Vehicle control system, vehicle operation detection method, system and storage medium

Through the communication architecture and heartbeat signal detection between the central computing unit and the edge control unit, the problem of equipment in the on-board control system is solved, efficient and convenient fault detection and unified management are achieved, and maintenance costs are reduced.

CN115617020BActive Publication Date: 2025-08-05HUIXI INTELLIGENT TECH (SHANGHAI) CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202211392181.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-08
Publication Date
2025-08-05
Estimated Expiration
2042-11-08

AI Technical Summary

Technical Problem

In the existing vehicle-mounted control systems, electronic components are incompatible due to the development of different suppliers, which makes them difficult to achieve unified management, resulting in low signal transmission efficiency and complex operation and detection.

Method used

The communication architecture of the central computing unit and multiple edge control units is adopted to realize fault detection through the heartbeat signal. The central computing unit and the edge control unit detect each other to form a redundant topological structure to ensure the efficient and convenient fault detection of the system.

Benefits of technology

It realizes unified adaptation of vehicle-mounted control equipment from different suppliers, improves fault detection efficiency and accuracy, and reduces maintenance costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115617020B_ABST
    Figure CN115617020B_ABST
Patent Text Reader

Abstract

The present application provides an on-board control system and an on-board operation detection method, system and storage medium, wherein the on-board control system includes: a plurality of edge control units are respectively connected to a central computing unit via a communication link to realize information transmission between the two; each edge control unit corresponds to a different on-board control device; the central computing unit and the edge control unit perform mutual operation detection, and the central computing unit and the edge control unit also perform operation detection with other edge control units respectively, so as to determine the operation faults existing in the on-board control system. By unifying a large number of edge control units and their corresponding on-board control devices with the central computing unit as an integral system, the incompatibility of the edge control units due to different suppliers or different models is avoided, and the unified management of the on-board system cannot be realized; the fault detection efficiency and accuracy of the on-board control system are improved, and the maintenance cost of the overall system is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of vehicle-mounted control technology, and in particular to a vehicle-mounted control system and a vehicle-mounted operation detection method, system and storage medium. Background Art

[0002] With the upgrading of automotive consumption, the number of in-vehicle electronic components has increased to achieve more functions. Using traditional CAN (Connected Controller Area Network) to communicate between these components and the vehicle controller has a high load rate. Even if network segments are divided through network management, the surge in interactive information still needs to be transmitted through gateway message routing and signal routing. Furthermore, different electronic components with different functions are independently developed by different suppliers, making it difficult to adapt the vehicle controller to each electronic component and making centralized in-vehicle control difficult.

[0003] Therefore, a new on-vehicle control solution is needed. Summary of the Invention

[0004] In view of this, the embodiments of this specification provide a vehicle-mounted control system and a vehicle-mounted operation detection method, system and storage medium, which are applied to the vehicle-mounted control process.

[0005] The embodiments of this specification provide the following technical solutions:

[0006] The embodiment of this specification provides a vehicle-mounted control system, which includes:

[0007] Multiple edge control units are connected to the central computing unit through communication links to achieve information transmission between them;

[0008] Each of the edge control units corresponds to a different vehicle-mounted control device;

[0009] The central computing unit and the edge control unit perform mutual operation detection. The central computing unit and the edge control unit are also used to perform operation detection with other edge control units respectively, so as to determine the operation faults existing in the vehicle control system.

[0010] The embodiments of this specification also provide a vehicle-mounted operation detection method, which uses a vehicle-mounted control system as described in any technical solution of the embodiments of this specification. The vehicle-mounted operation detection method includes:

[0011] detecting an operational failure of the central computing unit according to each edge control unit;

[0012] And / or, in combination with the central computing unit, detecting operational failures of each edge control unit; wherein the operational failures include failures of the central computing unit itself, failures of the edge control unit itself, failures between the central computing unit and the edge control unit, and failures between the edge control units.

[0013] An embodiment of this specification also provides a vehicle-mounted control system, including a memory, a processor, and a computer program, wherein the computer program is stored in the memory, and the processor runs the computer program to execute the vehicle-mounted operation detection method described in any technical solution of the embodiment of this specification.

