Method and system for controlling different functionalities of a vehicle

A central computing unit (CCU) in vehicles efficiently manages and reconfigures functionalities by dynamically assigning components, addressing the challenge of integrating new components and optimizing resource use in decentralized systems.

WO2026077517A1PCT designated stage Publication Date: 2026-04-16VOLKSWAGEN AG
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/076267
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-10-08
Publication Date
2026-04-16

AI Technical Summary

Technical Problem

Existing vehicle systems face challenges in efficiently extending or scaling functionalities due to the difficulty in integrating new components and functionalities into decentralized embedded systems, particularly in vehicles with multiple Electronic Control Units (ECUs).

Method used

A central computing unit (CCU) is employed to manage various vehicle functionalities through a distributed computing system, enabling efficient reconfiguration and plug-and-play capabilities by dynamically assigning and controlling components or functional groups based on their capabilities, using a unified software API and adaptable reference information.

Benefits of technology

The CCU facilitates flexible and adaptive management of vehicle functionalities, allowing seamless integration of new components, optimizing resource use, and maintaining consistent performance even with changes in the vehicle's configuration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024076267_16042026_PF_FP_ABST
    Figure EP2024076267_16042026_PF_FP_ABST
Patent Text Reader

Abstract

A method and a system for controlling different functionalities of a vehicle comprising a computing system in the form of a central computing unit, CCU, for simultaneously running multiple computer programs, e.g., applications relating to different functionalities of the vehicle. The method comprises an initialization process and a controlling process. The initialization process comprises: receiving, for each of a plurality of controllable components or controllable functional groups of components of the vehicle, capability information representing one or more capabilities of the respective component or functional group that are configured to be controlled by the CCU; and assigning to each functionality in a set of different functionalities of the vehicle, which are controllable by the CCU, a set of one or more of the components or functional groups based on the capability information and on reference information, wherein the reference information defines for each functionality in the set of functionalities a corresponding required set of one or more capabilities for performing this functionality. The controlling process comprises selectively maintaining, activating, deactivating, or configuring a functionality of the vehicle based on a comparison of the capabilities represented in the capability information and the required set of capabilities for that functionality as represented by the reference information.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] METHOD AND SYSTEM FOR CONTROLLING DIFFERENT FUNCTIONALITIES OF A VEHICLE

[0002] The present invention relates to the field of computing systems for vehicles. Specifically, the invention is directed to a method and a system for controlling different functionalities of a vehicle comprising a computing system in the form of a central computing unit (CCU) for simultaneously running multiple computer programs, e.g., applications relating to different functionalities of the vehicle.

[0003] Typically, a modern vehicle, such as an automobile, comprises a plurality of different electronic components, including in particular so-called Electronic Control Units (ECUs) which are interconnected by one or more communication links or whole networks, such as bus systems, e.g., of the well-known CAN or LIN type. Moreover, Ethernet-based networks are becoming more and more relevant in that context.

[0004] Many ECUs are, in fact, embedded systems comprising hardware, such as a processing platform and related software running on the processing platform. Accordingly, such an ECU forms an embedded system and when multiple ECUs are interconnected via a communication network, such network can be designated as a distributed embedded system (network). Why such an “embedded” set-up is particularly useful in terms of its capability to provide real-time processing and an optimal fit of the software of a given ECU to its respective processing platform, it is typically difficult to extend or scale such embedded systems or to add new functionality.

[0005] An alternative approach is based on the idea that rather than or instead of using dedicated software running on dedicated hardware to provide a certain specific functionality, i.e. , the functionality of a particular ECU, a central computing architecture is used, wherein the desired different functionalities are provided by multiple different computer programs, esp. applications, running on a same CCU, which is thus a shared computing resource.

[0006] Particularly, such a CCU-based approach allows for more flexibility than traditional decentralized approaches in terms of extending, scaling or reducing functionalities of a vehicle, as described above. However, care needs to be taken to properly assign the vehicle functionalities associated with the computer program(s) running on the CCU with the components and / or functional groups of components of the vehicle, such as sensors and actuators, that are at any given time actually available to perform these functionalities under control of the CCU. This is particularly, relevant considering the possibility to add, remove or replace such components or functional groups during the lifetime of the vehicle.

[0007] An exemplary CCU is described in PCT / EP2023 / 055182, which is incorporated herein in its entirety by way of reference.

[0008] It is an object of the present invention to enable an efficient (re-)configuration, such as in a plug-and-play manner, of functionalities of a vehicle having different functionalities being configured to be controlled by a CCU of the vehicle.

[0009] A solution to this problem is provided by the teaching of the independent claims. Various preferred embodiments of the present invention are provided by the teachings of the dependent claims.

[0010] Terms

[0011] Some terms used herein to define the present solution are explained below in more detail:

[0012] The term “central computing unit” or its abbreviation “CCU”, as used herein, may particularly refer to a computing device being configured as an on-board computing unit for a vehicle, such as an automobile, to centrally control different functionalities of the vehicle, the computing device comprising (i) a distributed computing system, DCS, (ii) a communication switch, and (iii) a power supply system, each as defined below:

[0013] The term “distributed computing system”, DCS, (and variations thereof), as used herein, may particularly refer to a computing system comprising a plurality of co-located (e.g., in a same housing, such as a closed housing or an open housing, e.g., a rack), autonomous computational entities, CEs, each of which has its own individual memory. The CEs are configured to communicate among each other by message passing via one or more communication networks, such as high-speed communication networks, e.g., of the on PCIexpress or Ethernet type, to coordinate among them an assignment of computing tasks to be performed by the DCS as a whole. Particularly, in the case of multiple communication networks, these networks may be coupled in such a way as to enable passing of a message between a sending CE and a receiving CE over a communication link that involves two or more of the multiple networks. For example, a given message may be sent from a sending CE in a PCIexpress-format over one or more first communication paths in a PCIexpress network to a gateway that then converts the message into an Ethernet-format and forwards the converted message over one or more second communication paths in an Ethernet- network to the receiving CE. Particularly, the set of individual CEs of the DCS may be configured to perform parallel task processing such that the CEs of the set simultaneously perform a set of similar or different computing tasks, e.g., such that each CE individually performs a true subset of the set of computing tasks to be performed by the DCS as a whole, wherein the computing tasks performed by different CEs may be different.

[0014] The communication switch may comprise a plurality of mutually independent (i.e. , at least functionally independent) switching fabrics, each configured to variably connect a subset or each of the CEs of the DCS to one or more of a plurality of interfaces for exchanging thereover information with CCU-external communication nodes of the vehicle, such as network endpoints, e.g., actuators or sensors, or intermediate network nodes, e.g., hubs, for connecting multiple other network nodes.

[0015] The power supply system may comprise a plurality of power supply sub-systems for simultaneous operation, each of which is individually and independently of each other capable of powering the DCS and at least two, preferably all, of the switching fabrics. Herein, “powering” means particularly delivering power to the entity to be powered and may optionally further comprise generating the power in the first place and / or converting it to a suitable power kind or level, e.g., by DC / DC, AC / DC, or DC / AC conversion, or a conversion of a time-dependency of a power signal (signal shaping).

[0016] The term “computational entity”, CE, (and variations thereof), as used herein, may particularly refer to an autonomous computing unit which is capable of performing computing tasks on its own and which comprises for doing so at least one own processor and at least one own associated memory. Particularly, each CE may be embodied separately from all other CEs. For example, it may be embodied in one or more circuits, such as in an integrated circuit (e.g., as a system-on-chip (SOC), a system-in-package (SIP), multi-chip module (MCM), or chiplet) or in a chipset.

[0017] The term “switching fabric” (and variations thereof), as used herein, may particularly refer to hardware for variably connecting multiple different nodes of a network, such as nodes of a computer network, to exchange data therebetween.

[0018] The term “communication switch” (and variations thereof), as used herein, may particularly refer to a switch that comprises at least two switching fabrics and is configured to use the switching fabrics, alternatively or simultaneously, to variably connect multiple different nodes of a network, such as nodes of a computer network, to exchange data therebetween. A communication switch may particularly include, without limitation, one or more PCI Express (PCIe) switches and / or Compute Express Links (CXL) as switching fabrics.

[0019] The term “switching” (and variations thereof), as used herein (including in the terms “switching fabric” and “communication switch”), refers generally to variably connecting different nodes of a network to exchange data therebetween, and unless explicitly specified otherwise herein in a given context, is not limited to any specific connection technology such as circuit switching or packet switching or any specific communication technology or protocol, such as Ethernet, PCIe, and the like.

[0020] The term “embedded system”, as used herein, may particularly refer to a computer system - i.e., a combination of a computer processor, computer memory, and input / output peripheral devices - that has a dedicated function within a larger mechanical or electronic system, e.g., the total electronic system of a vehicle, i.e., an embedded system is dedicated to one or more specific tasks forming a strict subset of the set of tasks of the larger mechanical or electronic system. An embedded system may particularly be embedded as part of a complete device, often including electrical or electronic hardware and mechanical parts. Because an embedded system typically controls physical operations of a machine of a vehicle, such as an engine (or a whole powertrain), a steering system or a braking system, that it is embedded within, it often has real-time computing constraints. Modern embedded systems are often based on microcontrollers (i.e., microprocessors with integrated memory and peripheral interfaces), but ordinary microprocessors (using external chips for memory and peripheral interface circuits) are also common, especially in more complex systems. In either case, the processor(s) used may be types ranging from general purpose to those specialized in a certain class of computations, or even custom designed for the application at hand. A common standard class of dedicated processors is the digital signal processor (DSP).

[0021] The term “initialization process”, as used herein, may particularly refer to a sequence of steps or activities involved in setting up or configuring a system, application, or device for use. This process typically involves a series of actions that need to be taken to prepare the system or device for operation. The initialization process can vary depending on the type of system, device, or application being initialized, and may involve different steps or activities. Specifically, in addition to the steps defined above in the subsection (i) for the initialization process, it may optionally further involve one or more of the following: 1. Bootstrapping: The process of starting up a computer or other device from a power- off state and loading the operating system and applications.

[0022] 2. Configuration: The process of setting up the system or device with the desired settings, options, and applications.

[0023] 3. Initialization: The process of initializing the system or device by setting its internal state to a known good configuration and preparing it for use.

[0024] 4. Startup: The process of starting the system or device after initialization and making it ready for use.

[0025] 5. Acceptance test: The process of determining, whether a newly identified component or functional group of components qualifies as an admissible component / group of components according to acceptance criteria. The process may further involve selectively enabling, registering in the system or device, and / or supplying with energy only such components / group of components which are determined by the process as being (sufficiently) qualified.

[0026] The term “functionality”, as used herein, may particularly refer to a set of one or more capabilities or features that a system, such as a vehicle, is designed to perform. It may encompass one or more tasks that can be performed by the system, and the degree to which it can perform those tasks effectively and efficiently. Functionality can include both the basic operations that a system must perform to be useful, and any additional features or capabilities that enhance its usefulness. For example, a vehicle may have different functionalities, such as automatic cruise control (ACC), automatic air conditioning, a navigation system, variable ambient lighting, cellular networking, Emergency call, airbags, or other safety features, and so forth, just to name a few.

[0027] The term “functional component” or “component” for short, as used herein, may particularly refer to a distinct part or element that contributes as a constituent to a larger system, such as a vehicle or subsystem thereof. Components are individual elements or modules that are combined to form a more complex system, such as a computing system or a vehicle. Each component typically has a specific function or purpose within the system, and may be designed to interact with other components in various ways. Examples of components in a system include: Hardware components: These are tangible parts of a system, such as computers, printers, or sensors.

[0028] - Software components: These are intangible parts of a system, such as applications, modules, or functions within a larger program.

[0029] - Network components: These are elements that make up a communication network, such as routers, switches, or servers.

[0030] - Human-machine interface (HMI) components: These are the visual and auditory elements of a system, such as displays, keyboards, or speakers.

[0031] - Data storage components: These are elements that store or retrieve data within a system, such as hard drives, memory modules, or databases.

[0032] - Security components: These are elements that protect a system from unauthorized access or malicious attacks, such as firewalls, intrusion detection systems, or encryption algorithms.

[0033] - Power supply components: These are elements that provide energy to a system, such as batteries, power supplies, or generators.

[0034] - Data transmission components: These are elements that transmit data within a system, such as cables, antennas, or wireless communication devices.

[0035] - Processing components: These are elements that perform calculations or operations within a system, such as central processing units (CPUs), graphics processing units (GPUs), or digital signal processors (DSPs).

[0036] - Control components: These are elements that regulate the behavior of a system, such as controllers, sensors, or actuators.

[0037] The terms “functional group of components” or “functional group” for short, as used herein, may particularly refer to a set of two or more components which collectively define a functionality so that each of the components in the set contributes to providing the functionality while none of the components can provide this functionality (completely) alone. For example, a memory system comprising as components one or more separate memory devices (e.g., memory chips) and an additional memory controller (chip) forms a function group of components because the memory functionality provided by the memory system (of a given memory size) requires each of these components.

