A monitoring method for functional application and vehicle controller system
By introducing a monitoring method for functional applications in the vehicle controller system, a high-security level controller sends monitoring requests to the service-oriented architecture (SOA) controller, the problem of insufficient functional safety monitoring in on-board computers is solved, and effective monitoring of functional applications and support for the highest functional safety level is achieved.
Patent Information
- Application Number
- CN202210857810.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-20
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2042-07-20
AI Technical Summary
Under the new automotive electronic and electrical architecture (EEA), the lack of complete functional safety monitoring in on-board computers makes it difficult to ensure the safety of vehicle control and decision-making functions.
By introducing a monitoring method for functional applications in the vehicle controller system, a high-security controller is used to send monitoring requests to the service-oriented architecture (SOA) controller, and the monitoring application sends the monitoring results of the functional applications back to the high-security controller for verification to ensure the normal operation of the functional applications.
It realizes effective monitoring of functional applications in on-board computers, ensures the correct execution of functional applications and the safety and reliability of hardware resources, supports the highest functional safety ASIL-D level, and saves software and hardware development costs.
Smart Images

Figure CN115291497B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of vehicle-mounted control, and in particular to a vehicle controller system with functional application monitoring and a functional application monitoring method. Background Art
[0002] The four new trends of automobiles, namely, electrification, intelligence, networking, and sharing, are major changes in the automobile industry. As the four new trends advance, the functions in vehicles are becoming increasingly complex, and the traditional distributed electrical and electronic architecture (EEA) can no longer adapt to this trend. Therefore, EEA has begun to change, gradually evolving from the original distributed to the domain-centralized and centrally centralized EEA. Figure 1 shown.
[0003] Take the centralized and regionally oriented EEA as an example. Figure 2 As shown. In the future, the car will have one or more high-computing-power onboard computers, several zone controllers, and several traditional embedded controllers. Among them, the zone controller and the embedded controller only have different division of responsibilities. Their implementation methods are still based on microcontroller (Micro-Controller Unit, MCU) products, and they all use the classic AUTOSAR platform (ClassicAUTOSAR Platform). However, high-computing-power onboard computers need to be based on microprocessors (Micro-ProcessingUnit, MPU), using other software platforms such as the Adaptive AUTOSAR Platform. For domain-centralized EEA, there are also controller products using MCU and MPU.
[0004] Secondly, as the automotive electronic control system becomes increasingly complex, the introduction of a large number of electrical and electronic components has brought convenience and diversity to control, but also brought certain risks to vehicle safety due to unavoidable systematic failures and random hardware failures. ISO26262 was born in response to this risk. The standard evaluates the safety level (Automotive Safety Integrity Level: ASIL) for different safety goals based on the analysis of the risks and hazards of the vehicle under various working conditions, and provides a set of practical functional safety development processes and safety measures for different failure modes. Therefore, it has been valued by various vehicle manufacturers.
[0005] In summary, under the new EEA, the car will have one or more high-computing computing units, which are different from traditional embedded controllers. For example, the on-board computer uses operating systems such as Linux and QNX, which are quite different from the real-time operating system (RTOS) in traditional embedded controllers. It will be designed based on the service-oriented architecture (SOA), and the software will be deployed in the on-board computer in the form of applications (APP) that implement various functions. However, while the software system is undergoing major changes, the results they calculate may be used for safety-critical vehicle control and decision-making functions. Therefore, how to ensure the functional safety of the entire system will be a major challenge. One of the technical solutions is to develop a set of monitoring software in the on-board computer, just like the traditional embedded controller. However, due to the huge difference between this type of controller software and traditional embedded software, it is difficult to use the existing monitoring strategy in it and it needs to be redesigned. In addition, for some key basic software (such as Linux, QNX and other operating systems, middleware) and the chip itself, it is also necessary to use versions that support functional safety, which will greatly increase the R&D cost. In addition, since the first version of ISO26262 standard was released in 2011, the industry has focused on the design and development of functional safety monitoring software, mainly on embedded controllers (MCU side), whose functional safety monitoring solutions are already relatively mature. However, the functional safety monitoring solutions for vehicle-mounted computers (MPU side) are still in the early stages.
[0006] In view of this, it is hoped to provide a monitoring method for the functional safety of an on-board computer to ensure the safe operation of the vehicle. Summary of the invention
[0007] A brief summary of one or more aspects is given below to provide a basic understanding of these aspects. This summary is not an exhaustive overview of all conceived aspects, and is neither intended to identify the key or critical elements of all aspects nor to define the scope of any or all aspects. Its only purpose is to give some concepts of one or more aspects in a simplified form as a prelude to a more detailed description that will be given later.
[0008] As described above, in order to solve the problem of lack of perfect functional safety monitoring in vehicle-mounted computers in the prior art, the present invention provides a monitoring method for functional applications and a vehicle controller system.