[0014] An embodiment of this specification also provides a readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, it is used to implement the vehicle operation detection method in any technical solution of the embodiment of this specification.

[0015] Compared with the prior art, the at least one technical solution adopted in the embodiments of this specification can achieve the following beneficial effects:

[0016] Each edge control unit and its corresponding on-board control device are unified with the central computing unit as an overall system; this avoids incompatibility of the edge control units with the on-board system due to different suppliers or different models, and the inability to achieve unified management of the on-board system; through redundant and complete topological architecture, mutual monitoring between nodes can be achieved, improving the fault detection efficiency and accuracy of the on-board control system and reducing the maintenance cost of the overall system. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0018] Figure 1 This is a typical architecture diagram of a vehicle-mounted control system in this application;

[0019] Figure 2 is a flow chart of a vehicle-mounted operation detection method in this application;

[0020] Figure 3 This is a schematic diagram of the architecture corresponding to the local detection of the vehicle control system in this application;

[0021] Figure 4 It is a structural diagram of a vehicle-mounted operation detection system in this application. DETAILED DESCRIPTION

[0022] The embodiments of the present application are described in detail below with reference to the accompanying drawings.

[0023] The following describes the embodiments of the present application through specific examples, and those skilled in the art can easily understand other advantages and effects of the present application from the contents disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. The present application can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present application. It should be noted that, in the absence of conflict, the features in the following embodiments and embodiments can be combined with each other. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without making creative work are within the scope of protection of this application.

[0024] It should be noted that various aspects of the embodiments within the scope of the appended claims are described below. It should be apparent that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is merely illustrative. Based on this application, it should be understood by those skilled in the art that an aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number and aspect described herein can be used to implement an apparatus and / or practice a method. In addition, other structures and / or functionalities other than one or more of the aspects described herein can be used to implement this apparatus and / or practice this method.

[0025] It should also be noted that the illustrations provided in the following embodiments are only schematic illustrations of the basic concept of the present application. The illustrations only show components related to the present application and are not drawn according to the number, shape and size of components in actual implementation. In actual implementation, the type, quantity and proportion of each component can be changed at will, and the component layout type may also be more complicated.

[0026] Additionally, in the following description, specific details are provided to provide a thorough understanding of the examples, however, one skilled in the art will appreciate that the examples can be practiced without these specific details.

[0027] As vehicle requirements and functionality increase, existing automotive electronic and electrical architectures are unable to meet these demands. While existing distributed vehicle architectures can adapt electronic components based on function and communicate with the vehicle's main controller, each electronic component is developed by a different supplier, preventing unified adaptation to the main controller. Even with the use of gateways and CAN communication, performance issues can arise, leading to inefficient signal transmission between the components and the main controller.

[0028] Based on this, the embodiment of this specification proposes a vehicle-mounted control and operation detection solution: Figure 1As shown, a vehicle-mounted control system is proposed, which includes a central computing unit A and multiple edge control units (such as B, C, and D) that communicate with it. Each edge control unit transmits information with the central computing unit. The entire vehicle-mounted control system is designed with safety and redundancy mechanisms to ensure the operation of the actual product. The central computing unit and each edge control unit are assigned a unique identifier ID. During operation, the central computing unit and the edge control units perform mutual operation detection, and the central computing unit and the edge control units perform operation detection with other edge control units respectively. This allows the timely detection of operational faults in the architecture during operation without affecting the operation of other normally operating units, thus achieving convenient and efficient operation detection.

[0029] The following describes the technical solutions provided by various embodiments of the present application in conjunction with the accompanying drawings.

