Domain controller failure mode judgment and redundancy control method and control system

By combining fault tree analysis and machine learning with a dual CAN-FD bus architecture, the health status of the chassis domain controller is monitored in real time and redundant control is implemented, solving the safety and reliability issues caused by failures in traditional chassis control systems and achieving efficient redundant control and rapid fault response.

CN120630935APending Publication Date: 2025-09-12ZHUHAI JOINT INNOVATION RESEARCH INSTITUTE +1

Patent Information

Application Number
CN202510612413.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-13
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

Traditional chassis control systems use a single-controller architecture. Once a controller fails, it may cause system failure and affect driving safety. Existing redundant control schemes have problems such as limited bandwidth, detection delays, and insufficient optimization of coordination mechanisms.

Method used

The fault tree analysis method is used to build a failure mode library, combined with a machine learning algorithm to determine the health status, real-time monitoring data and a dual CAN-FD bus dual-redundant architecture to achieve real-time judgment of the health status and failure mode prediction of the chassis domain controller, and implement redundant control strategies based on the severity of the fault, including controller switching, fault isolation and degraded operation.

Benefits of technology

It improves the security and reliability of the chassis domain controller, ensures the continuous and stable operation of key chassis functions, reduces the switching delay of redundant control, and enhances the system's fault tolerance and anti-interference capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120630935A_ABST
    Figure CN120630935A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of automotive electronics and intelligent control, and discloses a domain controller failure mode judgment and redundancy control method and system, and the method comprises the steps: collecting the operation state information of a chassis domain controller; a failure tree analysis method is adopted, a failure mode library of the chassis domain controller is constructed according to the operation state information, failure modes are classified, and the failure mode library comprises controller failures, communication link anomalies, sensor failures and power supply anomalies; in combination with real-time monitoring data, the health state is judged by utilizing a machine learning algorithm, the fault mode is predicted, and the severity of the fault mode is determined; according to the method, the corresponding redundancy control strategy is determined according to the severity of the fault mode, the redundancy control strategy is used for redundancy control, the redundancy control is carried out according to the severity of different fault modes, continuous and stable operation of key chassis functions is ensured, and the safety and reliability of the chassis domain controller are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of automotive electronics and intelligent control technology, and in particular to a domain controller failure mode judgment and redundancy control method and control system. Background Art

[0002] In recent years, with the development of automotive electrical / electronic architecture (E / E architecture), chassis domain controllers (CDCs) have become an essential component of smart cars. CDCs are responsible for key chassis functions such as braking, steering, and suspension, and their reliability and safety are crucial to overall vehicle performance.

[0003] Traditional chassis control systems typically use a single-controller architecture. A controller failure can cause system failure and impact driving safety. Therefore, improving the reliability and security of chassis domain controllers has become a key issue. Summary of the Invention

[0004] In view of this, the present invention provides a domain controller failure mode judgment and redundancy control method and control system to solve the problem of improving the reliability and safety of the chassis domain controller.

[0005] In a first aspect, the present invention provides a method for determining failure modes and controlling redundancy of a domain controller, the method comprising:

[0006] Collect the operating status information of the chassis domain controller, which includes sensor data, control instruction execution status, and communication link status;

[0007] Using the fault tree analysis method, a failure mode library of the chassis domain controller is constructed based on the operating status information, and the failure modes are classified. The failure mode library includes controller failure, communication link abnormality, sensor failure, and power supply abnormality.

[0008] Combined with real-time monitoring data, machine learning algorithms are used to determine health status, predict failure modes, and determine the severity of failure modes;

[0009] The corresponding redundant control strategy is determined according to the severity of the failure mode, and the redundant control strategy is used to perform redundant control.

[0010] The present invention collects the operating status information of the chassis domain controller, analyzes the failure mode using the fault tree analysis method, and combines real-time monitoring data with machine learning algorithms to achieve real-time judgment of the chassis domain controller's health status and prediction of failure modes. It also performs redundant control based on the severity of different failure modes, ensuring the continuous and stable operation of key chassis functions and improving the safety and reliability of the chassis domain controller.