[0009] One aspect of the present invention provides a method for monitoring functional applications, which is applied to multiple controllers of a vehicle, and includes: a first controller sends at least one monitoring request corresponding to a functional application to a monitoring application of a second controller, so as to monitor each functional application on the second controller based on the monitoring application; the monitoring application sends the monitoring result of each functional application to the first controller; and the first controller verifies the monitoring result to determine whether each functional application on the second controller is operating normally; wherein the ASIL level of the first controller is higher than the ASIL level of the second controller, and the second controller is a service-oriented architecture controller.
[0010] In one embodiment of the above-mentioned monitoring method, optionally, it also includes: the monitoring application converts at least one of the monitoring requests into at least one test service for calling by each of the functional applications corresponding to each of the monitoring requests; wherein the monitoring result of each of the functional applications is the calling result of each of the functional applications.
[0011] In one embodiment of the above-mentioned monitoring method, optionally, in response to receiving the monitoring request and after a preset time period, the monitoring application sends the monitoring results of each functional application corresponding to the at least one monitoring request to the first controller; wherein in response to the monitoring application receiving feedback after the functional application calls the test service within the preset time period, the feedback is used as the call result; in response to the monitoring application not receiving feedback from the functional application within the preset time period, the result representing the failure is used as the call result; the length of the preset time period is related to the time when the monitoring application converts the monitoring request, the time when each functional application calls the test service, and the functional safety fault tolerance time.
[0012] In one embodiment of the above-mentioned monitoring method, optionally, in response to the first controller sending multiple monitoring requests corresponding to multiple functional applications respectively, the monitoring application, in response to receiving the monitoring requests and after a preset time period, merges multiple monitoring results of the multiple functional applications corresponding to the multiple monitoring requests into a comprehensive monitoring result and sends it to the first controller, and the first controller verifies the comprehensive monitoring result to determine whether the multiple functional applications are operating normally.
[0013] In one embodiment of the above monitoring method, optionally, the first controller sends at least one monitoring request to the monitoring application of the second controller multiple times according to a preset first frequency; wherein for the same functional application, the multiple monitoring requests sent multiple times are different.
[0014] In an embodiment of the above monitoring method, optionally, the first frequency is less than the second frequency at which each functional application calls a service.
[0015] In an embodiment of the above monitoring method, optionally, the first controller forwards at least one monitoring request generated by a watchdog module of the SBC chip, and forwards the monitoring result returned by the monitoring application to the SBC chip for verification.
[0016] In one embodiment of the above-mentioned monitoring method, optionally, the first controller includes multiple first sub-controllers, the monitoring application of the second controller includes multiple monitoring sub-applications, each of the first sub-controllers corresponds one-to-one to each of the monitoring sub-applications, and each monitoring request sent by each of the first sub-controllers corresponds to a functional application corresponding to the corresponding monitoring sub-application.
[0017] In one embodiment of the above-mentioned monitoring method, optionally, the second controller includes a second main controller and at least one second sub-controller, the second main controller is provided with the monitoring application, and each of the second sub-controllers supports service-oriented communication with the second main controller, wherein the first controller also sends at least one monitoring request corresponding to each functional application on each of the second sub-controllers to the monitoring application on the second main controller, so as to monitor each functional application on each of the second sub-controllers based on the communication between the second main controller and each of the second sub-controllers.
[0018] Another aspect of the present invention further provides a vehicle controller system with functional application monitoring, comprising at least a first controller and a second controller, wherein the ASIL level of the first controller is higher than the ASIL level of the second controller, and the second controller is a service-oriented architecture controller; wherein the first controller sends at least one monitoring request corresponding to a functional application to a monitoring application of the second controller, so as to monitor each functional application on the second controller based on the monitoring application; the monitoring application sends the monitoring result of each functional application to the first controller; and the first controller verifies the monitoring result to determine whether each functional application on the second controller is operating normally.
[0019] In one embodiment of the above-mentioned vehicle controller system, optionally, the monitoring application of the second controller also converts at least one of the monitoring requests into at least one test service for calling by each of the functional applications corresponding to each of the monitoring requests; wherein the monitoring result of each of the functional applications is the calling result of each of the functional applications.
[0020] In one embodiment of the above-mentioned vehicle controller system, optionally, in response to receiving the monitoring request and after a preset time period, the monitoring application sends the monitoring results of each functional application corresponding to the at least one monitoring request to the first controller; wherein in response to the monitoring application receiving feedback after the functional application calls the test service within the preset time period, the feedback is used as the call result; in response to the monitoring application not receiving feedback from the functional application within the preset time period, the result representing the failure is used as the call result; the length of the preset time period is associated with the time when the monitoring application converts the monitoring request, the time when each functional application calls the test service, and the functional safety fault tolerance time.
[0021] In one embodiment of the above-mentioned vehicle controller system, optionally, in response to the first controller sending multiple monitoring requests corresponding to multiple functional applications respectively, the monitoring application, in response to receiving the monitoring requests and after a preset time period, merges multiple monitoring results of the multiple functional applications corresponding to the multiple monitoring requests into a comprehensive monitoring result and sends it to the first controller, and the first controller verifies the comprehensive monitoring result to determine whether the multiple functional applications are operating normally.
[0022] In one embodiment of the above-mentioned vehicle controller system, optionally, the first controller sends at least one monitoring request to the monitoring application of the second controller multiple times according to a preset first frequency; wherein for the same functional application, the multiple monitoring requests sent multiple times are different.
