Gateway connected to a main processor and a plurality of slave devices and method for operating the gateway

By designing a gateway device to connect to multiple slave devices in the P2P topology, using independent channels and buffered control signals, the problem of slave devices synchronization in the P2P topology is solved, and synchronous output and functional safety in ultrasonic systems are realized.

CN117896038BActive Publication Date: 2025-08-15ELMOS SEMICON AG
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202311327730.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2022-10-14
Filing Date
2023-10-13
Publication Date
2025-08-15
Estimated Expiration
2043-10-13

AI Technical Summary

Technical Problem

In the P2P topology, it is difficult to achieve time synchronization of multiple slave devices, especially in time-critical systems such as ultrasonic systems, and the prior art cannot ensure that the slave devices simultaneously output ultrasonic signals.

Method used

A gateway device is designed to use a P2P topology to organize connections with multiple slave devices. The gateway has an independent channel that receives and buffers the control signals of the master processor, and outputs signals at the same time only when all slave devices are available.

Benefits of technology

The time synchronization of multiple slave devices in the P2P topology is realized, ensuring the synchronous output of slave devices in the ultrasonic system and meeting functional safety requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117896038B_ABST
    Figure CN117896038B_ABST
Patent Text Reader

Abstract

The present invention provides a gateway for connecting to a main processor and multiple slave devices, wherein the gateway and the slave devices are organized in the form of a P2P topology, so that the gateway has an independent channel for each slave device, wherein the gateway is designed to receive multiple control signals from the main processor, including at least one control signal for each predetermined slave device among the multiple slave devices; thereby determining whether the slave device for which the at least one control signal is received is in an available state; and when all the slave devices for which the at least one control signal is received are in an available state, the control signal received from the main processor is simultaneously output to the slave devices for which the at least one control signal is received.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a gateway for connecting to a master processor and a plurality of slave devices (optionally motor vehicles), and a method for operating the gateway. Furthermore, a system for performing data processing using the gateway is provided. Additionally or alternatively, a computer program is provided, which, when executed, contains instructions that cause a computer to at least partially perform the method. Additionally or alternatively, a computer-readable medium is provided, which, when executed, contains instructions that cause a computer to at least partially perform the method. Background Art

[0002] DE 10 2019 215 568 A1 relates to a method for operating a gateway of a vehicle, wherein a vehicle controller connected to the gateway of the vehicle sends an identifier of the controller during each communication, and the gateway receives the identifier transmitted by the controller, as well as to a gateway for a vehicle, a controller for a vehicle and a vehicle.

[0003] DE 11 2008 001 599 T5 relates to a communication system for a vehicle, which has a plurality of communicators for a vehicle, which are installed in the vehicle and perform data transmission, wherein the communication device for the vehicle has a transmitter for sending a reception confirmation, which notifies the sender of the data of the receipt of the data when data is received; and wherein, when there is data to be sent to the sender, reception confirmation data is added and sent to the sender together with the reception confirmation.

[0004] In motor vehicles, the so-called DSI3 standard is used. The DSI3 standard can be understood as the third-generation distributed system interface. It specifies the bus topology, operating modes, and functional classes of the DSI3 bus system, as well as the associated electrical and physical characteristics.

[0005] In addition, the standard defines the message protocol, message transmission mode, message format, bit transmission order, and message error checking.

[0006] DSI3 is a third-generation satellite interface bus, primarily used for safety-critical communications between a central master interface and several satellite nodes (also known as slaves). Slave nodes can be implemented as simple state machines or as microprocessor- or DSP-based controllers. These slaves can provide raw or pre-processed data sources. Each slave can contain a single data source or multiple data sources. Slave nodes can also provide output and control functions.

[0007] The DSI3 protocol manages the formation of a network consisting of a master node and one or more slave nodes. A system can consist of one or more master nodes. Communication between the master and slave devices follows a command and response transmission pattern with separate command and response phases. The connection between the master node and one or more slave nodes is defined by a bus topology. The DSI3 protocol defines point-to-point, serial daisy-chain, and parallel bus topologies.

[0008] A peer-to-peer (P2P) topology consists of a single master node and a single slave node. In other words, a specific slave node is assigned only to a specific master node, and vice versa. Therefore, unlike daisy-chain and parallel bus topologies, the information or data exchanged between the master node and its corresponding slave node cannot be seen or received by other master nodes or other slave nodes. The connection between the master node and the slave node can be referred to as a private line.

[0009] In time-critical systems (such as ultrasound systems), multiple slave devices (such as USP sensors) need to perform a specific behavior (such as transmitting ultrasonic pulses) synchronously, that is, at essentially the same time. The P2P topology poses a challenge.

[0010] Specifically: Distance measurement is based on measuring the propagation time of an ultrasonic signal emitted or transmitted by a USPA sensor. An ultrasonic system has a plurality of such sensors, which emit a plurality of ultrasonic signals for distance measurement. The reflections of the ultrasonic signals are sensed and evaluated by all sensors. Therefore, in order for distance measurement to be possible, the ultrasonic signals must be emitted by all sensors substantially simultaneously. In conventional systems, this is achieved by using a daisy chain or parallel bus topology, whereby a control signal emitted by a master device causing a sensor or slave device to output an ultrasonic signal is received by all slave devices substantially simultaneously. As long as these slave devices have substantially the same latency, each slave device outputs an ultrasonic signal substantially simultaneously. As mentioned above, this is not possible in a P2P topology, since the individual slave devices are assigned to a single master node, which makes it impossible to achieve time synchronization of these slave devices by outputting a single signal from the master device to the slave devices. Summary of the Invention

[0011] Against the background of the prior art, the object of the present disclosure is to provide a device and a method, each of which is suitable for enriching the prior art.