[0030] like Figure 1 The vehicle-mounted control system includes a central computing unit A, an edge control unit B, and edge control units C and D adjacent to the edge control unit B. In some embodiments, the edge control units adjacent to the edge control unit B are not limited to edge control units C and edge control D. Figure 1 The solid line in the middle represents a basic star-shaped communication topology formed by the central computing unit and each edge control unit. The dashed line indicates that the central computing unit and each edge control unit are connected in sequence, forming a redundant ring communication topology. The central computing unit is the control core of the vehicle-mounted architecture, and the edge control unit is the sensing and execution unit in the vehicle-mounted architecture. In some embodiments, each edge control unit corresponds to a different vehicle-mounted control device. In this vehicle-mounted architecture, the central computing unit and the edge control units are connected via a communication link, which can be an on-board Ethernet or CAN. The central computing unit and the edge control units are each assigned a unique identifier ID. The central computing unit is required to periodically broadcast its own heartbeat signal to each edge computing unit. The edge control unit is required to periodically send heartbeat signals to adjacent edge computing units via a ring-topology link. The heartbeat signal is a frame containing its own ID and a cyclically accumulated count value. The heartbeat signal of the edge control unit also includes an activity status signal (Active / Inactive) confirmed by the central computing unit. The edge control unit is required to periodically send a heartbeat signal to the central computing unit. In addition to its own ID and the cyclically accumulated count value, it also includes the activity status signals (Active / Inactive) confirmed by the two adjacent nodes. In some embodiments, when the activity state signal indicates an activity state, the cyclic accumulated count value in the heartbeat signal continues to accumulate; if the activity state signal indicates an inactivity state, the cyclic accumulated count value in the heartbeat signal does not change.

[0031] Among them, the central control unit is the control core of the architecture, which includes: equipped with a rich set of functional interfaces, including CAN, LIN, vehicle Ethernet, video input, display output, audio bus, analog and digital input and output, etc. It has powerful logical computing and processing capabilities, and with the support of advanced operating systems, it can perform real-time processing of multiple different tasks in parallel. In conjunction with this, it may also have accelerated computing capabilities in specific fields such as image and video processing capabilities, digital signal processing, and neural network inference calculations. It has the function of a communication gateway, assumes the function of an on-board Ethernet backbone switch, and has sufficient Ethernet or CAN interfaces to connect directly to other edge control units through communication interfaces.

[0032] The edge control unit is the sensing and execution unit in this architecture. It includes a rich set of sensor drivers and communication interfaces, including CAN, LIN, automotive Ethernet, and analog and digital input and output drivers. It possesses sufficient logical computing capabilities and can utilize an embedded real-time operating system. It is responsible for collecting status information from the controlled hardware and transmitting it to the central computing unit. It also provides real-time and reliable control of the controlled hardware according to the central computing unit's instructions. It also has limited message forwarding capabilities, capable of forwarding a limited number of communication messages to adjacent nodes.

[0033] Therefore, through the mutual operation detection between the central computing unit and the edge control unit, and the operation detection between the central computing unit and the edge control unit and other edge control units respectively, fast and efficient fault detection can be achieved without affecting any normal operating functions, and there will be no failures that cannot be discovered in time, resulting in long maintenance time and high maintenance costs. The on-board control devices of different functions and different suppliers can be uniformly adapted to the on-board architecture corresponding to the central computing unit, thereby achieving efficient operation of various functions.

[0034] like Figure 2 As shown, an embodiment of this specification provides a vehicle-mounted operation detection method, which may include steps S210 to S220. In step S210, the operation failure of the central computing unit is detected according to each edge control unit. In step S220, the operation failure of each edge control unit is detected in combination with the central computing unit; wherein, the operation failure includes the failure of the central computing unit itself, the failure of the edge control unit itself, the failure between the central computing unit and the edge control unit, and the failure between each edge control unit. The heartbeat signal includes the non-repeating IDs of the sender and receiver of the heartbeat signal, and a cyclic count signal for indicating the activity status.

[0035] Specifically, step S210 detects an operation failure of the central computing unit according to each edge control unit.

[0036] In some embodiments, a detection heartbeat signal is periodically sent between the central computing unit and the edge control units. Each edge control unit also periodically sends a detection heartbeat signal to its adjacent edge control units. The heartbeat signal can be used to detect whether the sender and receiver of the heartbeat signal are in an active state. In the embodiment of the present specification, the central computing unit of the vehicle control system can receive the heartbeat information of each edge control unit, and if the activity status of each edge control unit node is valid, it is determined that the entire vehicle control system is operating normally and no faults have occurred.

