Electronic and electrical system, control method, controller, vehicle, and storage medium
Through the dual-controller architecture and status monitoring mechanism, the safety issues caused by the failure of vehicle safety control functions are solved, the continuity and reliability of vehicle control are achieved, and the increase of additional hardware costs is avoided.
Patent Information
- Application Number
- CN202411063423.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-05
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2044-08-05
AI Technical Summary
In the prior art, when the vehicle safety control function fails, the vehicle cannot travel normally, causing the life safety of the driver or passengers to be threatened.
A dual-controller architecture is adopted. The first controller is responsible for basic safety control functions. The second controller takes over its responsibilities when the first controller fails to implement the safety control function. The second controller monitors the status of the first controller through pulse width modulation messages and heartbeat messages to ensure the continuity of the safety control function.
When the first controller fails, the second controller can quickly take over, ensuring the safety and reliability of vehicle control without interrupting safety functions, thereby improving the overall safety and reliability of the vehicle and eliminating the need to add additional controllers, saving costs.
Smart Images

Figure CN118560508B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the automotive field, and in particular to an electronic and electrical system, a control method, a controller, a vehicle, and a storage medium. Background Art
[0002] With the continuous development of the automotive industry, users are paying more and more attention to vehicle safety. For example, the reliability and safety of vehicle control functions related to vehicle safety, such as power control, power management, steering, and braking, are the primary considerations for users.
[0003] Generally, when a vehicle control function related to vehicle safety fails, the vehicle will not be able to drive normally. In this case, for a vehicle that is in motion, the life safety of the driver or passengers in the vehicle will undoubtedly be threatened.
[0004] Therefore, how to improve the safety and reliability of vehicle control is a technical problem that needs to be solved urgently. Summary of the Invention
[0005] The present disclosure provides an electronic and electrical system, a control method, a controller, a vehicle, and a storage medium, which can improve the safety and reliability of vehicle control.
[0006] In order to achieve the above objectives, the present disclosure adopts the following technical solutions:
[0007] In one aspect, the present disclosure provides an electronic and electrical system for a vehicle, comprising a first controller and a second controller, wherein the first controller is connected to the second controller;
[0008] The control function of the first controller includes a safety control function;
[0009] The second controller is used to perform zone control, and is also used to implement the safety control function in the event that the first controller fails.
[0010] In another aspect, the present disclosure provides a vehicle control method, applied to an electronic and electrical system of the vehicle, the method comprising:
[0011] The second controller confirms that the first controller fails;
[0012] The second controller implements the safety control function.
[0013] In another aspect, the present disclosure provides a vehicle control method, applied to an electronic and electrical system of the vehicle, the method comprising:
[0014] When the first controller operates normally, the first controller realizes the safety control function of the vehicle;
[0015] The first controller sends an indication message to the second controller, so that the second controller determines whether the state of the first controller is a failure state according to a reception condition of the indication message.
[0016] In yet another aspect, the present disclosure provides a first controller comprising: a processor and a memory for storing instructions executable by the processor;
[0017] The processor is configured to execute the instructions so that the first controller executes any vehicle control method provided by the embodiments of the present disclosure.
[0018] In yet another aspect, the present disclosure provides a second controller comprising: a processor and a memory for storing instructions executable by the processor;
[0019] The processor is configured to execute the instructions so that the second controller executes any vehicle control method provided by the embodiments of the present disclosure.
[0020] In yet another aspect, the present disclosure provides a vehicle, comprising the electrical and electronic system; or comprising the first controller and the second controller.
[0021] On the other hand, a computer-readable storage medium is provided, on which computer program instructions are stored. When the computer program instructions are executed on a computer, the computer executes any one of the vehicle control methods provided in the embodiments of the present disclosure.
[0022] On the other hand, a computer program product is provided, which includes computer program instructions. When the computer instructions are run on a computer, the computer is caused to execute any one of the vehicle control methods provided in the embodiments of the present disclosure.
