver <b>110</b> sends periodic time signals that <i>S signals,</i> to the central computer <b>140.</b> The independent reference clock sends in parallel <b>130</b> periodic time signals, <i>the R signals,</i> to the central computer <b>140.</b> In the error-free state, the S signals and the nominal R signals should be identical in gear and phase.
0021The reference clock contains a precise clock, for example a temperature-compensated oscillator or an atomic clock. The primary signal generated by this precise clock is replaced by a digital<i>Micro</i>/<i>Macro-tick transformation unit</i> in the reference clock <b>130</b> transformed into the R signal that is at the interface to the central computer <b>140</b> is expected. This digital<i>Micro</i>/<i>Macro-tick transformation unit</i> can be parameterized by the central computer so that the status and rate of the reference clock <b>130</b> output R signal can be modified digitally. Normally, the central computer<b>140</b> the difference between the time signal from the satellite receiver <b>110,</b> the <i>S signal,</i> and the actual time signal from the reference clock <b>130,</b> the <i>R signal,</i> measured and the <i>Micro</i>/<i>Macro-tick transformation unit</i> parameterized in such a way that the actual R signal from the reference clock <b>130</b> the nominal R signal (given by the S signal of the satellite receiver). This adjustment is done in two ways. The status of the R signal is briefly adapted to the status of the S signal. In the long term, the rate of the R signal is adapted to the rate of the S signal. By adjusting the rate of the reference clock<b>130</b> to the S signal given by the satellite system, the accuracy of the drift of the R signal can be improved by up to two orders of magnitude [7, p. 72].
0022The satellite receiver <b>130</b> receives the navigation signals from a navigation satellite system [6], eg from the GPS system, the GLANOSS system or the future Galileo system and monitors the field strength of these signals. This monitoring of the field strength is carried out in order to discover possible security attacks on the satellite signal, e.g. the GPS signal. In the error-free state, the field strengths of the GPS signal are in one<i>common interval,</i> which is determined by measuring the field strengths occurring over a long period of time. If these field strengths change spontaneously and drastically and are outside the usual interval, this indicates a security attack. Basically, a distinction can be made between two types of security attacks on a satellite signal:<i>Blocking</i> or <i>Spoofing</i> [5]. At the<i>Blocking</i> the GPS signal is disturbed so that the satellite receiver cannot receive syntactically correct messages. <i>Blocking</i> Attacks can be easily recognized by the satellite receiver, as the signal virtually fails. At the<i>Spoofing</i> a falsified syntactically correct signal is generated in order to mislead the recipient. Since the fake spoofing signal is supposed to mask the authentic GPS signal, the field strength of the spoofing signal must be outside the usual range. Between the usual field strength and a clearly recognized fault condition due to spoofing, there is an intermediate range, which is referred to as an anomaly. As soon as an anomaly is detected, the rate correction of the reference watch is suspended in order to prevent a possible incorrect adjustment of the rate of the reference watch to an inauthentic satellite signal.
0023If there are no errors, the central computer generates <b>140</b> based on the S signal from the satellite receiver <b>110</b> periodically an Ethernet compatible synchronization message <b>220,</b> which corresponds to the SAE standard AS6802 from TT Ethernet or the IEEE standard 1588. The parameters of this message - frequency and phase - are included in the configuration data block<b>210</b> taken. If required, the synchronization message can be protected by an electronic signature [7] to ensure the authenticity of the message. The central computer<b>140</b> closes the closed synchronization message <b>220</b> by calculating and appending the CRC polynomial and sends the message to the designated recipient at exactly the time it is sent in the message.
0024When the S signal at the interface between the satellite receiver <b>110</b> and the central computer <b>120</b> fails or if the central computer detects a spoofing attack on the satellite signal, the central computer generates <b>140</b> the synchronization message <b>220</b> based on the R signal from the reference clock <b>130.</b> As soon as a correct S-signal is available again, the central computer determines the difference between the R-signal and the S-signal and changes the parameters of the <i>Micro</i>/<i>Macro-tick transformation unit</i> the rate of the reference clock <b>130</b> until the R signal again matches the S signal. A maximum<i>a priori</i> specified in the configuration data block <b>210</b> contained deviation of the rate of the reference clock from the rate of the satellite signal not exceeded. As soon as the level of the R signal has reached the level of the S signal, the central computer forms<b>140</b> the synchronization message again on the basis of the S signal.