[0012] The object is achieved by the features of the independent claim. Dependent claims and subclaims are optional developments of the disclosure.

[0013] Accordingly, the task is solved by a gateway for connecting to a master processor and multiple slave devices, wherein the gateway and the slave devices are organized in a peer-to-peer (P2P) topology, such that the gateway has an independent channel for each slave device. The gateway is designed to receive multiple control signals from the master processor (each including at least one control signal for a predetermined slave device among the multiple slave devices), determine whether the slave device receiving the at least one control signal is in an available state, and only when all slave devices receiving the at least one control signal are in an available state, simultaneously output the control signal received by the master processor to the slave devices receiving the at least one control signal.

[0014] A gateway can be understood as a component (including hardware and / or software) that establishes a connection between two systems or communication buses. Thus, a gateway represents a bridge for communication between a single or multiple master processors and multiple slave devices.

[0015] Here, a master processor is connected to multiple slave devices, optionally sensors (such as ultrasonic sensors), via a gateway. In automotive technology, such gateways often occur between various data buses. For specific purposes (such as diagnostics and / or control), some data may also be available on another bus. To this end, the gateway "copies" the data from one bus to another.

[0016] As the term gateway already implies, a gateway is a component that is designed to convert data received by a host processor according to a first communication standard (e.g., SPI) into a second communication standard (e.g., DSI3) different from the first communication standard and output it to a slave device, and / or to convert data received by a slave device according to the second communication standard into the first communication standard and output it to the host processor using the first communication standard. Furthermore, in the context of the prior art assessment, reference may be made to the introductory statements regarding gateways, which may be used mutatis mutandis or analogously herein.

[0017] A gateway can function as a standalone control unit or be part of an existing, larger control unit that can be used to connect to different or more bus variants.

[0018] The gateway may be an integrated circuit (IC), or may include such an integrated circuit. An IC is understood to be an electronic circuit applied to a large, optionally thin, semiconductor material plate, such as a few millimeters. This circuit is sometimes also referred to as a solid-state circuit or monolithic integrated circuit. In most cases, this chip (die) is packaged in a housing that is several times larger than the chip itself for safety and easier access. An IC may include a combination of numerous electrically connected electronic semiconductor devices, such as transistors, diodes, and / or other active and passive devices.

[0019] It is conceivable that the slave device is an ultrasonic sensor (optionally implemented as a transceiver), and the control signal is designed to cause each ultrasonic sensor to output an ultrasonic signal once the control signal is received at the respective ultrasonic sensor.

[0020] The gateway described above makes it possible to synchronize multiple slave devices, such as ultrasonic sensors, in time-critical systems (e.g. ultrasound systems) even when using a P2P (bus) topology, since intermediate buffering of the control signals can first be waited for until all control signals have reached the gateway and then these control signals are output simultaneously to the slave devices that are already in the available state, so that there is no longer any asynchronous behavior on the part of the slave devices.

[0021] The following will explain in detail possible expansion solutions of the above-mentioned data processing device. All of these expansion solutions enhance the above-mentioned advantages of the disclosed data processing device individually or in combination.

[0022] The gateway may be designed to determine whether the current slave device is in an available state based on information received from each slave device.

[0023] The gateway may be configured to determine, based on information received by the master processor, which slave device among the plurality of slave devices the control signal currently received by the master processor is from among the plurality of control signals.

[0024] Such a design offers the advantage that not all channels or slave devices connected to the gateway have to be synchronized, but rather the gateway can internally form a measurement group of synchronized slave devices.

[0025] The gateway may have a memory for buffering control signals received by the main processor. Depending on the requirements of functional safety, an error correction program (such as ECC: Error-Correction-Code) may be used to ensure the safety of this memory.

[0026] The gateway may be designed to receive another control signal from the master processor. The gateway may be designed so that the control signal received by the master processor is simultaneously transmitted to the slave device that received the control signal only when all slave devices receiving the control signal are in an available state and another control signal on the gateway has been received by the master processor.

[0027] Another control signal enables measurement groups consisting of slave devices controlled by different gateways or connected to the main processor via different gateways. Specifically, in ultrasound systems, most systems have six or twelve sensors or slave devices. These sensors may be controlled via gateways that have a different number of channels than the sensors, for example, four. To synchronize all channels or create measurement groups across gateways, the gateways can be synchronized by the main processor using the other control signal.

[0028] The gateway may include a first interface for communicating with a host processor using a first communication standard, a second interface for communicating with a sensor using a second communication standard, and a memory connected to the first and / or second interface for buffering data received via the first and / or second interface at the gateway. The memory may ensure security by means of an error detection process and / or an error correction process.

[0029] Therefore, as already implied by the term gateway, a gateway can be a component that is designed to convert data received by a main processor at a first interface according to a first communication standard into a second communication standard different from the first communication standard and output it to a sensor via the second interface, and / or to convert data received by a sensor at a second interface according to a second communication standard into the first communication standard and output it to the main processor via the first interface.

[0030] The first communication standard may be, for example, SPI (Serial Peripheral Interface and corresponding communication or bus protocol), and the second communication standard may be, for example, DSI (Distributed System Interface (eg with three inputs and outputs or DSI3) and corresponding communication or bus protocol).

[0031] The memory may be a buffer memory or a temporary memory in which data received via the second interface and in accordance with the second communication standard is temporarily stored before being output from the memory to the first interface and from there to the main processor, thereby reducing the burden on the main processor.