[0023] The electronic and electrical system of the vehicle provided by the embodiment of the present disclosure, on the one hand, can realize the safety control function of the vehicle through the first controller, and in the event of failure of the first controller, the second controller can replace the first controller to continue to realize the safety control function; thereby, it is ensured that the vehicle control will not be interrupted in the event of failure of the first controller, thereby improving the safety and reliability of vehicle control. On the other hand, it can support or integrate more types of safety control functions, not limited to a single function, thereby improving the safety of vehicle control. On the other hand, the focus of fault detection is placed on the second controller, so that even if the first controller cannot accurately convey its own fault condition, the second controller can accurately determine whether the first controller has failed, and realize the safety control function in the event of failure of the first controller. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] The accompanying drawings are used to provide a further understanding of the technical solution of the present disclosure and constitute a part of the specification. Together with the embodiments of the present disclosure, they are used to explain the technical solution of the present disclosure and do not constitute a limitation to the technical solution of the present disclosure.
[0025] Figure 1 A schematic structural diagram of an electronic and electrical system of a vehicle provided in an embodiment of the present disclosure;
[0026] Figure 2 A schematic structural diagram of a second controller provided in an embodiment of the present disclosure;
[0027] Figure 3 A schematic structural diagram of a first controller provided in an embodiment of the present disclosure;
[0028] Figure 4 This is a flow chart of a vehicle control method according to an embodiment of the present disclosure;
[0029] Figure 5 A second flow chart of a vehicle control method provided in an embodiment of the present disclosure;
[0030] Figure 6 A schematic structural diagram of an electronic device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION
[0031] The following will be combined with the accompanying drawings in the embodiments of the present disclosure to clearly and completely describe the technical solutions in the embodiments of the present disclosure. Obviously, the embodiments described are only part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by ordinary technicians in this field without making any creative efforts are within the scope of protection of the present disclosure.
[0032] Unless the context requires otherwise, throughout the specification and claims, the term "comprise" and its alternative forms, such as the third-person singular form "comprises" and the present participle form "comprising," are to be interpreted as open and inclusive, meaning "including, but not limited to." Throughout the specification, the terms "one embodiment," "some embodiments," "exemplary embodiments," "example," "specific example," or "some examples" are intended to indicate that a particular feature, structure, material, or characteristic associated with the embodiment or example is included in at least one embodiment or example of the present disclosure. The schematic representations of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the particular features, structures, materials, or characteristics described may be included in any one or more embodiments or examples in any appropriate manner.
[0033] The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of the technical features being referred to. Thus, a feature identified as "first" or "second" may explicitly or implicitly include one or more of such features. Throughout this disclosure, unless otherwise specified, "plurality" means two or more.
[0034] In the embodiments of the present disclosure, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present disclosure should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.
[0035] Additionally, the use of “based on” is meant to be open and inclusive, as a process, step, calculation, or other action “based on” one or more stated conditions or values may, in practice, be based on additional conditions or values beyond those stated.
[0036] With the continuous development of the automotive industry, users are paying more and more attention to vehicle safety. For example, the reliability and safety of vehicle control functions related to vehicle safety, such as power control, power management, steering, and braking, are the primary considerations for users.
[0037] Generally, when a vehicle control function related to vehicle safety fails, the vehicle will not be able to drive normally. In this case, for a vehicle that is in motion, the life safety of the driver or passengers in the vehicle will undoubtedly be threatened.
[0038] In this regard, an embodiment of the present disclosure provides an electronic and electrical system for a vehicle, including a first controller and a second controller, the first controller and the second controller being connected; wherein the control function of the first controller includes a safety control function; the second controller is used for performing area control, and the second controller is also used to implement the safety control function in the event that the first controller fails.
[0039] The electronic and electrical system of a vehicle provided by embodiments of the present disclosure, on the one hand, can implement vehicle safety control functions through a first controller. If the first controller fails, a second controller can replace the first controller to continue implementing the safety control functions. This ensures that vehicle control is not interrupted even if the first controller fails, thereby improving the safety and reliability of vehicle control. On the other hand, it can support or integrate a wider range of safety control functions, such as those not limited to a single electric parking brake (EPB) or vehicle control unit (VCU), thereby improving vehicle control safety. Furthermore, by focusing fault detection on the second controller, even if the first controller cannot accurately communicate its own fault status, the second controller can accurately determine whether the first controller has failed and implement safety control functions in the event of the first controller failure. Furthermore, considering that multiple domain controllers are typically configured in an electronic and electrical architecture, the method provided by the present disclosure can redundantly implement safety control functions based on the vehicle's original controller, eliminating the need to add new controllers, improving vehicle operation safety and reliability, and saving costs and storage space.