[0037] In some embodiments, as long as a normally operating edge control unit detects that the central computing unit is operating normally, the central computing unit is determined to be in an active state. In some embodiments, the redundancy design of multiple edge control units is used to detect whether the central computing unit is operating normally, thereby improving the efficiency and accuracy of the overall system fault detection and ensuring the efficient operation of the vehicle control system. The central computing unit can determine whether it has an operational failure based on the normally operating edge control units. If the central computing unit can receive the heartbeat signal of each edge control unit, and the adjacent node edge control units of each normally operating edge control unit also detect that the central computing unit is in an active state, then the central computing unit is determined to be in a normal operating state. In other embodiments, if all normally operating edge control units cannot receive the heartbeat signal sent by the central computing unit, then the central computing unit is deemed to have failed, and if adjacent normally operating edge control units all detect that the central computing unit is in an inactive state, then the central computing unit is determined to have failed.

[0038] Step S220 detects operational failures of each edge control unit in conjunction with the central computing unit; wherein the operational failures include failures of the central computing unit itself, failures of the edge control unit itself, failures between the central computing unit and the edge control unit, and failures between the edge control units.

[0039] Specifically, the operational failure of each edge control unit can be detected in combination with the normally operating central computing unit. In some embodiments, to ensure the accuracy of the detection, at least two normally operating units are used; such as at least one normally operating edge control unit and a normally operating central computing unit or two normally operating edge control units to efficiently detect operational failures. The operational detection of the vehicle-mounted architecture can determine different failure states in the system, including failure of the central computing unit, failure of the edge control unit, failure of the communication link between the central computing unit and the edge control unit, failure of the communication link between the two edge control units, etc. Then, different measures are taken for the failed state nodes according to the operational detection.

[0040] Combine Figure 1The illustrated vehicle-mounted control system implements an operation detection process, detecting the operation of the central computing unit and edge control unit based on the normal operation of some edge control units or central computing units. The vehicle-mounted operation detection in the overall architecture of the vehicle-mounted control system in the embodiment of this specification implements an efficient and convenient fault detection mode. The existing technology, due to adaptation issues between various vehicle-mounted control devices and the main processor, makes operation detection complex and cumbersome, and cannot achieve the efficient and convenient detection of the embodiment of this specification.

[0041] In some embodiments, the central computing unit is determined to be faulty when each edge control unit detects an operational failure of the central computing unit, including: all normally operating edge control units cannot receive the heartbeat information sent by the central computing unit, and adjacent normally operating edge control units detect that the central computing unit is in an inactive state; wherein the heartbeat information includes the identifier of the edge control unit, the identifier of the central computing unit, and a cycle count signal indicating the active state. In this embodiment, the use of heartbeat signals to implement fault detection occupies very little communication bandwidth.

[0042] Specifically, if all normally operating edge control units in the system cannot receive the heartbeat signal sent by the central computing unit, and the adjacent normally operating edge control units also detect that the central computing unit is in an inactive state, then the central computing unit is determined to be failed. A normally operating edge control unit is represented by the edge control unit, the central computing unit, and the edge control units adjacent to it being in a normal operating state. The heartbeat signal includes the identification of each unit of the vehicle control system itself and a cyclically accumulated count value. The cyclically accumulated count value is used to represent the activity state, such as the cyclically accumulated count value in each heartbeat signal in the active state is accumulated by 1. The activity state includes the activity state determined between the central computing unit and the edge control unit, and the activity state determined between adjacent edge control units.