[0032] Additionally or alternatively, it can be a buffer memory or temporary memory in which data received via the first interface in the first communication standard are temporarily stored before being output from the memory to the second interface and from there to the main processor. It is conceivable that the data of the first communication standard are first temporarily stored or buffered in the memory (in the case of SPI, a so-called SPI command queue), then output from the memory to the control unit of the gateway for conversion to the second communication standard, and that the data in the memory in the second communication standard are temporarily stored in this memory before being output to the second interface and from there to the sensor until the data have been completely converted from the first communication standard to the second communication standard by the control unit (in the case of DSI, a so-called DSI command queue).

[0033] Error correction, also known as error correction codes or error checking and correction (ECC), can be understood as a process for identifying errors when storing and / or transmitting data (e.g., bit flips) and, if possible, correcting them. Error detection is limited to determining whether an error exists, for example by evaluating parity bits. To this end, additional redundancy is typically added to the user data before the data is stored or transmitted, usually in the form of additional bits. This redundancy is used on the target page to identify errors and determine their location.

[0034] The above embodiment brings a series of advantages, as described in detail below.

[0035] Due to the increasing degree of automation in motor vehicles, the required level of functional safety of the individual systems used or installed in the motor vehicle and of the cooperation between these individual systems or components increases.

[0036] Functional safety (also abbreviated as FuSi) refers to the part of system safety that depends on the correct operation of safety-related systems and other risk mitigation measures.

[0037] To define the different requirements for functional safety in motor vehicles, the Automotive Safety Integrity Level (ASIL) is a risk classification scheme defined in ISO 26262, the functional safety standard for street vehicles. It is an adaptation of the Safety Integrity Level (SIL) used in the automotive industry in IEC 61508. This classification helps determine the safety requirements required for compliance with ISO 26262. The ASIL is determined through a risk analysis of potential hazards, taking into account the severity, exposure, and controllability of the vehicle's operational scenarios. The safety goal for this hazard, in turn, comprises the ASIL requirement.

[0038] The standard distinguishes four ASILs: ASIL A, ASIL B, ASIL C, and ASIL D. ASIL D has the highest requirements for product safety integrity, while ASIL A has the lowest. Hazards marked as QM do not have safety requirements.

[0039] Gateways should also meet the requirements of FuSi. In automotive technology, gateways are often located between different data buses, such as different speed versions of CAN, such as the MOST bus. A typical configuration in a car includes a "fast" CAN bus for engine control and similar real-time control units, and a "slow" CAN bus for controllers with little and rarely called data ("comfort bus", such as tire pressure control or fuel sensors). For specific purposes (such as diagnostics and / or control), some data must also be available on another bus. For this purpose, a gateway copies the data from one bus to the other. This gateway can act as its own control unit or be part of an existing larger controller that must be connected to all bus variants.

[0040] In particular, in ultrasonic measurement systems, such as those used for parking assistance, and other sensors in motor vehicles, signals output by the sensors are transmitted to the main processor via a gateway, and a control signal is transmitted from the main processor to the sensors via the gateway. The gateway ensures compatibility between two different communication standards: a first communication standard used by the sensors to communicate with the gateway, and a second communication standard used by the main processor to communicate with the gateway. In other words, the gateway "converts" from the first communication standard to the second communication standard, and vice versa, enabling communication between the sensors and the main processor, and vice versa. For this system, consisting of the main processor, gateway, and sensors, to meet ASIL requirements, it may be necessary to ensure that the gateway itself meets ASIL requirements.

[0041] Because the memory ensures safety using error detection and / or error correction methods, data corruption in the memory, particularly in the temporarily buffered data, can be avoided or detected during, in particular, bidirectional communication via the gateway. This allows certain functional safety goals to be achieved, such as the required ASIL level (optionally ASIL B).

[0042] The first interface may be configured to generate a first error correction code based on data received at the first interface, and output the generated first error correction code together with the data received at the first interface to the memory. Additionally or alternatively, the second interface may be configured to generate a second error correction code based on data received at the second interface, and output the generated second error correction code together with the data received at the second interface to the memory.

[0043] Error correction code (ECC) can be understood as a code designed to correct errors. Unlike parity check, it can correct 1-bit errors and identify 2-bit errors.

[0044] The ECC process requires, for example, 6 check bits for 32 bits and 7 check bits for 64 bits. The error correction code that is generated refers to these check bits. Specifically: Error correction codes (ECC) are used in computer science, telecommunications, information theory and coding theory to control data errors through unreliable or noisy communication channels. The core idea is that the sender encodes a message containing redundant information using a form of ECC. The redundancy allows the receiver to recognize a limited number of errors that may occur anywhere in the message and correct these errors, usually without retransmission. ECC differs from error recognition in that errors that occur can be corrected rather than just recognized. The advantage is that if an error occurs, the system using ECC does not need a return channel to request retransmission of the data.

[0045] The memory may be configured to identify errors in data received from the first interface using a first error correction code received at the memory, and optionally correct them. Additionally or alternatively, the memory may be configured to identify errors in data received from the second interface using a second error correction code received at the memory, and optionally correct them.

[0046] The memory may be configured to output the received first error correction code together with the data received from the first interface to the second interface. The second interface may be configured to identify errors in the data received from the memory at the first interface using the first error correction code received at the second interface, and optionally correct them. Additionally or alternatively, the memory may be configured to output the received second error correction code together with the data received from the second interface to the first interface. The first interface may be configured to identify errors in the data received from the memory at the first interface using the second error correction code received at the first interface, and optionally correct them.

[0047] The gateway may include a control unit connected to the first and / or second interface via a memory. The memory may be configured to output the received first error correction code together with the data received from the first interface to the second interface via the control unit. The control unit may be configured to identify errors in the data received by the control unit from the memory using the first error correction code received at the control unit and optionally correct them.

