Vehicle-mounted instrument redundancy switching method, device, equipment and medium

By acquiring multi-dimensional time series data of vehicles, using predictive models to generate failure probabilities and health scores, and dynamically triggering redundant operations, the problems of on-board instrument switching lag and resource waste are solved, improving the system's availability and fault tolerance, making it suitable for autonomous driving environments.

CN120645990AActive Publication Date: 2025-09-16CHONGQING WUTONG CAR LINK TECH CO LTD

Patent Information

Application Number
CN202511059012.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-30
Publication Date
2025-09-16
Estimated Expiration
2045-07-30

AI Technical Summary

Technical Problem

The existing vehicle instrument redundant switching technology has problems such as switching lag, single decision-making basis and resource waste. It is difficult to meet real-time requirements and poses a driving safety hazard.

Method used

By acquiring multi-dimensional time series data of the vehicle operation system, using the preset prediction model to generate a fault probability prediction value, combining the health score value to determine the health level, dynamically triggering redundant operation instructions, and realizing preloading or atomic switching of the backup system.

Benefits of technology

It realizes closed-loop management from fault prediction to redundant operation, identifies potential risks in advance, reduces the probability of system failure, avoids resource waste, improves availability and fault tolerance, and is suitable for high-reliability scenarios such as autonomous driving.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120645990A_ABST
    Figure CN120645990A_ABST
Patent Text Reader

Abstract

The invention provides a vehicle-mounted instrument redundancy switching method and device, equipment and a medium, and the method comprises the steps: obtaining multi-dimensional time sequence data of a vehicle-mounted instrument in a vehicle operation system, generating a fault probability prediction value of the vehicle operation system in a future preset time period through a preset prediction model, calculating a system health degree score value in combination with the multi-dimensional characteristic parameters and a preset weight thereof, determining a health level in combination with a fault probability predicted value, triggering a redundancy operation instruction based on the health level, executing preloading control of the standby system or atomic switching operation of the main and standby systems, and realizing predictive fault response and hierarchical accurate switching; according to the method, the problems of switching lag, single decision basis and resource waste in the traditional technology are effectively solved, and the reliability and the driving safety of the vehicle-mounted instrument are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of vehicle-mounted instruments, and in particular to a vehicle-mounted instrument redundancy switching method, device, equipment, and medium. Background Art

[0002] Existing redundant switching technologies for aftermarket in-vehicle instrument clusters have significant limitations. Traditional solutions rely on hardware heartbeat signals, triggering primary and backup system switching based on thresholds such as communication interruptions or CPU overload. However, these methods cannot predict potential failures, resulting in significant switching lags and difficulty meeting real-time requirements, posing a safety hazard. Furthermore, switching decisions are based solely on current status, such as heartbeat detection, lacking in-depth analysis of historical data. This can easily lead to misjudgments or missed detections, reducing the reliability of the redundant system.

[0003] At the same time, to ensure redundancy and reliability, existing technologies generally use hot backup systems. While these systems offer rapid response times, they consume a lot of resources, significantly increasing vehicle energy consumption and costs. In summary, existing technologies have significant shortcomings in terms of switching timeliness, comprehensive decision-making basis, and resource efficiency. Summary of the Invention

[0004] The present application provides a vehicle instrument redundancy switching method, device, equipment and medium to solve the technical problems of switching lag, single decision basis and resource waste in the existing equipment switching method.

[0005] The present application provides a method for redundant switching of on-board instruments, the method comprising: acquiring multidimensional time series data of on-board instruments in a vehicle operating system; generating a failure probability prediction value of the vehicle operating system within a preset future time period through a preset prediction model based on the multidimensional time series data; calculating a health score value of the vehicle operating system according to characteristic parameters and preset weights of the multidimensional time series data, and determining a health level of the vehicle operating system in combination with the failure probability prediction value; triggering corresponding redundant operation instructions based on the health level, and executing the redundant operation instructions to implement preloading control of a backup system or atomic switching operation of a primary-backup system of an instrument device.

[0006] In one embodiment of the present application, after executing the redundant operation instruction, it also includes: continuously monitoring the heartbeat signals of the data acquisition link and the operation execution link of the vehicle operation system; when the heartbeat signal is detected to be interrupted, cutting off the main system display output, switching to the backup system, and synchronizing real-time vehicle data to the backup system; when the main system is restarted, calculating the main system self-test health score based on the multi-dimensional time series data and preset weights; if the self-test health score continues to reach the preset normal threshold, freezing the backup system output and restoring the main system control and data link.

[0007] In one embodiment of the present application, a failure probability prediction value of the vehicle operation system within a preset future duration is generated, including: preprocessing the multidimensional time series data, the preprocessing at least including cleaning abnormal data and missing data; inputting the preprocessed multidimensional time series data into a preset prediction model to extract the time series features of the multidimensional time series data; calculating the importance score of each time series feature, and assigning a dynamic weight coefficient to each time series feature according to the importance score; multiplying the dynamic weight coefficient with the corresponding time series feature to obtain a weighted feature vector, and aggregating all the weighted feature vectors to form a fusion feature; based on the fusion feature, outputting the failure probability prediction value of the vehicle operation system within a preset future duration.

[0008] In one embodiment of the present application, the health score value of the vehicle operation system is calculated, including: extracting hardware operation status characteristic parameters, software behavior characteristic parameters and environmental parameter characteristic parameters from the multidimensional time series data; assigning a preset weight coefficient to each characteristic parameter, and performing weighted calculation on each characteristic parameter and the corresponding weight coefficient to generate a basic health score value; converting the fault probability prediction value into a corresponding health correction factor, and superimposing the basic health score value and the health correction factor to obtain the final health score value.

[0009] In one embodiment of the present application, the health level of the vehicle operation system is determined in combination with the fault probability prediction value, including: detecting the changing trend of the fault probability prediction value, if the fault probability prediction value continuously rises and the change rate exceeds the preset evolution threshold, then determining that the vehicle operation system is in a fault evolution state; when the health score value is greater than or equal to the first preset threshold, determining that the health level is a normal level; when the health score value is less than the first preset threshold and greater than or equal to the second preset threshold, if the vehicle operation system is not in a fault evolution state, then determining that the health level is a normal level, if the vehicle operation system is in a fault evolution state, then determining that the health level is a warning level; when the health score value is less than the second preset threshold, determining that the health level is a fault level.