[0011] In an optional embodiment, the severity of the fault mode includes a minor abnormality, a serious abnormality, and a fault. The corresponding redundancy control strategy is determined according to the severity of the fault mode, including:

[0012] When the severity of the fault mode is slightly abnormal, the redundant control strategy is to adjust the control parameters and optimize the algorithm;

[0013] When the severity of the fault mode is severe abnormality, the redundant control strategy is to trigger controller switching;

[0014] When the severity of the fault mode is failure, the redundancy control strategy is to perform fault isolation, cut off the faulty unit, and enter a degraded operation mode according to the situation.

[0015] The present invention realizes efficient domain controller redundancy control by adopting corresponding redundancy control strategies according to the severity of different failure modes, thereby improving safety.

[0016] In an optional embodiment, the machine learning algorithm uses any one of support vector machines, random forests, and deep learning models to perform fault prediction.

[0017] The present invention predicts faults by adopting a machine learning model to improve the accuracy of fault prediction results.

[0018] In a second aspect, the present invention provides a domain controller failure mode judgment and redundancy control system, the system comprising:

[0019] The status monitoring module is used to collect the operating status information of the chassis domain controller, which includes sensor data, control instruction execution status and communication link status;

[0020] The fault mode and judgment module includes a fault mode classification module and a fault mode classification module;

[0021] The failure mode classification module is used to build a failure mode library for the chassis domain controller based on operating status information using the fault tree analysis method and classify the failure modes. The failure mode library includes controller failure, communication link anomaly, sensor failure, and power supply anomaly.

[0022] The failure mode determination module is used to combine real-time monitoring data and use machine learning algorithms to determine the health status, predict the failure mode, and determine the severity of the failure mode;

[0023] The redundant control module is used to determine the corresponding redundant control strategy according to the severity of the failure mode and perform redundant control using the redundant control strategy.

[0024] The present invention collects the operating status information of the chassis domain controller through the status monitoring module. The fault mode and judgment module uses the fault tree analysis method to analyze the failure mode. Combined with real-time monitoring data and machine learning algorithms, it realizes real-time judgment of the health status of the chassis domain controller and prediction of the failure mode. The redundant control module performs redundant control according to the severity of different failure modes, ensuring the continuous and stable operation of key chassis functions and improving the safety and reliability of the chassis domain controller.

[0025] In an optional embodiment, the system further includes a communication management module, which adopts a dual CAN-FD bus dual redundant architecture and utilizes the dual CAN-FD bus for data transmission.

[0026] The present invention improves anti-interference capability by adopting a dual CAN-FD bus dual redundant architecture for communication management.

[0027] In an optional embodiment, the system further includes a redundant execution module, which includes a dual-controller hot backup and an FPGA heterogeneous computing architecture, and the dual-controller hot backup is used to implement switching between the active controller and the standby controller.

[0028] The present invention ensures the fault tolerance of key tasks through redundant execution modules.

[0029] In an optional embodiment, the FPGA heterogeneous computing architecture adopts a dual-core heterogeneous architecture, which includes a security core and a performance core. The security core adopts Lockstep mode to perform key chassis control tasks; the performance core is used for data processing and communication management.

[0030] The present invention adopts a dual-core heterogeneous architecture, uses the safety core to perform key chassis control tasks, and uses the performance core to perform data processing and communication management, so as to ensure the high reliability of key tasks while improving computing efficiency.

[0031] In an optional implementation, the operation status monitoring module collects the operation status information of the chassis domain controller through the vehicle-mounted sensor network and transmits it to the fault mode classification module through the dual CAN-FD bus.

[0032] The present invention collects the operating status information of the chassis domain controller by utilizing the vehicle-mounted sensor network to fully perceive the operating parameters of the chassis domain controller, and transmits data through the dual CAN-FD bus to ensure data transmission reliability.

[0033] In an optional implementation, the security core in the FPGA heterogeneous computing architecture adopts a triple redundant voting mechanism.

[0034] The present invention ensures the execution reliability of key tasks by adopting a triple redundant voting mechanism.

[0035] In an optional implementation, the redundant control module includes a main controller and a backup controller. A heartbeat monitoring mechanism is used between the main controller and the backup controller. When the main controller fails, the controller switches to the backup controller.

[0036] The present invention provides a main controller and a backup controller to ensure the normal operation of the system and improve the reliability of the system.