[0048] The first interface may be designed to detect data received at the first interface by means of a cyclic redundancy check. Additionally or alternatively, the second interface may be designed to detect data received at the second interface by means of a cyclic redundancy check.

[0049] A cyclic redundancy check (CRC) is a method for determining a test value for data in order to be able to identify errors during transmission and / or storage. Before the data are stored and / or transmitted, additional redundancy in the form of a so-called CRC value can be added to each data block of user data. This is a test value calculated according to a specific method, with the help of which any errors that may occur during storage or transmission can be identified. To verify the data, the same calculation process is applied to the data block including the attached CRC value. If the result is zero, the data block can be considered to be authentic. However, different technical applications may deviate from this approach, for example by initializing the calculation with a specific value or inverting the CRC value before transmission. This is also covered by the present disclosure.

[0050] In addition, the present disclosure also relates to a data processing system, which includes the above-mentioned gateway, a main processor connected to the gateway, and the main processor is designed to output multiple control signals to the gateway, each control signal including at least one control signal for a predetermined slave device among multiple slave devices, and multiple slave devices connected to the gateway, wherein the gateway and the slave devices are organized in the form of a P2P topology, so that the gateway has an independent channel for each slave device.

[0051] The main processor may be an ECU (electronic control unit). An electronic controller or ECU may be an intelligent, processor-controlled unit that can communicate with other modules, for example, via a gateway, optionally implemented as a central gateway (CGW), and optionally form a vehicle network via a fieldbus such as CAN, LIN, MOST, FlexRay, DSI, and / or Automotive Ethernet, for example, together with a telematics controller with single or multiple sensors and / or environmental sensors. It is conceivable that the controller may be used for functions related to controlling the driving behavior of the motor vehicle, such as engine control, powertrain control, braking system, steering, and / or tire pressure control systems. Furthermore, the controller may control driver assistance systems such as parking assistance, adaptive cruise control (ACC), lane keeping assistance, lane change assistance, traffic sign recognition, traffic signal recognition, start assist, night vision assistance, parking assistance, and / or intersection assistance.

[0052] The slave devices may be respectively designed to output information to the gateway, and the gateway may determine whether the current slave device is in an available state based on the information.

[0053] The main processor may be designed to output information to the gateway, and the gateway may determine, based on the information, to which slave device among the multiple slave devices a current control signal among the multiple control signals received by the main processor is directed.

[0054] The main processor may be designed to output another control signal to the gateway.

[0055] In addition, the present disclosure also relates to a motor vehicle including the above-mentioned gateway or the above-mentioned data processing system.

[0056] The motor vehicle may be a passenger vehicle, such as a car, a motorized two- or three-wheeled vehicle, and / or a commercial vehicle, such as a truck.

[0057] The motor vehicle may be autonomous. The motor vehicle may be designed to at least partially and / or at least temporarily adopt longitudinal steering and / or lateral steering during automatic driving of the motor vehicle.

[0058] Automatic driving can be achieved in such a way that the motor vehicle moves forward (largely) autonomously. Automatic driving can be at least partially and / or temporarily controlled by a gateway or a data processing system.

[0059] The motor vehicle may be a Level 1 automated driving motor vehicle, ie, it has certain driver assistance systems that assist the driver in operating the vehicle, such as, for example, Adaptive Cruise Control (ACC).

[0060] The motor vehicle may be a Level 2 automated driving vehicle, that is to say semi-automated, i.e. functions such as automatic parking, lane keeping or lateral steering, general longitudinal steering (especially starting off), acceleration and / or deceleration may be taken over by a driver assistance system.

[0061] The vehicle may be capable of Level 3 automated driving, meaning it is automated under certain conditions, meaning the driver does not need to constantly monitor vehicle systems. The vehicle independently performs functions such as triggering turn signals, changing lanes, and / or maintaining track. The driver can perform other tasks but, if necessary, can be instructed by the system to take over driving during the warning period.

[0062] The motor vehicle can be a Level 4 autonomous driving vehicle, that is to say a highly automated vehicle, in which the vehicle's driving is permanently controlled by the vehicle system. If the system is no longer capable of driving, the driver can be asked to take over the driving task.

[0063] The vehicle may be a Level 5 autonomous vehicle, meaning it is fully automated, meaning the driver does not need to perform any driving tasks. Other than setting a destination and activating the system, no human intervention is required. Such a vehicle may not have a steering wheel or pedals.

[0064] What has been described above with respect to the gateway and the data processing system also applies analogously to the motor vehicle, and vice versa.

[0065] The present disclosure also relates to a method for operating the aforementioned gateway. The method includes receiving a plurality of control signals from a main processor at the gateway, including at least one control signal for each predetermined slave device among a plurality of slave devices. The method also includes determining whether the slave device that received the at least one control signal is in an available state, and only when all slave devices that received the at least one control signal are in an available state, simultaneously outputting the control signal received by the main processor to the slave devices that received the at least one control signal.

[0066] The method may be a computer-implemented method, ie one, some or all steps of the method may be at least partially executed by a computer or by a device for processing data or a data processing device.

[0067] The method may include ensuring security of data received through the first and / or second interface by performing an error identification process and / or an error correction process at the first interface, the second interface, and / or the memory.

[0068] What has been described above with respect to the gateway, the system for data processing, and the motor vehicle also applies analogously to the method, and vice versa.

[0069] Furthermore, the computer program contains instructions which, when the program is executed by a computer, cause the computer to at least partially carry out the above-described method.

[0070] The program code of the computer program may be in the form of any desired code, in particular a code suitable for controlling a motor vehicle.

[0071] The computer may be the aforementioned gateway or the aforementioned data processing system.