[0010] In one embodiment of the present application, the atomic switching operation includes: if the health level is determined to be a warning level, the interface display resources of the backup system are loaded into the cache area, the real-time vehicle operation data of the main system is synchronized to the background buffer of the backup system, and the backup system is kept in a low-power standby state; if the health level is determined to be a fault level, the display screen output of the main system is frozen, the display interface of the backup system is activated and switched to the foreground display, the real-time data of the background buffer of the main system is submitted to the foreground display of the backup system, and the main system restart process is triggered.

[0011] The present application provides a redundant switching device for on-board instruments, which includes: a data acquisition module for acquiring multi-dimensional time series data of on-board instruments in a vehicle operation system, wherein the multi-dimensional time series data includes hardware operation status data, software behavior characteristic data and environmental parameter data; a fault prediction module for generating a failure probability prediction value of the vehicle operation system within a preset time period in the future based on the multi-dimensional time series data through a preset prediction model; a health assessment module for calculating a health score value based on the characteristic parameters and preset weights of the multi-dimensional time series data, and determining the health level of the vehicle operation system in combination with the failure probability prediction value; and a switching execution module for triggering a redundant operation instruction based on the health level to execute preloading control of the backup system or atomic switching operation of the primary and backup systems of the instrument equipment.

[0012] In one embodiment of the present application, the device also includes: a heartbeat monitoring module, which is used to continuously monitor the heartbeat signals of the data acquisition link and the operation execution link of the on-board instrument in the vehicle operation system; a failure takeover module, which is used to cut off the main system display output and switch to the backup system display interface when a heartbeat signal interruption is detected, and synchronize real-time vehicle data to the backup system; a self-healing control module, which is used to calculate the self-test health score value based on the re-collected multi-dimensional time series data, and freeze the backup system output and restore the control of the main system if the self-test health score value meets the preset recovery conditions; a preloading submodule, which is embedded in the switching execution module, and is used to load the interface display resources of the backup system into the cache area and synchronize the real-time data of the main system to the background buffer of the backup system when the health level is the warning level; an atomic switching submodule, which is embedded in the switching execution module, and is used to freeze the main system display screen, activate the backup system display interface, and submit the real-time data of the background buffer to the foreground of the backup system when the health level is the fault level.

[0013] The present application provides an electronic device, which includes: one or more processors; a storage device for storing one or more programs, and when the one or more programs are executed by the one or more processors, the electronic device implements the above-mentioned vehicle instrument redundant switching method.

[0014] The present application provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor of a computer, the computer is enabled to execute the above-mentioned vehicle instrument redundancy switching method.

[0015] Beneficial effects of the present invention: The redundant switching method for on-board instruments proposed in the present invention collects multi-dimensional time series data of on-board instruments, combines the prediction model to generate fault probability and health scores, builds a dynamic health assessment system, and realizes closed-loop management from fault prediction to redundant operation. Specifically, data-driven fault probability prediction can identify potential risks in advance, transform redundant switching from passive response to active prevention, and effectively reduce the probability of system failure caused by sudden failures; the multi-dimensional health assessment system quantifies the degree of system degradation through weighted calculation of characteristic parameters to avoid the waste of redundant resources caused by misjudgment of a single indicator; the hierarchical redundancy strategy triggers differentiated operations according to the health level: in the case of mild anomalies, pre-load control is used to reduce switching delays, and in the case of serious failures, atomic switching of the main and standby systems is performed to ensure operational integrity, taking into account both safety and resource efficiency. This method significantly improves the availability and fault tolerance of the on-board instrument system, and is particularly suitable for high-reliability scenarios such as autonomous driving. At the same time, it optimizes the occupancy of redundant resources through a hierarchical response mechanism, achieving energy efficiency balance while ensuring system safety. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] The accompanying drawings are incorporated into and constitute a part of the specification, illustrate embodiments consistent with the present application, and together with the specification, are used to explain the principles of the present application. Obviously, the drawings described below are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be derived from these drawings without inventive effort.

[0017] In the attached figure:

[0018] Figure 1 A schematic diagram of an implementation environment for a vehicle instrument redundancy switching method provided in an embodiment of the present application;

[0019] Figure 2 This is an overall flow chart of a vehicle instrument redundancy switching method provided in one embodiment of the present application;

[0020] Figure 3 This is a schematic diagram of the overall steps of the vehicle instrument redundancy switching method provided in one embodiment of the present application;

[0021] Figure 4 This is a schematic diagram of the dual-modal neural network structure provided in one embodiment of the present application;

[0022] Figure 5 is a block diagram of a redundant switching device for an on-vehicle instrument, shown in an exemplary embodiment of the present application;

[0023] Figure 6 A schematic diagram of the structure of a computer system suitable for implementing an electronic device according to an embodiment of the present application is shown. DETAILED DESCRIPTION

[0024] The following describes the embodiments of the present application through specific examples. Those skilled in the art can easily understand other advantages and functions of the present application from the contents disclosed in this specification. The present application can also be implemented or applied through other different specific embodiments. The details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present application. The following embodiments and features in the embodiments can be combined with each other without conflict.

[0025] It should be noted that the illustrations provided in the following embodiments are only schematic illustrations of the basic concept of the present application. The drawings only show components related to the present application and are not drawn according to the number, shape and size of components in actual implementation. In actual implementation, the type, quantity and proportion of each component can be changed at will, and the component layout type may also be more complicated.

[0026] In the following description, a large number of details are discussed to provide a more thorough explanation of the embodiments of the present application. However, it is obvious to those skilled in the art that the embodiments of the present application can be implemented without these specific details. In other embodiments, well-known structures and devices are shown in the form of block diagrams rather than in detail to avoid making the embodiments of the present application difficult to understand.

[0027] See Figure 1 , Figure 1 A schematic diagram of the implementation environment of the vehicle instrument redundancy switching method provided in one embodiment of the present application.

[0028] like Figure 1 As shown, the implementation environment of the vehicle instrument redundancy switching method includes a data acquisition module 101 and a vehicle system 102 .

[0029] Among them, the data acquisition module 101 captures the vehicle system operation status information in real time through multi-dimensional sensors. The hardware status monitoring unit is integrated into the vehicle main control chipset to continuously collect processor temperature, memory usage and storage device performance indicators; the software behavior monitoring unit is embedded in the instrument system kernel to dynamically track program crash frequency, thread blocking duration, communication delay and other characteristics; the environmental parameter acquisition unit is deployed on the vehicle body vibration sensor and temperature probe to record the vibration intensity inside the vehicle and the external ambient temperature changes, providing a physical environment basis for system stability analysis; the fault injection simulation unit generates a standardized test data set through a preset abnormal operating condition database for training AI prediction models.

