Redundancy control method, device, apparatus, system and autonomous vehicle

CN115743154BActive Publication Date: 2026-09-11BEIJING BAIDU NETCOM SCI & TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211433335.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-16
Publication Date
2026-09-11
Estimated Expiration
2042-11-16

AI Technical Summary

Benefits of technology

[0011] According to one aspect of this disclosure, a redundant control system is provided, comprising: a first controller; and a second controller communicatively connected to the first controller, wherein either the first controller or the second controller is configured to perform the aforementioned redundant control method.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115743154B_ABST
    Figure CN115743154B_ABST
Patent Text Reader

Abstract

The present disclosure provides a redundancy control method, device, electronic equipment, medium and system and an autonomous vehicle, relates to the technical field of computers, in particular to the field of autonomous driving, vehicle-mounted systems and domain controllers. The implementation scheme is: obtaining a current state of a first controller; in response to the current state being a first state: obtaining a state monitoring result of a second controller; based on the state monitoring result, determining a first target state of the first controller and performing state switching; in response to the current state being a second state, determining a second target state of the first controller based on a first event for the first controller and performing state switching.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of computer technology, and more particularly to the fields of autonomous driving, vehicle systems and domain controllers, specifically to a redundancy control method, apparatus, electronic device, computer-readable storage medium, computer program product and system. Background Technology

[0002] A redundant system is a system in which some important components are duplicated to improve the system's security and reliability. This involves connecting two identical and relatively independent sets of components. When a component in the system fails, the redundant component can take over the work of the failed component.

[0003] With the increasing demand for automotive safety, more and more automotive electronic components are adopting redundant control systems that include dual electronic control units (ECUs) to cope with the interference caused by harsh environments and various factors to the automotive control system.

[0004] The methods described in this section are not necessarily methods that had been previously conceived or adopted. Unless otherwise specified, no method described in this section should be assumed to be prior art simply because it is included in this section. Similarly, unless otherwise specified, the issues mentioned in this section should not be considered to be accepted in any prior art. Summary of the Invention

[0005] This disclosure provides a redundancy control method, apparatus, electronic device, computer-readable storage medium, computer program product, and system.

[0006] According to one aspect of this disclosure, a redundancy control method is provided, applied to a first controller in a redundant control system, the redundant control system including the first controller and a second controller, the method comprising: acquiring a current state of the first controller; in response to the current state being a first state: acquiring a state monitoring result of the second controller, wherein the state monitoring result indicates whether the second controller has entered the first state; based on the state monitoring result, determining a first target state of the first controller and performing a state switch, wherein the first target state is the same as the next state of the second controller after entering the first state; and in response to the current state being a second state, determining a second target state of the first controller based on a first event for the first controller and performing a state switch.

[0007] According to one aspect of this disclosure, a redundancy control device is provided, applied to a first controller in a redundant control system, the redundant control system including the first controller and a second controller. The device includes: an acquisition module configured to acquire the current state of the first controller; a first response module including: an acquisition unit configured to acquire a state monitoring result of the second controller in response to the current state being a first state, wherein the state monitoring result indicates whether the second controller has entered the first state; a determination unit configured to determine a first target state of the first controller based on the state monitoring result and perform a state switch, wherein the first target state is the same as the next state of the second controller after entering the first state; and a second response module configured to determine a second target state of the first controller and perform a state switch in response to the current state being a second state, based on a first event for the first controller.

[0008] According to one aspect of this disclosure, an electronic device is provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform the redundancy control method described above.

[0009] According to one aspect of this disclosure, a non-transitory computer-readable storage medium is provided storing computer instructions, wherein the computer instructions are used to cause a computer to perform the above-described redundancy control method.

[0010] According to one aspect of this disclosure, a computer program product is provided, comprising a computer program, wherein the computer program, when executed by a processor, implements the above-described redundancy control method.

[0011] According to one aspect of this disclosure, a redundant control system is provided, comprising: a first controller; and a second controller communicatively connected to the first controller, wherein either the first controller or the second controller is configured to perform the aforementioned redundant control method.

[0012] According to one aspect of this disclosure, an autonomous vehicle is provided, including the aforementioned electronic devices.

[0013] According to one or more embodiments of this disclosure, the reliability of redundant control systems can be improved.

[0014] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description

[0015] The accompanying drawings exemplify embodiments and form part of the specification, serving together with the textual description to explain exemplary implementations of the embodiments. The illustrated embodiments are for illustrative purposes only and do not limit the scope of the claims. Throughout the drawings, the same reference numerals refer to similar but not necessarily identical elements.

[0016] Figure 1 A schematic diagram of an exemplary system in which the various methods described herein may be implemented according to embodiments of the present disclosure is shown;

[0017] Figure 2 A flowchart of a redundancy control method according to an embodiment of the present disclosure is shown;

[0018] Figure 3 A state transition diagram of a first controller according to some embodiments of the present disclosure is shown;

[0019] Figure 4 A structural block diagram of a redundancy control device according to an embodiment of the present disclosure is shown;

[0020] Figure 5 A schematic diagram of the structure of a redundant control system according to an embodiment of the present disclosure is shown;

[0021] Figure 6 A connection diagram of a first controller and a second controller according to some embodiments of the present disclosure is shown; and

[0022] Figure 7 A structural block diagram of an exemplary electronic device that can be used to implement embodiments of the present disclosure is shown. Detailed Implementation

[0023] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.

[0024] In this disclosure, unless otherwise stated, the use of terms such as "first," "second," etc., to describe various elements is not intended to limit the positional, temporal, or importance relationships of these elements; such terms are merely used to distinguish one element from another. In some examples, the first element and the second element may refer to the same instance of that element, while in other cases, based on the context, they may refer to different instances.

[0025] The terminology used in the description of the various examples described in this disclosure is for the purpose of describing particular examples only and is not intended to be limiting. Unless the context explicitly indicates otherwise, an element may be one or more unless the number of elements is specifically limited. Furthermore, the term "and / or" as used in this disclosure covers any one of the listed items and all possible combinations thereof.