[0040] For ease of understanding, the following first introduces an electronic and electrical system of a vehicle involved in the present disclosure.
[0041] like Figure 1 As shown, the vehicle's electrical and electronic system includes a first controller 110 and a second controller 120, and the second controller 120 is connected to the first controller 110. In some embodiments, the vehicle's electrical and electronic system may further include a reset device 130.
[0042] The first controller 110 is configured to implement overall vehicle control of the vehicle, and the control functions of the first controller include safety control functions. Safety control functions, which may also be referred to as basic safety functions, include but are not limited to at least one of the following: electric power steering (EPS), integrated powertrain brake (IPB), vehicle control unit (VCU), and body control module (BCM). In some embodiments, the first controller 110 may also send control signals to the second controller 120 to control the second controller 120.
[0043] The second controller 120 is used to perform regional control. The vehicle is divided into multiple areas according to the location, and the second controller 120 can be used to perform regional control on an area. For example, the second controller 120 can be set in the area or close to the area, so that the devices in the area can be connected to the second controller nearby, shortening the length of the connection harness. Optionally, the second controller 120 can also have the control function of some functional domains. The second controller 120 is also used to implement safety control functions in the event that the first controller 110 fails. In some embodiments, the second controller 120 is also used to monitor the status of the first controller 110. It should be noted that in the event that the first controller 110 does not fail, the second controller 120 can also implement its own control functions, such as power management functions.
[0044] In some embodiments, the first controller 110 is further configured to send an indication message to the second controller 120 to indicate the status of the first controller 110. Exemplarily, the indication message includes one or more of a pulse width modulation (PWM) message and a heartbeat message (not shown). A PWM message may also be referred to as hard-wired PWM, a PWM signal, or a PWM waveform. Accordingly, the second controller 120 determines whether the first controller 110 is in a failed state based on receipt of the indication message.
[0045] Exemplarily, when the PWM message meets the first failure condition and / or the heartbeat message meets the second failure condition, it is determined that the first controller 110 has failed, wherein the relevant contents of the first failure condition and the second failure condition can be referred to the description in the method embodiment below.
[0046] In some embodiments, when a communication connection is not established between the first controller 110 and the second controller 120, the second controller 120 implements a handshake process with the first controller 110; when the handshake time in the handshake process exceeds a preset time threshold, it is determined that the first controller 110 has failed.
[0047] In some embodiments, the first controller 110 is further configured to send an auxiliary control request message to the second controller 120 in the event of a failure. The auxiliary control request message is used to request the second controller 120 to implement a safety control function. Accordingly, upon receiving the auxiliary control request message, the second controller 120 determines that the first controller 110 has failed. Furthermore, the second controller 120 implements the safety control function after determining that the first controller 110 has failed.
[0048] In some embodiments, the first controller 110 and the second controller 120 are both connected to a bus (not shown in the figure) and obtain vehicle operating parameters from the bus so as to determine control instructions suitable for the vehicle based on the vehicle operating parameters; wherein the vehicle operating parameters include but are not limited to at least one of the following: a start button signal, a brake signal, an accelerator pedal depth signal, a brake pedal depth signal, and an Ethernet signal (ETH), etc.
[0049] It should be noted that if the first controller 110 persists, the second controller 120 can continue to determine control instructions based on vehicle operating parameters without executing any outbound operations. If the first controller 110 fails, the second controller 120 implements safety control functions based on the determined control instructions. This ensures a smooth transition of safety control functions, reduces command delays caused by controller switching, and improves vehicle control safety and reliability.
[0050] In some embodiments, the electronic and electrical system includes multiple regional controllers, the first controller 110 is the first regional controller among the multiple regional controllers, and the second controller 120 is the second regional controller among the multiple regional controllers. In a specific example, the first regional controller is deployed with the function of a central domain controller.