[0038] The term “functional capability” or “capability” for short, as used herein, may particularly refer to the functionality of a component or group of components, to how (i.e., according to which technical approach), and / or how well the component or group of components can perform its intended function (i.e., its functionality) within a system, such as a vehicle or subsystem thereof. Accordingly, capability is a measure of whether and / or how well a component / group of components can execute its designed tasks, and is often evaluated in terms of performance, reliability, maintainability, and scalability. (Non-limiting) Examples of capabilities for different types of components include:

[0039] For hardware components:

[0040] - Processing power: The ability of a computer or device to perform complex calculations or operations quickly and efficiently;

[0041] - Memory capacity: The amount of data that can be stored in a system's memory, such as RAM or hard drive space;

[0042] - Network connectivity: The ability of a system to connect to other devices or networks, such as Wi-Fi or Ethernet capabilities.

[0043] For software components:

[0044] - Functionality: The range of tasks that a software application can perform;

[0045] - Performance: The ability of an application to run smoothly and efficiently, without significant delays or errors;

[0046] - Security features: The ability of an application to protect itself and its data from unauthorized access or malicious attacks.

[0047] For network components:

[0048] - Interfaces: kind of communication technology used, e.g., cellular or WLAN communication;

[0049] - Throughput: The amount of data that can be transmitted over a network in a given time period, e.g., frame rate or maximum bitrate;

[0050] - Format: Format used for formatting data to be communicated

[0051] - Reliability: The likelihood that a network connection will be disrupted or fail, measured in terms of downtime or failure rate;

[0052] - Scalability: The ability of a network to accommodate increasing amounts of data or users without significant performance degradation. For human-machine interface (HMI) components:

[0053] - Usability: The ease with which users can interact with a system, such as through intuitive interfaces or clear instructions;

[0054] - Readability: The ability of a system to present information in a clear and readable format;

[0055] - Accessibility: The ease with which users with disabilities can access and use a system.

[0056] For data storage components:

[0057] - Capacity: The amount of data that can be stored within a system, such as the memory size of a memory system (e.g., flash memory system) or the capacity of a database.

[0058] - Retrievability: The ability of a system to retrieve data in a timely manner, without significant delays or errors.

[0059] - Security: The ability of a system to protect data from unauthorized access or tampering.

[0060] In summary, “(functional) capability” may refer to a measure of how well a component / group of components can perform its intended function within the system, and it can be influenced by various factors such as design, materials, configuration, maintenance, and environmental factors. When used in relation to a functionality, the required set of capabilities for a functionality refers to one or more capabilities that must be provided to enable the functionality, wherein these one or more capabilities may be provided by a single component or multiple components collectively.

[0061] The term “control” and variations thereof, as used herein, may particularly refer to the process of managing, regulating, or directing the behavior or performance of a specific functionality or component within a larger system, such as a vehicle. The goal of controlling is to ensure that the component or function operates within desired parameters, tolerances, or performance levels, and to make adjustments as needed to maintain optimal system performance. Controlling can involve various activities, including:

[0062] Monitoring: Regularly tracking and analyzing the performance of a component or functionality to identify any deviations from expected behavior or performance standards. Adjustment: Making changes or adjustments to the component or function to improve its performance or to correct any deviations that have been identified through monitoring.

[0063] - Control: Implementing controls or constraints on the component or function to ensure that it operates within desired parameters, such as limiting maximum power consumption or ensuring that a sensor output remains within a certain range.

[0064] - Optimization: Identifying opportunities for improvement in the component or function and implementing changes to enhance performance, efficiency, or reliability.

[0065] - Failure detection and recovery: Establishing procedures for detecting and recovering from failures of components or functions, such as graceful degradation or redundancy.

[0066] - Predictive maintenance: Using data analytics and machine learning to predict when a component or function is likely to fail, allowing for proactive maintenance and minimizing downtime.

[0067] - Performance optimization: Identifying opportunities to improve the performance of a component or function through algorithms, data analysis, or other techniques.

[0068] The term “subsystem”, as used herein, relates to a system, such as a sensor system or actuator system, which is designed and / or used as a functional unit of a higher-level system. For example, sensor systems and actuator systems designed or used as functional units of a vehicle may each be considered a “subsystem” of the higher-level system “vehicle”.

[0069] The terms “first”, “second”, “third” and the like in the description and in the claims, are used for distinguishing between similar elements and not necessarily for describing a sequential or chronological order. It is to be understood that the terms so used are interchangeable under appropriate circumstances, and that the embodiments of the present solution described herein are capable of operation in other sequences than described or illustrated herein.

[0070] Unless the context requires otherwise, where the term “comprising” or “including” or a variation thereof, such as “comprises” or “comprise” or “include”, is used in the present description and claims, it does not exclude other elements or steps and are to be construed in an open, inclusive sense, that is, as “including but not limited to”. Where an indefinite or definite article is used when referring to a singular noun, e.g., “a” or “an”, “the”, this includes a plural of that noun unless something else is specifically stated.

[0071] Appearances of the phrases “in some embodiments”, “in one embodiment” or “in an embodiment”, if any, in the description are not necessarily all referring to the same embodiment. Furthermore, the particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0072] Further, unless expressly stated to the contrary, “or” refers to an inclusive “OR” and not to an exclusive XOR. For example, a condition A or B is satisfied by any one of the following: A is true (or present) and B is false (or not present), A is false (or not present) and B is true (or present), and both A and B are true (or present).

[0073] By the terms “configured” or “arranged” to perform a particular function, (and respective variations thereof) as used herein, it is to be understood that a relevant device or component is already in a configuration or setting in which it can perform the function, or it is at least adjustable - i.e., configurable - in such a way that it can perform the function after appropriate adjustment. In this context, the configuration can be carried out, for example, through a corresponding setting of parameters of a process sequence or of hardware (HW) or software (SW) or combined HW / SW-switches or the like for activating or deactivating functionalities or settings. In particular, the device may have a plurality of predetermined configurations or operating modes so that the configuration can be performed using a selection of one of these configurations or operating modes.

[0074] A first aspect of the invention is directed to a method of controlling different functionalities of a vehicle. The method, which may particularly be performed in whole or part by

[0075] - a central computing unit, CCU, of the vehicle itself;

[0076] - a test infrastructure for the vehicle as a whole or for subsystems thereof, or

[0077] - the CCU in collaboration with the test infrastructure, comprises:

[0078] (i) an initialization process comprising:

[0079] - receiving, for each of a plurality of controllable components or controllable functional groups of components of the vehicle (such as sensors or actuators, for example), capability information representing one or more capabilities (such as capabilities of sensors, and / or actuators, data or signal processing entities, signal restoration entities, energy distribution entities, zonal controllers (ZeC), signal transmission lines) of the respective component or functional group that are configured to be controlled by the CCU; and

[0080] - assigning to each functionality in a set of different functionalities of the vehicle, which are controllable by the CCU, a set of one or more of the components or functional groups based on the capability information and on (static or dynamically adaptable, e.g., by software update and / or SW parameter adaptions) reference information, wherein the reference information defines for each functionality in the set of functionalities a corresponding required set of one or more capabilities for performing this functionality; and

[0081] (ii) a controlling process comprising selectively maintaining, activating, deactivating, or configuring a functionality of the vehicle based on a comparison of the capabilities represented in the capability information and the required set of capabilities for that functionality as represented by the reference information.

[0082] To this purpose, the controlling process may particularly comprise communicating control information to the one or more components or functional groups being assigned to this functionality to cause it or them, respectively, to maintain, activate, deactivate, or (re-)configure this functionality.

[0083] Accordingly, while the initialization process may be considered as a process which provides a proper assignment, i.e. , “logical” association, of components and / or functional groups to the respective functionality, the controlling process may be considered as a process which takes care of actually realizing this functionality “physically” by controlling the assigned components and / or functional groups to actually provide the functionality.

[0084] Accordingly, the method provides for a matching of controllable components or controllable functional groups of components of the vehicle on the one side with requirements of a respective vehicle functionality in question. Based on this matching (comparison), the respective functionality can be operated (or deactivated instead) according to the matching result. Thus, care is taken to avoid situations where in the context of controlling different functionalities of the vehicle, the available capabilities are insufficient for performing requested functionalities. The comparison may be performed either as part of the initialization process or as part of the controlling process, or by both in combination. In fact, the method supports a plug & play capability, where the set of controllable components or groups of components may not only be considered in an initial configuration of the vehicle, such as ex works, but also later, when the vehicle configuration is changed, e.g., by adding further components, removing components or upgrading or otherwise modifying components.

[0085] Similarly, plug & play is also supported in situations, where instead or in addition to a change on the component side, functionalities of the vehicle are added, removed, upgraded, or otherwise modified on the functionality side.

[0086] In the following, preferred embodiments of the method of the first aspect are described, which can be arbitrarily combined with each other or with other aspects of the present solution, unless such combination is explicitly excluded herein or technically impossible.

[0087] In some embodiments, the reference information is dynamically adjusted, e.g., through a software or data update. For example, if an algorithm used to implement a given functionality is updated to become more efficient, fewer components or more primitive components or functional groups, respectively, might be required by the updated algorithm, which can be reflected in updated reference information. Accordingly, the controlling process for future uses of the functionality can thus be impacted, and the functionality can be improved, e.g., in terms of efficiency (such as reduced energy consumption) and / or effectiveness, e.g., higher performance. Furthermore, in some instances, freed resources, which are no longer required at all for a particular functionality or only to a lesser extent than before the update, might be used for other purposes instead. For example, if a set of three- cameras for monitoring the environment of the vehicle is replaced by a radar sensor in the course of the update, one or more other cameras or camera positions might be added instead, e.g., for visually monitoring another space in or around the vehicle.

[0088] In some embodiments, the controlling process comprises: (i) receiving from at least one of the components or functional groups assigned to a functionality and having at least one sensor capability identified in the corresponding capability information, sensor information representing the result of at least one sensory measurement performed by the component or functional group, respectively, and (ii) communicating control information to one or more components or functional groups, respectively, being assigned to this functionality and having at least one actuator capability or user-interface capability identified in the corresponding capability information to cause it or them, respectively, to perform the functionality as a function of the sensor information. The functionality may particularly be a functionality which is to be maintained (i.e. , kept in a currently non-deactivated state, such as an activated or sleeping, e.g., hibernating, but not switched-off state) by the controlling process. It may also be controlled to transition between different non-deactivated states, such as a hibernation state and an active state.

[0089] Thus, based on sensor information being generated by one or more first components or functional groups, one or more second components or functional groups being configured as actuators or user interfaces can be properly controlled based on the sensor information to perform a functionality to which both the first and second components or functional groups are assigned. For example, in the context of driver assistance functionalities or automated driving functionalities of the vehicle, if a light sensor detects that the environment of the vehicle is dark, e.g., below a defined brightness level for at least a defined time span (such as by night or in foggy environments or in forests), then a Lidar or radar subsystem (as a second component or functional group) of the vehicle might be automatically activated in addition to an already activated camera subsystem (as a first component or functional group) to support the functionality.

[0090] In some embodiments, the selectively maintaining, activating, deactivating, or configuring a functionality of the vehicle is further based on demand information defining for each component or functional group assigned to the functionality a respective set of one or more requirements which the component or functional group, respectively, needs for its operation. This is particularly useful, if a given functionality can be implemented in various ways, i.e., using different components or sets of components. If, for example, an available energy budget for performing the functionality is currently very limited, then the demand information can be used as an additional criterion for selecting an optimal component or functional group for performing the functionality considering the limited energy budget, i.e., a low-energy way of performing the functionality.

[0091] In some embodiments, the initialization process is performed repeatedly, such as periodically or continuously, during operation of the CCU. The controlling process is then performed based on the assignments of components and functional groups, respectively, to functionalities of the vehicle resulting from the respective last completed run of the initialization process. This approach allows for an iterative evolution of the controlling of the functionalities controlled by the CCU. If, for example, the set of components and functional groups is extended, reduced, or otherwise modified over time, be it by intention, e.g., by adding or removing a component, or by failure or parameter drifting of components or functional groups, then the implementation of the related vehicle functionalities can be repeatedly, esp. continuously, adapted “in the field” automatically, i.e., in a plug & play manner.

[0092] In some embodiments, the method comprises: (i) monitoring, whether a component or functional group has been physically added or removed from the plurality of components or functional groups of the vehicle, and (ii) when the monitoring yields that one or more components or functional groups have been physically added or removed, initiating a new run of the initialization process. Thus, the method is even adaptive when the underlying physical system, i.e., the set of components and / or functional groups is changed, such as when the vehicle is upgraded or adapted to other use cases post-production.