[0026] As one of the core electronic components of modern automobiles, the ECU is known as the "vehicle computer." The ECU can monitor various operating states of the vehicle (such as parking, acceleration, etc.) and various input data (such as braking, shifting, etc.) at any time, and process various information according to a pre-designed program, sending the processed parameters to relevant actuators to execute various predetermined control functions.

[0027] To meet safety requirements, redundant ECUs can be installed in vehicles, forming a redundant control system with two ECUs. One ECU in the redundant control system can be the primary ECU, and the other serves as a backup, i.e., a standby ECU. Compared to a control system with only a single ECU, a redundant control system can further ensure vehicle safety, but it increases the complexity of the control system. Therefore, ensuring the reliability of the redundant control system becomes a pressing issue.

[0028] To address the aforementioned problems, this disclosure provides a redundancy control method for a redundant control system. This method enables the primary controller and the backup controller to synchronize their states in a timely manner while maintaining relatively independent operating states, thereby improving the reliability and security of the entire system and ensuring its stable operation.

[0029] The embodiments of this disclosure will now be described in detail with reference to the accompanying drawings.

[0030] Figure 1 A schematic diagram of an exemplary system 100 in which the various methods and apparatus described herein can be implemented according to embodiments of this disclosure is shown. Reference Figure 1 The system 100 includes a motor vehicle 110, a server 120, and one or more communication networks 130 that couple the motor vehicle 110 to the server 120.

[0031] In embodiments of this disclosure, the motor vehicle 110 may include a redundant control system according to embodiments of this disclosure.

[0032] Server 120 may run one or more services or software applications. In some embodiments, server 120 may also provide other services or software applications, which may include non-virtual environments and virtual environments. Figure 1In the configuration shown, server 120 may include one or more components that implement the functions performed by server 120. These components may include software components, hardware components, or combinations thereof that can be executed by one or more processors. A user of motor vehicle 110 may sequentially interact with server 120 using one or more client applications to utilize the services provided by these components. It should be understood that various different system configurations are possible and may differ from system 100. Therefore, Figure 1 This is an example of a system used to implement the various methods described herein, and is not intended to be limiting.

[0033] Server 120 may include one or more general-purpose computers, special-purpose server computers (e.g., PC (personal computer) servers, UNIX servers, mid-range servers), blade servers, mainframe computers, server clusters, or any other suitable arrangement and / or combination. Server 120 may include one or more virtual machines running a virtual operating system, or other computing architectures involving virtualization (e.g., one or more flexible pools of logical storage devices that can be virtualized to maintain virtual storage devices for servers). In various embodiments, server 120 may run one or more services or software applications.

[0034] The computing unit in server 120 can run one or more operating systems, including any of the aforementioned operating systems and any commercially available server operating system. Server 120 can also run any of a variety of additional server applications and / or middleware applications, including HTTP servers, FTP servers, CGI servers, JAVA servers, database servers, etc.

[0035] In some implementations, server 120 may include one or more applications to analyze and merge data feeds and / or event updates received from vehicle 110. Server 120 may also include one or more applications to display data feeds and / or real-time events via one or more display devices of vehicle 110.

[0036] Network 130 can be any type of network well known to those skilled in the art, and can support data communication using any of a variety of available protocols (including, but not limited to, TCP / IP, SNA, IPX, etc.). By way of example only, one or more networks 130 can be satellite communication networks, local area networks (LANs), Ethernet-based networks, token ring networks, wide area networks (WANs), the Internet, virtual networks, virtual private networks (VPNs), intranets, extranets, blockchain networks, public switched telephone networks (PSTNs), infrared networks, wireless networks (including, for example, Bluetooth, Wi-Fi), and / or any combination of these with other networks.

[0037] System 100 may also include one or more databases 150. In some embodiments, these databases may be used to store data and other information. For example, one or more of the databases 150 may be used to store information such as audio files and video files. The data repository 150 may be applied in various locations. For example, a data repository used by server 120 may be local to server 120, or it may be located away from server 120 and may communicate with server 120 via a network-based or dedicated connection. The data repository 150 may be of different types. In some embodiments, the data repository used by server 120 may be a database, such as a relational database. One or more of these databases may store, update, and retrieve data from and from the database in response to commands.

[0038] In some embodiments, one or more of the databases 150 may also be used by an application to store application data. The databases used by the application may be of different types, such as key-value stores, object stores, or regular stores supported by a file system.

[0039] Motor vehicle 110 may include sensors 111 for sensing the surrounding environment. Sensors 111 may include one or more of the following sensors: a visual camera, an infrared camera, an ultrasonic sensor, a millimeter-wave radar, and a lidar (LiDAR). Different sensors can provide different detection accuracy and range. Cameras may be mounted in front of, behind, or at other locations on the vehicle. Visual cameras can capture the situation inside and outside the vehicle in real time and present it to the driver and / or passengers. In addition, by analyzing the images captured by the visual cameras, information such as traffic light indications, intersection conditions, and the operating status of other vehicles can be obtained. Infrared cameras can capture objects in night vision conditions. Ultrasonic sensors may be mounted around the vehicle to measure the distance of objects outside the vehicle using the strong directionality of ultrasound. Millimeter-wave radar may be mounted in front of, behind, or at other locations on the vehicle to measure the distance of objects outside the vehicle using the characteristics of electromagnetic waves. LiDAR may be mounted in front of, behind, or at other locations on the vehicle to detect the edges and shape information of objects, thereby performing object recognition and tracking. Due to the Doppler effect, the radar device can also measure the speed changes of the vehicle and moving objects.