[0051] In some embodiments, the first controller 110 is a central domain controller of the electrical and electronic system.
[0052] In some embodiments, the second controller 120 is a zone controller of the electrical and electronic system.
[0053] In some embodiments, one of the first controller 110 and the second controller 120 is a left domain controller of the electronic and electrical system, and the other is a right domain controller of the electronic and electrical system.
[0054] In some embodiments, the reset device 130 is connected to the first controller 110 and is configured to output a reset signal to the first controller 110 to reset the first controller 110 when a failure of the first controller 110 is detected.
[0055] In one specific example, the reset device 130 is configured with a reset count threshold, also referred to as a maximum reset count. If the reset device 130 fails to reset N times consecutively, and N reaches the reset count threshold, the reset device 130 will no longer output a reset signal. This prevents the reset device 130 from frequently resetting the first controller 110 even when the second controller 120 has successfully implemented the safety control function. N is a positive integer.
[0056] In some embodiments, the second controller 120 includes multiple cores, one of the multiple cores is used to implement the security control function in the event of a failure of the first controller, and the other cores in the multiple cores are used to be responsible for implementing the control function of the second controller 120 itself. For example, the first core in the multiple cores is used to implement the security control function in the event of a failure of the first controller, and the second core in the multiple cores is used to be responsible for implementing the control function of the second controller 120 itself. Based on this, the security control function can be deployed on the second controller 120 through core redundancy. Compared to deploying the security control function directly on the second controller 120, the use of core redundancy to achieve functional redundancy can achieve the migration of the security control function when the first controller 110 fails, without affecting the implementation of the control function of the second controller 120 itself.
[0057] For example, Figure 2 As shown, the second controller 120 includes a first core 210, a second core 220, and a third core 230. The first core 210 is used to implement safety control functions. The second core 220 is used to deploy single-domain safety functions and single-domain body system control functions. Single-domain safety functions are control functions of the second controller 120 itself, including but not limited to power management functions and / or electronic parking brake (EPB) functions. When the second controller 120 is a right-domain body controller, the single-domain body system control functions deployed by the second core 220 are used to control the right-domain body system; when the second controller 120 is a left-domain body controller, the single-domain body system control functions deployed by the second core 220 are used to control the left-domain body system. The third core 230 is used to deploy network functions.
[0058] In a specific example, if the first controller 110 fails, the second controller 120 implements safety control functions through the first core 210. For example, the second controller 120 calls the first core 210 to implement safety control functions and hardwire outputs based on vehicle operating parameters. Furthermore, the second core 220 and the third core 230 maintain normal operation.
[0059] It should be noted that the kernel can also be called core, core or module, etc. Each kernel can be understood as a basic unit for executing instructions and processing data.
[0060] In some embodiments, the multiple cores in the second controller 120 are integrated into a single hardware device with processing capabilities. For example, the multiple cores in the second controller 120 can be deployed on the same chip or the same central processing unit (CPU). As technology evolves, they may also be deployed on other hardware devices, such as an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), and a digital signal processor (DSP). Alternatively, the multiple cores in the second controller 120 can be deployed on different chips.
[0061] In other embodiments, each core in the second controller 120 utilizes independent hardware devices. For example, the second controller 120 includes multiple hardware devices, each of which implements a core of the second controller 120. For example, the first core 210, second core 220, and third core 230 are implemented on separate chips. It should be understood that the hardware devices may also take other forms, and reference can be made to the above description for details.
[0062] In yet other embodiments, some of the multiple cores in the second controller 120 are deployed on independent hardware devices, while some are integrated and deployed on the same hardware device. For example, the first core 210 can be independently deployed on a chip, while the second core 220 and the third core 230 can be integrated and deployed on another chip.
[0063] In some embodiments, the first controller 110 also includes multiple cores, one of the multiple cores is responsible for implementing a security control function, and the other cores of the multiple cores are responsible for implementing control functions other than the security control function.