[0023] In one embodiment of the above-mentioned vehicle controller system, optionally, the first frequency is less than the second frequency at which each of the functional applications calls up the service.
[0024] In one embodiment of the above-mentioned vehicle controller system, optionally, the vehicle controller system also includes an SBC chip that communicates with the first controller, wherein the first controller forwards at least one monitoring request generated by the watchdog module of the SBC chip, and forwards the monitoring results returned by the monitoring application to the SBC chip for verification.
[0025] In one embodiment of the above-mentioned vehicle controller system, optionally, the first controller includes multiple first sub-controllers, the monitoring application of the second controller includes multiple monitoring sub-applications, each of the first sub-controllers corresponds one-to-one to each of the monitoring sub-applications, and each monitoring request sent by each of the first sub-controllers corresponds to a functional application corresponding to the corresponding monitoring sub-application.
[0026] In one embodiment of the above-mentioned vehicle controller system, optionally, the second controller includes a second main controller and at least one second sub-controller, the second main controller is provided with the monitoring application, and each of the second sub-controllers supports service-oriented communication with the second main controller, wherein the first controller also sends at least one monitoring request corresponding to each functional application on each of the second sub-controllers to the monitoring application on the second main controller, so as to monitor each functional application on each of the second sub-controllers based on the communication between the second main controller and each of the second sub-controllers.
[0027] Another aspect of the present invention further provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the method for monitoring the functional application as described in any one of the embodiments of the present invention is implemented.
[0028] According to the functional application monitoring method and vehicle controller system provided by the present invention, without the need for hardware support, full use is made of the service-oriented software under the service-oriented architecture (SOA), and a high-security-level controller is used to monitor whether each APP running in the on-board computer is executing correctly and whether the hardware resources and basic software used are safe and reliable. The highest functional safety ASIL-D level can be supported. The present invention can realize the reuse of monitoring software at the vehicle level to save software and hardware development costs. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] The above features and advantages of the present invention can be better understood after reading the detailed description of the embodiments of the present disclosure in conjunction with the following drawings. In the drawings, the components are not necessarily drawn to scale, and components with similar related properties or features may have the same or similar reference numerals.
[0030] Figure 1 A schematic diagram showing the evolution trend of the automotive electrical and electronic architecture (EEA) in the prior art.
[0031] Figure 2 A schematic diagram of the structure of a region-oriented centralized electrical and electronic architecture (EEA) is shown.
[0032] Figure 3 A schematic diagram of an embodiment of a vehicle controller system provided by one aspect of the present invention is shown.
[0033] Figure 4 A schematic diagram showing another embodiment of a vehicle controller system provided by one aspect of the present invention is shown.
[0034] Figure 5 A schematic diagram showing another embodiment of a vehicle controller system provided by one aspect of the present invention is shown.
[0035] Figure 6 A schematic diagram showing another embodiment of a vehicle controller system provided by one aspect of the present invention is shown.
[0036] Figure 7 A schematic diagram showing another embodiment of a vehicle controller system provided by one aspect of the present invention is shown.
[0037] Figure 8 A schematic diagram showing another embodiment of a vehicle controller system provided by one aspect of the present invention is shown.
[0038] Fig. 9 A schematic flow chart of a method for monitoring functional applications provided in one aspect of the present invention is shown.
[0039] Fig.10 A general structural schematic diagram of each vehicle controller in the present invention is shown. DETAILED DESCRIPTION
[0040] The present invention is described in detail below in conjunction with the accompanying drawings and specific embodiments. Note that the aspects described below in conjunction with the accompanying drawings and specific embodiments are only exemplary and should not be construed as limiting the scope of protection of the present invention in any way.
[0041] The following description is given to enable those skilled in the art to implement and use the invention and incorporate it into a specific application context. Various modifications, as well as various uses in different applications will be readily apparent to those skilled in the art, and the general principles defined herein are applicable to a wide range of embodiments. Thus, the present invention is not limited to the embodiments given herein, but should be granted the broadest scope consistent with the principles and novel features disclosed herein.
[0042] In the following detailed description, many specific details are set forth to provide a more thorough understanding of the present invention. However, it will be apparent to those skilled in the art that the practice of the present invention need not be limited to these specific details. In other words, known structures and devices are shown in block diagram form without detailed display to avoid obscuring the present invention.
[0043] The reader is reminded of all documents and literature filed simultaneously with this specification and open to public inspection, and the contents of all such documents and literature are incorporated herein by reference. Unless otherwise directly stated, all features disclosed in this specification (including any attached claims, abstracts and drawings) can be replaced by alternative features for achieving the same, equivalent or similar purposes. Therefore, unless otherwise explicitly stated, each feature disclosed is only an example of a group of equivalent or similar features.
[0044] Note that, where used, the symbols left, right, front, back, top, bottom, forward, reverse, clockwise and counterclockwise are used only for convenience and do not imply any specific fixed direction. In fact, they are used to reflect the relative position and / or direction between the various parts of the object. In addition, the terms "first" and "second" are used only for descriptive purposes and should not be understood as indicating or implying relative importance.