[0093] In some embodiments, the initialization process further comprises: (i) determining, based on the capability information, that a previously available component or functional group is no longer available to support a given functionality of the vehicle, and (ii) the controlling process comprises selectively deactivating this given functionality of the vehicle. In this way defunct or removed components or function groups can be detected and the related functionality, which requires such previously available component(s) or functional group(s) is automatically deactivated to keep the overall set of available vehicle functionalities consistent with the actual capabilities.

[0094] Specifically, in some embodiments, when the monitoring yields that one or more components or functional groups have been physically added, each such new component or functional group, respectively, is checked regarding fulfillment of each acceptance criteria in a defined set comprising one or more of the following acceptance criteria individually or in any combination of at least two of them, and is only admitted for control by the CCU according to the controlling process if all the acceptance criteria in the set are fulfilled: (i) the component or functional group has been previously registered with the vehicle; (ii) the component or functional group has a defined trusted digital certificate; (iii) the component or functional group is connected to a power supply. This may be used to increase the security level of the vehicle, e.g., by identifying wrong or counterfeited components or functional groups and denying their use within the vehicle.

[0095] In some embodiments, the initialization process comprises: (i) determining, based on the capability information, that a previously available component or functional group is no longer available to support a given functionality of the vehicle, and (ii) the controlling process comprises: (a) selectively deactivating this given functionality of the vehicle; or

[0096] (b) communicating control information to at least one other component or functional group being available to support the given functionality, at least to a reduced extent, to cause this at least one other component or functional group to perform the functionality, at least to a reduced extent, as a replacement of the no longer available component or functional group, respectively.

[0097] Accordingly, while option (a) is most suitable, if no other component or functional group is available to take over the tasks of the “lost” component / functional group, option (b) can be more suitable in other situations where such replacement is available, at least to a sufficient extent. Accordingly, in the latter case, when a functionality for which one or more previously available components or functional groups for its implementation are no longer available, the functionality does not need to be deactivated but instead a different basis of implementation, i.e., one or more other components or functional groups which are suitable and available to perform the functionality can be used instead to keep the functionality available despite the falling away of the previously available components or functional group. This flexibility is useful in several cases, particularly in a failure scenario when a component of functional group becomes unavailable by way of failure, or in a modification scenario, when one or more components or functional groups are intentionally removed from the set of components / functional groups or replaced by different components or functional groups during a conversion of the vehicle,

[0098] In some embodiments, the method further comprises selectively assigning a respective priority from a set of different priorities to each functionality in the set of different functionalities of the vehicle. The controlling process then further comprises deactivating or reducing an operational scope or performance of at least one further functionality in the set of functionalities that has a priority being lower than that of the given functionality. This is particularly useful in scenarios, where not enough resources, e.g., energy or computing or data storage capacity, is currently available to perform all desired functionalities simultaneously. The prioritization based on the assigned priorities thus allows for a smart, situation-adapted allocation of the scarce resources such as to use them in an optimal manner, thus keeping any adverse impacts of such shortage low.

[0099] Specifically, reducing an operational scope or performance of the least one further functionality in the set of functionalities that has a priority being lower than that of the given functionality may comprise communicating control information to one or more of the components and / or functional groups being assigned to this further functionality to cause it or them, respectively, to transition to a low-power and / or low-performance mode of operation to thereby reduce an operational scope or performance of the further functionality.

[0100] In some embodiments, the reference information is provided in a look-up table being accessible by the CCU. This allows for a simple, efficient, and easily adjustable manner of providing current reference information accessible for the CCU.

[0101] In some embodiments, the controlling process further comprises:

[0102] - performing or causing at least one of the components or functional groups to perform one or more functional tests to determine whether or not, or to which degree the respective component or functional group, respectively, is currently actually capable of providing the capabilities represented in its associated capability information; and

[0103] - when it is thereby determined that the component or functional group, respectively, is currently failing to provide one or more of the capabilities represented in its associated capability information, performing one or more of the following steps: a) treating the component or functional group, respectively, as if it was not present; b) deactivating the component or functional group, respectively; c) determining that the component or functional group, respectively, is or might be a fake product; d) modifying the capability information of the component or functional group, respectively, for further use with a reduced set of capabilities, based on its determined actual capabilities; e) issuing or causing one or more of the components or functional groups having, according to the associated capability information, a suitable capability, to issue warning information or a signal indicating a failure or a reduced functionality; f) reporting or causing one or more of the components or functional groups having, according to the associated capability information, a suitable capability, to report the determined failure to a vehicle-external report collection system.

[0104] In this manner, the method is capable of identifying and reacting “on the fly” to any deviations from a defined target setting, as defined by the initial capability information properly to keep the vehicle safe and avoid undetected unavailabilities of functionalities which are expected to be available, e.g., by a driver of the vehicle. A second aspect of the present solution is directed to a central computing unit, CCU, comprising at least one processor being configured to perform the method of the first aspect to control different functionalities of a vehicle by selectively controlling a plurality of components or functional groups of components of the vehicle.

[0105] A third aspect of the present solution is directed to a system for controlling a functionality of a vehicle. The system comprises: (i) a plurality of components or functional groups of components for a vehicle, and (ii) a CCU according to the second aspect, wherein the CCU is configured to perform the method of the first aspect to control one or more of the components or functional groups of the system.

[0106] The system may particularly have one or more of the following properties:

[0107] (a) all the components and / or functional groups in the plurality of components or functional groups of components of the vehicle are connected, directly or indirectly via one or more intermediate devices, to the CCU using a detachable physical connection of a same type;

[0108] (b) the CCU uses a same unified software API to control two or more, preferably all, of the components and / or functional groups in the plurality of components or functional groups of components of the vehicle;

[0109] (c) the system comprises a set of different hardware drivers to be used for different types of components or groups of components, and is configured to select for each given type of component or group of components an associated hardware driver based on the capability information of the respective component or group of components;

[0110] (d) at least one, preferably all, of the components and / or functional groups in the plurality of components or functional groups of components of the vehicle is configured to authenticate itself to the CCU using identification information which is uniquely associated with that particular component or group of components or is associated with a specific type of component or group of components;

[0111] (e) at least one, preferably all, of the components and / or functional groups in the plurality of components or functional groups of components of the vehicle is a digital component or a digital functional group, respectively;

[0112] (f) the CCU is configured to communicate with all the components and / or functional groups in the plurality of components or functional groups of components via one or more digital communication links or digital networks.

[0113] Specifically, property (a) allows for a fast and easy exchange or replacement of components or functional groups and thus a convenient way of reconfiguring the hardware of the vehicle, such as its set of components and functional groups, such as sensors and actuators. Using detachable physical connections of a same type avoids a need of adding complexity to the cost and / or assembly of the wiring harness of the vehicle. For example, a camera and a radar sensor can use the same type of connector and therefore be interchangeable in the same position at the vehicle 800. In the case, where an intermediate device, such as a zonal controller is used, the design of such an intermediate device can be kept simpler because there is also no need for different connectors at such device either.

[0114] Property (b) may help to reduce the complexity of signal processing, e.g., in the CCU because a unified API is used for multiple different components and / or functional groups. It may also help to simplify zonal controllers of the system, if present, because there is less / no need to provide for different API-dependent signal processing at the level of zonal controllers.

[0115] Property (c) may help to reduce the memory capacity needed for storing hardware drivers, particularly when one or more of them can be used in a multi-use manner for various hardware entities of a same type, such as identical or similar hardware devices, e.g., identical or similar sensors or actuators.

[0116] Property (d) may help to increase the security of the system and to ensure that only admissible components and functional groups are operatively used in the system.

[0117] Properties (e) and (f) may each help to increase compatibility with other digital components or functional groups and to increase reliability of signal processing. Herein, the term “digital” indicates that the related component or functional group has one or more of a digital input, a digital processing capability, and a digital output.

[0118] A fourth aspect of the present solution is directed to a vehicle comprising the system of the third aspect.

[0119] A fifth aspect of the present solution is directed to a computer program or computer program product, comprising instructions which, when executed on a CCU according to the second aspect, cause the CCU to perform the method of the first aspect.

[0120] The features and advantages explained regarding the first aspect of the solution apply accordingly to the further aspects of the solution. BRIEF DESCRIPTION OF THE DRAWINGS

[0121] Further advantages, features, and applications of the present solution are provided in the following detailed description and the appended figures, wherein:

[0122] Fig. 1 illustrates, according to embodiments of the present solution, a first block diagram illustrating functional building blocks of an exemplary CCU and a related high-level communication structure for communication within the CCU and with CCU-external nodes;

[0123] Fig. 2 illustrates in more detail some functional building blocks of the CCU of Fig.1 ;

[0124] Fig. 3 illustrates, according to embodiments of the present solution, a first view of a second block diagram showing more details of the functional building blocks of the CCU of Fig. 1 , with a focus on the redundant set-up of power supply and power supply coordination, control coordination, and computing coordination within the CCU;

[0125] Fig. 4 illustrates a second view of the second block diagram of Fig. 3, however now with a focus on abnormality detection in the power supply domain;

[0126] Fig. 5 illustrates a redundancy concept with multiple instantiations per master CE and / or per associated switching fabric;

[0127] Fig. 6 illustrates a classical strictly hierarchical communication scheme from the prior art, according to the PCI Express communication technology;

[0128] Fig. 7 illustrates, according to embodiments of the present solution, an exemplary adapted communication scheme using the PCI Express technology as a basis;

[0129] Fig. 8 illustrates, according to embodiments of the present solution, various exemplary communication links being enabled by the adapted communication scheme of Fig. 7;

[0130] Fig. 9 illustrates, according to embodiments of the present solution, a third block diagram 500 showing more details of an exemplary CCU, e.g., the CCU of Fig. 1 , particularly of its communication switch;

[0131] Fig. 10 illustrates, according to embodiments of the present solution, an exemplary housing concept of an exemplary CCU, e.g., the CCU of Fig. 1 ; Fig. 11 schematically illustrates a computing platform with a CCU of or for a vehicle;

[0132] Fig. 12 schematically illustrates a vehicle (specifically an automobile) comprising the computing platform of Fig. 1 and various suitable locations for placing the CCU within the vehicle;

[0133] Fig. 13 is a flow chart illustrating the method of controlling different functionalities of a vehicle in accordance with at least one exemplary embodiment;

[0134] Fig. 14 is a flow chart illustrating an exemplary embodiment of the initialization process of the method of Fig. 13; and

[0135] Fig. 15 is a flow chart illustrating an exemplary embodiment of the controlling process of the method of Fig. 13.

[0136] In the figures, in many instances, identical reference signs are used for the same or mutually corresponding elements of the methods and apparatus described herein. For the sake of clarity, the following detailed description is structured into sections, introduced in each case by a heading. These headings are, however, not to be understood as limiting the content of the respective section corresponding to a heading or of any figures described therein. When the following refers to a “step” or “steps” of the method, this does not mean that the associated action must necessarily take place in a single coherent operation. Rather, it is also possible that a “step” is composed of several individual operations in the sense of a process and thus corresponds to a sub-process of the method.

[0137] Although the method steps are, at least in parts, described in the context of the specific systems illustrated in some figures, such as Figs. 10 and 11 , a person skilled in the art will understand that any system configured to perform the method steps, in any order, falls within the scope of the present solution.

[0138] DETAILED DESCRIPTION OF EMBODIMENTS

[0139] Central Computing Unit, CCU

[0140] Figs. 1 and 2 show a (first) block diagram illustrating selected functional building blocks of an exemplary computing platform 700 having a central computing unit (CCU) 105 and a related high-level communication structure for communication within the CCU 105 and with CCU-external communication nodes.

[0141] CCU 105 comprises (i) a computer module cluster 110 with a main computing module 115, one or more general-purpose computing modules 120, and one or more special-purpose modules 125, (ii) a service module 135, and (iii) a connection device 130, such as a backplane (which may particularly be a passive backplane), for interconnecting the modules both among each other and with the service module 135.

[0142] The interconnections provided by the connection device 130 may particularly comprise power connections for exchanging power, such as electrical power P, data connections (e.g., Ethernet, PCI, or PCIe) for exchanging data D, control connections (e.g., I2C) for exchanging control information C, alarm connections for exchanging alarm information A, and power management connections for exchanging power management information I.

[0143] In the example of Fig. 1 , the CCU-external communication nodes comprise a first endpoint cluster 140 which is optically connected, for example via a fiber communication link O, to CCU 105, a second endpoint cluster 145 that connected via a wireless communication link W, e.g., a Bluetooth, WLAN, ZigBee, or cellular mobile connection link, to CCU 105. A third endpoint cluster 150, which may particularly be or comprise a zonal hub for interconnecting the CCU 105 to further endpoints 330, may be connected by a cable connection. A fourth endpoint cluster 155 may be connected to CCU 105 via a separate intermediate wireless transceiver 160.