[0072] What has been described above with respect to the gateway, the data processing system, the motor vehicle and the method also applies analogously to the computer program and vice versa.

[0073] Furthermore, a computer-readable medium, in particular a computer-readable storage medium, is provided, which at least partially includes the above-mentioned computer program.

[0074] That is, a computer-readable medium comprising the computer program defined above may be provided. The computer-readable medium may be any digital data storage device, such as, for example, a USB stick, a hard drive, a CD-ROM, an SD card or an SSD card.

[0075] The computer program does not necessarily have to be stored on such a computer-readable storage medium in order to be made available to the motor vehicle, but can also be obtained from outside via the Internet or in some other way.

[0076] The computer-readable medium may include instructions, and when a computer (optionally the gateway and / or the data processing system) executes the instructions, the computer at least partially performs the method.

[0077] What was described above with respect to the gateway, the data processing system, the motor vehicle, the method and the computer program also applies analogously to the computer-readable medium and vice versa. BRIEF DESCRIPTION OF THE DRAWINGS

[0078] The following will refer to Figures 1 to 5 An alternative embodiment is described.

[0079] Figure 1 A data processing system is schematically shown, which has a gateway according to the present disclosure,

[0080] Figure 2 Schematically shows a method for operating Figure 1 Flowchart of a method of a data processing system shown in FIG.

[0081] Figure 3 A gateway according to the present disclosure is schematically shown. Figure 1 A portion of a data processing system is shown in a first state, in which data from a main processor is transmitted to a sensor via a gateway.

[0082] Figure 4 A gateway according to the present disclosure is schematically shown. Figure 1 A portion of the data processing system is shown in a second state in which sensor data is transmitted to a main processor via a gateway, and

[0083] Figure 5 Schematically shows a method for operating Figure 1 The data processing system shown in Figure 3 and 4 Flowchart of another method according to the present disclosure of a gateway shown in FIG. DETAILED DESCRIPTION

[0084] Figure 1The data processing system 10 shown in FIG. 1 has a master processor 1, two gateways 2, 3, each with four slave devices 4 implemented as (ultrasonic) sensors. The master processor 1 is connected via the gateways 2, 3, which are connected to the respective slave devices 4 via a P2P bus topology (i.e., via independent channels 5). The sensors are divided into a first group 6 and a second group 7 depending on the gateway 2, 3 to which they are connected. The data processing system is part of a motor vehicle 100.

[0085] The data processing system 10 is designed to perform the following Figure 2 Described method.

[0086] In the first step S1 of the method, the main processor 1 outputs multiple control signals from the main processor 1 to the gateways 2 and 3, and the multiple control information includes at least one control signal for each predetermined slave device 4 among the multiple slave devices 4, and includes information about which slave device 4 the current control signal is directed to.

[0087] In the second step S2 of the method, the gateways 2, 3 respectively determine to which slave device 4 the currently received control signal is directed, and store the current control signal in a memory 21, 31 of the gateways 2, 3, respectively, for temporarily storing the control signal received by the master processor 1. This is done based on information contained in the control signal, which is received together with the control signal by the master processor 1 at the respective gateways 2, 3.

[0088] In the third step S3 of the method, the slave devices 4 each output a message to the respective gateway 2 , 3 to which they are connected via the respective channel 5 , wherein the message indicates that the respective slave device 4 is in an available state.

[0089] In the fourth step S4 of the method, each gateway 2, 3 determines whether the current slave device 4 is available based on the information received from the corresponding slave device 4. The first gateway 2 performs this operation for the first group 6 of slave devices 4, while the second gateway 3 performs this operation for the second group 7 of slave devices 4. It is conceivable that the respective gateway 2, 3 outputs a signal to the main processor 1 as soon as the slave device 4 connected to the respective gateway 2, 3 is available.

[0090] In the fifth step S5 of the method, the main processor 1 outputs another control signal to the gateways 2, 3, which signals to the gateways 2, 3 that the slave device 4 of the current other gateway 2, 3 is also available, and indicates that the control signals stored in the corresponding memory 21, 31 should be output to the corresponding group 6, 7 of the slave devices 4.

[0091] In the sixth step S6 of the method, when the gateways 2 and 3 respectively determine that the slave device 4 targeted by the control signal in the corresponding (intermediate) memory 21 and 31 is available, and the corresponding gateways 2 and 3 also receive another control signal sent by the main processor, the gateways 2 and 3 will simultaneously output the control signals stored in the corresponding memories 21 and 31 to the slave device 4 targeted by the current control signal.

[0092] In a seventh step S7 of the method, the slaves 4 of both groups 6 , 7 , which receive corresponding control signals from the gateways 2 , 3 to which they are connected, then output ultrasonic signals substantially simultaneously.

[0093] The above method therefore basically offers two advantages. Firstly, slave devices 4 can be synchronized, which are connected to the same gateway via a P2P topology. In addition, slave devices 4 connected to different gateways 2, 3 (see groups 6, 7 above) can also be synchronized in time. It should be noted that not all slave devices 4 connected to the same gateway 2, 3 have to belong to a unique group, that is to say not all slave devices 4 of a gateway 2, 3 have to output (ultrasonic) signals at the same time. Rather, the method also offers a third advantage, which results from the combination of the two advantages mentioned above. More precisely, this third advantage is that, despite the P2P topology, slave devices 4 of different gateways 2, 3 can be synchronized in time with each other in any way, which is achieved by Figure 1 The group 8 is represented by the dotted line.

[0094] In the following, reference is made to Figures 3 to 5 Optional embodiments of gateways 2 , 3 and their operation are described in detail below, wherein only one of gateways 2 , 3 is shown there as an example. However, the description applies equally to both gateways 2 , 3 .