[0045] Note that, in the case of use, further, preferably, further and more preferably are simple beginnings for explaining another embodiment based on the previous embodiment, and the content of further, preferably, further or more preferably followed by the above embodiment is combined with the previous embodiment as a complete composition of another embodiment. Several further, preferably, further or more preferably settings followed by the same embodiment can be arbitrarily combined to form another embodiment.
[0046] As described above, in order to solve the problem of lack of perfect functional safety monitoring in vehicle-mounted computers in the prior art, the present invention provides a monitoring method for functional applications and a vehicle controller system.
[0047] First, please combine Figure 3 and Fig. 9 To understand the monitoring method of the functional application and a specific implementation method of the vehicle controller system provided by the present invention. Fig. 9 As shown, a method for monitoring functional applications provided by one aspect of the present invention comprises the steps of:
[0048] S100: The first controller sends at least one monitoring request corresponding to each functional application to a monitoring application of the second controller;
[0049] S200: The monitoring application sends the monitoring results of each functional application to the first controller; and
[0050] S300: The first controller checks the monitoring result to determine whether each functional application on the second controller is running normally.
[0051] Please combine Figure 3 The vehicle controller system shown, the first controller in the present invention refers to a controller with a higher ASIL level, such as Figure 3 The ASIL level of the second controller is lower than that of the first controller. Figure 3 The on-board computer in the vehicle.
[0052] Furthermore, the second controller is a service-oriented architecture controller. Figure 3As can be seen from the figure, the software is deployed in the vehicle-mounted computer in the form of an application (APP). The first controller is connected to the second controller through a communication connection.
[0053] In the present invention, the first controller and the second controller can also be divided into different forms according to different vehicle-mounted hardware structures, and according to different hardware distribution situations, the above-mentioned communication connection can be divided into different situations, which will be described in conjunction with the accompanying drawings below and will not be repeated here.
[0054] In one embodiment of the functional application monitoring method provided by the present invention, in order to ensure the correct execution of the "functional APPn" (n=1, 2, 3, 4...), hereinafter referred to as "functional APP", in the second controller (on-board computer), a question / answer mechanism is adopted, that is, the first controller (embedded controller) with a high ASIL level sends a Question to the second controller (on-board computer) with a low ASIL level (step S100), and the "safety monitoring APP" specially provided in the present invention on the second controller receives the Question and converts it into a service for calling by other "functional APPs" that need to be monitored (step S110).
[0055] Since each "Function APP" on the second controller will send a request to the real service provider module to call the relevant service in order to realize its own function, when the "Safety Monitoring APP" on the second controller converts the Question into a service, it is equivalent to providing a "virtual service" for the "Function APP" to call. Under normal circumstances, that is, when there is no abnormality, the "Function APP" will feedback the call result after calling the "virtual service", and an Answer value can also be obtained based on the "virtual service" converted from the Question. Each "Function APP" feeds back the Answer to the "Safety Monitoring APP", and the "Safety Monitoring APP" sends the feedback results of each "Function APP" to the first controller (embedded controller) with a high ASIL level (step S200), so that the first controller verifies the monitoring result (i.e. the feedback call result) (step S300). If the verification fails, a safety response is made according to the safety goal (SG) corresponding to the specific application.
[0056] In order to improve the diagnostic coverage, the Question (monitoring request) sent by the embedded controller with high ASIL level can be dynamically changed, that is, for the same functional application, multiple monitoring requests sent multiple times are different, for example: 0x0, 0x1, 0x2, 0x3...0xF, etc. appear randomly, so as to avoid the "functional APP" predicting the call result. Secondly, the method of obtaining the Answer based on the Question in the "functional APP" can also be selected according to the diagnostic coverage requirements, which can be obtained by directly looking up the table or based on the linear feedback shift register (LFSR) and other operations. Furthermore, if the diagnostic coverage is to be further improved, the above operation can also integrate the monitoring results of various software and hardware resources. For example: if the CPU instruction set used by the "functional APP" is involved in the calculation of the Answer, and the Answer is written first and then read in the storage area used by the "functional APP", the operation to obtain the Answer can cover the chip resources (CPU, storage, etc.) used by the "functional APP".
[0057] Secondly, if there are restrictions on time-related parameters such as the execution time and operation cycle of the "Function APP", time-related monitoring can be performed in an embedded controller with a high ASIL level. For example, the frequency at which the embedded controller sends monitoring requests can be adjusted to verify whether the frequency (operation cycle) at which the "Function APP" calls services is reasonable. In order to ensure that the frequency adjustment can reasonably reflect the operation cycle of the "Function APP", it is necessary to set the frequency at which the first controller sends monitoring requests less than the second frequency at which each functional application calls services.
[0058] At the same time, the monitoring application can be set to respond to receiving the monitoring request and after a preset time period, send the monitoring results of each functional application corresponding to at least one monitoring request to the first controller. Within the preset time period, if the monitoring application receives feedback after the functional application calls the test service, it will feedback the call result (indicating that the execution time of the "functional APP" is reasonable). If the monitoring application does not receive feedback from the functional application within the preset time period, the result representing the failure will be fed back to the first controller as the call result, that is, it is considered that the execution time of the "functional APP" is abnormal.