[0030] The vehicle computer system 102, as the core processing unit, specifically includes a data cleaning module, an AI prediction engine, a health assessment module, a dynamic switching controller, and a failure protection module. The functions of each module are as follows:

[0031] The data cleaning module performs multi-dimensional preprocessing and feature extraction on raw data. It uses a sliding window algorithm to remove outliers, interpolation to fill in missing data, and normalization to eliminate dimensional differences. The AI ​​prediction engine is based on a bimodal neural network architecture. The LSTM layer analyzes time-dependent features such as processor load trends, and the Attention mechanism dynamically weights key abnormal events to output a health score and failure probability assessment for the short term. The health assessment module calculates real-time health using a multi-dimensional feature weighting model and triggers corresponding policies based on grading criteria. The dynamic switching controller includes a preloading mechanism that caches backup system modules such as the navigation interface and warning icons during the early warning phase. The atomic switching strategy uses hardware-level operations to quickly freeze the main system screen and activate the backup system display during a failure. A double buffering mechanism and transaction rollback protocol ensure data consistency. The self-healing mechanism performs a health self-check after the main system restarts and automatically switches back to the main system when conditions are met, forming a closed-loop recovery link. The failover module continuously monitors the operating status of data collection, AI prediction, and decision-making links. If a program anomaly or interruption is detected, it directly activates the instrument panel system to ensure basic functions and ensure driving safety.

[0032] It is understandable that if Figure 1 The implementation environment shown realizes a complete closed loop from data collection to fault prediction, health assessment, dynamic switching and failure protection. Compared with the traditional threshold-triggered switching solution, redundant switching is triggered in advance through AI prediction, which significantly improves the system response efficiency, effectively reduces the risk of misjudgment, and optimizes resource utilization performance.

[0033] Figure 2 This is an overall flow chart of the vehicle instrument redundancy switching method provided in one embodiment of the present application.

[0034] like Figure 2 As shown, in an exemplary embodiment, the load meter redundancy switching method includes at least steps S210 to S240, which are described in detail as follows:

[0035] Step S210: Acquire multi-dimensional time series data of the vehicle operation system.

[0036] In one embodiment of the present application, multi-dimensional time series data of the vehicle operation system is first collected in real time through the vehicle-mounted sensors and the system interface of the vehicle operation system, covering three categories: hardware status, software behavior and environmental parameters.

[0037] Hardware status data includes temperature curves for the CPU and GPU, memory usage fluctuations, and dynamic monitoring of battery voltage. This data is periodically acquired through the on-board diagnostic interface (OBD) and the hardware monitoring module, with a sampling frequency set to 10 times per second to capture transient anomalies. Software behavior data is collected through system log analysis and process monitoring tools, recording the crash frequency of key processes, task scheduling delays, and packet loss rates of communication protocols. CAN bus analysis tools are also used to track changes in communication delays between vehicle control units. Furthermore, environmental parameter data is collected jointly by on-board cameras, accelerometers, and temperature sensors, including spectrum analysis of in-vehicle vibration intensity, real-time changes in external ambient temperature, and dynamic fluctuations in light intensity.

[0038] The collected raw data is then cleaned through a preprocessing module to remove outliers, noise, and missing data segments. Missing values ​​are filled in using a linear interpolation algorithm to ensure data continuity. The multidimensional feature data is then normalized, mapping indicators of different dimensions to a unified numerical range (0-1) to eliminate the impact of dimensional differences on model training.

[0039] Finally, the preprocessed data is divided into training set, validation set and test set. The training set contains tens of thousands of sets of multi-dimensional time series data under normal driving scenarios, covering typical road conditions such as urban roads and highways. By simulating extreme working conditions, tens of thousands of sets of fault scenario data are generated as negative samples, providing a comprehensive data foundation for the prediction model and realizing accurate prediction of the system health status.

[0040] Step S220 , based on the multi-dimensional time series data, a failure probability prediction value of the vehicle operation system within a preset time period in the future is generated through a preset prediction model.

[0041] In one embodiment of the present application, the preset prediction model is taken as an example of a bimodal neural network model.

[0042] First, preprocessed multidimensional time series data is fed into a bimodal neural network model consisting of an LSTM layer and an Attention mechanism. The LSTM layer extracts long-term dependent features of system status, such as CPU load trends or GPU temperature fluctuations. The Attention mechanism dynamically weights key features such as sudden increases in communication latency or abnormal memory fragmentation to enhance fault sensitivity. The input layer receives data on hardware status, such as normalized CPU / GPU temperature and memory utilization; software behavior, such as process crash frequency and communication packet loss rate; and environmental parameters such as vibration intensity and ambient temperature. The model outputs a health score (0-1) and a failure probability (0-100%) within the next 50ms.

[0043] Secondly, during the training phase, mean squared error (MSE) is used as the loss function, and backpropagation is used to optimize parameters until convergence. The training data includes a large number of normal driving scenarios and fault scenarios, and extreme operating conditions are used to enhance the ability to identify sudden faults. The final model achieves a fault probability prediction accuracy of ≤±0.05 on the test set. It can generate real-time fault prediction values ​​for the vehicle's operating system 50ms into the future, providing an accurate basis for health assessment and redundant switching decisions.

[0044] In one embodiment of the present application, a failure probability prediction value of a vehicle operation system within a preset future duration is generated, including: preprocessing multidimensional time series data, the preprocessing at least including cleaning abnormal data and missing data; inputting the preprocessed multidimensional time series data into a preset prediction model to extract the time series features of the multidimensional time series data, including long-term state-dependent features; calculating the importance score of each time series feature, and assigning a dynamic weight coefficient to each time series feature according to the importance score; multiplying the obtained dynamic weight coefficient with the corresponding time series feature to obtain a weighted feature vector, and aggregating all the weighted feature vectors to form a fusion feature; based on the fusion feature, outputting the failure probability prediction value of the vehicle operation system within a preset future duration.