[0095] As mentioned above, the gateways 2, 3 are not only connected to the main processor 1, but also to the sensors 4 (where Figure 3 and Figure 4 Only one of the sensors is shown as an example in the figure), so that two-way (data) communication can be carried out between the main processor 1 and the sensor 4 via the gateways 2 and 3.

[0096] exist Figure 3 and Figure 4 The gateways 2, 3 shown in detail in FIG include a first pin 12 implemented as a master output slave input pin (MOSI), a first interface 9 implemented here as an SPI interface, a (buffer) memory 21, 31 implemented here as a RAM (English: Random-Access Memory) with multiple storage areas 311, 511, 911 (see FIG. Figure 1), a control unit 11, a second interface 10 implemented here as a DSI interface, a second pin 14 implemented as a DSI output pin, a third pin 15 implemented as a DSL input pin, and a fourth pin 16 implemented as a master device input slave device output pin (MISO).

[0097] The gateway 2 , 3 is connected to the main processor 1 via its SPI interface 9 and is designed to communicate bidirectionally with the main processor 1 by means of a first communication standard, here the SPI communication standard.

[0098] The SPI interface 9 connected to the MOSI pin 12 and the MISO pin 16 includes a register 222 implemented as a MOSI register, a module 233 implemented as an SPI-CRC checker for performing a cyclic redundancy check, a module 244 implemented for generating a correction code (ECC) 211 based on data stored in the MOSI register 222 or received from the main processor 1 via the MOSI pin 12, a module implemented as an SPI-CRC generator for generating a code for a cyclic redundancy check based on data received from the storage area 911, a register 266 implemented as a MISO register, and a module 277 implemented as an ECC decoder for checking the ECC 677.

[0099] The memories 21, 31 connected to the SPI and DSI interfaces are used for temporary storage of data received at the gateways 2, 3 via the SPI and DSI interfaces, wherein the security of the memories 21, 31 is ensured by error correction processes. Therefore, the memory areas 311, 511, 911 are respectively connected to modules 322, 522, 922 implemented as RAM-ECC checkers for checking the ECC 211 or ECC 677.

[0100] The RAM-ECC checker can be designed to check the received ECC 211 or 677. The RAM-ECC checker 322, 522, 922 can be designed to form an ECC from the data received from the memory 21, 31 and the memory address where the data is to be stored, and store it together with the data. The RAM-ECC checker 322, 522, 922 can also be designed to check the stored ECC when reading data, and then form the ECC 211, 677 again from the data and output it together with the data.

[0101] The control unit 11 (also called main controller), which is connected to the SPI and DSI interfaces 9, 10 via a memory, comprises a control module 411 implemented as a command control and a module 422 implemented as an ECC decoder for checking the ECC 211. The control module 411 can be designed to determine for which unit (for example for which sensor 4 or for the gateway 2, 3 itself) the data received by the main processor 1 is intended and to forward the data to this specific unit.

[0102] The gateway 2 , 3 is connected to the sensor 4 via its DSI interface 10 and is designed to communicate bidirectionally with the sensor 4 by means of a second communication standard, here the DSI communication standard.

[0103] The DSI interface 10 connected to the DSI output pin 14 and the DSI input pin 15 includes a module implemented as a DSI-CRC-generator for generating a code for a cyclic redundancy check 611 based on data received from the storage area 511, a register 622 implemented as a DSI-Tx-register, a module 633 implemented as an ECC decoder for checking the ECC 211, a register 644 implemented as a DSI-Rx-register, a module 655 implemented as a DSI-CRC-checker and for a cyclic redundancy check, and a module 666 for generating an ECC 677 based on data stored in the DSI-Rx-register 644 or received from the sensor 4 via the DSI input pin 15.

[0104] Therefore, the gateways 2 and 3 are designed according to the following also reference Figure 5 The described method is run.

[0105] The first fourteen steps S10-S140 described below correspond to Figure 3 The following steps S150-S240 correspond to the gateways 2 and 3 shown in FIG. Figure 4 The gateways 2 and 3 shown in FIG. In these two figures, the relevant parts of the gateways 2 and 3 for the respective communication directions are shown (and the irrelevant parts are omitted). As is known to those skilled in the art, the components of the gateways 2 and 3 are shown in FIG. Figure 3 and Figure 4 The representations chosen are schematic, as the actual physical arrangement of the components can vary, provided gateways 2 and 3 are designed to execute the methods described below. The schematic diagram of memories 21 and 31 is used as an example. These can be implemented as physical memory blocks, but for illustrative purposes, they are not shown as assembled units. Another example is memory areas 311, 511, and 911, which can be implemented as physically separate areas within memories 21 and 31, but this is not required, and other solutions are also conceivable.

[0106] In the first step S10 of the method, the main processor 1 sends first data to the SPI interface 9 via the MOSI pin 12 using the SPI communication standard, wherein the received first data is temporarily buffered in the MOSI register 222 .

[0107] In a second step S20 of the method, the ECC encoder 244 generates the ECC 211 based on the first data contained in the MOSI register 222 .

[0108] In a third step S30 of the method, the SPI CRC checker 233 performs a cyclic redundancy check on the first data contained in the MOSI register 222 based on a CRC contained in the first data (optionally generated by the main processor 1).

[0109] In a fourth step S40 of the method, the SPI interface 9 transfers or outputs the first data of the CRC test together with the ECC 211 to the storage area 311 of the RAM 21 , 31 .

[0110] In a fifth step S50 of the method, the RAM ECC checker 322 checks the data received from the SPI interface 9 via the ECC 211 for errors and corrects them if present and possible.

[0111] In general, it should be noted that the identification of uncorrectable errors during method execution may result in the termination of the process and / or in the re-request of these erroneous or inaccurate data.