[0144] Furthermore, two or more of the endpoint clusters 515 may be directly linked with each other by communication links that do not involve CCU 105, as exemplarily illustrated with a wireless communication link W between the third endpoint cluster 150 and the fourth endpoint cluster 155. Each of the endpoints 330 is a node within the communication network being formed by the communications links connecting the endpoints 330 directly or indirectly to CCU 105 or among each other. Particularly, an endpoint 330 may be or comprise one or more of an actuator 715, a sensor 720, and an intermediate network node, e.g., hub, for connecting multiple other endpoints 330.

[0145] The term “endpoint cluster” 515, as used herein, refers to a set of endpoints 330 which are connected directly or indirectly via respective communication links to a same network node so that all of them can exchange information with that common node. Typically, this common node will have some sort of hub functionality, i.e., serve as an intermediate node in a communication link between other nodes being connected to it.

[0146] CCU 105 further comprises (not shown in Figs. 1A and 1 B) a communication switch and a power supply system. These building blocks of CCU 105 will be discussed further below with reference to Figures 2 to 5.

[0147] Referring now to Fig. 2, which illustrates the main computing module 115, the general- purpose computing modules 120, and the special-purpose modules 125 of the computing module cluster 110 of Fig. 2 in more detail. Turning first to main computing module 115, which comprises within the same module and thus in co-location at least a first computational entity (CE) 115a, a separate second computational entity 115b and optionally one or more further CEs 115c. All of these CEs are autonomous and independent of each other in the sense that all of them have comparable, ideally identical, computing capabilities and their respective own individual memory, so that each of these CEs can serve as a replacement for a respective other one of these CEs.

[0148] In the further discussion, for the sake of simplicity and without limitation, an exemplary case is considered where beyond the first CE 115a and the second CE 115b no further CEs 115c are present in the main computing module 115. Each of the first CE 115a and the second CE 115b may be embodied in a respective separate hardware unit, such as a semiconductor chip, e.g., a system-on-chip (SOC).

[0149] The first CE 115a and the second CE 115b are configured, e.g., by a respective software (computer program(s)), to work redundantly in such a way that they synchronously perform identical computing tasks to enable a proper functioning of the CCU 105 for as long as at least one of the first CE 115a and the second CE 115b is properly working. Accordingly, there is not only a redundancy among the first CE 115a and the second CE 115b in terms of a redundant hardware, but also in terms of the computing tasks they perform synchronously, such that if one of the first CE 115a and the second CE 115b fails (with or without pre-warning), the respective other one of these CEs can immediately step in and thus maintain the computing functionality of the main computing module 115 based on its own already ongoing synchronous performance of the same computing tasks.

[0150] Now, before continuing with an explanation of the remaining building blocks of main computing module 115, reference is made to general-purpose computing module 120. It comprises at least one autonomous CE 120a and optionally one or more additional CEs 120b. Each of autonomous CEs 120a and additional CEs 120b is designed as general- purpose computing entity, i.e., as a computing entity which is designed to perform all kind of different computing tasks rather than being limited to performing only computing tasks of one or more specific kinds, such as graphics or audio processing or running an artificial neural network or some other artificial intelligence algorithm. Each of autonomous CEs 120a and additional CEs 120b has its own memory and is independently of other CEs capable of autonomously performing computing tasks having been assigned to it.

[0151] In addition, each general-purpose computing module 120 comprises a respective individual fault management system (FMS) 120c, which is configured to detect malfunctions, such as hardware and / or software-based errors or defects, occurring within or at least with an involvement of general-purpose computing module 120. FMS 120c is further configured to communicate any such detected malfunctions to the main computing module 115 via the connection device 130 using alarm information A.

[0152] Turning now to special-purpose module(s) 125, in contrast to general-purpose computing module(s) 120, special-purpose module 125 is designed specifically to perform one or more selected tasks, such as computing tasks or communications tasks, and is generally less suitable or even incapable of performing general computing tasks like main computing module 115 and general-purpose computing modules 120. For example, one or more of special-purpose module(s) 125 may be or comprise a graphics processing unit (GPU), a module being specifically designed to run one or more artificial intelligence algorithms, a neural processing unit (NPU), or an in-memory compute unit (IMCU) or a local hub module. Accordingly, a special-purpose module 125 may particularly comprise one or more of such special CEs 125a and / or one or more communication interfaces 125b for establishing communication links, such as links to endpoints 330 or endpoint clusters 515. Each special CE 125a has its own memory and is independently of other CEs capable of autonomously performing computing tasks having been assigned to it.

[0153] In addition, also each of special-purpose module(s) 125 comprises a respective special individual fault management system (SFMS) 125c, which is configured to detect malfunctions, such as hardware and / or software-based errors or defects, occurring within or at least with an involvement of the respective special-purpose module 125. Each SFMS 125c is further configured to communicate any such detected malfunctions to the main computing module 115 via the connection device 130 using alarm information A. While computing module cluster 110 may thus comprise one or more general-purpose computing modules 120 and / or one or more special-purpose modules 125, and / or even other modules, it may, in a simple form, be implemented without such additional modules such that only main module 115 remains as a computing module. Particularly, it is possible to implement computing module cluster 110 or any one or more of its computing modules based on a set of interconnected chiplets as components thereof.

[0154] Returning now to main computing module 115, among all modules, this module takes - among other roles - the role of assigning tasks, including particularly computing tasks, to the various modules of the computing module cluster 110. This assignment process thus provides a resource coordination functionality 115d for the computing module cluster 110. First CE 115a and second CE 115b may thus be designated “master CEs” while the other CEs within general-purpose CE 120 and special purpose CE(s) 125 are at the receiving end of such task assignment process and may thus be designated “slave CEs”, as they have to perform the tasks being assigned to them by the master CE(s).

[0155] The assignment of tasks as defined by the master CE(s) is communicated to the slave CEs using message passing via the connection device 130, thus communicating, for example, corresponding control information C and / or data D.

[0156] Particularly, the resource coordination functionality 115d may comprise a process wherein the main computing module 115 receives periodic reports of major software operations (including parallel & sequential operations) on all CCU 105 processes (running on the set of CEs) and the current priority master CE assigns tasks between and towards the various CEs based on such reports (while the other master CE synchronously runs the same process, although its related task assignments will be discarded). Instead, or in addition, the assignment may depend on an amount of available energy that is currently available to power the CCU 105.

[0157] While such assignment may even include an assignment of computing tasks to the master CEs themselves, such assignment will address both master CEs similarly so that both will then perform such self-assigned tasks synchronously, thus maintaining the fully redundant operation of both master CEs.

[0158] Overall, the set of CEs of the various modules, which are co-located, as will be explained in more detail below with reference to the exemplary embodiment of a CCU 105 in Fig. 6, thus forms a distributed computing system (DCS) in which computing tasks to be performed by the DCS as a whole can be variably assigned to different CEs within computing module cluster 110, and wherein such assignment is communicated by way of message passing among the involved CEs.

[0159] The main computing module 115 further comprises a central fault management system (CFMS) 115f which is configured to receive via alarm information A provided by one or more of the FMS 120c of the other modules or even from an own individual FMS (iFMS) 115g of the main computing module 115 itself, fault associated anomalies having been detected within the DCS. CFMS 115f is configured to categorize and classify such alarm information A and to initiate countermeasures, such as a reassignment of computing tasks from a defect CE or module to another module or in case of insufficient remaining computing power, a prioritization of the tasks such as to support the more important tasks at the cost of less important ones.

[0160] The main computing module 115 further comprises a safety management system (SMS) 115e that is configured to take decisions on and if needed initiate necessary safety measures (i.e. , safe state escalation incl. real time scheduling) to bring the CCU 105 and / or a vehicle 800 (see Fig. 11) it helps control into a safe state. Accordingly, safety management system 115e may particularly rely as an input on the alarm information A being available from the CFMS 115f, which in turn consolidates the alarm information A received from the various individual FMS 120c and iFMS 115g of the various modules of the CCU 105.

[0161] If, for example, the alarm information A (or some other information being available to SMS 115e indicates a loss of power in the power supply for CCU 105, SMS 115e might take a decision to use all remaining power for steering the vehicle 800 to the roadside while turning off the power supply to all non-essential systems of the vehicle 800. Such non-essential systems might for example relate to air conditioning or entertainment, and to such modules of the CCU 105 which are not needed for essential tasks for enabling the process of safely steering the vehicle 800 to the roadside. Such essential tasks might, for example, include turning on the warning lights and tasks related to the braking system of the vehicle 800.

[0162] The central fault management system 115f and the resource coordination functionality (RCOS) 115d are preferably implemented in a redundant manner in multiple instantiations, such that a failure of one instantiation can be compensated by another instantiation. Particularly, each of the first CE 115a and second CE 115b may have an associated different one of such instantiations so that each of first CE 115a and second CE 115b is autonomous and has its own autonomous CFMS 115f and own autonomous RCOS 115d. The RCOS 115d, SMS 115e, CFMS 115f, FMS 120c and iFMS 115g may particularly be implemented, individually or jointly, in whole or in part, as one or more computer programs designed to run synchronously (in separated instantiations) on each of master CEs, i.e., on each of the first CE 115a and the second CE 115b, respectively. Hybrid implementations are possible too, wherein dedicated hardware is provided in addition to the one or more processors for running the software to enable a selective offloading of certain tasks, e.g., to a high-performance dedicated system-on-chip, SoC).

[0163] Fig. 2 illustrates, according to embodiments of the present solution, a second block diagram 200 showing more details of the functional building blocks of the CCU 105 of Fig. 1 , with a focus on a redundant set-up thereof.

[0164] As already discussed above with reference to Figs. 1 and 2, the computing module cluster 110 comprises within its main computing module 115 two or more master CEs, in the present example first CE 115a and second CE 115b. Accordingly, redundancy is available at the level of master CEs.

[0165] Furthermore, CCU 105 comprises a communication switch, which in turn comprises a plurality of mutually independent switching fabrics. In the example of Fig. 3, there are two mutually independent and autonomously operating (main) switching fabrics, namely a first switching fabric 225a and a second switching fabric 225b, and a third switching fabric 225c for emergency situations. All switching fabrics 225a, b,c are provided within service module 135. Each of the first switching fabric 225a, the second switching fabric 225b, and the third switching fabric 225c comprises hardware for variably connecting multiple different nodes of a network, such as nodes of a computer network, to variably exchange data D therebetween. In the present example, the network comprises as nodes the modules of computing module cluster 110 and the various endpoints 330 or endpoint clusters 515 thereto, for example as illustrated in any one or more of Figs. 1 , Figs. 7, 8 and 9.

[0166] Each of the (main) switching fabrics, i.e., the first switching fabric 225a and the second switching fabric 225b, is signal connected 730 to an associated one of the master CEs in main computing module 115, so that it can selectively switch flows of information between the respective master CE, i.e., the first CE 115a or the second CE 115b, and other nodes, such as nodes 120, 125 and 140 to 160, of the network. Specifically, the switching fabrics may be designed as switches conforming to the PCI Express (PCIe) industry standard (PCIe switch 325). The same applies to the third switching fabric 225c, although it may have a restricted connectivity. For example, it may be connected to only a true subset of the set of endpoints 330 and / or to only a true subset of the set of slave CEs 120a, 120b, 125a, or even to none of these CEs.

[0167] For security purposes, the network connections between the switching fabrics and other nodes of the network may be protected by one or more first security functions 230a, b at the CE side and / or one or more second security functions 235a, b at the endpoint 330 side, such as authentication, packet inspection, encryption, digital signatures, and / or obfuscation and may involve offloading to specified security devices. Particularly, the first security functions 230a, b and / or the second security functions 235a, b may be implemented as building blocks of the respective associated switching fabric, as illustrated in Figs. 3 and 4, where authentication and packet inspection are provided in the first security functions 230a, b as a guarding function at the endpoint 330 side of the fabrics, while one or more of the second security functions 235a, b may be provided in each of security blocks at the respective CE side of the first switching fabric 225a, the second switching fabric 225b, and the third switching fabric 225c.

[0168] The main computing module 115 with the master CEs 115a and 115b and the switching fabrics 225a, 225b and 225c with their related security functions / blocks can be said to define together a computing task coordination domain 205 205 of CCU 105, wherein computing tasks can be assigned variably among the modules of computing module cluster 110. The CCU 105 may particularly be configured to fully enumerate all nodes of the network during a boot process and / or a reset process such that upon completion of these processes all nodes have a defined identity within the network, e.g., an assigned identification code by which they can be unambiguously identified within the network. The enumeration process may particularly be performed under the guidance of the communication switch and / or the main computing module 115.

[0169] To avoid any confusion, at each given point in time, only one of the master CEs is defined (e.g., by a related flag) as a current priority master CE, which means that the other entities of the CCU 105 will only “listen” to its commands (such as assignments of computing tasks) while ignoring any commands coming from any of the other master CEs. In Fig. 3, the first CE 115a is currently defined as the current priority master CE, while the second CE 115b is not.