[0064] For example, Figure 3 As shown, the first controller 110 includes a fourth core 310, a fifth core 320, and a sixth core 330. The fourth core 310 is used to implement safety control functions. The fifth core 320 is used to deploy single-domain body system control functions, chassis functions, and network drive functions. If the first controller 110 is a right-domain body controller, the single-domain body system control functions deployed by the fifth core 320 are used to control the right-domain body system. If the first controller 110 is a left-domain body controller, the single-domain body system control functions deployed by the fifth core 320 are used to control the left-domain body system. The sixth core 330 is used to deploy network functions.
[0065] Similarly, the multiple cores in the first controller 110 are integrated into the same hardware device with processing capabilities. Alternatively, each core in the first controller 110 utilizes an independent hardware device. Alternatively, some of the multiple cores in the first controller 110 are deployed on independent hardware devices, while others are integrated and deployed on the same hardware device. For details, please refer to the above description of the integrated deployment method for the multiple cores in the second controller 120.
[0066] It should be noted that when both the first controller 110 and the second controller 120 include a core responsible for implementing the security control function, this facilitates updating or maintaining the security control function. For example, only the corresponding cores in the first controller 110 and the second controller 120 need to be updated or maintained, thereby improving the efficiency and reliability of maintaining the security control function. Furthermore, this facilitates redundancy of the security control function in the second controller 120, allowing redundancy of the security control function by simply copying the contents of the fourth core in the first controller 110 through the first core, without affecting the normal operation of the other cores.
[0067] In some embodiments, if the first controller 110 fails, the safety control function is always implemented by the second controller 120, and no function migration is performed. After receiving a restart instruction, such as after the vehicle is powered off and on again, the first controller 110 is enabled by default to implement the safety control function.
[0068] It should be understood that the above terminal examples are only for the purpose of more clearly illustrating the technical solutions of the present disclosure and do not constitute a limitation of the present disclosure. Those skilled in the art will appreciate that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided by the present disclosure are also applicable to similar technical problems.
[0069] To more clearly illustrate the vehicle control method provided by the present disclosure, the window transmission method provided by the present disclosure is described below with reference to the accompanying drawings. It should be noted that the various embodiments of the present disclosure may refer to or be mutually referenced. For example, the same or similar steps, method embodiments, and device embodiments may refer to each other without limitation.
[0070] like Figure 4 As shown, an embodiment of the present disclosure provides a vehicle control method, which is applied to the electronic and electrical system of the above-mentioned vehicle, and the method includes:
[0071] S101: The second controller confirms that the first controller fails.
[0072] The control function of the first controller includes a safety control function. In addition, the first controller can also realize the whole vehicle control of the vehicle.
[0073] Safety control functions, also known as basic safety functions, are functions related to the fundamental safety requirements of vehicle operation. For example, these functions include at least one of the following: power steering (EPS), integrated powertrain braking (IPB), vehicle control unit (VCU), and body control module (BCM). The EPS function assists the driver in steering via an electric motor; the IPB function integrates the engine, generator, motor, and brake system to improve efficiency and reduce emissions; the VCU monitors and manages various vehicle functions; and the BCM controls the vehicle's body systems.
[0074] The safety control function is deployed on the first controller, and the second controller also has the same function. This means that the second controller redundantly implements the safety control function of the first controller. By introducing a redundant domain within the vehicle's controllers, multiple controllers can be equipped with safety control functions without adding new controllers, achieving mutual redundancy. This ensures reliable operation of the vehicle's basic control systems even in the event of a single controller failure, improving the safety and reliability of vehicle operation.
[0075] In some embodiments, the first controller may integrate single-domain body system functions and network functions in addition to the aforementioned safety control functions. The second controller may also integrate its own control functions, such as single-domain safety functions, in addition to redundant safety control functions. It should be understood that the structure and functions of the first and second controllers can also refer to the description of the vehicle's electrical and electronic systems above.
[0076] In some embodiments, the second controller may also monitor the status of the first controller while the first controller is implementing the safety control function.
[0077] In some embodiments, the second controller may further initialize the Ethernet protocol to determine whether it has a fault. For example, if the second controller fails to initialize and remains unsuccessful after three attempts, it is determined that the second controller has a fault.
[0078] In some embodiments, the second controller is further connected to a reset device. When the second controller fails, the reset device receives a reset signal sent by the reset device and resets the second controller in response to the reset signal. The reset device includes a hardware reset device and / or a software reset device.