0025In normal operation, the expiring closed synchronization message <b>220</b> from the monitor <b>120</b> in the <i>cut through</i> Process reviewed. The time interval between two successive synchronization messages<b>220</b> with the clock of the monitor <b>120</b> measured and the content of the synchronization message checked. If the time interval between two consecutive synchronization messages<b>220</b> is outside a predetermined tolerance interval or if a content-related error is detected, the expiring closed synchronization message <b>220</b> changed in such a way, for example by premature termination of the transmission process, that every recipient of the synchronization message <b>220</b> can recognize the synchronization message as faulty. In addition, the monitor sends an error message with the reason for the error to the central computer<b>140.</b>
0026The tolerance interval by which the distance between two successive synchronization messages <b>220</b> is allowed to lie, is in the initialization phase of the master clock by measuring the message interval between a set of synchronization messages by the monitor <b>120</b> certainly. Alternatively, the length of this tolerance interval can be specified in the configuration data block<b>210</b> can be specified.
0027The central computer <b>140</b> sends periodically (the period is in the configuration data block <b>210</b> set) a diagnostic message to a designated diagnostic computer. In this diagnosis message, all essential parameters, such as measured field strength of the satellite signal, rate and level difference of the actual R signal and any error messages that have occurred during the last period, are communicated to the diagnosis computer.
Literature cited:
0028<ol id="ol0001" ol-style=""><li>[1] <patcit id="pcit0003" dnum="US5694542A"><text>U.S. 5,694,542 Kopetz, H.</text></patcit>. <i>Time-triggered communication control unit and communication method.</i> Granted December 2,1997.</li><li>[2] <patcit id="pcit0004" dnum="US7839868B"><text>U.S. 7,839,868. Kopetz, H.</text></patcit>. <i>Communication method and system for the transmission of time-driven and event-driven Ethernet messages.</i> Granted November 23, 2010.</li><li>[3] <patcit id="pcit0005" dnum="US8089991B"><text>US 8,089,991 Ungermann</text></patcit>. <i>Network and method for clock synchronization of clusters in a time triggered network.</i> Granted January 3, 2012.</li><li>[4] <patcit id="pcit0006" dnum="US8018950B"><text>U.S. 8,018,950 Wu, et al</text></patcit>. <i>Systems and methods for distributing GPS clock to communications devices.</i> Granted September 13, 2011</li><li>[5] <nplcit id="ncit0002" npl-type="b"><text>Warner, J. et. al. GPS Spoofing Countermeasures, Los Alamos National Laboratory. URL: http://lewisperdue.com/DieByWire/GPS-Vulnerability-LosAlamos.pdf</text></nplcit></li><li>[6] <nplcit id="ncit0003" npl-type="b"><text>Hofmann-Wellenhof, B. et al. GNSS - Global Navigation Satellite Systems: GPS, GLONASS, Galileo, and more. Springer Verlag, 2007</text></nplcit></li><li>[7] <nplcit id="ncit0004" npl-type="b"><text>Kopetz, H. Real-Time Systems, Design Principles for Distributed Embedded Applications. Springer publishing house. 2011</text></nplcit>.</li><li>[8] <nplcit id="ncit0005" npl-type="s" url="http://standards.sae.org/as6802"><text>SAE standard AS6802 from TT Ethernet. URL: http://standards.sae.org/as6802</text></nplcit></li><li>[9] <nplcit id="ncit0006" npl-type="s" url="http://www.ieee1588.com"><text>IEEE 1588 Standard for a Precision Clock Synchronization Protocol for Network Measurement and Control Systems. URL: http://www.ieee1588.com/</text></nplcit></li></ol>
1 sheet
Sheet 1
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO2004066530A1 | Cites | World Intellectual Property Organization (WIPO) | – |
| US2009225743A1 | Cites | United States of America | – |
| US6256507B1 | Cites | United States of America | – |
| US6687752B1 | Cites | United States of America | – |
| US7800534B1 | Cites | United States of America | – |