[0170] This is indicated in Fig. 3 by hatching, wherein the current priority master CE, i.e. , first CE 115a, and all other building blocks of the second block diagram 200, which are specifically associated with the current priority master are shown in “downward” hatching and the reference number attribute “a” (such as in “225a”), while the other master CE, i.e., second CE 115b, as well as all other building blocks of computing task coordination domain 205 which are specifically associated with the other master CE are shown “upward” hatching and the reference number attribute “b” (such as in “225b”).

[0171] If a malfunctioning of the current priority master CE or of a switching fabric being associated therewith is detected, the other / another master CE, which is determined to work properly (e.g., by a build-in-self test), as the new priority master CE such that the new priority master CE takes over the role previously held by the malfunctioning current master CE. The same applies to the associated switching fabrics. If, for example, current priority master CE (in the present example first CE 115a) and / or its associated first switching fabric 225a are found to be malfunctioning, e.g., because of a hardware defect, then previously redundant master CE, i.e., the second CE 115b and its associated second switching fabric 225b are determined to now have priority and take-over the roles previously taken by the first CE 115a and its associated first switching fabric 225a.

[0172] Furthermore, in an emergency situation, such as when in addition also the other switching fabric, i.e., the second switching fabric 225b (now acting as new priority switching fabric), is found to be malfunctioning, the third switching fabric 225c may be determined to now get priority and take-over the role of the previous priority switching fabric 225a or 225b. If the third switching fabric 225c has a restricted connectivity, as discussed above, then all nonconnected endpoints 330 and CEs will automatically be disconnected from the switching functionality of the service module 135 when the third switching fabric 225c takes over. In this way, the CCU 105 can focus on emergency tasks, even without having to involve the resource coordination functionality 115d.

[0173] Turning now to the power supply system for CCU 105, there are two (or more) redundant, mutually independent power sources, in the present example a first main power source 240a and a second main power source 240b, each of which is individually capable of providing enough power, such as electrical power P, to the CCU 105 to support all of its functions, at least under normal operating conditions. In normal operation, all of these power sources are configured to operate simultaneously to jointly provide a redundant and thus highly reliable power supply to the CCU 105. The power sources 240a and 240b may be components of CCU 105 itself or may be external thereto, e.g., as CCU-external vehicle 800 batteries, as shown in Fig. 3. Furthermore, the CCU 105 may comprise, e.g., in its service module 135, a further power source such as an emergency power source 240c. The emergency power source 240c may particularly be designed as a mere interim power source with a more limited capacity than each of the first main power source 240a and the second main power source 240b, but enough capacity to power at least the third switching fabric 225c, when the latter is in operation.

[0174] To further support the redundancy concept 201 , on which CCU 105 is based, for each of the main power sources there is an individual independent power network (cf. “main” path and “redundant” path, respectively in Figs. 3 and 4) for distributing the power provided by the respective main power source among the physical components of CCU 105 which have a need to be powered, including - without limitation - all CEs in each computing module and all switching fabrics. Specifically, each main power source and its respective power network is configured to simultaneously power all switching fabrics such that full redundancy is achieved and operation of CCU 105 can be maintained even in cases where one switching fabric or one main power source fails.

[0175] Current limiters 245a, b may be provided within the power networks to ensure that any currents flowing in power lines of the CCU 105, particularly in its service module 135, remain below a respective defined current threshold to avoid any current-based damages or malfunctions which might occur if current levels were to rise beyond such respective thresholds. The power networks and optionally also the main power sources (if part of the CCU 105) define a power supply domain 220 of CCU 105, which provides a high degree of reliability due to its redundant set-up.

[0176] The various hardware components of CCU 105 might have different voltage requirements for their power supply. Accordingly, the power system of CCU 105 may further comprise various redundantly provided, voltage generation units each being configured to provide a same set of different power supply voltage levels as needed and distributed to the switching fabrics 225a, 225b, 225c through the backplane. For example, a first voltage level may be at 3,3 V for powering a first set of devices, such as Ethernet to PCIe bridges of CCU 105, while a second voltage level may be at 1 ,8 V for powering a second set of devices, such as microcontrollers and NOR Flash memory devices of CCU 105, a third voltage level may be at 0,8V for powering a third set of devices, such as DRAM memory devices of CCU 105, etc. Particularly, this allows a control coordination domain 210 of CCU 105 to control the voltage levels of the entire service module 135 as well as those generated within the computer module cluster 110 itself. In addition, CCU 105, namely its service module 135, comprises two or more mutually redundant controllers 260a, b, e.g., microcontrollers, for controlling selected functions of service module 135. Particularly, controllers 260a, b may be configured to control, using power management information I, a power supply for the communication switch with switching fabrics 225a and 225b.

[0177] Specifically, there may be one or more first voltage generation units 250a, b and one or more second voltage generation units 255a, b, and they may all generate a same set of voltages. Each first voltage generation unit 250a, b provides the full set of voltage levels to an associated one of the first switching fabric 225a and the second switching fabric 225b, while each second voltage generation unit 255a, b provides the same full set of voltage levels to an associated one of controllers 260ab. Each controller 260a, b compares the voltage set delivered by its associated first voltage generation unit 250a, b to its associated switching fabric with the set received from said second voltage generation unit 255ab. Normally, these voltage sets should match. If the controller 260a, b determines, however, that the voltage level sets do not match, a problem is detected, and a reaction may be initiated by the controller 260a, b, e.g., the switching-off of one or more components.

[0178] All first voltage creation units and second voltage generation units 255a, b individually generate the set of output voltages based on a load sharing or voting process in relation to the power supplied simultaneously from the first main power source 240a and the second main power source 240b. For example, power supply sharing may be applied, when both main power sources are found to be stable, while voting may be applied in case where power supply by one of the main power sources is unstable.

[0179] Service module 135 comprises a monitoring functionally which is also redundantly implemented in at least two independent instantiations, e.g., first hardware components and second hardware components. The monitoring may particularly comprise a monitoring of one or more of a current monitoring, voltage monitoring and clock monitoring. Such monitoring may particularly relate to the power outputs of the first voltage generation units 250a, b and the second voltage generation units 255ab. The monitoring results are provided to the controllers 260a, b where they are analyzed and control information (signals) C defining a reaction to the results of the analysis and / or in case of a detected malfunction alarm information (signals) A may be issued and communicated to relevant other components of CCU 105, such as the CFMS 115f in the main computing module 115 and / or some other safety function of CCU 105, if any. The CFMS 115f can thus react accordingly, such as by reassigning current or upcoming computing tasks to CEs that are not affected by the detected malfunctioning.

[0180] The controllers 260a, b, the first voltage generation units 250a, b and the second voltage generation units 255a, b, and the monitoring units 265a, b thus may be designated as a control coordination domain 210 of the service module 135. In fact, grouping now separately the components of the priority path (i.e., being associated with the current priority master CE) on the one hand and the components of the redundant path (i.e., being associated with the currently other master CE) on the other hand, for each master CE a respective associated fabric power coordination domain 215 may be defined that comprise the components of the associated group. In Fig. 3, only one of these fabric power coordination domains 215 is drawn (dashed frame).

[0181] As illustrated in Fig. 4 (the power supply paths are not shown here to reduce the complexity of the drawing), the current limiters 245a, b may particularly be equipped with a diagnostic output functionality so as to generate and output diagnostic data based on the operation of the respective current limiter 245a, b and / or characteristics of the power it receives or provides. The diagnostic data can then be provided to the controllers 260a, b for further analysis and for initiating adequate reactions, e.g., changing the priority from one master CE and its associated switching fabric to the other master CE and its associated switching fabric, if the diagnostic data indicates a failure or malfunctioning of one or more components of the CCU 105 that may affect a proper functioning of the current priority master CE and / or its associated switching fabric.

[0182] As shown in Fig. 5, the set-up illustrated in Figs. 3 and 4 may be further enhanced by adding another level of redundancy beyond the fundamental redundancy provided by a redundancy concept 201 defining two or more pairs 170a, b, each having an associated master CE and an associated switching fabric, as discussed above. Said further level of redundancy is based on creating redundancy within such a pair 170a, b by providing the master CE and / or the switching fabric of the pair 170a, b redundantly (i.e., in multiple instantiations) and further providing per such pair 170a, b a configuration switch 270a, b for switching between different configurations of the pair 170ab.

[0183] Accordingly, if a redundantly provided master CE and / or a redundantly provided switching fabric within a given pair 170a,b fails, the pair 170a,b as a whole is still operable because of the remaining one or more other master CE(s) and / or switching fabric(s), respectively. The priority concept discussed above for the fundamental redundancy between pairs 170a, b may be adopted similarly for the further redundancy level within a given pair 170ab. Accordingly, if a pair 170a, b has multiple redundant instantiations of master CEs, such as a first instantiation of the first master CE 115a-1 , a second instantiation of the first master CE 115a-2, a first instantiation of the second master CE 115b-1 , and a second instantiation of the second master CE 115b-2, these instantiations may be operated so as to simultaneously perform the same computing tasks while one of the first CE 115a and the second CE 115b is defined as a priority master CE of that pair 170ab. The same applies to the switching fabrics per pair 170a, b, when a pair 170a, b has multiple instantiations per switching fabric, such a first instantiation of the first switching fabric 225a-1 , a second instantiation of the first switching fabric 225a-2, a first instantiation of the second switching fabric 225b-1 , and a 2nd instantiation of the second switching fabric 225b-2.

[0184] By way of example, Fig. 5 illustrates two separate ones of such pairs 170ab. Unless such pair 170a, b consists of a single master CE, (e.g., a single first instantiation of the first master CE 115a-1) and a single switching fabric (e.g., the first instantiation of the first switching fabric 225a-1) (“l-shape”), it comprises an own configuration switch 270a, b and either two (or more) associated master CEs, such as two or more instantiations of the first CE 115a or the second CE 115b, or two (or more) associated switching fabrics, such as two or more instantiations of the switching fabrics. The configuration switch 270a, b is operable to variably switch between at least two different possible configurations of the respective pair 170ab.

[0185] Exemplary shapes per pair 170a,b are: (i) multiple instantiations of master CEs, e.g., instantiations of the first CE 115a and a single switching fabric 225a-1 (or 225b-1) (“Y- shape”); (ii) a single master CEs 115a-1 (or 115b-1) and multiple switching fabrics 225a-1 and 225a-2 (or 225b-1 and 225b-2) (“inverted Y- shape”); and multiple instantiations of master CEs 115a-1 and 115a-2 (or 115b- 1 and 115b-2) and multiple instantiations of switching fabrics 225a-1 and 225a-2 (or 225b-1 and 225b-2) (“X- shape”). The pairs 170a, b may have a same or a different shape in general or at a given point in time. For example, a first pair 170a may have a Y- shape and a second pair 170b may at the same time have an X-shape. If a pair 170a,b has a shape apart from the l-shape, it can be configured using its associated configuration switch 270a, b, particularly based on the operational state of its components, such as error-free operation or malfunction / failure. If, for example, the first pair 170a has an X-shape or an inverted Y-shape, and a failure of the second instantiation of the first switching fabric 225a-2 is detected, the first configuration switch 270a can be (reconfigured so that it now connects the (error-free) second instantiation of the first switching fabric 225a-2 to the current priority master CE of the pair 170a, b, e.g., to the first instantiation of the first master CE 115a-1 .

[0186] Referring now to Fig. 6, which illustrates an exemplary conventional classical strictly hierarchical communication scheme 300 according to the standardized PCI Express (PCIe) communication technology, for communication between different nodes of a PCIe network, including, in particular, two different computing entities, such as a first central processing unit 305 (CPU) a second CPU 310.

[0187] The first CPU 305 comprises a first management functionality 305a, e.g., for scheduling computing tasks, a first processing functionality 305b for performing the scheduled computing tasks, and a PCIe first PCIe root complex 305c with three first PCIe root ports 315 (315-1 , 315-2 and 315-3).

[0188] Similarly, CPU 310 comprises a second management functionality 310a, e.g., for scheduling computing tasks, and a second processing functionality 310b for performing the scheduled computing tasks, and a second PCIe root complex 310c with three second PCIe root ports 320 (320-1 , 320-2 and 320-3).

[0189] All communication flows between such a CPU, e.g., the first CPU 305, and any endpoint 330 in a PCIe network being associated with the CPU have to go through the first PCIe root complex 305c using one or more of its first PCIe root ports 315 (315-1 , 315-2 and 315-3). In addition to PCIe endpoints 430, there may be intermediate hubs in the PCIe network, such as one or more PCIe switches 325.