[0040] The motor vehicle 110 may also include a communication device 112. The communication device 112 may include a satellite positioning module capable of receiving satellite positioning signals (e.g., BeiDou, GPS, GLONASS, and GALILEO) from satellite 141 and generating coordinates based on these signals. The communication device 112 may also include a module for communicating with a mobile communication base station 142. The mobile communication network can implement any suitable communication technology, such as current or emerging wireless communication technologies (e.g., 5G technology) like GSM / GPRS, CDMA, and LTE. The communication device 112 may also have a vehicle-to-everything (V2X) module, configured to enable vehicle-to-the-world communication, for example, vehicle-to-vehicle (V2V) communication with other vehicles 143 and vehicle-to-infrastructure (V2I) communication with infrastructure 144. Furthermore, the communication device 112 may also have a module configured to communicate with a user terminal 145 (including but not limited to smartphones, tablets, or wearable devices such as watches) via, for example, a wireless local area network conforming to the IEEE 802.11 standard or Bluetooth. Using the communication device 112, the motor vehicle 110 can also access the server 120 via the network 130.

[0041] The motor vehicle 110 may also include a control device 113. The control device 113 may include a processor, such as a central processing unit (CPU) or a graphics processing unit (GPU), or other dedicated processors, that communicates with various types of computer-readable storage devices or media. The control device 113 may include an autonomous driving system for automatically controlling various actuators in the vehicle. The autonomous driving system is configured to control the powertrain, steering system, and braking system of the motor vehicle 110 (not shown) via multiple actuators in response to inputs from multiple sensors 111 or other input devices to control acceleration, steering, and braking respectively, without human intervention or with limited human intervention. Some processing functions of the control device 113 can be implemented via cloud computing. For example, some processing can be performed using an onboard processor while other processing can be performed using cloud computing resources. The control device 113 may be configured to perform various embodiments of the control methods based on this disclosure. Furthermore, the control device 113 may be implemented as an example of a computing device on the motor vehicle side (client) according to this disclosure.

[0042] Figure 1 The system 100 can be configured and operated in various ways to enable the application of the various methods and apparatus described in this disclosure.

[0043] According to some embodiments, the motor vehicle 110 can be divided into multiple control domains, such as a powertrain domain, chassis domain, body domain, cockpit domain, and autonomous driving domain based on function. Each control domain may include one or more control devices 113. According to some embodiments, the control devices 113 in each control domain can be implemented as a redundant control system including two or more controllers (e.g., ECUs). Any controller in the redundant control system can execute the redundant control method of the embodiments of this disclosure, enabling it to synchronize its state with another controller while maintaining relatively independent operation, thereby improving the reliability of the entire system.

[0044] Figure 2 A flowchart of a redundancy control method 200 according to an embodiment of this disclosure is shown. The execution entity for each step of method 200 may be a first controller. The first controller may be any controller in the redundancy control system.

[0045] The redundant control system based on embodiments of this disclosure includes a first controller and a second controller, which are mutually primary and backup controllers; that is, when the first controller is the primary controller, the second controller is the backup controller, and vice versa. Therefore, the executing entity (first controller) of method 200 can be either the primary controller or the backup controller in the redundant control system.

[0046] like Figure 2 As shown, method 200 includes steps S210-S230.

[0047] In step S210, the current state of the first controller is obtained.

[0048] In response to the current state being the first state, steps S221 and S222 are executed.

[0049] In step S221, the status monitoring result of the second controller is obtained. The status monitoring result indicates whether the second controller has entered the first state.

[0050] In step S222, based on the state monitoring results, the first target state of the first controller is determined and a state switch is performed. The first target state is the same as the next state of the second controller after entering the first state.

[0051] In response to the current state being the second state, step S230 is executed.

[0052] In step S230, based on the first event for the first controller, the second target state of the first controller is determined and the state is switched.

[0053] According to embodiments of this disclosure, when the first controller is in a first state, its next operating state is determined based on the state monitoring results of the second controller, so as to synchronize the states of the first controller and the second controller; when the first controller is in a second state, it performs a state switch based on its own events, and this switching process is independent of the state switching process of the second controller. This redundant control method enables the first controller and the second controller to synchronize their states in a timely manner while maintaining independent operation, thereby improving the reliability of the entire system and ensuring that the system always operates smoothly.

[0054] The following details each step of method 200.

[0055] In step S210, the current state of the first controller is obtained.

[0056] According to some embodiments, the current state of the first controller can be either a first state or a second state. The first state refers to a state that requires state synchronization with the second controller. The second state refers to a state in which the first controller can operate independently without requiring state synchronization with the second controller.

[0057] When the first controller is in the first state, it needs to determine its next state (i.e., the first target state) based on the current state of the second controller, so that the first controller and the second controller can achieve state synchronization in the first target state, that is, the first target state is the same as the next state of the second controller after entering the first state.

[0058] When the first controller is in the first state, steps S221 and S222 are executed.

[0059] In step S221, the state monitoring result of the second controller is obtained. The state monitoring result indicates whether the second controller has entered the first state. In step S222, based on the state monitoring result, the first target state of the first controller is determined and a state switch is performed. That is, the state of the first controller is switched from the first state to the first target state. The first target state is the same as the next state of the second controller after entering the first state. Thus, the first controller and the second controller can achieve state synchronization under the first target state.

[0060] According to some embodiments, the redundant control system is powered by a power supply system, and the first state can be entered in response to a second event affecting the power supply system. According to this embodiment, the first and second controllers in the redundant control system are powered by the same power supply system, which improves system integration and facilitates maintenance and replacement of system components. In the first state triggered by the second event affecting the power supply system, synchronizing the states of the first and second controllers allows for synchronization of their power conditions, reducing system control complexity and improving system stability.

[0061] According to some embodiments, the second event may include a power-on event and a power-off event.

[0062] According to some embodiments, when the second event is a power-on event, the first state can be an initialization synchronization state entered after successful initialization in response to the power-on event, i.e., the first state is the initialization synchronization state. Accordingly, determining the first target state of the first controller and switching the state based on the state monitoring results includes: in response to detecting that the second controller has entered the initialization synchronization state within a first time after the first controller enters the initialization synchronization state, determining the first target state as the normal working state and switching the state, so that the first controller and the second controller synchronously enter the normal working state.