[0045] In a specific embodiment of the present application, the collected multi-dimensional time series data is first preprocessed to improve the data quality. In the data cleaning stage, an outlier detection algorithm is used to identify and eliminate hardware status data that exceeds a reasonable range, such as the CPU temperature instantly soaring to 120°C or the process crash frequency in the software behavior data suddenly increasing to an abnormal value. At the same time, a linear interpolation algorithm is used to fill in the missing data segments caused by sensor failures, such as the missing value of memory occupancy during the CAN bus communication interruption. The cleaned data is then normalized, and indicators of different dimensions are mapped to a unified numerical range (0-1) to eliminate the impact of dimensional differences on model training.

[0046] The preprocessed data is fed into a pre-configured bimodal neural network model consisting of an LSTM layer and an Attention mechanism. The LSTM layer captures long-term dependencies in system states through time series modeling, such as a trend in which CPU load gradually climbs from 40% to 85% over 10 seconds, or a persistent rise in GPU temperature in high-temperature environments. The Attention mechanism dynamically weights key features. For example, if communication latency suddenly increases from an average of 20ms to 50ms, this feature is assigned a higher weight of 0.35, while the weights of other features, such as memory fragmentation rate, are reduced to 0.15, thereby enhancing the model's sensitivity to sudden failures.

[0047] In the feature weighting stage, the extracted long-term state-dependent features are weighted and fused based on the preset multi-dimensional feature weight distribution scheme, such as "CPU load 30%, GPU temperature 25%, communication delay 20%, memory fragmentation rate 15%, and environmental interference 10%." For example, when the system is in a high-temperature environment and the GPU temperature is higher than 85°C for 5 consecutive seconds, the model will generate a higher failure probability prediction value. The final model outputs a failure probability prediction value within the next 50ms (range 0-100%), and optimizes the model parameters through the mean square error (MSE) loss function to ensure that the prediction accuracy error is controlled within ±0.05. This prediction value serves as the core basis for subsequent health determination and redundant switching strategy, realizing forward-looking early warning of vehicle operation system failures.

[0048] In step S230 , the health score of the vehicle operating system is calculated based on the characteristic parameters and preset weights of the multi-dimensional time series data, and the health level of the vehicle operating system is determined in combination with the failure probability prediction value.

[0049] In one embodiment of the present application, the health score of the vehicle operation system is first calculated based on the characteristic parameters and preset weights of the multidimensional time series data. The weight distribution scheme is set according to the importance of the key indicators of the system, such as CPU load 30%, GPU temperature 25%, communication delay 20%, memory fragmentation rate 15%, and environmental interference 10%. During the calculation, the normalized value (0-1) of each characteristic parameter is multiplied by the corresponding weight and then summed. For example, when the normalized value of the CPU load is 0.8, the normalized value of the GPU temperature is 0.7, the normalized value of the communication delay is 0.6, the normalized value of the memory fragmentation rate is 0.5, and the normalized value of the environmental interference is 0.4, the health score is 0.8×0.3+0.7×0.25+0.6×0.2+0.5×0.15+0.4×0.1=0.645.

[0050] The health score is then combined with the predicted value of the future 50ms fault probability (0-100%) output by the bimodal neural network model to determine: if the health score is ≥0.8 and the fault probability is <10%, it is judged to be normal; if the health score is between 0.5-0.8 and the fault probability is between 10%-30%, an early warning is triggered and preloading is performed; if the health score is <0.5 or the fault probability is >70%, it is directly judged as a fault and forced switching.

[0051] In one embodiment of the present application, the health score value of the vehicle operation system is calculated, including: extracting hardware operation status characteristic parameters, software behavior characteristic parameters and environmental parameter characteristic parameters from multidimensional time series data; assigning a preset weight coefficient to each characteristic parameter, and performing a weighted calculation on each characteristic parameter and its corresponding weight coefficient to generate a basic health score value; converting the fault probability prediction value into a corresponding health correction factor, and superimposing the basic health score value and the health correction factor to obtain a final health score value.

[0052] In a specific embodiment of the present application, hardware operating status characteristic parameters, software behavior characteristic parameters and environmental parameter characteristic parameters are first extracted from multi-dimensional time series data as the basis for calculating the health score. The hardware operating status characteristic parameters include indicators such as CPU load, GPU temperature, memory occupancy and battery voltage, which are periodically collected through the on-board diagnostic interface (OBD) and the hardware monitoring module, and the sampling frequency is set to 10 times per second to capture transient anomalies. The software behavior characteristic parameters cover the crash frequency of key processes, task scheduling delays and communication protocol packet loss rates, etc., which are obtained in real time through system log analysis tools and CAN bus monitoring modules. The environmental parameter characteristic parameters include the vibration intensity in the vehicle, the external ambient temperature (range -20°C to 60°C) and the light intensity, etc., which are jointly collected by the on-board camera, accelerometer and temperature sensor.

[0053] After the extracted feature parameters are normalized, they are weighted according to the preset weight coefficients to generate a basic health score. The preset weight coefficients are based on the importance of the system's key indicators, for example, giving a weight of 30% to the CPU load, 25% to the GPU temperature, 20% to the communication delay, 15% to the memory fragmentation rate, and 10% to the environmental interference. The specific calculation method is to multiply the normalized value (0-1) of each feature parameter by the corresponding weight and then sum it up. For example, when the normalized value of the CPU load is 0.8, the normalized value of the GPU temperature is 0.7, the normalized value of the communication delay is 0.6, the normalized value of the memory fragmentation rate is 0.5, and the normalized value of the environmental interference is 0.4, the basic health score is 0.8×0.3+0.7×0.25+0.6×0.2+0.5×0.15+0.4×0.1=0.645.

[0054] The fault probability prediction value (range 0-100%) within the next 50ms output by the bimodal neural network model is then converted into a corresponding health correction factor and superimposed with the basic health score value to obtain the final health score value. The correction factor of the fault probability prediction value is converted to a range of 0.8-1.2 through a linear mapping function, where the correction factor is 1 when the fault probability prediction value is 0%, and the correction factor is 0.8 when the fault probability prediction value is 70%. The remaining values ​​are interpolated proportionally. For example, if the basic health score is 0.645 and the fault probability prediction value is 20%, the correction factor is 1-(20%×0.05)=0.9, and the final health score value is 0.645×0.9=0.5805.

[0055] By dynamically integrating the basic health score and the fault probability correction factor, we not only retain the stability assessment driven by historical data, but also enhance the sensitivity to sudden failures, achieve accurate judgment of the system health level and dynamic adaptation of the redundancy strategy, and provide an accurate basis for subsequent health level judgment and redundancy switching strategy.