[0190] Accordingly, each of the first CPU 305 and the second CPU 310, respectively, has an own communication hierarchy including an own address space and / or clock domain for communication between any two nodes of its PCIe network, so that due to the hierarchy, every communication between two nodes of the same network must necessarily pass through the root complex of the associated CPU.

[0191] Communication between nodes of different communication hierarchies is enabled via an inter-CPU communication link 335 running between the first CPU 305 and the second CPU 310. Accordingly, if a first endpoint 330 being located in the communication hierarchy of the first CPU 305 needs to communicate with a second endpoint 330 being located in the communication hierarchy of the second CPU 310, then the communication path has to run - from the first endpoint 330 upstream through the communication hierarchy of the first CPU 305

[0192] - through the first root complex with a relevant first PCIe root port 315,

[0193] - through the first management functionality 305a of the first CPU 305,

[0194] - then further over the inter-CPU communication link 335 to the second CPU 310, and

[0195] - there in a downstream direction through its second management functionality 310a,

[0196] - its second root complex 310c and a relevant second root port 320 thereof,

[0197] - and, finally, to the second endpoint 330.

[0198] Accordingly, because the endpoints 330 of different communication hierarchies are isolated from the CPU of each respective other communication hierarchies, such a communication is not very efficient and may particularly suffer from a high latency.

[0199] In contrast to the conventional approach of Fig. 6, embodiments of the present solution may implement an adapted PCIe communication scheme 400, as illustrated in one example in Figs. 7 and 8. Also in this exemplary adapted PCIe communication scheme 400, there are two PCIe hierarchies, each having its own address space and a respective first PCIe single root complex 405c and second single root complex respectively. In the adapted PCIe communication scheme 400, the first CPU 305 of Fig. 6 is replaced by a master CE, e.g., the first CE 115a of Fig.1 B, and the second CPU 310 is replaced by a slave CE, e.g., the slave CE 120a of Fig. 3.

[0200] The first CE 115a (master CE) comprises a management functionality 405a, a processing functionality 405b, and the first single root PCIe root complex 405c with three PCIe root ports 405d (405d-1 , 405d-2, and 405d-3). Similarly, slave CE 120a comprises a further management functionality 410a, a further processing functionality 410b, and the second PCIe single root complex 410c with three further PCIe root ports 41 Od (410d-1 , 410d-2 and 410d-3), and resource coordination system block 415d comprising the resource coordination functionality (RCOS) 115d. All nodes of the adapted PCIe communication scheme 400 share a common clock, i.e. , they are in a same clock domain.

[0201] In each communication hierarchy, there is a hierarchy-related PCIe switch 415a, b having one or more first Non-transparent PCIe Bridges (NTB) 420a, b for connection with the associated CE and one or more second Non-transparent PCIe Bridges (NTB) 425a, b for direct or indirect connection with one or more PCIe endpoints 430 or the respective other communication hierarchy, namely its root complex. The inter-CPU communication link 335 of Fig. 6 has now become obsolete and can be dispensed with. Referring now particularly to Fig. 8, three exemplary communication paths are shown which are enabled by the adapted PCIe communication scheme 400.

[0202] A first communication path 435 enables a communication between a first selected PCIe endpoint 430-1 in the hierarchy of the first CE 115a serving as master CE and autonomous CE 120a serving as slave CE, specifically its further processing functionality 410b. The first communication path 435 runs from the first selected PCIe endpoint 430-1 to the corresponding first PCIe switch 415a in the same hierarchy and from there over a second NTB 425a to further PCIe root port 41 Od (specifically: root port 410d-2) of the second PCIe single root complex 410c of the other CE, namely slave CE 120a, from where it finally runs to further processing functionality 410b.

[0203] A second communication path 440 enables a communication between a second selected PCIe endpoint 430-2 in the hierarchy of slave CE 120a and the further processing functionality 410b of slave CE 120a. Accordingly, the second communication path 440 remains within a same hierarchy from the second selected PCIe endpoint 430-2 to corresponding second PCIe switch 415b to further PCIe root port 41 Od (specifically: root port 410d-1) and from there through further PCIe root port 41 Od (specifically: root port 41 Od- 2) to its further processing functionality 410b, i.e., that of slave CE 120a, like in the conventional case of Fig. 6.

[0204] A third communication path 445 enables a communication between the second selected PCIe endpoint 430-2 in the hierarchy of slave CE 120a and another selected PCIe endpoint 430 in the hierarchy of master CE 115a. The third communication path 445 runs from the second selected PCIe endpoint 430-2 to corresponding second PCIe switch 415b in the same hierarchy to further PCIe root port 410d (specifically: root port 410d-1) of the second PCIe single root complex 410c of slave CE 120a and from there to further PCIe root port 41 Od (specifically: root port 410d-2) from where it reaches over NTB 425a the corresponding first PCIe switch 415a, from where it finally proceeds to processing functionality 405b.

[0205] All of these communication paths, particularly the first and the third path which interconnect different hierarchies, can be managed by the management functionality 405a of master CE 115a. The adapted communication scheme 400 therefore uses NTBs to enable “direct” point-to-point communication between distributed locations within the same clock domain, including in different hierarchies, while the communication paths are managed, particularly configured, centrally.

[0206] Fig. 9 illustrates, according to embodiments of the present solution, a third block diagram 500 showing more details of an exemplary CCU 105, particularly of its communication switch with service module 135. This CCU 105 has a computing module cluster 110 comprising a main computing module 115, three general-purpose computing modules 120, and a single special-purpose module 125, each of the respective kind described above in connection with Figs.1 and 2.

[0207] Each of the modules of computing module cluster 110 is linked to two hierarchy-related PCIe switches 415ab. Each of these hierarchy-related PCIe switches 415a, b is equipped with a number of first NTBs 420a, b at the CE side and a number of second NTBs 425a, b at the PCIe endpoint 430 side. Accordingly, so far, this setup is similar to that of Figs. 7 / 8, albeit optionally with a different number of NTBs.

[0208] In addition, the CCU 105 of third block diagram 500 comprises for one or more, particularly all endpoint-side second NTBs 425a, b a respective conversion bridge 505 for performing a conversion between different communication technologies used in a related communication path running through the respective NTB. For example, such a conversion bridge 505 might be configured to perform a conversion from an Ethernet communication technology to a PCIe technology. Specifically, in the example of Fig. 9, the conversion bridges 505 are configured to perform a conversion from an Ethernet communication technology at the endpoint-side to a PCIe technology at the CE-side of the NTB.

[0209] Thus, PCIe technology is used for the communication among the modules of computing module cluster 110 and with the corresponding first PCIe switches 415a and corresponding second PCIe switches 415b and toward the conversion bridges 505, while Ethernet technology is used to communicate between the conversion bridges 505 and the PCIe endpoints 430. The latter may particularly be arranged, spatially or by some other common property such as a shared functionality, address space, or clock, in an endpoint cluster 515 of PCIe endpoints 430. Between the bridges 505 and endpoint cluster 515 Ethernet switches 510 may be arranged to variably connect selected individual PCIe endpoints 430 to selected conversion bridges 505. The set of hierarchy-related PCIe switches 415a, b and conversion bridges 505 may particularly be realized within a single SoC or using a chiplet solution where the hierarchy-related PCIe switches 415a,b and conversion bridges 505 are distributed across multiple chiplets, each chiplet bearing one or more of these components. Accordingly, each module of computing module cluster 110 is connected to each of the two switching fabrics, each switching fabric comprising a respective hierarchy-related PCIe switch 415a, b, various NTBs 420a / 425a or 420b / 425b, and several conversion bridges 505. In this way, the desired redundancy is achieved, where each PCIe endpoint 430 may be reached (and vice versa) via each of the communication fabrics and from any module of computing module cluster 110.

[0210] Fig. 10 illustrates, according to embodiments of the present solution, an exemplary housing 600 of an exemplary computing system, e.g., the CCU 105 of Fig. 1. Housing 600 comprises a rack-shaped housing structure 605 with several compartments, each for accepting, preferably in a replaceable manner, a module of the CCU 105 such as a computing module of computing module cluster 110 or the service module 135. In the present example, there are six compartments (slots) arranged in a fabric and housing 600 in total (in co-location, specifically in a neighboring manner) the main computing module 115, two general-purpose computing modules 120, two special-purpose modules 125, and the service module 135.

[0211] While a first end of the housing structure 605 comprises for each compartment a respective opening for inserting or extracting a module, the opposing end of the housing structure 605 comprises a connection device 130 that is configured to provide connections for exchanging one or more of power P, data D, control information C, alarm information A or power management information I among different modules.

[0212] The connection device 130 may particularly have a substantially planar shape and may thus be designated a “backplane”. Between the connection device 130 and the opposing rear faces of the modules there are one or more connectors 610 per module to provide the above-mentioned connections. Particularly, the connectors 610 may be designed as detachable connectors 610 so that the modules may be (i) inserted and connected simply by pushing them into their respective compartment until the associated one or more connectors 610 are connected and (ii) extracted and disconnected simply by pulling them from the compartment and thereby detaching the connections.

[0213] System, Computing Platform

[0214] Referring now to Fig. 11 , an exemplary embodiment of a system for controlling one or more functionalities of a vehicle 800. The system, which is implemented as a computing platform 700 of or for the vehicle 800 (cf. Figs. 3, 4), comprises a central computing unit (CCU) 105 having a modular design, wherein multiple different modules 105a through 105f are combined within a common housing 600, e.g., of a rack type, to jointly define a computing device. Modules 105a through 105f may particularly coincide with modules 115, 120 (2x), 125a, 125b and 135, described above (cf. Fig. 10). The housing 600 and optionally further sections of the CCU 105 form its fixed part. In contrast thereto, at least one of the modules 105a through 105f, preferably several thereof, are releasably connected in an exchangeable manner to the housing 600 so that they may be easily removed, based on releasable mechanical, electrical and / or optical connectors 610, such as to allow for a hardware-based reconfiguration, repair, or enhancement of the CCU 105 through adding, removing or exchanging one or more of the modules in relation to the fixed part. Specifically, one of the modules, e.g., module 105b, may be an energy supply module for supplying energy to at least one, preferably all the other modules 105a, and 105c to 105f. Energy supply module 105b may particularly belong to the fixed part of the CCU 105, but it is also conceivable for it to be releasably connected in an exchangeable manner to the housing 600 so that it may be easily removed, replaced etc.

[0215] The term “computing platform” 700, as used herein, may particularly refer to an environment in which a piece of software is executed. It may be the hardware or an operating system 1345 (OS), even a web browser and associated application programming interfaces, or other underlying software, as long as the program code is executed with it. Computing platforms 700 may have different abstraction levels, including a computer architecture, an OS, or runtime libraries. Accordingly, a computing platform 700 is the stage on which computer programs can run. It may particularly comprise or be based on multiple computers or processors.

[0216] The CCU 105 is designed to be used as a central computing entity of the computing platform 700 and is configured to provide on-demand computing to a plurality of different other functional units of the vehicle 800 based on a flexible software-defined resource and process management and / or control functionality of the CCU 105. Specifically, the CCU 105 may be designed to communicate with such other functional units over one or more, preferably standardized high-speed communication links 725, such as one or more highspeed bus systems or several individual communication links, such as Ethernet links, e.g., for data rates of 10 Mbit / s or above. These high-speed communication links 725 may particularly be used to communicate one or more of data D, control information C, alarm information A, and power management information I, as discussed above, e.g., in relation to Figures 1 , 2, 3, and / or 4. Furthermore, the CCU 105 may comprise a multi-kernel operating system 1345 comprising a main kernel and multiple other kernels, wherein the main kernel is configured to simultaneously control at least two of the multiple other kernels while these are running concurrently.

[0217] Another one of the modules, e.g., module 105a (which may particularly coincide with a main computing module 115, as described above), may comprise a general-purpose computing device, e.g., based on one or more general-purpose microprocessors. Particularly, module 105a may be used as a main computing resource (e.g., main controller unit) of CCU 105 and is configured to allocate computing demands among multiple computing resources of CCU 105, including computing resources of other ones of the CCU’s 105 modules.

[0218] Module 105c (which may particularly coincide with a special purpose computing module 125, as described above) may, for example, comprise a dedicated computing device, such as a graphics CPU (GPU) and / or a dedicated processor for running artificial intelligencebased algorithms, e.g., algorithms implementing one or more artificial neural networks. Furthermore, modules 105d, 105e and 105f may comprise other general-purpose or dedicated computing resources / devices and / or memory.

[0219] For example, module 105d may comprise a security controller for securing data and / or programs within the CCU 105 and restricted access thereto (module 105d may particularly comprise one or more of the first security functions 230a, b and / or second security functions 235a, b, as described above), and module 105e may comprise one or more interface controllers or communication devices for connecting CCU 105 to one or more communication links with other devices outside the CCU 105, such as actuators 715, sensors 720, or cluster hubs 710 (hubs) for aggregating / routing or splitting the signals from / to several actuators 715 and / or sensors 720 such as to form hub-centered clusters (e.g., one or more of endpoint clusters 515, 140, 145, 150, and 160 discussed above), and each comprising several actuators 715 and / or sensors 720.