[0059] Furthermore, in order to make the monitoring results more reasonably represent the actual call results of the "Function APP", the above preset time period needs to comprehensively consider the time for the monitoring application to convert the monitoring request and the time for each functional application to call the test service. At the same time, in order to ensure safety, it is also necessary to consider meeting the requirements of the functional safety fault tolerance time interval (FTTI).
[0060] In one embodiment, in response to the first controller sending multiple monitoring requests corresponding to multiple functional applications, the monitoring application, in response to receiving the monitoring requests and after a preset time period, merges multiple monitoring results of the multiple functional applications corresponding to the multiple monitoring requests into a comprehensive monitoring result and sends it to the first controller. The first controller verifies the comprehensive monitoring result to determine whether the multiple functional applications are operating normally.
[0061] For example, in the above-mentioned embodiment, if the first controller sends three monitoring requests corresponding to "Function APP1", "Function APP3", and "Function APP6" to the monitoring application, the monitoring application converts the three monitoring requests into corresponding test services, and receives the feedback results of "Function APP1", "Function APP3", and "Function APP6" within a preset time period. After the preset time period, regardless of whether the feedback results of "Function APP1", "Function APP3", and "Function APP6" are received, the monitoring results of the corresponding three "Function APPs" will be merged into a comprehensive monitoring result and sent to the first controller for inspection. In this process, if "Function APP1", "Function APP3", and "Function APP6" all feedback correct results, the comprehensive monitoring result is also correct, and the first controller can detect that "Function APP1", "Function APP3", and "Function APP6" are all operating normally.
[0062] Once any one of "Function APP1", "Function APP3" and "Function APP6" feeds back an incorrect result or no feedback result, the integrated monitoring results after fusion will be wrong, and the first controller will be able to detect abnormalities in "Function APP1", "Function APP3" and "Function APP6".
[0063] In the above-mentioned embodiment, although the integrated monitoring results after fusion are not conducive to locating the abnormality after the abnormality occurs, the data transmission and inspection amount of the feedback results can be reduced, thereby reducing the data processing amount and increasing the processing speed when the "functional APP" are all normal, and when an abnormality occurs in any "functional APP", the abnormality can be detected quickly (only one data needs to be processed) and accurately.
[0064] As described above, in the present invention, the first controller and the second controller can be divided into different forms according to different vehicle-mounted hardware structures, and according to different hardware distribution conditions, the above communication connection can be divided into different conditions, for example, in the case of Figure 3In the illustrated embodiment, the first controller and the second controller are both independent controllers. In this embodiment, the first controller (embedded controller) and the second controller (on-board computer) communicate with each other through boards.
[0065] In such Figure 4 In the illustrated embodiment, the first controller and the second controller may be two independent chips in the same controller, such as an MCU chip with a high ASIL level and an MPU chip with a low ASIL level. In this embodiment, the MCU chip and the MPU chip communicate within the board.
[0066] In such Figure 5 In the illustrated embodiment, the first controller and the second controller may be two independent cores in the same System On Chip (SoC), that is, an MCU core with a high ASIL level and an MPU core with a low ASIL level. In this embodiment, the communication between the MCU core and the MPU core is intra-chip.
[0067] In another embodiment of the present invention, Figure 6 As shown, the mechanism for generating Questions can also be generated by the intelligent watchdog inside the System Basis Chip (SBC). The system basis chip and the MCU of the embedded controller communicate through the Serial Peripheral Interface (SPI), MicroSecond Channel (MSC), etc. At present, mainstream SBCs all have intelligent watchdog functions. Under certain configurations, the SBC will send Questions periodically, and the MCU needs to feedback the Answer within a certain time window. If the feedback Answer is wrong, a fault response will be triggered.
[0068] In the above embodiment, since the Question generated by the SBC is generated by Markov Chain (MC) and other mechanisms, it has a certain randomness and can effectively prevent failure modes such as stuck. In addition, through certain mathematical transformations, the Answer obtained by summarizing the "security monitoring APP" can be forwarded by the embedded controller to the SBC for verification, which can not only detect the functional APP, but also check whether the embedded controller is normal because the inspection is performed by the SBC chip, so that the diagnostic coverage of the entire solution is further improved, and the security of the entire system can be further guaranteed.
[0069] In another embodiment of the present invention, Figure 7As shown, in this solution, multiple “safety monitoring APPs” (such as Figure 7 In the security monitoring APP1-APP3), each "security monitoring APP" corresponds to a first controller with a high ASIL level, and each monitoring request sent by each first sub-controller corresponds to the functional application corresponding to the corresponding monitoring sub-application, so as to realize the aforementioned Question / Answer mechanism.