[0056] In one embodiment of the present application, the health level of the vehicle operating system is determined in combination with the fault probability prediction value, including: detecting the changing trend of the fault probability prediction value, if the fault probability prediction value continuously increases and the change rate exceeds the preset evolution threshold, then determining that the vehicle operating system is in a fault evolution state; when the health score value is greater than or equal to the first preset threshold, determining that the health level is a normal level; when the health score value is less than the first preset threshold and greater than or equal to the second preset threshold, if the vehicle operating system is not in a fault evolution state, then determining that the health level is a normal level, if the vehicle operating system is in a fault evolution state, then determining that the health level is a warning level; when the health score value is less than the second preset threshold, determining that the health level is a fault level.

[0057] In one specific embodiment of the present application, the bimodal neural network model first continuously monitors the changing trend of the predicted fault probability within the next 50 milliseconds. If the predicted fault probability shows a continuous increase and the rate of change exceeds a preset evolution threshold, such as an increase of 3% per second, the vehicle operating system is determined to be in a fault evolution state. For example, if the predicted fault probability increases from an initial 10% to 20% at a rate of 2% per second within 5 seconds, and this growth rate exceeds the preset evolution threshold of 1.5% per second, the system triggers a fault evolution state flag.

[0058] Subsequently, the health level is determined based on the joint judgment rule of the health score value and the fault evolution state. When the health score value is greater than or equal to the first preset threshold value, such as 0.8, it is judged to be a normal level regardless of whether there is a fault evolution state. At this time, the system does not need to intervene and maintains the operation of the main system. When the health score value is less than the first preset threshold value and greater than or equal to the second preset threshold value, such as 0.5, the fault evolution state is further judged: if it is not in a fault evolution state, it is judged to be a normal level; if it is in a fault evolution state, it is judged to be a warning level and triggers the preloading strategy, such as caching the navigation interface and warning icons. When the health score value is less than the second preset threshold value, it is directly judged as a fault level and forced to perform atomic switching, freezing the main system screen and activating the standby system display.

[0059] It can be understood that the solution proposed in this embodiment, by dynamically integrating the changing trend of the fault probability prediction value and the dual judgment logic of the health score value, not only retains the long-term dependence on the system stability assessment, but also enhances the sensitive capture capability of sudden faults. For example, when the health score is 0.6, between 0.5 and 0.8, and the fault probability prediction value increases at a rate of 4% per second to 30%, exceeding the preset evolution threshold of 1.5% per second, the system adjusts the health level from normal to warning, and preloads key modules in advance to shorten the subsequent switching response time. Ultimately, through a multi-dimensional dynamic adaptation mechanism, accurate judgment of the health level of the vehicle operation system and forward-looking decision-making of the redundant switching strategy are achieved.

[0060] Step S240 : triggering corresponding redundant operation instructions based on the health level, executing the redundant operation instructions, and implementing preloading control of the backup system or atomic switching operation of the primary and backup systems of the instrument equipment.

[0061] In one embodiment of the present application, redundant operation instructions are dynamically triggered based on the health level and specific control logic is executed. When the health level is determined to be normal, the main system is maintained in operation and the data link is continuously monitored without additional operation. When the health level enters the warning state, the preload instruction is triggered, and the backup system is awakened through the cold backup mechanism, and key modules such as the navigation interface and warning icons are cached. The preload process is controlled within 15ms to reserve resources for subsequent switching. If the health level is reduced to a fault state, the atomic switch instruction is executed immediately, and the hardware-level operation is used to freeze the main system screen within 1ms and activate the backup system display. At the same time, data consistency is guaranteed through the double buffering mechanism and the transaction rollback protocol. After the switch, the main system enters the self-test process. When the health level recovers to above the first preset threshold, it automatically switches back to the main system and releases the backup resources.

[0062] In one embodiment of the present application, the atomic switching operation of the primary and backup systems includes: if the health level is determined to be a warning level, the interface display resources of the backup system are loaded into the cache area, the real-time vehicle operation data of the primary system is synchronized to the background buffer of the backup system, and the backup system is kept in a low-power standby state; if the health level is determined to be a fault level, the display screen output of the primary system is frozen, the display interface of the backup system is activated and switched to the foreground display, the real-time data in the background buffer of the primary system is submitted to the foreground display of the backup system, and the fault isolation operation is performed on the primary system and the main system restart process is triggered; when the primary system completes the restart, the multi-dimensional time series data of the primary system is re-collected and the self-test health score value is calculated. If the self-test health score value continues to meet the preset recovery conditions, the display output of the backup system is frozen, the display control and data link of the primary system are restored, and the backup system is switched back to the standby state.

[0063] In a specific embodiment of the present application, the atomic switching operation of the master-slave system is dynamically triggered and executes specific control logic according to the health level. The details are as follows:

[0064] When the health level is determined to be a warning level, the system activates the preloading mechanism of the backup system. First, key interface display resources such as the navigation interface and warning icons are loaded into the cache area of ​​the backup system. The real-time vehicle operation data of the main system, such as vehicle speed, rotation speed, and fault codes, are synchronized to the background buffer of the backup system. At the same time, the backup system is maintained in standby mode through the low-power management module, consuming only about 5% of system resources to reduce energy consumption. If the health level is further reduced to the fault level, the display output of the main system is immediately frozen. The display interface of the backup system is activated within 1ms through hardware-level signal control and switched to the foreground display. At the same time, the real-time data in the background buffer of the main system, such as the current vehicle speed and battery status, are submitted to the foreground display of the backup system to ensure data consistency. During this process, the main system performs fault isolation operations, cuts off the power supply or communication link of the abnormal module, and triggers the main system restart process.

[0065] When the main system completes the restart, it re-collects multi-dimensional time series data such as CPU temperature, GPU load, and communication delay and calculates the self-check health score. If the self-check health score continues to meet the preset recovery conditions, such as a score ≥ 0.8 for 5 consecutive seconds, the display output of the backup system is frozen, the display control and data link of the main system are restored, and the backup system is switched back to a low-power standby state through a double buffering mechanism. For example, after the main system restarts, the health score gradually recovers from 0.6 to 0.85, and the score fluctuation does not exceed ±0.05 for 30 consecutive seconds. The system determines that it has returned to normal, automatically releases the backup system resources, and terminates the pre-loading cache.

[0066] It can be understood that the solution proposed in this embodiment, through hierarchical triggering and dynamic control, not only achieves resource pre-configuration before a failure, but also ensures millisecond-level switching and recovery during a failure, taking into account both redundancy reliability and resource efficiency.