[0079] In order to more clearly illustrate the vehicle control method provided by the present disclosure, the manner in which the second controller monitors the state of the first controller is briefly introduced below.
[0080] In some embodiments, the control method further includes: the second controller receiving an instruction message sent by the first controller; and determining the state of the first controller based on the receipt of the instruction message. Thus, the second controller can monitor the state of the first controller based on the receipt of the instruction message.
[0081] In some embodiments, the indication message includes one or more of a pulse width modulation (PWM) message and a heartbeat message. It should be understood that there may be other possible indication messages, which are not specifically limited in this disclosure.
[0082] In some embodiments, the second controller confirms that the first controller has failed, including: the indication message includes a pulse width modulation (PWM) message, and the first controller is determined to have failed if the PWM message meets a first failure condition; wherein the first failure condition includes at least one of the following: no PWM message is received within a first preset time period; a target parameter of the received PWM message exceeds a preset parameter range, the target parameter including frequency and / or duty cycle; and / or,
[0083] The indication message includes a heartbeat message. When the heartbeat message meets the second failure condition, the first controller is determined to be failed; wherein the second failure condition includes at least one of the following: no heartbeat message is received within a second preset time period; the handshake time during the handshake process with the first controller before receiving the heartbeat message exceeds a preset time threshold.
[0084] It should be understood that when the PWM message meets the first failure condition, it can be considered that the PWM message reception has failed; when the heartbeat message meets the first failure condition, it can be considered that the heartbeat message reception has failed.
[0085] In other words, the above method can also be understood as: when the PWM message meets the first failure condition and / or the heartbeat message meets the second failure condition, determining that the first controller has failed.
[0086] Furthermore, the present disclosure briefly describes the state determination method of the first controller with several specific embodiments.
[0087] (1) Embodiment 1: The indication message includes a pulse width modulation (PWM) message, and the first controller is determined to be failed when the PWM message meets a first failure condition.
[0088] In a specific example, the first preset time length is 1 second. It should be understood that the first preset time length may have other possible values; the time length set by the first preset time length may be shortened, for example, by setting the first preset time length to 0.1 seconds, 0.5 seconds, etc., to improve the efficiency of failure judgment and ensure that the second controller can quickly take over when the first controller fails; for example, by extending the time length set by the first preset time length, for example, by setting the first preset time length to 1.1 seconds, 1.2 seconds, etc., to reduce misjudgment of failure and improve the reliability of failure judgment.
[0089] In one specific example, the target parameter of the received PWM message exceeds the preset parameter range, which includes: the target parameter of the received PWM message continuously exceeds the preset parameter range within a first preset duration. For example, when a PWM message is received and the target parameter of the PWM message is not within the preset parameter range, the second controller accumulates a first timeout period; if the first timeout period exceeds the first preset duration, the second controller determines that the PWM message meets a first failure condition or determines that the PWM message has failed to be received.
[0090] In a specific example, failure to receive the PWM message includes failure to receive the PWM message within a first preset duration. For example, if the PWM message is not received, the second controller accumulates a first timeout period; and if the first timeout period exceeds the first preset duration, determines that the PWM message meets a first failure condition or determines that the PWM message has failed to be received.
[0091] In a specific example, when a PWM message is received and the target parameters of the PWM message are all within a preset parameter range, the first timeout period may be cleared.
[0092] Based on this, when the PWM message reception fails, the second controller can be directly switched to implement the safety control function without making other judgments, reducing the judgment steps; especially when the first controller of the vehicle does fail, it can be more quickly switched to other controllers for safety control, thereby improving the safety and reliability of vehicle driving.
[0093] (2) Embodiment 2: The indication message includes a heartbeat message, and the first controller is determined to be failed when the heartbeat message meets the second failure condition.
[0094] In a specific example, the second preset time length is 1 second. It should be understood that the second preset time length may have other possible values; the second preset time length may be shortened, for example, by setting the second preset time length to 0.1 seconds, 0.5 seconds, etc., to improve the efficiency of failure judgment and ensure that the second controller can quickly take over when the first controller fails; for example, the second preset time length may be extended, for example, by setting the second preset time length to 1.1 seconds, 1.2 seconds, etc., to reduce misjudgment of failure and improve the reliability of failure judgment.