[0063] According to the above embodiment, in response to a power-on event, the redundant control system is powered on. After being powered on, the first controller enters an initialization state to perform initialization (including hardware self-test, software initialization, etc.). After successful initialization, the first controller enters an initialization synchronization state, i.e., the first state. In the initialization synchronization state, the first controller determines its next state (i.e., the first target state) by monitoring the state of the second controller and the time when the second controller enters the initialization synchronization state. The first time is calculated from the moment the first controller enters the initialization synchronization state. If the second controller also enters the initialization synchronization state within the first time, the initialization synchronization is successful, and both the first and second controllers simultaneously jump to the normal operating state, providing complete functionality to the system. For example, the first time can be set to 30 seconds. If the second controller also enters the initialization synchronization state within 30 seconds after the first controller enters the initialization synchronization state, the initialization synchronization is successful, and both enter the normal operating state simultaneously.

[0064] According to some embodiments, when the second event is a power-on event, determining the first target state of the first controller and switching the state based on the state monitoring results may further include: in response to the failure to detect the second controller entering the initialization synchronization state within a first time after the first controller enters the initialization synchronization state, determining the first target state as a degraded operating state and switching the state. That is, if the second controller does not enter the initialization synchronization state within the first time, the initialization synchronization of the first controller and the second controller fails, and the first controller automatically switches to the degraded operating state to provide degrade functionality to ensure the safe operation of the system. For example, the first time can be set to 30 seconds. If the second controller does not enter the initialization synchronization state within 30 seconds after the first controller enters the initialization synchronization state, the initialization synchronization fails, and the first controller enters the degraded operating state.

[0065] According to the above embodiment, the controller that enters the initialization synchronization state first will monitor the state of the other controller in this state and determine the next transition state based on the time when the other controller enters the initialization synchronization state. This setting is to prevent the control system from being unable to provide control functions if either controller fails and the state transition cannot be achieved, or if the other controller waits too long in the initialization synchronization state. By setting a maximum waiting time (i.e., the first time), in the event of a controller failure, the other controller can enter a degraded working state to provide degraded functionality to the system, ensuring the safe operation of the system.

[0066] According to some embodiments, when the second event is a power outage event, the first state is a pre-power outage synchronization state entered after successfully completing power outage preparation work in response to the power outage event; that is, the first state is a pre-power outage synchronization state. Accordingly, determining the first target state of the first controller and switching the state based on the state monitoring results includes: in response to detecting that the second controller has entered the pre-power outage synchronization state within a second time after the first controller enters the pre-power outage synchronization state, determining the first target state as a shutdown state and switching the state so that the first controller and the second controller synchronously enter the shutdown state.

[0067] According to the above embodiment, in response to a power outage event, the redundant control system is powered down. After being powered down, the first controller enters a shutdown preparation state to perform power outage preparation work (including memory writing, hardware shutdown, etc.). After successfully completing the power outage preparation work, the first controller enters a pre-power outage synchronization state. In the pre-power outage synchronization state, the first controller determines its next state (i.e., the first target state) by monitoring the state of the second controller and the time when the second controller enters the pre-power outage synchronization state. The second time is calculated from the time the first controller enters the pre-power outage synchronization state. If the second controller also enters the pre-power outage synchronization state within the second time, the pre-power outage synchronization is successful, and both the first and second controllers shut down simultaneously to reduce system power consumption. For example, the second time can be set to 30 seconds. If the second controller also enters the pre-power outage synchronization state within 30 seconds after the first controller enters the pre-power outage synchronization state, the pre-power outage synchronization is successful, and both enter the shutdown state simultaneously.

[0068] According to some embodiments, when the second event is a power outage event, determining the first target state of the first controller and switching the state based on the state monitoring results may further include: in response to the failure to detect the second controller entering the pre-power outage synchronization state within a second time after the first controller enters the pre-power outage synchronization state, determining the first target state as a hibernation state and switching the state. That is, if the second controller does not enter the pre-power outage synchronization state within the second time, the pre-power outage synchronization fails, and the first controller automatically switches to a hibernation state to reduce system power consumption. For example, the second time can be set to 30 seconds. If the second controller does not enter the pre-power outage synchronization state within 30 seconds after the first controller enters the pre-power outage synchronization state, the pre-power outage synchronization fails, and the first controller automatically enters a hibernation state.

[0069] According to the above embodiment, the controller that first enters the pre-power-out synchronization state will monitor the state of the other controller in this state and determine the next transition state based on the time when the other controller enters the pre-power-out synchronization state. This setting is to prevent the system from failing to shut down properly if either controller malfunctions, thus affecting the next normal system startup. By setting a maximum waiting time (i.e., the second time), in the event of a controller failure, the other controller can enter a hibernation state, promptly shutting down the corresponding systems and components, and reducing system energy consumption.

[0070] It should be noted that the first time and the second time in the embodiments of this disclosure can be set as needed, and this disclosure does not limit the values ​​of the two. The first time and the second time can be the same or different.

[0071] According to some embodiments, the second state is an independent operating state of the first controller. When the first controller is in the second state, it can operate independently, switching states based on its own events (i.e., the first event), without needing to synchronize with the state of the second controller. In other words, when the first controller is in the second state, the switching process of the first controller is independent of the state switching process of the second controller. It can be understood that the second state is an independent operating state of the first controller, where the two controllers operate in relatively independent states, improving the system's flexibility.

[0072] In response to the first controller being in the second state, step S230 is executed.

[0073] In step S230, based on the first event for the first controller, the second target state of the first controller is determined and the state is switched.

[0074] According to some embodiments, the second state may include at least one of the following: initialization state, normal operation state, degraded operation state, sleep state, fault state, development state, or shutdown preparation state.

[0075] In the initialization state, the first controller performs initialization after power-on.

[0076] Under normal operating conditions, the first controller can provide full functionality.

[0077] In degraded operating mode, the functions provided by the first controller are limited. Compared to normal operating mode, the first controller provides fewer functions and is less complex in degraded operating mode.