[0067] In one embodiment of the present application, after executing the redundant operation instruction, the vehicle instrument redundant switching method also includes: continuously monitoring the heartbeat signals of the data acquisition link and the operation execution link of the vehicle operation system; when the heartbeat signal is detected to be interrupted, cutting off the main system display output, switching to the backup system display interface, and synchronizing real-time vehicle data to the backup system; when the main system is restarted, calculating the main system self-test health score based on multi-dimensional time series data and preset weights; if the self-test health score continues to reach the preset normal threshold, freezing the backup system output and restoring the main system display control and data link.

[0068] In a specific embodiment of the present application, after executing the redundant operation instruction, the vehicle instrument redundancy switching method further includes continuously monitoring the heartbeat signals of the data acquisition link and the operation execution link of the vehicle operation system. The heartbeat signal of the data acquisition link is detected by periodically polling the response status of each sensor interface, such as the OBD bus and the CAN bus, and the heartbeat signal of the operation execution link is detected by the message interaction frequency between the main and standby systems, such as the health status report of 10 times per second. When the heartbeat signal of any link is detected to be interrupted, for example, the data acquisition link does not receive OBD interface data for 3 consecutive seconds due to abnormal sensor power supply, or the operation execution link causes the message reporting frequency to drop to less than 1 time per second due to the main system being stuck, the takeover control operation is immediately triggered.

[0069] The takeover operation consists of three steps: first, the primary system's display output is cut off, freezing the primary system's screen refresh via hardware-level signal control; second, the backup system's display interface is activated and switched to the foreground display, ensuring real-time visualization of basic dashboard functions such as vehicle speed and fault codes; finally, real-time vehicle data from the primary system's backend buffer, such as current vehicle speed and battery voltage fault codes, is synchronized to the backup system's foreground display, ensuring data consistency through a double-buffering mechanism. During this period, the primary system enters a forced restart process, cutting off power or communication links to abnormal modules, such as isolating a navigation process that has crashed due to a memory leak.

[0070] When the main system completes the restart, it re-collects multi-dimensional time series data such as CPU temperature, GPU load, and communication delay, and calculates the self-check health score based on the preset weights. If the self-check health score continues to meet the preset normal threshold, for example, the score is ≥0.8 for 5 consecutive seconds, the display output of the backup system is frozen, and the display control and data link of the main system are restored through the double buffering mechanism, and the backup system is switched back to a low-power standby state. For example, after the main system restarts, the health score gradually recovers from 0.6 to 0.85, and the score fluctuation does not exceed ±0.05 for 30 consecutive seconds. The system determines that it has returned to normal, automatically releases the backup system resources, and terminates the pre-loading cache.

[0071] It can be understood that the solution proposed in this embodiment, through dynamic monitoring of heartbeat signals and a hierarchical takeover mechanism, not only ensures rapid takeover when the main system is abnormal, but also achieves seamless switching after the main system is restored, taking into account both redundancy reliability and resource efficiency.

[0072] Figure 3 The figure is a schematic diagram of the overall steps of the vehicle instrument redundancy switching method provided in one embodiment of the present application.

[0073] In a specific embodiment of the present application, a vehicle instrument redundancy switching method based on an AI prediction engine is proposed. The specific steps are as follows: Figure 3 As shown, the data acquisition module first acquires raw data such as hardware status, software behavior, and environmental parameters. This data is then fed into an AI prediction engine consisting of an LSTM layer and an Attention layer for processing. The LSTM layer uses a long-short-term memory network to capture long-term dependencies in time series data, such as identifying trends such as a sustained increase in CPU load or a sudden rise in GPU temperature. The Attention mechanism layer dynamically weights the processed features, focusing on key time points or features such as sudden increases in communication latency and abnormal memory fragmentation to improve prediction accuracy. The processed data enters a multi-dimensional feature weighting model, which calculates a health score using preset weights (e.g., 30% for CPU load and 25% for GPU temperature), providing a quantitative assessment of system status. The assessment results are classified by a three-level health assessment module as normal, warning, or fault. The resulting health assessment triggers a corresponding switchover strategy: in normal status, the primary system maintains operation; in warning status, the cache is preloaded; and in fault status, hardware-level signaling controls freeze the primary system screen within 1ms and activate the backup system display, while ensuring data consistency. The entire process embodies closed-loop management from data collection to intelligent decision-making, highlighting the core role of AI technology in improving system reliability and resource efficiency.

[0074] Figure 4 Schematic diagram of the dual-modal neural network structure provided in one embodiment of the present application.

[0075] In a specific embodiment of the present application, a dual-mode neural network structure is used to implement the above-mentioned redundant switching of vehicle-mounted equipment. Figure 4 As shown in the figure, its core process consists of five parts: the input layer receives multidimensional feature data covering time series information such as hardware status such as device temperature and voltage, software behavior such as process running status and communication frequency, and environmental parameters such as temperature and humidity. The data first enters the LSTM layer, which uses a long short-term memory network to capture the dynamic relationship between features over time. Subsequently, the Attention mechanism layer dynamically weights the processed features, focusing on the key features that have the greatest impact on fault prediction. The fully connected layer integrates and abstracts the output of the Attention layer to extract higher-dimensional related information. Finally, the output layer generates a "fault and probability" prediction based on the integration results, clarifying the current fault status of the device and its probability of occurrence. By combining time series modeling with the attention mechanism, this architecture achieves high-precision prediction of complex system faults, making it suitable for scenarios requiring real-time performance and stability, such as industrial equipment monitoring and vehicle system health management.

[0076] Finally, it's important to emphasize that the vehicle instrument redundancy switching method proposed in this application significantly optimizes reliability, resource efficiency, and safety through the combination of AI prediction and dynamic assessment. First, an AI prediction engine based on LSTM and Attention mechanisms can proactively identify failure trends, such as sudden increases in communication latency or GPU temperature, significantly reducing response time compared to traditional threshold-triggered mechanisms. Second, a weighted model of multi-dimensional features, including hardware status, software behavior, and environmental parameters, is combined with predicted failure probability to dynamically determine health levels, effectively reducing false positives. Furthermore, a cold backup and preloading strategy is employed to cache only critical modules during the early warning phase, minimizing preloading time and significantly reducing standby power consumption compared to traditional hot backup systems. After the primary system restarts, a health score is generated through multi-dimensional data self-inspection. If conditions are met, the primary system automatically switches back to the primary system and releases backup resources, eliminating the need for manual intervention and achieving seamless switching. This method supports a hierarchical strategy encompassing normal, warning, and fault states, adapting to varying fault evolution rates. Data consistency is ensured through a double buffering mechanism and a transaction rollback protocol. Compared with traditional mechanical brake redundancy solutions, this solution effectively controls the fluctuation range of vehicle braking force during the switching process, taking into account both user experience and resource efficiency, and providing an innovative path for on-board instrument redundancy that is both forward-looking and practical.