[0043] In some embodiments, the central computing unit and the edge control unit both determine whether the sender node of the heartbeat message is in an active state by verifying that the identification ID matches and the cycle count value changes. In other embodiments, one edge control unit and another edge control unit both determine whether the sender node of the heartbeat message is in an active state by verifying that the identification ID matches and the cycle count value changes. In some embodiments, whether it is the central computing unit and the edge control unit, or the two edge control units, based on the sent heartbeat signal, it is determined that the sending node is in an inactive state at the current moment. If the start time delay judgment or the cycle value therein does not change, it is determined that the relevant node is in an inactive state. In some embodiments, the inactive state is finally determined to be when the start time exceeds a certain time threshold or the cycle count value exceeds a preset threshold.

[0044] Combine Figure 1 If edge control units B, C, and D are unable to receive heartbeat information from central computing unit A, and both edge control units C and D, which are adjacent to edge control unit B, detect that central computing unit A is inactive, the central computing unit is deemed to have failed, and the overall system is uncontrollable. In some embodiments, when a central computing unit fails, the edge control units can transmit information according to a predefined emergency plan.

[0045] When the central computing unit is operating normally, the central computing unit is combined to detect whether each edge control unit is operating normally, including:

[0046] The central computing unit detects the heartbeat signal of a first edge control unit operating normally, the first edge control unit detects that a second edge control unit adjacent to it is in an inactive state, and the central computing unit detects that the second edge control unit is in an active state, then determines that the communication link between the first edge control unit and the second edge control unit has failed; or, the central computing unit detects that a first edge control unit operating normally, the first edge control unit detects that a second edge control unit adjacent to it is in an inactive state, and the central computing unit cannot detect the heartbeat signal of the second edge control unit, then determines that the second edge control unit has failed.

[0047] Specific reference Figure 3 , when the central computing unit A receives the heartbeat signals of the edge control unit B and the edge control unit C respectively, the central computing unit A detects the heartbeat signal of the edge control unit B, indicating that the edge control unit B is in an active state, and the central computing unit A detects the heartbeat signal of the edge control unit C, indicating that the edge control unit C is in an active state, but the edge control unit B receives the heartbeat signal of the edge control unit C, indicating that the edge control unit C is in an inactive state. Among them, the edge control unit B and the edge control unit C are adjacent edge control nodes, and it is determined that the communication link between the edge control unit B and the edge control unit C has failed. At this time, the control of the central computing unit and each edge control unit is basically unaffected, and the full function operation of the overall system can still be achieved. The user can be warned by a visual reminder of the failure of the communication link between the edge control unit C and the edge control unit B.

[0048] Alternatively, when central computing unit A receives heartbeat signals from edge control unit B and edge control unit C, central computing unit A detects the heartbeat signal from edge control unit B, indicating that edge control unit B is active; central computing unit A detects the heartbeat signal from edge control unit C, indicating that edge control unit C is inactive; and edge control unit B receives the heartbeat signal from edge control unit C, indicating that edge control unit C is also inactive. If edge control unit B and edge control unit C are adjacent edge control nodes, edge control unit C is determined to be faulty.

[0049] In some embodiments, the vehicle operation detection method further includes: determining at least two adjacent edge control units that are operating normally; correspondingly, detecting an operation failure of each edge control unit in conjunction with the central computing unit includes:

[0050] If the central computing unit cannot detect the heartbeat signal of the first edge control unit, and the second edge control unit and the third edge control unit adjacent to the first edge control unit can both detect that the first edge control unit is in an inactive state and the central computing unit is in an active state, then the first edge control unit is determined to be failed; or, if the central computing unit cannot detect the heartbeat signal of the first edge control unit, and the second edge control unit and the third edge control unit adjacent to the first edge control unit detect that the first edge control unit is in an active state and the central computing unit is in an active state, then the communication between the central computing unit and the first edge control unit is determined to be failed.

[0051] like Figure 1 As shown, when central computing unit A cannot receive the heartbeat signal from edge control unit B, but edge control unit C, which is adjacent to edge control unit B, can receive the heartbeat signal from edge control unit B, and this heartbeat signal indicates that edge control unit B is active. Edge control unit D, which is adjacent to edge control unit B, can also receive the heartbeat signal from edge control unit B, indicating that edge control unit B is active. Edge control units C and D also indicate that central computing unit A is active. Then, it is determined that the communication link between central computing unit A and edge control unit B is interrupted. At this time, central computing unit A should send a routing message to edge control units C and D, the adjacent nodes of edge control unit B, which will route and forward the message to edge control unit B. The routing message can enable edge control unit B to maintain the minimum safety function operation state.