[0037] In a third aspect, the present invention provides a computer device comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the domain controller failure mode judgment and redundancy control method of the first aspect or any corresponding embodiment thereof by executing the computer instructions.

[0038] In a fourth aspect, the present invention provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to enable a computer to execute the domain controller failure mode determination and redundancy control method of the above-mentioned first aspect or any corresponding embodiment thereof.

[0039] In a fifth aspect, the present invention provides a computer program product comprising computer instructions for causing a computer to execute the domain controller failure mode determination and redundancy control method of the first aspect or any corresponding embodiment thereof. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the specific embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0041] Figure 1 is a flow chart of a method for determining failure mode and redundancy control of a domain controller according to an embodiment of the present invention;

[0042] Figure 2is a schematic diagram of a domain controller failure mode determination and redundancy control system according to an embodiment of the present invention;

[0043] Figure 3 is a schematic diagram of a dual CAN-FD bus architecture according to an embodiment of the present invention;

[0044] Figure 4 is a schematic diagram of an FPGA dual-core heterogeneous architecture according to an embodiment of the present invention;

[0045] Figure 5 This is a workflow diagram of dual CAN-FD buses and FPGA dual-core heterogeneity according to an embodiment of the present invention;

[0046] Figure 6 Schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0047] To make the purpose, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of the present invention.

[0048] Traditional chassis control systems typically utilize a single-controller architecture. A controller failure can lead to system failure and compromise driving safety. Therefore, redundant control strategies are introduced to improve system fault tolerance and reliability. Common redundant designs include dual-controller hot standby, dual CAN-FD (CAN with Flexible Data rate) bus architectures, and FPGA (Field Programmable Gate Array) dual-core heterogeneous designs. These ensure that the system maintains basic functionality even in the event of a critical failure.

[0049] Current redundant control schemes still face some challenges. For example, the traditional CAN bus (Controller Area Network) has limited bandwidth and cannot meet the data transmission requirements of complex control systems. The existing redundant control switching mechanism may have detection delays, affecting real-time performance. The coordination mechanism between different control modules needs to be further optimized to reduce system recovery time.

[0050] According to an embodiment of the present invention, an embodiment of a domain controller failure mode judgment and redundancy control method is provided, which is applicable to smart cars, autonomous driving systems and other automotive electronic control systems with high safety and real-time requirements. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0051] In this embodiment, a method for determining failure mode and redundancy control of a domain controller is provided, which can be used in a mobile terminal. Figure 1 FIG. 1 is a flow chart of a method for determining failure mode and controlling redundancy of a domain controller according to an embodiment of the present invention. Figure 1 As shown, the process includes the following steps:

[0052] Step S101: Collect the operating status information of the chassis domain controller.

[0053] In an embodiment of the present invention, the operating data of the chassis domain controller is collected through the vehicle-mounted sensor network, and the operating status information includes sensor data, control instruction execution status and communication link status.

[0054] In step S102 , a fault tree analysis method is used to construct a failure mode library of the chassis domain controller according to the operation status information, and the failure modes are classified.

[0055] In an embodiment of the present invention, a fault tree analysis (FTA) method is adopted to construct a failure mode library of the chassis domain controller using the previously collected operating status information, and classify different failure modes. The failure mode library includes categories such as controller failure, communication link anomaly, sensor failure, and power supply anomaly.

[0056] Step S103 , combining the real-time monitoring data, using a machine learning algorithm to judge the health status, and predict the failure mode to determine the severity of the failure mode.

[0057] In this embodiment of the present invention, a machine learning algorithm is used to determine the current system health status and predict possible failure modes, in conjunction with real-time monitoring data. The health status and failure mode are related, and the health status and failure mode predictions are determined based on real-time monitoring data. The machine learning algorithm is combined with fault tree analysis for reasoning, and the failure probability is calculated using a Bayesian network.

[0058] Specifically, the machine learning algorithm uses any one of the support vector machine (SVM), random forest and deep learning models to perform fault prediction to improve the accuracy of the fault prediction results.

[0059] Step S104 : determining a corresponding redundant control strategy according to the severity of the failure mode, and performing redundant control using the redundant control strategy.