[0078] In sleep mode, only the storage device in the first controller is powered, while other circuits are powered off, which can reduce power consumption and save electricity.

[0079] In a fault condition, the first controller is unable to provide functionality.

[0080] In development mode, developers or testers can configure the hardware or software of the first controller.

[0081] In the shutdown preparation state, the first controller performs pre-shutdown preparation work.

[0082] According to some embodiments, the first event can be a system request sent based on management needs, such as a sleep request, wake-up request, reset request, and mode switching request (e.g., switching between developer mode and user mode). The first event can also be a system fault event of the first controller itself, such as a temporary fault caused by electromagnetic interference or poor contact, or a fault caused by its own sensors or other hardware. The first event can also be the monitored current state of the second controller, and the controller can switch its own state based on the monitored state. The first event and the corresponding switching conditions can be set according to requirements, and are not limited here.

[0083] According to some embodiments, when the second state is an initialization state, determining the second target state of the first controller and switching the state based on a first event for the first controller includes: obtaining the current operating mode of the first controller; and, in response to the current operating mode being a developer mode, determining the second target state as a development state and switching the state. According to this embodiment, a developer mode can be provided for redundant control systems. When in developer mode, the first controller enters a development state to support the product (e.g., ...). Figure 1 The development and testing requirements for the vehicle 110 shown are as follows before delivery. During the development phase, a higher safety level can be enabled as needed to facilitate testing under extreme conditions.

[0084] According to some embodiments, the redundant control system is configured as the vehicle's domain controller system, thereby improving the reliability of the domain controller system and ensuring the safe operation of the vehicle.

[0085] According to some embodiments, either the first controller or the second controller is the master controller in a redundant control system, and the other controller is a backup controller. That is, when the first controller is the master controller, the second controller is the backup controller, and vice versa. A redundant control system may include multiple master controllers and corresponding backup controllers, thereby enabling the vehicle to perform a variety of different functions.

[0086] Based on the redundancy control method 200, Figure 3 A state transition diagram of a first controller according to some embodiments of the present disclosure is shown (the state transition diagram of a second controller is the same as that of the first controller). Figure 3 The state transition diagram shown can be understood as the state machine of any controller in a redundant system.

[0087] like Figure 3As shown, the states of the first controller include initialization state (Init) 310, initialization synchronization state (InitSyn) 320, normal operation state (Normal) 330, sleep state (Sleep) 340, power-off preparation state (PreOff) 350, power-off synchronization state (OffSyn) 360, power-off state (Off) 370, fault state (Error) 380, degraded operation state (Limit) 390, and development state (Product) 311.

[0088] In response to the power-on of the redundant control system, the first controller enters the initialization state 310. In the initialization state 310, the first controller performs hardware initialization self-tests and software initialization operations. If initialization is successful, it enters the initialization synchronization state 320; if initialization fails, it switches to the fault state 380. If the system's current operating mode is detected as developer mode, it switches to the development state 311.

[0089] When the first controller is in development state 311, a higher safety level can be enabled according to testing requirements to facilitate testing under extreme conditions. In this state, if a shutdown request is received, it switches to shutdown preparation state 350.

[0090] When the first controller is in initialization synchronization state 320, primary and backup controllers are initialized and synchronized to simultaneously enter normal operating state and provide functionality to the system. Timing begins from when the first controller enters this state. If, within the specified maximum waiting time (corresponding to the first time mentioned above), the second controller is also detected to have entered initialization synchronization state 320, then the system jumps to normal operating state 330 together with the second controller. If, within the specified maximum waiting time, the second controller is not detected to have entered initialization synchronization state 320, the system automatically jumps to degraded operating state 390.

[0091] When the first controller is in normal operating state 330, both the primary and backup controllers are in full-function mode. In this state, if the first controller detects a fault in its own hardware or related components such as sensors, it switches to fault state 380. If it receives a sleep request from the system, it switches to sleep state 340. If it detects that the second controller is in fault state 380, it automatically switches to degraded operating state 390.

[0092] When the first controller is in sleep state 340, it only operates some necessary components (such as memory, hard disk, and other storage devices) to reduce power consumption under specific operating conditions. In this state, if a wake-up request from the system is received, it jumps to normal operating state 330. If a shutdown request from the system is received, it jumps to shutdown preparation state 350 to prepare for shutdown.

[0093] When the first controller is in the power-off preparation state 350, it performs the corresponding memory write operation and hardware shutdown operation. If a system reset request is received in this state, a software reset is performed, and the system jumps to the initialization state 310. If no system reset request is received, the system jumps to the pre-power-off synchronization state 360 ​​after the memory write operation and hardware shutdown operation are completed, preparing to shut down.

[0094] When the first controller is in the pre-power-off synchronization state 360, the primary and backup controllers are synchronized before power-off to achieve simultaneous power-off. Timing begins from the first controller entering this state. Within the specified maximum waiting time (corresponding to the second time mentioned above), if the second controller is also detected to have entered the pre-power-off synchronization state 360, both controllers switch to the shutdown state 370 to complete the shutdown. If the second controller is not detected to have entered the pre-power-off synchronization state 360 ​​within the specified maximum waiting time, it automatically enters sleep mode. At this time, the non-sleep second controller, unable to receive communication information from the sleep-enabled first controller, will also immediately switch to sleep mode, ensuring that both controllers enter the shutdown state 370 synchronously.

[0095] After the first controller enters the shutdown state 370, it needs to wait for the next system power-on.

[0096] The first controller is in fault state 380, indicating that it cannot recover from the fault within the current working cycle (one working cycle is from system power-on to system shutdown). If the first controller receives a system shutdown request in this state, it will jump to the shutdown preparation state and prepare to shut down.