[0112] In a sixth step S60 of the method, the data temporarily buffered in the memory area 311 and checked by the RAM ECC checker 322 are output together with the ECC 211 to the command control 411 of the control unit 11 .

[0113] In a seventh step S70 of the method, the ECC decoder 422 of the control unit 11 checks the received ECC 211 based on the data received from the storage area 311 at the command control 411 to check whether there are errors in the data received from this storage area 311 and correct them if they exist and are possible.

[0114] In an eighth step S80 of the method, the control unit 11 outputs the data checked by using the ECC decoder 422 to the storage area 511 of the memory 21 , 31 .

[0115] In a ninth step S90 of the method, the RAM ECC checker 522 checks the data received from the control unit 11 with the aid of the ECC 211 for errors and corrects them if present and possible.

[0116] In a tenth step S100 of the method, the data temporarily buffered in the memory area 511 and checked by the RAM ECC checker 522 is output together with the ECC 211 to the DSI CRC generator 611 of the DSI interface 10 .

[0117] In the eleventh step S110 of the method, the DSI CRC generator 611 generates a CRC based on the data received from the storage area 511 and outputs these data together with the generated CRC and ECC 211 to the DSI Tx register 622 in the twelfth step S120 of the method.

[0118] In the thirteenth step S130 of the method, the ECC decoder 633 of the DSI interface 10 checks the received ECC 211 based on the data temporarily buffered in the DSI-Tx-register 622, determines whether there are errors in the data received from the storage area 511, and corrects them if they exist and possible.

[0119] In the fourteenth step S140 of the method, the DSI interface 10 sends the detection data temporarily buffered in the DSI-Tx-register 622 together with the CRC generated in the eleventh step S110 to the sensor 4 via the DSI output pin 14 using the DSI communication standard, wherein these sent data correspond to the first data received at the gateway 2, 3 in the first step S10.

[0120] As described above with reference to steps S10-S140, since the complete communication path from the main processor 1 via the gateway 2, 3 to the sensor 4 (via CRC between the main processor 1 and the gateway 2, 3, via ECC within the gateway 2, 4, and from the gateway 2, 3 to the sensor 4 via CRC) is safe, at least ASIL B can be achieved here.

[0121] The following describes the communication path from sensor 4 via gateways 2 and 3 to host processor 1. The aforementioned steps S10-S140 can be considered as independent methods, and the following steps S150-S240 can also be considered as independent methods. These methods can be combined with one another and can be performed sequentially and / or at least partially simultaneously during the operation of gateways 2 and 3.

[0122] In a fifteenth step S150 of the method, the sensor 4 sends second data to the DSI interface 10 via the DSI input pin 15 using the DSI communication standard, wherein the received second data is temporarily buffered in the DSI-Rx register 644 .

[0123] In a sixteenth step S160 of the method, the ECC encoder 666 generates an ECC 677 based on the second data contained in the DSI-Rx register 644 .

[0124] In a seventeenth step S170 of the method, the DSI CRC checker 655 performs a cyclic redundancy check on the second data contained in the DSI Rx register 644 based on a CRC contained in the second data (optionally generated by the sensor 4 ).

[0125] In the eighteenth step S180 of the method, the DSI interface 10 transfers or outputs the second data of the CRC test together with the ECC 677 to the storage area 911 of the RAM 21 , 31 .

[0126] In a nineteenth step S190 of the method, the RAM-ECC-checker 922 checks the data received from the DSI interface 10 via the ECC 677 for errors and corrects them if they exist and are possible.

[0127] In the twentieth step S200 of the method, the data temporarily buffered in the storage area 911 and checked by the RAM ECC checker 922 are output together with the ECC 677 to the SPI CRC generator 255 of the SPI interface 9 .

[0128] In the twenty-first step S210 of the method, the SPI-CRC generator 255 generates a CRC based on the data received from the storage area 911 and outputs these data together with the generated CRC and ECC677 to the SPI-MISO register 267 of the SPI interface 9 in the twenty-second step S220 of the method.

[0129] In the twenty-third step S230 of the method, the ECC decoder 277 of the SPI interface 9 checks the received ECC 677 based on the data temporarily buffered in the SPI-MISO-register 266, determines whether there are errors in the data received from the storage area 911, and corrects them if they exist and are possible.

[0130] In the twenty-fourth step S240 of the method, the SPI interface 9 sends the detection data temporarily cached in the MISO register 266 together with the CRC generated in the twenty-first step S210 to the main processor 1 via the MISO pin 16 using the SPI communication standard, wherein these sent data correspond to the second data received at the gateways 2 and 3 in the fifteenth step S150.

[0131] As described above with reference to steps S150-S240, since the security of the complete communication path from the sensor 5 via the gateways 2, 3 to the main processor 1 (via CRC between the main processor 1 and the gateways 2, 3, via ECC within the gateways 2, 3, and from the sensor 4 to the gateways 2, 3 via CRC) is also ensured here, at least ASIL B can be achieved here.

[0132] These advantages are achieved because the method comprises ensuring the security of data received via the first and second interfaces by performing error correction and / or error identification processes at the first interface 9, the second interface 10 and the memories 21, 31 and the control unit 11.