[0220] When such a cluster / hub concept is used, it may particularly be implemented based on a tree topology with various actuators 715 and / or sensors 720 being connected via related signal connections 730 to one or more cluster hubs 710 or multiple cascaded cluster hubs 710 to the CCU 105, e.g., to its module 105e. The cluster hubs 710, which may for example be denoted as “Zone Electric Controllers” 260a, b (ZeC) may specifically have a functionality of aggregating signals coming from different sources, such as actuators 715 and / or sensors 720 and may thereby be also configured to serve as a gateway between different communication protocols such as CAN, LIN, and Ethernet. Consequently, a lot of wiring can be saved, and the central computing approach can be used to provide the processing power for processing the signals from / to the actuators 715 and / or sensors 720, particularly for the purpose of controlling one or more functionalities of the vehicle 800 as a function of those signals. However, it is also possible to have a hub-less topology or a mixed topology, where some or all of the actuators 715 and / or sensors 720 are directly connected to the CCU 105 without any intermediate cluster hub 710.

[0221] The computing platform 700 may be designed as a multi-computing-layer platform and thus comprise multiple computing layers, e.g., (i) a first computing layer 740 for handling basic mobility functionalities of a vehicle 800, e.g., automobile, such as accelerating, decelerating and steering, (ii) a second computing layer for handling all kinds of other (e.g., digitalized) functionalities of the vehicle 800, such as driver assistance, infotainment or (other) comfort- related functionalities like climate control, and others, as described herein, and (iii) a third computing layer 750 handling vehicle 800 functionalities related to highly automated or even autonomous driving, e.g., handling the signals of related sensors 720 for detection of objects or road markings etc. in a vehicle's environment. The second computing layer may particularly be designed according to the Fig. 11 (but excluding the first computing layer 740 and the third computing layer 750 and related interfaces to the second computing layer (as described below), respectively.

[0222] In a multi-computing layer embodiment of the computing platform 700, one of the modules 105a-f of CCU 105 may further comprise or be configured to be linked to (i) a first interface unit 735 for connecting the second computing layer to the first computing layer 740 and (ii) a second interface unit 745 for connecting the second computing layer to the third computing layer 750 to exchange information therewith, respectively, in a controlled manner, e.g., according to one or more defined protocols.

[0223] Module 105f may, for example, comprise, among other things, communication interface 125b for implementing an interface functionality to the third computing layer 750. In fact, it is also possible that module 105f itself comprises itself one or more computing units of the third computing layer 750 so that the second computing layer and the third computing layer 750, although being defined as separate computing layers with individual functionalities and structures, are then physically integrated in a same physical device, namely in the housing 600 and even, at least in part, within a same module of CCU 105.

[0224] Vehicle Fig. 12 illustrates an exemplary vehicle 800 particularly an automobile, comprising an exemplary computing platform 700 according to Fig. 11 , including a CCU 105. The CCU 105 is configured to control different functionalities (not shown) of the vehicle 800 centrally. For the sake of reducing complexity, only some elements of the computing platform 700 (particularly of its second computing layer) are illustrated while other elements are not explicitly shown, including in particular all actuators 715 and sensors 720 and in the case of a multi-computing layer embodiment, all elements of the first computing layer 740 and the third computing layer 750 and the first interface unit 735 and the second interface unit 745.

[0225] Fig. 12 (a) also shows several cluster hubs 710 of the second computing layer and related high-speed communication links 725 725 of the cluster hubs 710 to the CCU 105. Each of these hubs 710 may in turn be connected to a plurality of actuators 715 and / or sensors 720, as illustrated in more detail in Fig. 11.

[0226] While in principle, the CCU 105 might be located anywhere within vehicle 800, there are certain preferred places, particularly considering safety requirements and the need to make it easily accessible for enabling an easy removal and replacement of modules 105a through 105f into the housing 600 of CCU 105.

[0227] Fig. 12 (b) shows another simplified view of vehicle 800, wherein three different exemplary locations, i.e. , a first location 805, a second location 810, and a third location 815 within the vehicle 800, that are particularly suitable for placing the CCU 105 within the vehicle 800 are identified. The first location 805 and the third location 815 are arranged on or near the (virtual) centerline of the vehicle 800 which centerline runs in the middle between the two side faces of the vehicle 800 along the latter’s main extension dimension (y dimension). While the first location 805 is between two front seats, e.g., in a middle console, of the vehicle 800, the third location 815 is under a rear seat or seat bench in a second or third seating row. These central locations (at least in x and y dimensions) are particularly advantageous considering safety and protection from damage or destruction in case of an accident. They are also easily accessible for purposes of maintenance, repair, or replacement, particularly when one or more of the modules 105a through 105f need to be extracted from the CCU 105, particularly from its housing 600.

[0228] The second location 810810 is also highly accessible and is protected well against crashes coming from almost any direction. This second location 810 810 may also be particularly suitable for entertaining wireless communication links Wwith communication nodes outside the vehicle 800, such as communication nodes of traffic infrastructure or of other vehicles 800 (e.g., for car-to-car communication) because due to its position close to the windshield, it will typically suffer less from electromagnetic shielding by the vehicle 800 itself.

[0229] Accordingly, CCU 105 may particularly be located in or near the glove compartment or in a central console of the vehicle 800, i.e., somewhere in or near a center of the passenger compartment of vehicle 800, such that CCU 105 is both well protected against external mechanical impacts, e.g., in the case of a vehicle 800 accident, and easily accessible.

[0230] Method

[0231] Fig. 13 is a flow chart illustrating a method 900 of controlling different functionalities of a vehicle in accordance with at least one exemplary embodiment. The method 900 may particularly be performed by a CCU 105 or system 600 or 700 as illustrated in one or more of Figures 1 to 11.

[0232] The method 900 comprises an exemplary initialization process 901 and an exemplary controlling process 910. Furthermore, it comprises an exemplary admission control process. An exemplary implementation of the initialization process 901 is illustrated in Fig 14, while an exemplary embodiment of the controlling process is illustrated in Fig. 15.

[0233] The initialization process 901 serves to define, for each functionality of the vehicle 800 that is to be controlled by the CCU 105 a proper assignment, i.e., “logical” association, of components and / or functional groups of the vehicle 800 to such functionality. Such components or functional groups may particularly be sensor subsystems or actuator subsystems of the vehicle. For example, sensor subsystems may be cameras, LIDAR sensors, radar sensors, temperature sensors, pressure sensors, air pressure sensors etc. actuator subsystems may be electric motors, piezoelectric actuators, user interface devices, air conditioning systems, infotainment systems, entertainment systems etc. In other words, one purpose of the initialization process is to selectively assign components and / or functional groups of the vehicle 800 to its various functionalities so that for each such functionality a predetermined scheme exists which defines which components and / or functional groups are to be used for the actual implementation of the functionality. The controlling process, on the other hand, serves to control the various functionalities “physically” by controlling the assigned components and / or functional groups so as to actually maintain, activate, deactivate, or configure the functionality.

[0234] The admission controlling process serves to ensure that only such components and / or functional groups are involved in the implementation of the functionalities which meet predefined acceptance criteria. This may particularly be used to prevent a potentially dangerous use of counterfeited components or functional groups for operation of the vehicle.

[0235] Specifically, the admission process illustrated in Fig. 13 comprises a monitoring process 920 wherein a defined set of components or functional groups of the vehicle 800 is monitored in a repeated or continuous manner to detect any changes to the set. The set may particularly comprise all currently available components and functional groups under control of the CCU 105. If a change in the set is detected (921 - yes), a determination is made whether the change relates to an addition of a component or functional group to the set. If so (922 - yes), an examination is made whether the added component or functional group, respectively, meets a predefined set of one or more acceptance criteria. If yes (923 - yes), the added component / functional group is admitted (925) for control by the CCU 105 to support one or more of the functionalities, while otherwise (923 - no) admission is denied (924). In each case, method 900 proceeds to a step 926, which is explained below.

[0236] If, however, the set has not changed (921 - no) or a change in the set does not involve an addition of a component or functional group (922 - no), the admission controlling process proceeds with step 926 which comprises testing whether a predefined refresh period has elapsed since the last performance of the initialization process 901. If so (926 - yes), the method 900 returns for another cycle, starting with running the initialization process 901 anew. Otherwise (926 - no), the method 900 only returns to the controlling process 910 without an intermediate (re-)initialization using initialization process 901.

[0237] Referring now to Fig. 14, initialization process 901 comprises a step 902 for obtaining capability information in relation to, preferably all, components and functional groups being controlled by the CCU 105. Optionally, step 902 may comprise, in addition, obtaining demand information in relation to one or more of these components and functional groups. Specifically, the capability information and demand information may be received directly from the components and functional groups themselves or from another source keeping this information, such as a predefined look-up table (LUT). The demand information, if available, defines for each component or functional group assigned to the functionality a respective set of one or more requirements (such as power consumption, voltage stability, or minimum current supply, control information, temperature range etc.) which the component or functional group, respectively, needs for its operation.

[0238] While the capability information and / or demand information may in principle be static once initially defined, it may instead be variable, i.e., dynamically adjustable. The latter case may particularly involve a repeated testing or self-testing of the components / functional groups such as to detect any changes occurring over time, which might have an impact on the actual capabilities or demands, respectively, of the related component / functional group. A change may occur, for example, if an update, such as an over-the-air (OTA) update, of a software used by a components enhances or otherwise modifies its capabilities. For example, considering an automatic cruise control (ACC) functionality of the vehicle, the configuration of such a functionality, e.g., a setting of a limiting speed, might be dynamically modified based on a current capability of a front camera of the vehicle, such as a current frame rate.

[0239] Similarly, initialization process 901 further comprises a step 903 for obtaining reference information in relation to, preferably all, functionalities of the vehicle 800, which functionalities are under the control of the CCU 105. The reference information may be static or dynamic too, and may particularly be obtained from a related LUT.

[0240] Initialization process 901 further comprises a step 903 in which for each functionality its related reference information is compared to the capability information for the purpose of determining, which set of one or more components and / or functional groups can be used and meets the requirements defined in the reference information for the functionality. While in some instances, a single component and / or functional group might be available and sufficient for such implementation, in other cases one or more sets of two or more available components and / or functional groups might be required to meet the requirements defined in the reference information. In a step 905, a respective assignment of one or more components or functional groups is made for each functionality, based on the results of the comparison in step 903 and optionally the demand information. Data representing the assignment may be stored in a memory, e.g., in the format of a LUT or other data structure, as a data source for the future operation of the functionalities and particularly for the controlling process 910. The demand information becomes particularly relevant in scenarios, where two or more different sets of components / functional groups exist, which each meet the requirements of the respective functionality as defined in the reference information. Then the demand information may become decisive for determining which of the sets is to be selected as the optimal set to support the functionality under the current circumstances as determined, at least in parts, by the current capability information and the current reference information. For example, the set involving a minimal energy consumption or being best suited for current or expected temperature conditions may be selected as the optimal set.

[0241] In some instances, however, the comparison in step 904 may yield that not even a single set of one or more components and / or functional groups is sufficient to meet the requirements. In the latter case (not illustrated), no proper assignment can be made for the functionality and eventually, the functionality has to be deactivated, e.g., completely disabled, by the subsequent controlling process.

[0242] Optionally, the initialization process 901 may also comprise assigning a respective priority (i.e. , priority level) to one or more, preferably all, functionalities. These priorities may then be used subsequently by the controlling process 910 to define a preference of one or more functionalities at the cost of one or more other functionalities (cf. step 912 in Fig. 15) in cases where not all desired functionalities can be fully supported simultaneously for lack of enough resources on the component / functional group level.

[0243] In addition, initialization process 901 comprises determining whether one or more previously available (fault-free) components or functional groups have been “lost” meanwhile. In this context, the term “lost” is used to indicate that the respective component or functional group is either no longer present or enabled at all (it might have been removed or disabled). If so (907 - yes), loss information identifying the lost one or more components or functional groups is provided in a step 908 to the subsequent controlling process 910.

[0244] Turning now to the exemplary controlling process 910, as illustrated in Fig. 15, this process may particularly be performed individually per functionality. Controlling process 910 comprises a step 911 for receiving the loss information, if any, as provided by the initialization process 901. Furthermore, controlling process 910 comprises selectively controlling each functionality, such controlling comprising selectively maintaining, activating, deactivating, or (re-)configuring the functionality based on the results of the initialization process 901 , including particularly the assignments made in step 905, which in turn are based on the results of the comparisons made in step 904. In addition, the loss information and demand information, if any, may be used in addition for such controlling of the functionalities, so that for a given functionality, if possible at all, a set-up of one or more active components and / or functional groups results, which (preferably optimally) meets the current requirements of the functionality as defined in its current reference information.