[0097] The first controller enters degraded operating state 390 because the second controller is in a faulty state, there is a communication signal problem, or the controller itself can only provide degraded functionality due to hardware issues such as sensor malfunctions. If the first controller enters degraded operating state 390 due to a temporary fault such as electromagnetic interference or poor contact, it can switch back to normal operating state 330 once the temporary fault is resolved. If the first controller experiences a permanent fault in degraded operating state 390 that cannot be recovered within the current operating cycle, it switches to fault state 380. If the first controller receives a sleep request from the system in this state, it switches to sleep state 340.

[0098] It is understood that, for the purpose of facilitating the understanding of the redundancy control method of the embodiments of this disclosure, the working state and state switching conditions of the redundancy control system described above are merely exemplary, and the specific state settings and switching conditions can be set and changed according to the actual situation.

[0099] According to embodiments of this disclosure, a redundant control device is also provided. Figure 4A structural block diagram of a redundancy control device 400 according to an embodiment of the present disclosure is shown. Figure 4 As shown, the device 400 includes an acquisition module 410, a first response module 420, and a second response module 430, wherein the first response module 420 includes an acquisition unit 421 and a determination unit 422.

[0100] The acquisition module 410 is configured to acquire the current state of the first controller.

[0101] The first response module 420 includes: an acquisition unit 421, configured to acquire the status monitoring result of the second controller in response to the current state being the first state, wherein the status monitoring result indicates whether the second controller has entered the first state; and a determination unit 422, configured to determine the first target state of the first controller and perform a state switch based on the status monitoring result, wherein the first target state is the same as the next state after the second controller enters the first state.

[0102] The second response module 430 is configured to respond to the current state being the second state, and based on the first event for the first controller, determine the second target state of the first controller and perform a state switch.

[0103] According to some embodiments, the redundant control system is powered by a power supply system, and the first state is entered in response to a second event concerning the power supply system.

[0104] According to some embodiments, the second event includes a power-on event, the first state includes an initialization synchronization state entered after successful initialization in response to the power-on event, and the determining unit 421 is further configured to: in response to detecting that the second controller has entered the initialization synchronization state within a first time after the first controller enters the initialization synchronization state, determine the first target state as the normal working state and perform a state switch so that the first controller and the second controller enter the normal working state synchronously.

[0105] According to some embodiments, the determining unit 421 is further configured to: in response to the failure to detect the second controller entering the initialization synchronization state within a first time after the first controller enters the initialization synchronization state, determine the first target state as a degraded working state and perform a state switch.

[0106] According to some embodiments, the second event includes a power outage event, and the first state includes a pre-power outage synchronization state entered after successfully completing the power outage preparation work in response to the power outage event. The determining unit 421 is further configured to: in response to detecting that the second controller enters the pre-power outage synchronization state within a second time after the first controller enters the pre-power outage synchronization state, determine the first target state as the shutdown state and perform a state switch so that the first controller and the second controller enter the shutdown state synchronously.

[0107] According to some embodiments, the determining unit 421 is further configured to: determine the first target state as a sleep state and perform a state switch in response to the second controller not entering the pre-power-off synchronization state within a second time after the first controller enters the pre-power-off synchronization state.

[0108] It should be understood that Figure 4 The various modules or units of the device 400 shown can be connected with Figure 2 The steps in method 200 described correspond to each other. Therefore, the operations, features, and advantages described in method 200 are also applicable to device 400 and its various modules and units. For the sake of brevity, some operations, features, and advantages will not be repeated here.

[0109] Although specific functions have been discussed with reference to specific modules above, it should be noted that the functions of the various modules discussed in this article can be divided into multiple modules, and / or at least some functions of multiple modules can be combined into a single module.

[0110] It should also be understood that the various techniques described herein can be implemented in software, hardware, components, or program modules. The above... Figure 4 The various modules described herein may be implemented in hardware or in hardware in combination with software and / or firmware. For example, these modules may be implemented as computer program code / instructions configured to execute in one or more processors and stored in a computer-readable storage medium. Alternatively, these modules may be implemented as hardware logic / circuit. For example, in some embodiments, one or more modules of 410-430 may be implemented together in a System on Chip (SoC). The SoC may include an integrated circuit chip (which includes a processor (e.g., a Central Processing Unit (CPU), microcontroller, microprocessor, digital signal processor (DSP), etc.), memory, one or more communication interfaces, and / or one or more components of other circuitry) and may optionally execute received program code and / or include embedded firmware to perform functions.

[0111] According to embodiments of the present disclosure, an electronic device is also provided, including: at least one processor; and a memory communicatively connected to the at least one processor, the memory storing instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform the redundancy control method of the embodiments of the present disclosure.

[0112] According to embodiments of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions for causing a computer to execute the redundancy control method of embodiments of the present disclosure is also provided.

[0113] According to embodiments of this disclosure, a computer program product is also provided, including a computer program that, when executed by a processor, implements the redundancy control method of embodiments of this disclosure.

[0114] According to embodiments of this disclosure, a redundant control system is also provided. The redundant control system includes a first controller and a second controller communicatively connected to the first controller. Either the first controller or the second controller is configured to execute the redundant control method of the embodiments of this disclosure.

[0115] According to embodiments of this disclosure, an autonomous driving vehicle is also provided, which includes the aforementioned electronic equipment. It will be understood that the autonomous driving vehicle also includes the aforementioned redundant control system.

[0116] Figure 5 A schematic diagram of a redundant control system according to an embodiment of the present disclosure is shown. Figure 5 As shown, the redundant control system 500 includes: a first controller 510; and a second controller 520 communicatively connected to the first controller 510, wherein either the first controller 510 or the second controller 520 is configured to execute the redundant control method 200 of the embodiments of this disclosure.

[0117] According to some embodiments of this disclosure, the first controller 510 and the second controller 520 are respectively the master controller and the backup controller in the redundant control system 500. That is, when the first controller 510 is the master controller of the redundant control system, the second controller 520 is the backup controller of the redundant control system, and vice versa. The redundant control system is mostly controlled by the master controller for the vehicle (e.g., Figure 1 The main controller (110) provides functions, and when the main controller fails, the backup controller provides the corresponding functions. The main controller and the backup controller have the same or similar structure, but their processing speed and capabilities may differ.