[0052] Alternatively, when the central computing unit A cannot receive the heartbeat information of the edge control unit B, and the edge control unit C and edge control unit D adjacent to the edge control unit B also indicate that the edge control unit B is in an inactive state, but the central computing unit A is in an active state, it indicates that the edge control unit B has failed.

[0053] The central computing unit of the embodiments of this specification can integrate hardware devices of different design sources and models, integrating a large number of control units on the vehicle to form a reliable and safe operating brain for the entire vehicle. Through redundancy and a comprehensive topological architecture, mutual monitoring between nodes can be achieved, thereby efficiently and accurately detecting faults in the overall system. There is no need to add dedicated monitoring hardware during the operation of the overall system. Even if a fault occurs in the overall system, it will not affect the normal operation of other functions, and other normal functions can still be implemented.

[0054] In some embodiments, if the communication connection between an edge control unit and a central computing unit fails, the edge control unit operates at a preset safety power according to the routing message system.

[0055] Specifically, when a communication connection failure is detected between an edge control unit and the central computing unit, the failed edge control unit is controlled with minimum security functions, and its adjacent nodes forward messages to the central computing unit through routing, thereby ensuring indirect communication between the edge control unit and the central computing unit.

[0056] In some embodiments, a fault level is determined according to the operational fault so that the central computing unit or the edge control unit can take corresponding measures.

[0057] In some embodiments, if the central computing unit fails, it is determined to be the highest failure level;

[0058] Alternatively, if one of the edge control units fails, or if a communication failure occurs between the central computing unit and the edge control unit, then the fault is determined to be the second fault level; or if a communication failure occurs between the edge control unit and its adjacent edge control units, then the fault is determined to be the first fault level. In some embodiments, a higher fault level indicates a more severe fault, while in other embodiments, the opposite may be true, with a higher fault level indicating a less severe fault.

[0059] Specifically, if the central computing unit fails, it is determined to be the highest fault level, that is, the core control of the vehicle control system fails and many important functions cannot be realized. Because if the central computing unit fails, it is determined that the vehicle control system is at the highest fault level, and countermeasures should be adopted in time.

[0060] If an edge control unit fails, the entire control system loses some functions, but does not affect other normal functions. Therefore, this failure is less controllable than a central computing unit failure, and the failure of an edge control unit is determined to be the second fault level. In addition, if a link failure occurs in the communication between the central computing unit and the edge control unit, the control of the central computing unit and each edge computing unit is basically unaffected, and the system can still be in a fully functional operating state, so the fault level is determined to be the second fault level. In some embodiments, if a communication failure occurs between an edge control unit and its adjacent edge control unit, it only has a slight impact on the redundancy design, so it is determined to be the first fault level.

[0061] The vehicle-mounted control system of this embodiment can determine the fault level according to the operating fault of each operating unit, so as to flexibly take countermeasures to ensure the normal operation of the entire vehicle-mounted control system.

[0062] Figure 4 This is a structural diagram of a vehicle-mounted operation detection system provided in an embodiment of this specification. Figure 4 As shown, the system 40 includes: a processor 41, a memory 42 and a computer program; wherein the memory 42 is used to store the computer program, which can also be a flash memory. The computer program is, for example, an application program, a functional module, etc. that implements the above method.

[0063] The processor 41 is configured to execute the computer program stored in the memory to implement the various steps performed by the device in the above method. For details, please refer to the relevant description in the above method embodiment.

[0064] Optionally, the memory 42 may be independent or integrated with the processor 41 .

[0065] When the memory 42 is a device independent of the processor 41, the device may further include:

[0066] The bus 43 is used to connect the memory 42 and the processor 41 .

[0067] The present invention also provides a readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, it is used to implement the methods provided in the various embodiments described above.