[0060] In this embodiment of the present invention, the health status is related to the failure mode. The health status is evaluated based on monitoring data. Different health states correspond to different failure modes, which in turn determine the applicable redundancy control strategy. Based on the severity of the failure mode, an appropriate redundancy control strategy is selected, including controller switching, fault isolation, and degraded operation mode. Redundancy control is then performed according to the redundancy control strategy.

[0061] Among them, the controller switching strategy is dynamically adjusted based on the fault detection results, including hot standby switching, cold standby switching and task migration mode.

[0062] Compared with the prior art, the embodiments of the present invention improve the recognition accuracy of failure modes, adopt an intelligent prediction algorithm, and reduce the switching delay of redundant control.

[0063] Specifically, the severity of the fault mode includes minor abnormality, serious abnormality and fault. The above step S104 includes:

[0064] Step S1041: When the severity of the fault mode is slightly abnormal, the redundant control strategy is to adjust the control parameters and optimize the algorithm.

[0065] Step S1042: When the severity of the fault mode is severe abnormality, the redundant control strategy is to trigger controller switching.

[0066] Step S1043: When the severity of the fault mode is fault, the redundancy control strategy is to perform fault isolation, cut off the faulty unit, and enter a degraded operation mode according to the situation.

[0067] In the embodiment of the present invention, the health status includes normal, slight abnormality, serious abnormality, and fault. The health status is related to the fault mode, and the severity of the corresponding fault mode is no fault, slight abnormality, serious abnormality, and fault.

[0068] When the severity of the fault mode is slightly abnormal, the redundant control strategy is to adjust the control parameters, optimize the algorithm, and improve the robustness of the system.

[0069] When the severity of the failure mode is severe abnormality, the redundant control strategy is to trigger controller switching, for example, switching from the main controller to the backup controller to ensure normal operation of the system.

[0070] When the severity of the fault mode is failure, the redundant control strategy is to perform fault isolation, cut off the faulty unit, and enter a degraded operation mode according to the situation, such as reducing the output of the execution unit or limiting the function to ensure minimum safe operation.

[0071] By adopting corresponding redundancy control strategies according to the severity of different failure modes, efficient domain controller redundancy control can be achieved to improve safety.

[0072] The domain controller failure mode judgment and redundancy control method provided in this embodiment collects the operating status information of the chassis domain controller, analyzes the failure mode using the fault tree analysis method, and combines real-time monitoring data with machine learning algorithms to achieve real-time judgment of the chassis domain controller's health status and failure mode prediction. Redundancy control is also performed based on the severity of different failure modes, ensuring the continuous and stable operation of key chassis functions and improving the safety and reliability of the chassis domain controller.

[0073] The embodiment of the present invention also provides a domain controller failure mode judgment and redundancy control system, such as Figure 2 As shown, the system includes:

[0074] The status monitoring module is used to collect the operating status information of the chassis domain controller, which includes sensor data, control instruction execution status and communication link status;

[0075] The fault mode and judgment module includes a fault mode classification module and a fault mode classification module;

[0076] The failure mode classification module is used to build a failure mode library for the chassis domain controller based on operating status information using the fault tree analysis method and classify the failure modes. The failure mode library includes controller failure, communication link anomaly, sensor failure, and power supply anomaly.

[0077] The failure mode determination module is used to combine real-time monitoring data and use machine learning algorithms to determine the health status, predict the failure mode, and determine the severity of the failure mode;

[0078] The redundant control module is used to determine the corresponding redundant control strategy according to the severity of the failure mode and perform redundant control using the redundant control strategy.

[0079] In practical applications, the operating status monitoring module collects operating status information from the chassis domain controller via onboard sensors and a communication bus, and transmits it to the fault mode classification module via a dual CAN-FD bus. When the fault mode classification module detects a potential fault, indicating a deviation in the system's operating status, the redundancy control module implements a corresponding redundancy control strategy based on the severity and impact of the fault mode.

[0080] For example, when a communication anomaly is detected, the system switches to the backup CAN-FD channel. If a controller anomaly is detected, the backup controller is started and the control parameters are adjusted.