[0245] The controlling process 910 further comprises performing or causing (one or more other entities, such as the components or functional groups themselves (for self-testing) or some testing entity, to perform a functional test of one or more currently active components and / or functional groups pertaining to the set-up for the functionality. The functional test has a purpose of confirming that all components and / or functional groups that are required for a proper functioning of the set-up are in fact (currently) working in a fault-free manner so that the functionality can be expected to be performing without issues. If the functional test yields a failure (914-yes), then one or more predefined fault mitigation actions may be initiated. Such action may particularly include one or more of :

[0246] (a) treating the component or functional group, respectively, as if it was not present;

[0247] (b) deactivating the component or functional group, respectively;

[0248] (c) determining that the component or functional group, respectively, is or might be a fake product;

[0249] (d) modifying the capability information of the component or functional group, respectively, for further use with a reduced set of capabilities, based on its determined actual capabilities;

[0250] (e) issuing or causing one or more of the components or functional groups having, according to the associated capability information, a suitable capability, to issue warning information or a signal indicating a failure or a reduced functionality;

[0251] (f) reporting or causing one or more of the components or functional groups having, according to the associated capability information, a suitable capability, to report the determined failure to a vehicle-external report collection system.

[0252] While above at least one exemplary embodiment of the present solution has been described, it has to be noted that a great number of variations thereto exists. Furthermore, it is appreciated that the described exemplary embodiments only illustrate non-limiting examples of how the present solution can be implemented and that it is not intended to limit the scope, the application, or the configuration of the herein-described apparatuses and methods. Rather, the preceding description will provide the person skilled in the art with constructions for implementing at least one exemplary embodiment of the present solution, wherein it must be understood that various changes of functionality and the arrangement of the elements of the exemplary embodiment can be made, without deviating from the subject-matter defined by the appended claims.

[0253] LIST OF REFERENCE SIGNS

[0254] 100 first block diagram

[0255] 105 CCU

[0256] 110 computer module cluster

[0257] 115 main computing module

[0258] 115a first computational entity (CE)

[0259] 115a-1 first instantiation of the first master CE

[0260] 115a- 2 second instantiation of the first master CE

[0261] 115b second computational entity

[0262] 115b- 1 first instantiation of the second master CE

[0263] 115b- 2 second instantiation of the second master CE

[0264] 115c further CEs

[0265] 115d resource coordination functionality

[0266] 115e safety management system

[0267] 115f central fault management system

[0268] 115g own individual FMS

[0269] 120 general purpose computing module

[0270] 120a autonomous CE

[0271] 120b additional CE

[0272] 120c individual fault management system

[0273] 125 special-purpose module

[0274] 125a special CE

[0275] 125b communication interface

[0276] 125c special individual fault management system

[0277] 130 connection device

[0278] 135 service module

[0279] 140 first endpoint cluster

[0280] 145 second endpoint cluster

[0281] 150 third endpoint cluster

[0282] 155 fourth endpoint cluster

[0283] 160 intermediate wireless transceiver

[0284] 170 a first pair

[0285] 170a, b pair

[0286] 170b second pair

[0287] 200 second block diagram

[0288] 201 redundancy concept 205 computing task coordination domain

[0289] 210 control coordination domain

[0290] 215 fabric power coordination domain

[0291] 220 power supply domain

[0292] 225a first switching fabric

[0293] 225a-1 first instantiation of the first switching fabric

[0294] 225a-2 second instantiation of the first switching fabric

[0295] 225b second switching fabric

[0296] 225b- 1 first instantiation of the second switching fabric

[0297] 225b-2 2nd instantiation of the second switching fabric

[0298] 225c third switching fabric

[0299] 230a, b first security functions

[0300] 235a, b second security functions

[0301] 240a first main power source

[0302] 240b second main power source

[0303] 240c emergency power source

[0304] 245a, b Current limiters

[0305] 250a, b first voltage generation units

[0306] 255a, b second voltage generation unit

[0307] 260a, b controller

[0308] 265a, b monitoring unit

[0309] 270a first configuration switch

[0310] 270a, b configuration switch

[0311] 300 hierarchical communication scheme

[0312] 305 first central processing unit (CPU)

[0313] 305a first management functionality

[0314] 305b first processing functionality

[0315] 305c first PCIe root complex

[0316] 310 second CPU

[0317] 310a second management functionality

[0318] 310b second processing functionality

[0319] 310c second PCIe root complex

[0320] 315 first PCIe root ports

[0321] 320 second PCIe root ports

[0322] 325 PCIe switch

[0323] 330 endpoint

[0324] 335 inter-CPU communication link 400 adapted PCIe communication scheme

[0325] 405a management functionality

[0326] 405b processing functionality

[0327] 405c first PCIe single root complex

[0328] 405d PCIe root ports

[0329] 410a further management functionality

[0330] 410b further processing functionality

[0331] 410c second PCIe single root complex

[0332] 410d further PCIe root ports

[0333] 415a corresponding first PCIe switch

[0334] 415a, b hierarchy-related PCIe switch

[0335] 415b corresponding second PCIe switch

[0336] 415d resource coordination system block

[0337] 420a, b first Non-transparent PCIe Bridges (NTB) 425a, b second Non-transparent PCIe Bridges (NTB)

[0338] 430 PCIe endpoint

[0339] 430-1 first selected PCIe endpoint

[0340] 430-2 second selected PCIe endpoint

[0341] 435 first communication path

[0342] 440 second communication path

[0343] 445 third communication path

[0344] 500 third block diagram

[0345] 505 conversion bridge

[0346] 510 Ethernet switch

[0347] 515 endpoint cluster

[0348] 600 housing

[0349] 605 housing structure

[0350] 610 connectors

[0351] 700 computing platform

[0352] 710 cluster hub

[0353] 715 actuator

[0354] 720 sensor

[0355] 725 high-speed communication link

[0356] 730 signal connection

[0357] 735 first interface unit

[0358] 740 first computing layer

[0359] 745 second interface unit 750 third computing layer

[0360] 800 vehicle

[0361] 805 first location

[0362] 810 second location 815 third location

[0363] 900 method of controlling different functionalities of a vehicle

[0364] 901-920 processes or steps within method 900

Claims

CLAIMS1. A method of controlling different functionalities of a vehicle, the method comprising: an initialization process comprising: receiving, for each of a plurality of controllable components or controllable functional groups of components of the vehicle, capability information representing one or more capabilities of the respective component or functional group that are configured to be controlled by the CCU; and assigning to each functionality in a set of different functionalities of the vehicle which are controllable by the CCU, a set of one or more of the components or functional groups based on the capability information and on reference information, wherein the reference information defines for each functionality in the set of functionalities a corresponding required set of one or more capabilities for performing this functionality; and a controlling process comprising selectively maintaining, activating, deactivating, or configuring a functionality of the vehicle by based on a comparison of the capabilities represented in the capability information and the required set of capabilities for this functionality as represented by the reference information.

2. The method of claim 1 , wherein the reference information is dynamically adjusted.

3. The method of any one of the preceding claims, wherein the controlling process comprises: receiving from at least one of the components or functional groups assigned to a functionality and having at least one sensor capability identified in the corresponding capability information, sensor information representing the result of at least one sensory measurement performed by the component or functional group, respectively; and communicating control information to one or more components or functional groups, respectively, being assigned to this functionality and having at least one actuator capability or user-interface capability identified in the corresponding capability information to cause it or them, respectively, to perform the functionality as a function of the sensor information.

4. The method of any one of the preceding claims, wherein the selectively activating, deactivating, or configuring a functionality of the vehicle is further based on demand information defining for each component or functional group assigned to thefunctionality a respective set of one or more requirements which the component or functional group, respectively, needs for its operation.

5. The method of any one of the preceding claims, wherein: the initialization process is performed repeatedly; and the controlling process is performed based on the assignments of components and functional groups, respectively, to functionalities of the vehicle resulting from the respective last completed run of the initialization process.

6. The method of any one of the preceding claims, further comprising: monitoring, whether a component or functional group has been physically added or removed from the plurality of components or functional groups of the vehicle; and when the monitoring yields that one or more components or functional groups have been physically added or removed, initiating a new run of the initialization process.

7. The method of claim 6, wherein, when the monitoring yields that one or more components or functional groups have been physically added, each such new component or functional group, respectively, is checked with regard to fulfillment of each acceptance criteria in a defined set comprising one or more of the following acceptance criteria individually or in any combination of at least two of them, and is only admitted for control by the CCU according to the controlling process if all of the acceptance criteria in the set are fulfilled:- the component or functional group has been previously registered with the vehicle;- the component or functional group has a defined trusted digital certificate;- the component or functional group is connected to a power supply.

8. The method of any one of claims 5 to 7, wherein: the initialization process further comprises: determining, based on the capability information, that a previously available component or functional group is no longer available to support a given functionality of the vehicle; and the controlling process comprises: selectively deactivating this given functionality of the vehicle; or communicating control information to at least one other component or functional group being available to support the given functionality, at least to a reduced extent, to cause this at least one other component or functional group toperform the functionality, at least to a reduced extent, as a replacement of the no longer available component or functional group, respectively.

9. The method of any one of the preceding claims, further comprising selectively assigning a respective priority from a set of different priorities to each functionality in the set of different functionalities of the vehicle; and wherein the controlling process comprises deactivating or reducing an operational scope or performance of at least one further functionality in the set of functionalities that has a priority being lower than that of the given functionality.

10. The method of claim 9, wherein reducing an operational scope or performance of the least one further functionality in the set of functionalities that has a priority being lower than that of the given functionality comprises communicating control information to one or more of the components and / or functional groups being assigned to this further functionality to cause it or them, respectively, to transition to a low-power and / or low-performance mode of operation to thereby reduce an operational scope or performance of the further functionality.

11. The method of any one of the preceding claims, wherein the reference information is provided in a look-up table being accessible by the CCU.

12. The method of any one of the preceding claims, wherein the controlling process further comprises: performing or causing at least one of the components or functional groups to perform one or more functional tests to determine whether or not or to which degree the respective component or functional group, respectively, is currently actually capable of providing the capabilities represented in its associated capability information; and when it is thereby determined that the component or functional group, respectively, is currently failing to provide one or more of the capabilities represented in its associated capability information, performing one or more of the following steps: a) treating the component or functional group, respectively, as if it was not present; b) deactivating the component or functional group, respectively; c) determining that the component or functional group, respectively, is or might be a fake product; d) modifying the capability information of the component or functional group, respectively, for further use with a reduced set of capabilities, based on its determined actual capabilities;e) issuing or causing one or more of the components or functional groups having, according to the associated capability information, a suitable capability, to issue warning information or a signal indicating a failure or a reduced functionality; f) reporting or causing one or more of the components or functional groups having, according to the associated capability information, a suitable capability, to report the determined failure to a vehicle-external report collection system.

13. A central computing unit, CCU, comprising at least one processor being configured to perform the method of any one of the preceding claims to control different functionalities of a vehicle by selectively controlling a plurality of components or functional groups of components of the vehicle.

14. A system for controlling a functionality of a vehicle, the system comprising: a plurality of components or functional groups of components for a vehicle; and a CCU according to claim 13; wherein the CCU is configured to perform the method of any one of claims 1 to 12 to control one or more of the components or functional groups of the system.

15. The system of 14, wherein the system has one or more of the following properties:- all the components and / or functional groups in the plurality of components or functional groups of components of the vehicle are connected, directly or indirectly via one or more intermediate devices, to the CCU using a detachable physical connection of a same type;- the CCU uses a same unified software API to control two or more of the components and / or functional groups in the plurality of components or functional groups of components of the vehicle;- the system comprises a set of different hardware drivers to be used for different types of components or groups of components, and is configured to select for each given type of component or group of components an associated hardware driver based on the capability information of the respective component or group of components;- at least one of the components and / or functional groups in the plurality of components or functional groups of components of the vehicle are processorless;- at least one of the components and / or functional groups in the plurality of components or functional groups of components of the vehicle is a digital component or a digital functional group, respectively;- the CCU is configured to communicate with all the components and / or functional groups in the plurality of components or functional groups of components via one or more digital communication links or digital networks.

16. A vehicle comprising the system of claim 14 or 15.

17. A computer program or computer program product, comprising instructions which when executed on a CCU according to claim 13 or on a test-infrastructure for the vehicle as a whole or for subsystems thereof, cause the CCU or the test infrastructure, respectively, or both in collaboration, to perform the method of any one of claims 1 to 12.

Citation Information

Patent Citations

  • Central computing unit for a vehicle and vehicle comprising such a central computing unit as an on-board computing unit

    WO2024179678A1

  • In-vehicle distributed computing environment

    US20220321655A1

  • Elastic computing for in-vehicle computing systems

    WO2020210729A1