[0068] Among them, the readable storage medium can be a computer storage medium or a communication medium. Communication media include any medium that facilitates the transmission of computer programs from one place to another. Computer storage media can be any available medium that can be accessed by a general-purpose or special-purpose computer. For example, a readable storage medium is coupled to a processor so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be an integral part of the processor. The processor and the readable storage medium can be located in an application-specific integrated circuit (ASIC). In addition, the ASIC can be located in a user device. Of course, the processor and the readable storage medium can also exist in a communication device as discrete components. The readable storage medium can be a read-only memory (ROM), a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, and an optical data storage device, etc.

[0069] The present invention also provides a program product, which includes execution instructions stored in a readable storage medium. At least one processor of a device can read the execution instructions from the readable storage medium, and at least one processor executes the execution instructions so that the device implements the methods provided in the various embodiments described above.

[0070] In the embodiments of the above-mentioned devices, it should be understood that the processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), etc. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the method disclosed in the present invention may be directly implemented by a hardware processor or implemented by a combination of hardware and software modules in the processor.

[0071] In this specification, references to the same or similar parts between the various embodiments can be made to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the product embodiments described later, since they correspond to the methods, the description is relatively simple, and the relevant parts can be referred to the partial description of the system embodiment.

[0072] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. A vehicle-mounted control system, characterized in that: The vehicle-mounted control system includes: In the vehicle architecture, multiple edge control units are connected to a central computing unit (CCU) via communication links, enabling information transmission between them. A CCU is the control core of the vehicle architecture, while the edge control units serve as the sensing and execution units within the vehicle architecture. A CCU integrates hardware devices of different design sources and models, integrating the vehicle's control units to form the operating brain of the entire vehicle. Each of the edge control units corresponds to a different vehicle-mounted control device; The central computing unit and the edge control unit perform mutual operation detection. The central computing unit and the edge control unit are further configured to perform operation detection with other edge control units, respectively, to determine an operation fault in the vehicle control system and obtain a failure state in the system. The failure state includes failure of the central computing unit, failure of the edge control unit, failure of the communication link between the central computing unit and the edge control unit, and failure of the communication link between two edge control units corresponding to one central computing unit. Among them, the central computing unit and the edge control unit both determine whether the sender node of the heartbeat message is in an active state by verifying that the identification ID matches and the cycle count value changes; one edge control unit and the other edge control unit both determine whether the sender node of the heartbeat message is in an active state by verifying that the identification ID matches and the cycle count value changes; Among them, whether it is the central computing unit and the edge control unit, or the two edge control units, based on the sent heartbeat signal, it is determined that the sending node is in an inactive state at the current moment. If the start time delay judgment or the cycle value does not change, the relevant node is determined to be in an inactive state; the inactive state is finally determined to be when the start time exceeds a certain time threshold or the cycle count value exceeds a preset threshold. Wherein, the central computing unit detects a heartbeat signal of a first edge control unit that is operating normally, the first edge control unit detects that a second edge control unit adjacent to it is in an inactive state, and the central computing unit cannot detect the heartbeat signal of the second edge control unit, then determines that the second edge control unit has failed; Alternatively, the central computing unit cannot detect the heartbeat signal of the first edge control unit, and the second edge control unit and the third edge control unit adjacent to the first edge control unit detect that the first edge control unit is active and the central computing unit is active, then it is determined that the communication between the central computing unit and the first edge control unit has failed.