| KOPETZ H ET AL: "Integration of Internal and External Clock Synchronization by the Combination of Clock-State and Clock-Rate Correction in Fault-Tolerant Distributed Systems", REAL-TIME SYSTEMS SYMPOSIUM, 2004. PROCEEDINGS. 25TH IEEE INTERNATIONA L LISBON, PORTUGAL 05-08 DEC. 2004, PISCATAWAY, NJ, USA,IEEE, 5 December 2004 (2004-12-05), pages 415 - 425, XP010759558, ISBN: 978-0-7695-2247-0, DOI: 10.1109/REAL.2004.27 | Non-patent | – | Examiner |
| JON S WARNER ET AL: "GPS Spoofing Countermeasures", INTERNET CITATION, 1. Dezember 2003 (2003-12-01), XP007914429, Gefunden im Internet: URL:http://www.homelandsecurity.org/bullet in/dual%20benefit/warner_gps_spoofing.html [gefunden am 2010-08-13] | Non-patent | – | – |
| KOPETZ H ET AL: "Integration of Internal and External Clock Synchronization by the Combination of Clock-State and Clock-Rate Correction in Fault-Tolerant Distributed Systems", REAL-TIME SYSTEMS SYMPOSIUM, 2004. PROCEEDINGS. 25TH IEEE INTERNATIONA L LISBON, PORTUGAL 05-08 DEC. 2004, PISCATAWAY, NJ, USA,IEEE, 5 December 2004 (2004-12-05), pages 415-425, XP010759558, DOI: 10.1109/REAL.2004.27 ISBN: 978-0-7695-2247-0 | Non-patent | – | – |
9 members in 6 offices
Members9
| Document | Office | Kind | |
|---|---|---|---|
| AT512743A1 | Austria | A1 | |
| WO2013152378A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP2803154A1 | European Patent Office (EPO) | A1 | |
| CN104365042A | China | A | |
| US2015098492A1 | United States of America | A1 | |
| JP2015523613A | Japan | A | |
| US9130661B2 | United States of America | B2 | |
| JP6113829B2 | Japan | B2 | |
| EP2803154B1This record | European Patent Office (EPO) | B1 |
66 legal events, as 8 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapse because of not paying annual feesLapsedMM01 | MM01 | AT | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed because of non-payment of the annual feeLapsedMM | MM | BE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filed against granted patent, or epo opposition proceedings concluded without decisionGrantedR097 | R097 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent invalid in the netherlands as no translation has been filedMP | MP | NL | |
| Invalidated european patentMG4D | MG4D | LT | |
| Reference to at number (ep patent validated in austria)REF | REF | AT | |
| European patents granted designating irelandGrantedLANGUAGE OF EP DOCUMENT: GERMANFG4D | FG4D | IE | |
| Dpma publication of mentioned ep patent grantGrantedR096 | R096 | DE | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Designated contracting statesAK | AK | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE PATENT HAS BEEN GRANTEDSTAA | STAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Intention to grant announcedINTG | INTG | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: GRANT OF PATENT IS INTENDEDSTAA | STAA | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: EXAMINATION IS IN PROGRESSSTAA | STAA | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | EP | |
| Request for extension of the european patent (deleted)DAX | DAX | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 2803154
- Publication, DOCDB
- 2803154
- Publication, EPODOC
- EP2803154
- Application
- 13724148
- Application, DOCDB
- 13724148
- Application, EPODOC
- EP20130724148
Titles4
- German
- VERFAHREN UND MASTERCLOCK ZUR ERSTELLUNG VON FAIL-SILENT SYNCHRONISATIONSNACHRICHTEN
- English
- METHOD AND MASTERCLOCK FOR PROVIDING FAIL-SILENT SYNCHRONISATION MESSAGES
- French
- PROCÉDÉ ET HORLOGE MAÎTRE AFIN DE METTRE A DISPOSITION DE MESSAGES DE SYNCHRONISATION
- English
- METHOD AND MASTERCLOCK FOR PROVIDING FAIL-SILENT SYNCHRONISATION MESSAGES
Classification
- CPC, 8
- H04B1/7087
- H04J3/0641
- H04J3/0661
- H04J3/0688
- H04L41/0654
- H04L43/106
- G06F1/14
- H04L1/22
- IPC, 3
- H04J3 06
- G01S19 21
- H04L12 26
Designated states38
- Contracting states, 38
- Albania
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Croatia
- Hungary
- Ireland
- Iceland
- Italy
- Liechtenstein
- Lithuania
- Luxembourg
- Latvia
and 14 moreShow fewer
- Monaco
- North Macedonia
- Malta
- Netherlands (Kingdom of the)
- Norway
- Poland
- Portugal
- Romania
- Serbia
- Sweden
- Slovenia
- Slovakia
- San Marino
- Türkiye