[0133] Reference Signs List

[0134] 1 main processor

[0135] 2First Gateway

[0136] 21 First gateway (cache) memory, optional RAM

[0137] 3Gateway

[0138] 31 Second gateway (cache) memory, optional RAM

[0139] 4 slave devices, optional sensors

[0140] 5 channels

[0141] 6 The first group of slave devices

[0142] 7 The second group of slave devices

[0143] 8 possible additional or optional slave devices

[0144] 9SPI interface

[0145] 10Data processing system

[0146] 11Control unit or main controller

[0147] 12 Master output slave input pins (MOSI)

[0148] 14 DSI output pin

[0149] 15 DSI input pin

[0150] 16 Master Input Slave Output pins (MISO)

[0151] 100 motor vehicles

[0152] 211ECC

[0153] 222MOSI register

[0154] 233SPI-CRC-Checker

[0155] 244ECC encoder

[0156] 255SPI-CRC-Generator

[0157] 266MISO register

[0158] 277ECC decoder

[0159] 311 First Storage Area

[0160] 322RAM-ECC-Checker

[0161] 411 control module or command control

[0162] 422ECC decoder

[0163] 511 Second storage area

[0164] 522RAM-ECC-Checker

[0165] 10DSI interface

[0166] 611DSI-CRC-Generator

[0167] 622DSI-Tx-Register

[0168] 633ECC encoder

[0169] 644DSI-Rx-Register

[0170] 655DSI-CRC-Checker

[0171] 665ECC encoder

[0172] 677ECC

[0173] 911 Third Storage Area

[0174] 922RAM-ECC-Checker

[0175] S1–S7 Process steps of the first method

[0176] S10–S240 Process steps of the second method

Claims

1. A gateway (2, 3) for connecting to a master processor (1) and a plurality of slave devices (4), wherein: The gateways (2, 3) and the slave devices (4) are organized in a P2P topology, so that the gateways (2, 3) have an independent channel (5) for each slave device (4), and are characterized in that the gateways (2, 3) are designed to: - receiving a plurality of control signals from the master processor (1), including at least one control signal respectively for each predetermined slave device (4) of the plurality of slave devices (4), - determining whether the slave device (4) that received the at least one control signal is in an available state, and - Only when all the slave devices (4) that have received the at least one control signal are in an available state, the control signal received from the master processor (1) is output simultaneously to these slave devices (4), wherein the gateway comprises: a first interface for communicating with a host processor using a first communication standard, a second interface for communicating with the sensor via a second communication standard, and a memory connected to the first interface and / or the second interface and configured to cache data received via the first interface and / or the second interface at the gateway, The memory is secured by means of an error detection process and / or an error correction process.

2. The gateway (2, 3) according to claim 1, characterized in that The gateway (2, 3) is designed to determine whether the current slave device (4) is in an available state based on information received from the corresponding slave device (4).

3. The gateway (2, 3) according to claim 1 or 2, characterized in that The gateway (2, 3) is designed to determine, based on information received from the master processor (1), which slave device (4) among a plurality of control signals a currently received control signal from the master processor (1) is intended for.

4. The gateway (2, 3) according to claim 1, characterized in that The gateway (2, 3) has a memory (21, 31) for temporarily storing a control signal received from the main processor (1).

5. The gateway (2, 3) according to claim 1, characterized in that The gateways (2, 3) are designed to: - receiving another control signal from said main processor (1), and -When all slave devices (4) that have received the control signal are in an available state and the gateway (2, 3) has received the other control signal from the main processor (1), the control signal received from the main processor (1) is output simultaneously to the slave devices (4) that have received the control signal.

6. A data processing system (10), characterized in that The system comprises: - A gateway (2, 3) according to any one of claims 1 to 5, a main processor (1) connected to the gateway (2, 3), the main processor being designed to output the plurality of control signals to the gateway (2, 3), the control signals respectively comprising at least one control signal for each predetermined slave device among the plurality of slave devices (4), and - a plurality of slave devices (4) connected to the gateway (2, 3), wherein the gateway (2, 3) and the slave devices (4) are organized in the form of a P2P topology, so that the gateway (2, 3) has an independent channel (5) for each slave device (4).

7. The data processing system (10) according to claim 6, characterized in that The slave devices (4) are respectively designed to output information to the gateways (2, 3), and the gateways (2, 3) determine whether the corresponding slave device (4) is in an available state based on the information.

8. The data processing system (10) according to claim 6, characterized in that The main processor (1) is designed to output information to the gateway (2, 3), and the gateway (2, 3) determines based on the information which of the multiple slave devices (4) a control signal currently received from the main processor (1) is directed to.

9. The data processing system (10) according to claim 6, characterized in that The main processor (1) is designed to output a further control signal to the gateway (2, 3).

10. A motor vehicle (100), characterized in that: The motor vehicle (100) comprises a gateway (2, 3) according to any one of claims 1 to 5 or a data processing system (10) according to any one of claims 6 to 9.

11. A method for operating a gateway (2, 3) according to any one of claims 1 to 5, characterized in that The method comprises: - receiving a plurality of control signals from the master processor (1) at the gateway (2, 3), said control signals respectively comprising at least one control signal for each predetermined slave device of said plurality of slave devices (4), - determining whether the slave device (4) that has received the at least one control signal is in an available state, and - Only when all the slave devices (4) that have received the at least one control signal are in an available state, the control signal received from the master processor (1) is simultaneously output to the slave devices (4) that have received the at least one control signal.

12. A computer program product, characterized in that The computer program product contains instructions which, when a computer executes the computer program, cause the computer to perform the method according to claim 11 .

13. A computer-readable medium having a computer program stored thereon, characterized in that: When the computer program is executed, the method according to claim 11 is implemented.

Citation Information

Patent Citations

  • Gateway for a vehicle

    DE102019215568A1

  • Communication system for a vehicle, communication device for a vehicle and communication method for a vehicle

    DE112008001599T5

  • Vehicle control system, vehicle, and control method

    CN115139944A

  • Method for integration of plug load controllers in a lighting system

    US20210400787A1

  • In-vehicle network management using virtual networks

    US6484082B1