[0118] Figure 6 A schematic diagram illustrating the connection between a first controller and a second controller according to some embodiments of the present disclosure is shown. Figure 6 As shown, the first controller 610 and the second controller 620 communicate via SPI (Serial Peripheral Interface). Based on the communication between the first controller 610 and the second controller 620, either the first controller 610 or the second controller 620 can implement the redundancy control method 200 of this embodiment. Figure 6 In the embodiment shown, the first controller 610 is the main controller in the redundant control system 600, and the second controller 620 is the backup controller.

[0119] The SPI interface is a full-duplex, three-wire synchronous serial peripheral interface, employing a master-slave architecture. Data from the first controller 610 or the second controller 620 is synchronized on the rising or falling edge of the clock, enabling simultaneous data transmission between the two controllers. Figure 6 As shown, CS 611 and CS 621 are chip select signal pins, which can be fixed at a low level, i.e., active low. SCLK 612 and SCLK 622 are clock signal pins, and the data or signals transmitted between the first controller 610 and the second controller 620 are synchronized with the clock signal generated by the first controller 610.

[0120] Data from the first controller 610 is transmitted to the second controller 620 via the MOSI 613 pin and the SDI 623 pin. For example, the first controller 610 can send its own status monitoring results to the second controller 620 via the MOSI 613 pin, and the second controller 620 can receive the status monitoring results sent by the first controller 610 via the SDI 623 pin. Simultaneously, data from the second controller 620 is transmitted to the first controller 610 via the SDO 624 pin and the MISO 614 pin. For example, the second controller 620 can send its own status monitoring results to the first controller 610 via the SDO 624 pin, and the first controller 610 can receive the status monitoring results sent by the second controller 620 via the MISO 614 pin. Based on the status monitoring results of each other, the first controller 610 and the second controller 620 can perform corresponding state synchronization or state switching operations to implement the redundancy control method 200 according to the embodiments of this disclosure.

[0121] In SPI communication, the master and slave controllers can select the clock polarity and clock phase. Based on the selected clock polarity and clock phase (clock polarity can be 1 or 0, and clock phase can be 1 or 0), there are four SPI modes. The data transmitted via SPI is generally related data from the underlying hardware library, such as synchronization data, and can be further configured according to specific needs.

[0122] According to some embodiments of this disclosure, the first controller and the second controller can also communicate via CAN (Controller Area Network). Based on the communication between the first controller 610 and the second controller 620, either the first controller 610 or the second controller 620 can implement the redundancy control method 200 of the embodiments of this disclosure. The communication via the CAN bus can supplement the SPI communication method. SPI communication is mainly used for low-level synchronization, while CAN communication can be used for application-level synchronization. CAN communication sends signals at fixed intervals, and the signals include variable value signals related to the system state. For example, the standby controller can determine the current working state of the main controller by the variable signal values ​​sent by the main controller, and this information is also one of the judgment conditions for the standby controller's own state switching, and vice versa. In this way, the main controller and the standby controller can obtain each other's state in real time, thereby maintaining their own state according to the actual situation.

[0123] It is understood that the communication method between the first controller and the second controller is not limited to the SPI communication method and CAN communication method mentioned above, and will not be elaborated on here.

[0124] refer to Figure 7 The present invention describes a structural block diagram of an electronic device 700 that can serve as a server or client of the present disclosure, which is an example of a hardware device that can be applied to various aspects of the present disclosure. The electronic device is intended to represent various forms of digital electronic computer devices, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0125] like Figure 7 As shown, the electronic device 700 includes a computing unit 701, which can perform various appropriate actions and processes based on a computer program stored in a read-only memory (ROM) 702 or a computer program loaded from a storage unit 708 into a random access memory (RAM) 703. The RAM 703 may also store various programs and data required for the operation of the electronic device 700. The computing unit 701, ROM 702, and RAM 703 are interconnected via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.

[0126] Multiple components in electronic device 700 are connected to I / O interface 705, including: input unit 706, output unit 707, storage unit 708, and communication unit 709. Input unit 706 can be any type of device capable of inputting information to electronic device 700. Input unit 706 can receive input digital or character information and generate key signal input related to user settings and / or function control of electronic device, and may include, but is not limited to, a mouse, keyboard, touch screen, trackpad, trackball, joystick, microphone, and / or remote control. Output unit 707 can be any type of device capable of presenting information, and may include, but is not limited to, a monitor, speaker, video / audio output terminal, vibrator, and / or printer. Storage unit 708 may include, but is not limited to, disk and optical disk. Communication unit 709 allows electronic device 700 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks, and may include, but is not limited to, modems, network cards, infrared communication devices, wireless communication transceivers, and / or chipsets, such as Bluetooth. TM Equipment, 802.11 equipment, Wi-Fi equipment, WiMAX equipment, cellular communication equipment and / or the like.

[0127] The computing unit 701 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 701 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 701 performs the various methods and processes described above, such as method 200. For example, in some embodiments, method 200 may be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 708. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 700 via ROM 702 and / or communication unit 709. When the computer program is loaded into RAM 703 and executed by the computing unit 701, one or more steps of method 200 described above may be performed. Alternatively, in other embodiments, the computing unit 701 may be configured to perform method 200 by any other suitable means (e.g., by means of firmware).

[0128] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0129] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0130] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0131] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0132] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), the Internet, and blockchain networks.

[0133] Computer systems can include clients and servers. Clients and servers are generally located far apart and typically interact via communication networks. Client-server relationships are created by computer programs running on the respective computers and having a client-server relationship with each other. Servers can be cloud servers, servers in distributed systems, or servers incorporating blockchain technology.

[0134] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be performed in parallel, sequentially, or in a different order, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.