[0077] Figure 5 This is a block diagram of a redundant switching device for vehicle-mounted instruments shown in an exemplary embodiment of the present application. The device can be applied to Figure 1 The device may also be applicable to other exemplary implementation environments and specifically configured in other devices. This embodiment does not limit the implementation environment to which the device is applicable.

[0078] like Figure 5 As shown, the exemplary vehicle instrument redundancy switching device includes: a data acquisition module 510 , a fault prediction module 520 , a health assessment module 530 , and a switching execution module 540 .

[0079] Among them, the data acquisition module 510 is used to obtain multi-dimensional time series data of the vehicle operation system, and the multi-dimensional time series data includes hardware operation status data, software behavior characteristic data and environmental parameter data; the fault prediction module 520 is used to generate a failure probability prediction value of the vehicle operation system within a preset time period in the future based on the multi-dimensional time series data through a preset prediction model; the health assessment module 530 is used to calculate the health score value according to the characteristic parameters and preset weights of the multi-dimensional time series data, and determine the health level of the vehicle operation system in combination with the failure probability prediction value; the switching execution module 540 is used to trigger redundant operation instructions based on the health level, and execute preloading control of the backup system or atomic switching operation of the main and standby systems.

[0080] In one embodiment of the present application, the above-mentioned vehicle instrument redundant switching device further includes: a heartbeat monitoring module, a failover module, a self-healing control module, a preloading submodule, and an atomic switching submodule.

[0081] Among them, the heartbeat monitoring module is used to continuously monitor the heartbeat signals of the data acquisition link and the operation execution link of the vehicle operation system; the failure takeover module is used to cut off the main system display output and switch to the backup system display interface when the heartbeat signal interruption is detected, and synchronize the real-time vehicle data to the backup system; the self-healing control module is used to calculate the self-inspection health score value based on the re-collected multi-dimensional time series data, and freeze the backup system output and restore the control of the main system if the self-inspection health score value continues to meet the preset recovery conditions; the preloading submodule is embedded in the switching execution module, and is used to load the interface display resources of the backup system to the cache area and synchronize the real-time data of the main system to the background buffer of the backup system when the health level is the warning level; the atomic switching submodule is embedded in the switching execution module, and is used to freeze the main system display screen, activate the backup system display interface, and submit the real-time data of the background buffer to the foreground of the backup system when the health level is the fault level.

[0082] It should be noted that the redundant switching device for in-vehicle instruments provided in the above-mentioned embodiments and the redundant switching method for in-vehicle instruments provided in the above-mentioned embodiments are based on the same concept. The specific manner in which the various modules and units perform their operations has been described in detail in the method embodiments and will not be repeated here. In actual applications, the redundant switching device for in-vehicle instruments provided in the above-mentioned embodiments can, as needed, distribute the aforementioned functions among different functional modules. That is, the internal structure of the device can be divided into different functional modules to perform all or part of the aforementioned functions, and this is not a limitation herein.

[0083] An embodiment of the present application also provides an electronic device, comprising: one or more processors; a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the electronic device implements the vehicle instrument redundancy switching method provided in the above-mentioned embodiments.

[0084] Figure 6 The following is a schematic diagram showing the structure of a computer system suitable for implementing an electronic device according to an embodiment of the present application. Figure 6 The computer system 600 of the electronic device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.

[0085] like Figure 6 As shown, the computer system 600 includes a central processing unit (CPU) 601, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 602 or the program loaded from the storage part 608 into the random access memory (RAM) 603, such as executing the method described in the above embodiment. Various programs and data required for system operation are also stored in the RAM 603. The CPU 601, ROM 602 and RAM 603 are connected to each other via a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.

[0086] The following components are connected to the I / O interface 605: an input section 606 including a keyboard, a mouse, and the like; an output section 607 including devices such as a cathode ray tube (CRT), a liquid crystal display (LCD), and a speaker; a storage section 608 including a hard disk; and a communication section 609 including a network interface card such as a LAN (Local Area Network) card or a modem. The communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the I / O interface 605 as needed. Removable media 611, such as a magnetic disk, an optical disk, a magneto-optical disk, or a semiconductor memory, is installed in the drive 610 as needed, so that computer programs read therefrom can be installed into the storage section 608 as needed.

[0087] In particular, according to an embodiment of the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a computer program for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 609, and / or installed from a removable medium 611. When the computer program is executed by the central processing unit (CPU) 601, the various functions defined in the system of the present application are executed.

[0088] It should be noted that the computer-readable medium shown in the embodiments of the present application can be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium can be, for example, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, which carries a computer-readable computer program. This propagated data signal can take a variety of forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device. A computer program embodied on a computer-readable medium may be transmitted using any suitable medium, including but not limited to wireless, wired, or any suitable combination thereof.

[0089] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. Among them, each box in the flowchart or block diagram can represent a module, program segment, or part of the code, and the above-mentioned module, program segment, or part of the code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of boxes in the block diagram or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0090] The units involved in the embodiments of the present application can be implemented by software or hardware, and the units described can also be set in a processor. In some cases, the names of these units do not constitute limitations on the units themselves.

[0091] Another aspect of the present application provides a computer-readable storage medium storing a computer program. When executed by a computer processor, the computer program causes the computer to perform the aforementioned vehicle instrument redundancy switching method. The computer-readable storage medium may be included in the electronic device described in the above embodiments, or may exist independently and not be incorporated into the electronic device.

[0092] Another aspect of the present application provides a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the vehicle instrument redundancy switching method provided in each of the above embodiments.

[0093] The above embodiments are merely illustrative of the principles and effects of this application and are not intended to limit this application. Anyone skilled in the art may modify or alter the above embodiments without departing from the spirit and scope of this application. Therefore, all equivalent modifications or alterations made by one of ordinary skill in the art without departing from the spirit and technical concepts disclosed in this application shall be covered by the claims of this application.