[0081] By utilizing the on-board sensor network to collect the operating status information of the chassis domain controller, the operating parameters of the chassis domain controller can be fully perceived, and data transmission is carried out through the dual CAN-FD bus to ensure data transmission reliability.

[0082] Specifically, the redundant control module includes a main controller and a backup controller. A heartbeat monitoring mechanism is used between the main controller and the backup controller. When the main controller fails, the system switches to the backup controller within 10ms.

[0083] The domain controller failure mode judgment and redundancy control system provided in this embodiment collects operating status information of the chassis domain controller through a status monitoring module. The failure mode and judgment module uses a fault tree analysis method to analyze failure modes. Combined with real-time monitoring data and machine learning algorithms, it realizes real-time judgment of the health status of the chassis domain controller and prediction of failure modes. The redundancy control module performs redundant control according to the severity of different failure modes, ensuring the continuous and stable operation of key chassis functions and improving the safety and reliability of the chassis domain controller.

[0084] In some optional embodiments, such as Figure 2 As shown, the system also includes a communication management module, which adopts a dual CAN-FD bus dual redundant architecture and uses dual CAN-FD buses for data transmission.

[0085] In the embodiment of the present invention, Figure 3 As shown, the dual CAN-FD bus architecture utilizes two physical channels for transmission: a primary CAN-FD bus and a secondary CAN-FD bus. The primary CAN-FD bus has a data length of 64 bytes, and the secondary CAN-FD bus utilizes a 0.3mm shield and is physically isolated from the primary CAN-FD bus by over 15cm. The primary and secondary CAN-FD buses operate independently, each with its own physical channel and differential signaling, ensuring real-time redundancy switching and interference immunity.

[0086] At the same time, the central node adopts a dual-switch hot standby mechanism to ensure communication continuity.

[0087] ECU nodes include brake system ECU, steering system ECU, suspension system ECU, other chassis ECUs, and chassis domain controllers using FPGA dual-core heterogeneous design.

[0088] The dual CAN-FD bus architecture adopts a star topology dual redundancy design to ensure protection against common cause failures and automatic switching mechanism.

[0089] The dual CAN-FD bus architecture ensures real-time transmission of critical data and improves the anti-interference ability of communication.

[0090] In some optional embodiments, such as Figure 2 As shown, the system also includes a redundant execution module, which includes a dual-controller hot backup and an FPGA heterogeneous computing architecture. The dual-controller hot backup is used to realize switching between the main controller and the backup controller.

[0091] In this embodiment of the present invention, the redundant execution module utilizes dual-controller hot backup and an FPGA heterogeneous computing architecture to ensure fault tolerance for critical tasks. Furthermore, it acts on the vehicle chassis system (brakes, steering, and suspension) to ensure stable operation even if a domain controller fails.

[0092] Specifically, the FPGA heterogeneous computing architecture adopts a dual-core heterogeneous architecture, which includes a security core and a performance core. The security core adopts the Lockstep mode to perform key chassis control tasks; the performance core is used for data processing and communication management.

[0093] In the embodiment of the present invention, Figure 4 As shown in the figure, an FPGA dual-core heterogeneous design is adopted, with a safety core and a performance core set separately to achieve efficient fault-tolerant control.

[0094] The safety core operates in Lockstep mode and is responsible for executing critical chassis control tasks, such as braking and steering, ensuring high reliability. The Lockstep processing core consists of Core A (main execution) and Core B (mirror execution). Comparators verify execution results to achieve critical function control. These critical functions include braking and steering, which are critical to vehicle safety. A three-level fault tolerance strategy is employed: first discrepancy: instruction tampering (within 2ms); second discrepancy: switching to a backup core; and final anomaly: issuing an alarm and entering a safe state. Redundant fault migration time is less than 5ms.

[0095] The performance core is responsible for data processing and communication management, improving computing efficiency. The high-performance processing core utilizes a dynamic priority scheduling algorithm, reducing the standard deviation of task response time to 3ms and optimizing performance by 70%. Non-critical functional processing includes: data processing for sensor data fusion and environmental perception; communication processing for network data transmission and diagnostic information processing; suspension system control and comfort optimization; and system resource monitoring for CPU utilization tracking, dynamic memory usage adjustment, and load balancing algorithm optimization.