[0070] For example, if Figure 7 As shown. The Question provided by the embedded controller 1 with a high ASIL level is used for "Safety Monitoring APP1", and "Function APP1" and "Function APP2" call the service provided by "Safety Monitoring APP1". The final Answer is fed back to the embedded controller 1 for verification. The Question provided by the embedded controller 3 with a high ASIL level is used for "Safety Monitoring APP2", and "Function APP3" calls the service provided by "Safety Monitoring APP2". The final Answer is fed back to the embedded controller 3 for verification. The Question provided by the regional controller n with a high ASIL level is used for "Safety Monitoring APP3", and "Function APPn" calls the monitoring service provided by "Safety Monitoring APP3", and the final Answer is fed back to the regional controller n for verification. If Figure 7 The embedded controller 3 in the embodiment has a longer path covered, which can cover more hardware resources and software failures.
[0071] In another embodiment, based on service-oriented communication such as SOME / IP (Scalable service-oriented MiddlewarE over IP) based on vehicle Ethernet (Ethernet), if the services in different controllers in the vehicle can be dynamically discovered, that is, the "security monitoring APP" can be reused in the entire vehicle, such as Figure 8 As shown. Figure 8 In the figure, the second controller includes a controller 1 (a second main controller, on which a security monitoring APP is set) based on MPU supporting a service-oriented architecture and a controller 2 (a second sub-controller) based on MPU supporting a service-oriented architecture. The second main controller and the second sub-controller support service-oriented communication, that is, the function APP of the second sub-controller can send a request to call a service to the second main controller, thereby being able to call the test service provided by the security monitoring APP of the second main controller.
[0072] So far, the monitoring method of the functional application and the vehicle controller system with functional application monitoring provided by the present invention have been described. According to the present invention, not only the hardware resources used by each "functional APP" such as power supply, clock, instruction set, memory, etc. can be covered, but also the basic software resources such as operating system, etc. can be involved, and the failure of the communication link between the vehicle-mounted computer and the embedded controller can be covered.
[0073] The biggest feature of this solution is that it makes full use of the service-oriented software under the service-oriented architecture (SOA) without the need for hardware support, and monitors whether the various APPs running in the on-board computer are executing correctly and whether the hardware resources and basic software they use are safe and reliable through the existing high-security level embedded controller. It can support the highest functional safety ASIL-D level. This solution can also realize the reuse of monitoring software at the vehicle level to save software and hardware development costs.
[0074] As described above, in the present invention, the first controller and the second controller can be divided into different forms according to different vehicle-mounted hardware structures, and according to different hardware distribution situations, the above-mentioned communication connection can be divided into different situations, but in any case, whether it is an independent controller, chip or core, it can be considered that the first controller and the second controller have the capabilities of a general-purpose processor.
[0075] Fig.10 The specific structure of an embodiment of a general purpose processor 1 is shown. The components of the general purpose processor 1000 may include one or more memories 1001, one or more processors 1002, and a bus 1003 connecting different system components (including the memories 1001 and the processors 1002).
[0076] The bus 1003 includes a data bus, an address bus, and a control bus. The product of the number of bits of the data bus and the operating frequency is proportional to the data transmission rate, the number of bits of the address bus determines the maximum addressable memory space, and the control bus (read / write) indicates the type of bus cycle and the time when the input / output operation is completed. The processor 1002 is connected to the memory 1001 via the bus 1003, and is configured to implement the monitoring method of the functional application provided by any of the above embodiments.
[0077] Processor 1002 is the computing and control core of general-purpose processor 1000 and is the final execution unit for information processing and program running. All software layer operations in the computer system will eventually be mapped to processor 1002 operations through the instruction set. The functions of processor 1002 are mainly to process instructions, execute operations, control time, and process data.
[0078] The memory 1001 refers to various storage devices in a computer for storing programs and data. The memory 1001 may include a computer system readable medium in the form of a volatile memory, such as a random access memory (RAM) 1004 and / or a cache memory 1005.
[0079] Random Access Memory (RAM) 1004 is an internal memory that directly exchanges data with the processor 1002. It can be read and written at any time (except when refreshed) and is very fast. It is usually used as a temporary data storage medium for the operating system or other running programs. Once the power is off, the data stored in it will be lost. Cache Memory (Cache) 1005 is a primary memory between the main memory and the processor 1002. Its capacity is relatively small but its speed is much higher than the main memory, close to the speed of the processor 1002.
[0080] It should be noted that, in the case where the general processor 1000 includes multiple memories 1001 and multiple processors 1002, there can be a distributed structure between the multiple memories 1001 and between the multiple processors 1002, and the controllers of multiple functional systems jointly implement the above-mentioned monitoring method of functional applications. Furthermore, in the embodiment adopting the distributed structure, each step can adjust the specific execution terminal according to the actual situation, and the specific scheme of each step implemented in a specific terminal should not unduly limit the protection scope of the present invention.
[0081] The general purpose processor 1000 may further include other removable / non-removable, volatile / non-volatile computer system storage media. In this embodiment, the storage system 1006 may be used to read and write non-removable, non-volatile magnetic media.
[0082] The memory 1001 may also include at least one set of program modules 1007. The program modules 1007 may be stored in the memory 1001. The program modules 1007 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data, each of which or some combination thereof may include an implementation of a network environment. The program modules 1007 generally perform the functions and / or methods of the embodiments described herein.