Claims

1. A vehicle instrument redundancy switching method, characterized in that: The method comprises: Acquire multi-dimensional time series data of onboard instruments in vehicle operation systems; Based on the multi-dimensional time series data, a failure probability prediction value of the vehicle operation system within a preset time period in the future is generated by a preset prediction model; Calculating a health score of the vehicle operating system based on the characteristic parameters and preset weights of the multidimensional time series data, and determining a health level of the vehicle operating system in combination with the failure probability prediction value; A corresponding redundant operation instruction is triggered based on the health level, and the redundant operation instruction is executed to implement preload control of the backup system or atomic switching operation of the primary and backup systems of the instrument equipment.

2. The vehicle instrument redundancy switching method according to claim 1, characterized in that: After executing the redundant operation instruction, the method further includes: Continuously monitor the heartbeat signals of the data acquisition link and the operation execution link of the vehicle operation system; When the heartbeat signal is detected to be interrupted, the main system display output is cut off, the backup system is switched to, and the real-time vehicle data is synchronized to the backup system; After the main system is restarted, a main system self-check health score is calculated based on the multi-dimensional time series data and the preset weights; If the self-check health score value continuously reaches the preset normal threshold, the backup system output is frozen and the control right and data link of the main system are restored.

3. The vehicle instrument redundancy switching method according to claim 1, characterized in that: Generating a predicted value of the failure probability of the vehicle operating system within a preset future time period, including: Preprocessing the multidimensional time series data, wherein the preprocessing at least includes cleaning abnormal data and missing data; Inputting the preprocessed multidimensional time series data into a preset prediction model to extract the time series features of the multidimensional time series data; Calculating the importance score of each time series feature, and assigning a dynamic weight coefficient to each time series feature according to the importance score; Multiplying the obtained dynamic weight coefficient with the corresponding time series feature to obtain a weighted feature vector, and aggregating all the weighted feature vectors to form a fusion feature; Based on the fusion features, a predicted value of the failure probability of the vehicle operation system within a preset time period in the future is output.

4. The vehicle instrument redundancy switching method according to claim 1, characterized in that: Calculating the health score of the vehicle operating system includes: Extracting hardware operation status characteristic parameters, software behavior characteristic parameters and environmental parameter characteristic parameters from the multidimensional time series data; Assign a preset weight coefficient to each characteristic parameter, and perform weighted calculation on each characteristic parameter and the corresponding weight coefficient to generate a basic health score value; The failure probability prediction value is converted into a corresponding health correction factor, and the basic health score value and the health correction factor are superimposed and calculated to obtain the final health score value.

5. The vehicle-mounted instrument redundant switching method according to claim 1, characterized in that: Determining the health level of the vehicle operating system in combination with the failure probability prediction value includes: detecting a change trend of the fault probability prediction value, and determining that the vehicle operating system is in a fault evolution state if the fault probability prediction value continuously increases and the change rate exceeds a preset evolution threshold; When the health score value is greater than or equal to a first preset threshold, the health level is determined to be normal; When the health score value is less than a first preset threshold value and greater than or equal to a second preset threshold value, if the vehicle operating system is not in a fault evolution state, the health level is determined to be a normal level; if the vehicle operating system is in a fault evolution state, the health level is determined to be a warning level; When the health score value is less than a second preset threshold, the health level is determined to be a fault level.

6. The vehicle instrument redundancy switching method according to any one of claims 1 to 5, characterized in that: Atomic switch operations include: If the health level is determined to be a warning level, the interface display resources of the backup system are loaded into the cache area, the real-time vehicle operation data of the main system is synchronized to the background buffer of the backup system, and the backup system is kept in a low-power standby state; If the health level is determined to be a fault level, the display screen output of the main system is frozen, the display interface of the backup system is activated and switched to the foreground display, the real-time data in the background buffer of the main system is submitted to the foreground display of the backup system, and the main system restart process is triggered.

7. A redundant switching device for vehicle-mounted instruments, characterized in that: The device comprises: A data acquisition module is used to obtain multi-dimensional time series data of on-board instruments in the vehicle operation system, wherein the multi-dimensional time series data includes hardware operation status data, software behavior characteristic data and environmental parameter data; A fault prediction module, configured to generate a fault probability prediction value of the vehicle operation system within a preset time period in the future based on the multi-dimensional time series data using a preset prediction model; A health assessment module, configured to calculate a health score value based on the characteristic parameters of the multi-dimensional time series data and preset weights, and determine a health level of the vehicle operating system in combination with the failure probability prediction value; The switching execution module is used to trigger a redundant operation instruction based on the health level to execute the preload control of the backup system or the atomic switching operation of the primary and backup systems of the instrument equipment.

8. The vehicle-mounted instrument redundant switching device according to claim 7, characterized in that: The device further comprises: A heartbeat monitoring module, used to continuously monitor the heartbeat signals of the data acquisition link and the operation execution link of the on-board instrument in the vehicle operation system; The failover module is used to cut off the main system display output and switch to the backup system display interface when the heartbeat signal is interrupted, and synchronize real-time vehicle data to the backup system; A self-healing control module is used to calculate a self-check health score based on the re-collected multi-dimensional time series data, and freeze the backup system output and restore control of the main system if the self-check health score meets the preset recovery conditions; A preloading submodule is embedded in the switching execution module and is used to load the interface display resources of the backup system into the cache area and synchronize the real-time data of the main system to the background buffer of the backup system when the health level is the warning level; The atomic switching submodule is embedded in the switching execution module and is used to freeze the main system display screen, activate the standby system display interface, and submit the real-time data in the background buffer to the standby system foreground when the health level is the fault level.

9. An electronic device, characterized in that: The electronic device comprises: one or more processors; A storage device for storing one or more programs, which, when executed by the one or more processors, enables the electronic device to implement the vehicle instrument redundancy switching method according to any one of claims 1 to 6.

10. A computer-readable storage medium, characterized in that A computer program is stored thereon, and when the computer program is executed by a processor of a computer, the computer is caused to execute the vehicle instrument redundant switching method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Driving assistance device

    CN109476319A

  • Redundancy control method and device for vehicle-mounted display device

    CN111077763A

  • Nuclear power plant redundant instrument signal prediction system and method

    CN113344266A

  • Control method and system of industrial monitoring redundant system with gateway and PLC matched

    CN114563946A

  • Vehicle operation control method, device and equipment and storage medium

    CN120288060A

Cited By

  • Automatic switching method and system for main and auxiliary redundant hot backup mechanism of electric energy meter

    CN120928676A