[0096] The security core and the performance core are connected through the inter-core data channel to control data flow and interact with the outside world through the critical mission interface and non-critical mission interface respectively.

[0097] This architecture supports inter-core data isolation to prevent fault propagation and features real-time self-diagnosis, enabling rapid fault detection and isolation to prevent interference. Furthermore, combined with redundant control strategies, the system completes failover within 100ms, ensuring rapid response and enhancing the system's overall fault tolerance and stability.

[0098] In some optional implementations, the security core in the FPGA heterogeneous computing architecture adopts a triple redundant voting mechanism.

[0099] In the embodiment of the present invention, the safety core adopts a triple redundant voting mechanism to ensure the execution reliability of key tasks.

[0100] This embodiment of the present invention was tested under the functional safety requirements of ISO 26262 ASIL D. The results showed that the system can detect critical faults within 50ms and complete redundancy switchover within 100ms. The mean time between failures (MTBF) reached 1×10^6 hours, significantly improving the safety and reliability of the chassis domain controller.

[0101] like Figure 5 As shown, Figure 5 The following is a workflow diagram based on dual CAN-FD buses and FPGA dual-core heterogeneous architecture, which specifically includes the following steps:

[0102] S1: Dual CAN-FD bus initialization: The process begins by initializing the CAN-FD bus to prepare for subsequent data communication.

[0103] S2: Activate the FPGA dual-core heterogeneous processing unit: After completing bus initialization, activate the FPGA dual-core heterogeneous processing unit and start the security core and performance core.

[0104] S3: Parallel processing of the security core and the performance core: The security core uses Lockstep mode, and the performance core performs non-critical tasks;

[0105] S4: The security core performs key functions, and the performance core performs data processing and fusion;

[0106] S5: Fault detection: If a fault is detected, the system enters the fault tolerance phase and switches to a redundant path to cope with the fault. If no fault is detected, the system proceeds to the next step.

[0107] S6: System status update: Regardless of whether fault tolerance is performed, the system status is updated to complete the work cycle.

[0108] The embodiment of the present invention also provides a computer device having the above Figure 2 The domain controller failure mode judgment and redundant control system shown.

[0109] See also Figure 6 , Figure 6 is a structural diagram of a computer device provided by an optional embodiment of the present invention, such as Figure 6 As shown, the computer device includes: one or more processors 10, memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components utilize different buses to communicate with each other and can be installed on a common mainboard or installed in other ways as needed. The processor can process the instructions executed in the computer device, including instructions stored in the memory or on the memory to display the graphical information of the GUI on an external input / output device (such as, a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Equally, multiple computer devices can be connected, and each device provides part of the necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 6 A processor 10 is taken as an example.

[0110] The processor 10 may be a central processing unit, a network processor, or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit, a programmable logic device, or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic, or any combination thereof.

[0111] The memory 20 stores instructions that can be executed by at least one processor 10, so as to enable at least one processor 10 to execute the method shown in the above embodiment.

[0112] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created based on the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely located relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0113] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid-state drive; the memory 20 may also include a combination of the above types of memory.

[0114] The computer device further includes an input device 30 and an output device 40. The processor 10, the memory 20, the input device 30 and the output device 40 may be connected via a bus or other means. Figure 6 The bus connection is taken as an example.

[0115] The input device 30 can receive input digital or character information and generate key signal input related to user settings and function control of the computer device, such as a touch screen, etc. The output device 40 can include a display device, etc.

[0116] The embodiment of the present invention also provides a computer-readable storage medium. The above-mentioned method according to the embodiment of the present invention can be implemented in hardware, firmware, or implemented as a computer code that can be recorded in a storage medium, or implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and downloaded through a network and will be stored in a local storage medium, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state drive, etc.; further, the storage medium can also include a combination of the above-mentioned types of memory. It can be understood that a computer, a processor, a microprocessor controller or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor or hardware, the method shown in the above embodiment is implemented.

[0117] A portion of the present invention may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present invention through the operation of the computer. Those skilled in the art should understand that the form in which the computer program instruction exists in a computer-readable medium includes, but is not limited to, a source file, an executable file, an installation package file, etc. Accordingly, the way in which the computer program instruction is executed by the computer includes, but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium may be any available computer-readable storage medium or communication medium that can be accessed by the computer.