[0083] The general purpose processor 1000 may also communicate with one or more external devices 1008. The external devices 1008 in this embodiment include other controllers described above.
[0084] The general purpose processor 1000 may also communicate with one or more devices that enable a user to interact with the general purpose processor 1000, and / or with any device that enables the general purpose processor 1000 to communicate with one or more other computing devices (e.g., a network card, a modem, etc.). Such communication may be performed through an input / output (I / O) interface 1009.
[0085] The general purpose processor 1000 may also communicate with one or more networks (eg, a local area network (LAN), a wide area network (WAN), and / or a public network such as the Internet) via a network adapter 1010. Fig.10 As shown, the network adapter 1010 communicates with other modules of the general processor 1000 via the bus 1003. It should be understood that, although not shown in the figure, other hardware and / or software modules can be used in conjunction with the general processor 1000, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.
[0086] Another aspect of the present invention further provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the monitoring method of the functional application described in any one of the embodiments above. For details, please refer to the above description, which will not be repeated here. In addition, it can be understood that the above-mentioned computer-readable storage medium can be in the form of a system, that is, it includes multiple computer-readable storage sub-mediums, and the steps of the monitoring method of the functional application described above are jointly implemented by multiple computer-readable storage media.
[0087] The various illustrative logic modules and circuits described in conjunction with the embodiments disclosed herein may be implemented or executed with a general purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. A general purpose processor may be a microprocessor, but in the alternative, the processor may be any conventional processor, controller, microcontroller, or state machine. The processor may also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in cooperation with a DSP core, or any other such configuration.
[0088] The steps of the method or algorithm described in conjunction with the embodiments disclosed herein may be embodied directly in hardware, in a software module executed by a processor, or in a combination of the two. The software module may reside in a RAM memory, a flash memory, a ROM memory, an EPROM memory, an EEPROM memory, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art. An exemplary storage medium is coupled to a processor so that the processor can read and write information from / to the storage medium. In an alternative, a storage medium may be integrated into a processor. The processor and the storage medium may reside in an ASIC. The ASIC may reside in a user terminal. In an alternative, the processor and the storage medium may reside in a user terminal as discrete components.
[0089] In one or more exemplary embodiments, the functions described may be implemented in hardware, software, firmware, or any combination thereof. If implemented as a computer program product in software, each function may be stored on or transmitted by a computer-readable medium as one or more instructions or codes. Computer-readable media include both computer storage media and communication media, including any medium that facilitates the transfer of a computer program from one place to another. Storage media may be any available medium that can be accessed by a computer. As an example and not limitation, such a computer-readable medium may include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, disk storage or other magnetic storage device, or any other medium that can be used to carry or store the desired program code in the form of an instruction or data structure and can be accessed by a computer. Any connection is also properly referred to as a computer-readable medium. For example, if the software is transmitted from a website, a server, or other remote source using a coaxial cable, a fiber optic cable, a twisted pair, a digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwaves, the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwaves are included in the definition of the medium. Disk and disc as used herein include compact disc (CD), laser disc, optical disc, digital versatile disc (DVD), floppy disk and Blu-ray disc, wherein disk often reproduces data magnetically, while disc reproduces data optically with lasers. Combinations of the above should also be included within the scope of computer-readable media.
[0090] The foregoing description is provided to enable any person skilled in the art to practice the various aspects described herein. However, it should be understood that the scope of protection of the present invention shall be subject to the appended claims and shall not be limited to the specific structures and components of the above-described embodiments. Those skilled in the art may make various changes and modifications to the embodiments within the spirit and scope of the present invention, and these changes and modifications also fall within the scope of protection of the present invention.
Claims
1. A monitoring method for functional applications, applied to multiple controllers of a vehicle, characterized in that: include: The first controller sends at least one monitoring request corresponding to each functional application to a monitoring application of the second controller, so as to monitor at least one functional application on the second controller based on the monitoring application; The monitoring application sends the monitoring results of each of the functional applications to the first controller; as well as The first controller checks the monitoring result to determine whether each functional application on the second controller is operating normally; The ASIL level of the first controller is higher than the ASIL level of the second controller, and the second controller is a service-oriented architecture controller; Wherein, the method further comprises: The monitoring application converts at least one of the monitoring requests into at least one test service for invoking by each of the functional applications corresponding to each of the monitoring requests; The monitoring result of each of the functional applications is the calling result of each of the functional applications.
2. The monitoring method according to claim 1, characterized in that: The monitoring application sends the monitoring result of each functional application corresponding to the at least one monitoring request to the first controller in response to receiving the monitoring request and after a preset time period; in In response to the monitoring application receiving feedback from the functional application after calling the test service within the preset time period, taking the feedback as the calling result; In response to the monitoring application not receiving feedback from the functional application within the preset time period, taking a result indicating failure as the calling result; The length of the preset time period is associated with the time when the monitoring application converts the monitoring request, the time when each functional application calls the test service, and the functional safety fault tolerance time.