2. A vehicle-mounted operation detection method, characterized in that: The vehicle-mounted operation detection method adopts the vehicle-mounted control system according to claim 1, and the vehicle-mounted operation detection method includes: detecting an operational failure of the one central computing unit according to each edge control unit; and / or, detecting operational failures of the respective edge control units in conjunction with the central computing unit; wherein the two edge control units belong to the one central computing unit; Among them, the central computing unit and the edge control unit both determine whether the sender node of the heartbeat message is in an active state by verifying that the identification ID matches and the cycle count value changes; one edge control unit and the other edge control unit both determine whether the sender node of the heartbeat message is in an active state by verifying that the identification ID matches and the cycle count value changes; Among them, whether it is the central computing unit and the edge control unit, or the two edge control units, based on the sent heartbeat signal, it is determined that the sending node is in an inactive state at the current moment. If the start time delay judgment or the cycle value does not change, the relevant node is determined to be in an inactive state; the inactive state is finally determined to be when the start time exceeds a certain time threshold or the cycle count value exceeds a preset threshold. Wherein, the central computing unit detects a first edge control unit operating normally, the first edge control unit detects that a second edge control unit adjacent to it is in an inactive state, and the central computing unit cannot detect a heartbeat signal of the second edge control unit, then determines that the second edge control unit has failed; Alternatively, the central computing unit cannot detect the heartbeat signal of the first edge control unit, and the second edge control unit and the third edge control unit adjacent to the first edge control unit detect that the first edge control unit is active and the central computing unit is active, then it is determined that the communication between the central computing unit and the first edge control unit has failed.

3. The vehicle-mounted operation detection method according to claim 2, characterized in that: Detecting an operational failure of the central computing unit according to each edge control unit includes: If all normally operating edge control units cannot receive the heartbeat signal sent by the central computing unit, and adjacent normally operating edge control units detect that the central computing unit is in an inactive state, then the central computing unit is determined to be failed; the heartbeat signal includes the edge control unit identifier, the central computing unit identifier and a cycle count signal indicating the active state.

4. The vehicle-mounted operation detection method according to claim 2, characterized in that: The detecting the operation failure of each edge control unit in combination with the central computing unit includes: The central computing unit detects a heartbeat signal of a first edge control unit operating normally, the first edge control unit detects that a second edge control unit adjacent to it is in an inactive state, and the central computing unit detects that the second edge control unit is in an active state, then determines that the communication link between the first edge control unit and the second edge control unit has failed.

5. The vehicle-mounted operation detection method according to claim 2, characterized in that: The vehicle-mounted operation detection method further includes: determining at least two adjacent edge control units that are operating normally; Correspondingly, the detecting of an operational failure of each edge control unit in combination with the central computing unit includes: If the central computing unit cannot detect the heartbeat signal of the first edge control unit, and the second edge control unit and the third edge control unit adjacent to the first edge control unit both detect that the first edge control unit is in an inactive state and the central computing unit is in an active state, it is determined that the first edge control unit has failed.

6. The vehicle-mounted operation detection method according to claim 4 or 5, characterized in that: The vehicle-mounted operation detection method further includes: If the communication connection between the fourth edge control unit and the central computing unit fails, the fourth edge control unit operates at a preset safety power according to the routing message system.

7. The vehicle-mounted operation detection method according to claim 2, characterized in that: The vehicle-mounted operation detection method further includes: Based on the operational fault, a fault level is determined so that the central processing unit or the edge control unit can take countermeasures.

8. The vehicle-mounted operation detection method according to claim 7, characterized in that: The vehicle-mounted operation detection method further includes: If the central computing unit fails, it is determined to be the highest fault level; Alternatively, if one of the edge control units fails, or if a communication failure occurs between the central computing unit and the edge control unit, it is determined to be a second fault level; Alternatively, if a communication failure occurs between the edge control unit and its adjacent edge control units, it is determined to be a first failure level.

9. A vehicle-mounted control system, characterized in that: include: A memory, a processor, and a computer program, wherein the computer program is stored in the memory, and the processor runs the computer program to execute the vehicle-mounted operation detection method according to any one of claims 2 to 8.

10. A readable storage medium, characterized in that: The readable storage medium stores a computer program, which, when executed by a processor, is used to implement the vehicle-mounted operation detection method according to any one of claims 2 to 8.

Citation Information

Patent Citations

  • Method for detecting communication state of cluster system and gateway cluster

    CN106452952A

  • Edge computing fault or security threat monitoring system and method based on multi-point cooperation

    CN112688822A

  • Whole vehicle signal routing method and system based on central gateway centralized architecture

    CN114244653A