[0118] Although the embodiments of the present invention have been described with reference to the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention, and such modifications and variations are intended to fall within the scope of this application.

Claims

1. A method for determining failure mode and redundancy control of a domain controller, characterized in that: The method comprises: Collecting operating status information of the chassis domain controller, the operating status information including sensor data, control instruction execution status and communication link status; Using a fault tree analysis method, a failure mode library of the chassis domain controller is constructed based on the operating status information, and the failure modes are classified. The failure mode library includes controller failure, communication link abnormality, sensor failure, and power supply abnormality. Combined with real-time monitoring data, machine learning algorithms are used to determine health status, predict failure modes, and determine the severity of failure modes; A corresponding redundant control strategy is determined according to the severity of the failure mode, and redundant control is performed using the redundant control strategy.

2. The method according to claim 1, characterized in that The severity of the failure mode includes a minor abnormality, a serious abnormality, and a failure. The corresponding redundant control strategy is determined according to the severity of the failure mode, including: When the severity of the fault mode is slightly abnormal, the redundant control strategy is to adjust the control parameters and optimize the algorithm; When the severity of the fault mode is severe abnormality, the redundant control strategy is to trigger controller switching; When the severity of the fault mode is failure, the redundancy control strategy is to perform fault isolation, cut off the faulty unit, and enter a degraded operation mode according to the situation.

3. The method according to claim 1, characterized in that The machine learning algorithm uses any one of support vector machines, random forests and deep learning models to perform fault prediction.

4. A domain controller failure mode judgment and redundancy control system, characterized in that: The system comprises: A status monitoring module is used to collect operating status information of the chassis domain controller, the operating status information including sensor data, control instruction execution status and communication link status; The fault mode and judgment module includes a fault mode classification module and a fault mode classification module; a failure mode classification module, configured to construct a failure mode library of the chassis domain controller based on the operating status information using a fault tree analysis method and classify the failure modes, wherein the failure mode library includes controller failure, communication link anomaly, sensor failure, and power supply anomaly; The failure mode determination module is used to combine real-time monitoring data and use machine learning algorithms to determine the health status, predict the failure mode, and determine the severity of the failure mode; The redundancy control module is used to determine a corresponding redundancy control strategy according to the severity of the failure mode and perform redundancy control using the redundancy control strategy.

5. The system according to claim 4, characterized in that The system further includes a communication management module, which adopts a dual CAN-FD bus dual-redundancy architecture and utilizes the dual CAN-FD buses for data transmission.

6. The system according to claim 4, characterized in that The system further includes a redundant execution module, which includes a dual-controller hot backup and an FPGA heterogeneous computing architecture. The dual-controller hot backup is used to implement switching between a primary controller and a backup controller.

7. The system according to claim 6, characterized in that The FPGA heterogeneous computing architecture adopts a dual-core heterogeneous architecture, which includes a security core and a performance core. The safety core adopts Lockstep mode to perform key chassis control tasks; The performance core is used for data processing and communication management.

8. The system according to claim 5, wherein: The operation status monitoring module collects the operation status information of the chassis domain controller through the vehicle-mounted sensor network and transmits it to the fault mode classification module through the dual CAN-FD bus.

9. The system according to claim 7, wherein: The security core in the FPGA heterogeneous computing architecture adopts a triple redundant voting mechanism.

10. The system according to claim 4, wherein: The redundant control module includes a main controller and a backup controller. A heartbeat monitoring mechanism is adopted between the main controller and the backup controller. When the main controller fails, the controller switches to the backup controller.

Citation Information

Patent Citations

  • Intelligent automobile information flow redundancy safety control system based on chassis domain controller

    CN112849055A

  • Centralized chassis domain control architecture and method

    CN115384528A

  • Redundancy control method and device for automobile chassis, automobile, equipment and storage medium

    CN115923823A

  • Chassis control system and vehicle

    CN116039661A

  • Chassis domain controller redundancy architecture and control method thereof

    CN117681814A

Cited By

  • Electric loader domain centralized electronic and electrical architecture based on vibration self-adaption and control method

    CN121486387A