3. The monitoring method according to claim 2, characterized in that: In response to the first controller sending multiple monitoring requests corresponding to multiple functional applications, the monitoring application, in response to receiving the monitoring requests and after a preset time period, merges the multiple monitoring results of the multiple functional applications corresponding to the multiple monitoring requests into a comprehensive monitoring result and sends it to the first controller. The first controller verifies the comprehensive monitoring result to determine whether the multiple functional applications are operating normally.
4. The monitoring method according to claim 1, characterized in that: The first controller sends at least one monitoring request to the monitoring application of the second controller multiple times according to a preset first frequency; in For the same functional application, the multiple monitoring requests sent multiple times are different.
5. The monitoring method according to claim 4, characterized in that: The first frequency is less than the second frequency at which each of the functional applications invokes a service.
6. The monitoring method according to claim 1, characterized in that: The first controller forwards at least one monitoring request generated by the watchdog module of the SBC chip, and forwards the monitoring result returned by the monitoring application to the SBC chip for verification.
7. The monitoring method according to claim 1, characterized in that: The first controller includes multiple first sub-controllers, and the monitoring application of the second controller includes multiple monitoring sub-applications. Each of the first sub-controllers corresponds one-to-one to each of the monitoring sub-applications, and each monitoring request sent by each of the first sub-controllers corresponds to at least one functional application corresponding to the corresponding monitoring sub-application.
8. The monitoring method according to claim 1, characterized in that: The second controller includes a second main controller and at least one second sub-controller, the second main controller is provided with the monitoring application, and each of the second sub-controllers supports service-oriented communication with the second main controller, wherein The first controller also sends at least one monitoring request corresponding to each functional application on each second sub-controller to the monitoring application on the second main controller, so as to monitor each functional application on each second sub-controller based on the communication between the second main controller and each second sub-controller.
9. A vehicle controller system with functional application monitoring, characterized in that: At least comprising a first controller and a second controller, the ASIL level of the first controller is higher than the ASIL level of the second controller, and the second controller is a service-oriented architecture controller; in The first controller sends at least one monitoring request corresponding to each functional application to the monitoring application of the second controller, so as to monitor at least one functional application on the second controller based on the monitoring application; The monitoring application sends the monitoring results of each of the functional applications to the first controller; as well as The first controller checks the monitoring result to determine whether each of the functional applications on the second controller is operating normally; The monitoring application of the second controller further converts at least one of the monitoring requests into at least one test service for invoking by each of the functional applications corresponding to each of the monitoring requests; in The monitoring result of each of the functional applications is the calling result of each of the functional applications.
10. The vehicle controller system according to claim 9, characterized in that The monitoring application sends the monitoring result of each functional application corresponding to the at least one monitoring request to the first controller in response to receiving the monitoring request and after a preset time period; in In response to the monitoring application receiving feedback from the functional application after calling the test service within the preset time period, taking the feedback as the calling result; In response to the monitoring application not receiving feedback from the functional application within the preset time period, taking a result indicating failure as the calling result; The length of the preset time period is associated with the time when the monitoring application converts the monitoring request, the time when each functional application calls the test service, and the functional safety fault tolerance time.
11. The vehicle controller system according to claim 10, characterized in that: In response to the first controller sending multiple monitoring requests corresponding to multiple functional applications, the monitoring application, in response to receiving the monitoring requests and after a preset time period, merges the multiple monitoring results of the multiple functional applications corresponding to the multiple monitoring requests into a comprehensive monitoring result and sends it to the first controller. The first controller verifies the comprehensive monitoring result to determine whether the multiple functional applications are operating normally.
12. The vehicle controller system according to claim 9, characterized in that The first controller sends at least one monitoring request to the monitoring application of the second controller multiple times according to a preset first frequency; in For the same functional application, the multiple monitoring requests sent multiple times are different.
13. The vehicle controller system according to claim 12, characterized in that: The first frequency is less than the second frequency at which each of the functional applications invokes a service.
14. The vehicle controller system according to claim 9, characterized in that: The vehicle controller system also includes an SBC chip that communicates with the first controller, wherein The first controller forwards at least one monitoring request generated by the watchdog module of the SBC chip, and forwards the monitoring result returned by the monitoring application to the SBC chip for verification.
15. The vehicle controller system of claim 9, wherein: The first controller includes multiple first sub-controllers, and the monitoring application of the second controller includes multiple monitoring sub-applications. Each of the first sub-controllers corresponds one-to-one to each of the monitoring sub-applications, and each monitoring request sent by each of the first sub-controllers corresponds to at least one functional application corresponding to the corresponding monitoring sub-application.
16. The vehicle controller system of claim 9, wherein: The second controller includes a second main controller and at least one second sub-controller, the second main controller is provided with the monitoring application, and each of the second sub-controllers supports service-oriented communication with the second main controller, wherein The first controller also sends at least one monitoring request corresponding to each functional application on each second sub-controller to the monitoring application on the second main controller, so as to monitor each functional application on each second sub-controller based on the communication between the second main controller and each second sub-controller.
17. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the monitoring method of the functional application according to any one of claims 1 to 8 is implemented.
Citation Information
Patent Citations
Fault processing method and fault processing device
CN105847057A
Vehicle domain controller
CN109995628A