[0135] While embodiments or examples of this disclosure have been described with reference to the accompanying drawings, it should be understood that the methods, systems, and devices described above are merely exemplary embodiments or examples, and the scope of this disclosure is not limited by these embodiments or examples, but only by the granted claims and their equivalents. Various elements in the embodiments or examples may be omitted or replaced by their equivalents. Furthermore, the steps may be performed in a different order than that described in this disclosure. Further, various elements in the embodiments or examples may be combined in various ways. Importantly, as technology evolves, many elements described herein can be replaced by equivalents that appear after this disclosure.

Claims

1. A redundancy control method applied to a first controller in a redundant control system, the redundant control system comprising the first controller and a second controller, the method comprising: Obtain the current state of the first controller; In response to the current state being the first state: Obtain the status monitoring result of the second controller, wherein the status monitoring result indicates whether the second controller has entered the first state; and Based on the state monitoring results, the first target state of the first controller is determined and the state is switched, wherein the first target state is the same as the next state of the second controller after entering the first state; as well as In response to the current state being the second state, based on the first event for the first controller, a second target state of the first controller is determined and a state switch is performed. The redundant control system is powered by a power supply system. The first state is entered in response to a second event related to the power supply system, including a power-on event. The first state includes an initialization synchronization state entered after successful initialization in response to the power-on event. Determining the first target state of the first controller and switching states based on the state monitoring results includes: In response to detecting that the second controller has entered the initialization synchronization state within a first time after the first controller enters the initialization synchronization state, the first target state is determined to be a normal working state and a state switch is performed so that the first controller and the second controller enter the normal working state synchronously.

2. The method according to claim 1, wherein, The step of determining the first target state of the first controller and switching states based on the state monitoring results further includes: If the second controller is not detected to enter the initialization synchronization state within a first time after the first controller enters the initialization synchronization state, the first target state is determined to be a degraded working state and a state switch is performed.

3. The method according to claim 1 or 2, wherein, The second event includes a power outage event, and the first state includes a pre-power outage synchronization state entered in response to the successful completion of power outage preparation work after the power outage event. The step of determining the first target state of the first controller and switching states based on the state monitoring results includes: In response to detecting that the second controller enters the pre-power-off synchronization state within a second time after the first controller enters the pre-power-off synchronization state, the first target state is determined to be the power-off state and a state switch is performed so that the first controller and the second controller enter the power-off state synchronously.

4. The method according to claim 3, wherein, The step of determining the first target state of the first controller and switching states based on the state monitoring results further includes: In response to the second controller failing to enter the pre-power-out synchronization state within a second time after the first controller enters the pre-power-out synchronization state, the first target state is determined to be a sleep state and a state switch is performed.

5. The method according to claim 1, wherein, The second state is the independent operating state of the first controller.

6. The method according to claim 5, wherein, The second state includes at least one of the following: Initialization state, normal working state, degraded working state, sleep state, fault state, development state, or shutdown preparation state.

7. The method according to claim 6, wherein, The second state includes the initialization state, and the step of determining the second target state of the first controller and switching states based on the first event for the first controller includes: Obtain the current operating mode of the first controller; and In response to the current working mode being developer mode, the second target state is determined to be the development state and a state switch is performed.

8. The method according to claim 1, wherein, The redundant control system is configured as the vehicle's domain controller system.

9. A redundant control device, applied to a first controller in a redundant control system, the redundant control system including the first controller and a second controller, the device comprising: The acquisition module is configured to acquire the current state of the first controller; The first response module includes: The acquisition unit is configured to acquire a status monitoring result of the second controller in response to the current state being a first state, wherein the status monitoring result indicates whether the second controller has entered the first state; and The determining unit is configured to determine a first target state of the first controller and perform a state switch based on the state monitoring results, wherein the first target state is the same as the next state of the second controller after entering the first state; as well as The second response module is configured to respond to the current state being a second state by determining a second target state of the first controller based on a first event related to the first controller and switching the state accordingly. The redundant control system is powered by a power supply system. The first state is entered in response to a second event related to the power supply system, the second event including a power-on event. The first state includes an initialization synchronization state entered after successful initialization in response to the power-on event. The determining unit is further configured as follows: In response to detecting that the second controller has entered the initialization synchronization state within a first time after the first controller enters the initialization synchronization state, the first target state is determined to be a normal working state and a state switch is performed so that the first controller and the second controller enter the normal working state synchronously.

10. The apparatus according to claim 9, wherein, The determining unit is further configured as follows: If the second controller is not detected to enter the initialization synchronization state within a first time after the first controller enters the initialization synchronization state, the first target state is determined to be a degraded working state and a state switch is performed.

11. The apparatus according to claim 9 or 10, wherein, The second event includes a power outage event, and the first state includes a pre-power outage synchronization state entered in response to the successful completion of power outage preparation work after the power outage event. The determining unit is further configured to: In response to detecting that the second controller enters the pre-power-off synchronization state within a second time after the first controller enters the pre-power-off synchronization state, the first target state is determined to be the power-off state and a state switch is performed so that the first controller and the second controller enter the power-off state synchronously.

12. The apparatus according to claim 11, wherein, The determining unit is further configured as follows: In response to the second controller failing to enter the pre-power-out synchronization state within a second time after the first controller enters the pre-power-out synchronization state, the first target state is determined to be a sleep state and a state switch is performed.

13. An electronic device comprising: At least one processor; as well as A memory that is communicatively connected to the at least one processor; in The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1-8.

14. A non-transitory computer-readable storage medium storing computer instructions, wherein, The computer instructions are used to cause the computer to perform the method according to any one of claims 1-8.

15. A computer program product comprising a computer program, wherein, The computer program, when executed by a processor, implements the method of any one of claims 1-8.

16. A redundant control system, comprising: First controller; as well as The second controller is communicatively connected to the first controller. Either the first controller or the second controller is configured to perform the method as described in any one of claims 1-8.

17. An autonomous vehicle, including the electronic equipment as claimed in claim 13.

Citation Information

Patent Citations

  • Method and device for controlling actuator,equipment and automatic driving vehicle

    CN113635919A

  • Control method and device

    WO2021232237A1