[0095] In a specific example, failure to receive a heartbeat message includes failure to receive a heartbeat message within a second preset duration. For example, if the heartbeat message is not received, the second controller accumulates a second timeout period; and if the second timeout period exceeds the second preset duration, the second controller determines that the heartbeat message meets the first failure condition or determines that the heartbeat message has failed to be received.
[0096] In a specific example, when a heartbeat message is received, the second timeout period may be cleared.
[0097] Based on this, when the heartbeat message fails to be received, the second controller can be directly switched to implement the safety control function without making other judgments, reducing the judgment steps; especially when the first controller of the vehicle fails, it can be more quickly switched to other controllers for safety control, thereby improving the safety and reliability of vehicle driving.
[0098] (3) Example 3: The indication message includes a pulse width modulation (PWM) message and a heartbeat message, and the first controller is determined to be failed when the PWM message meets the first failure condition and the heartbeat message meets the second failure condition.
[0099] For details about whether the PWM message meets the first failure condition, please refer to the description in the first embodiment above. For details about whether the heartbeat message meets the second failure condition, please refer to the description in the second embodiment above.
[0100] Based on this, compared to determining the status of the first controller only by the reception of the PWM message or only by the reception of the heartbeat message. The comprehensive reception of the PWM message and the reception of the heartbeat message can more accurately determine the status of the first controller. For example, in the case where the heartbeat message reception fails but the PWM message reception is successful, it does not necessarily mean that the first controller has failed. For example, there may be other problems such as message flag configuration errors, or signal interference. In the case where the PWM message reception fails but the heartbeat message reception is successful, it does not mean that the first controller has failed. For example, the first controller may have selected a PWM waveform with a different data format from the second controller, or line noise interference, or poor hard wire contact. Therefore, in the case where the PWM message reception fails and the heartbeat message reception fails, it is determined that the first controller has failed, which can improve the accuracy of failure judgment.
[0101] In some embodiments, the second controller confirming that the first controller has failed includes: determining that the first controller has failed when a handshake time between the second controller and the first controller exceeds a preset time threshold. In one example, the handshake between the first controller and the second controller occurs when no communication connection is established between the first controller and the second controller.
[0102] In some embodiments, the second controller confirms the failure of the first controller, including: upon receiving an auxiliary control request message from the first controller, the second controller determines that the first controller has failed, wherein the auxiliary control request message is used to request the second controller to implement a safety control function. Based on this, the auxiliary control request can directly inform the second controller of the status of the first controller, reducing the monitoring workload of the second controller and allowing the second controller to be quickly called to implement the safety control function.
[0103] To more clearly illustrate the vehicle control method provided by the present disclosure, please refer to Figure 5 , the following uses a specific example as an example to illustrate that the second controller can determine whether the first controller fails through the following steps S201 to S212.
[0104] S201: Receive a PWM message sent by a first controller.
[0105] S202, determining whether a PWM message is received; if a PWM message is received, executing step S203; if not, executing step S204.
[0106] S203 , determining whether the target parameter of the received PWM message falls within a preset parameter range; if so, executing step S206 ; if not, executing step S204 .
[0107] S204: Accumulate the first timeout period, and execute step S205.
[0108] S205. Determine whether the first timeout period exceeds a first preset duration. If the first timeout period exceeds the first preset duration, determine that the PWM message reception fails, and execute step S212. If the first timeout period does not exceed the first preset duration, return to step S201.
[0109] S206: Clear the first timeout period and return to step S201.
[0110] S207 , determining whether handshake with the first controller has been successful; if so, executing step S209 , otherwise executing step S208 .
[0111] S208: Determine whether the handshake time exceeds a preset time threshold; if so, execute step S212; otherwise, return to execute step S207.
[0112] S209, determining whether a heartbeat message sent by the first controller is received; if a heartbeat message is received, repeating step S209; if no heartbeat message is received, executing step S210.
[0113] S210: Accumulate the second timeout period, and execute step S211.
[0114] S211. Determine whether the second timeout period exceeds the second preset duration; if the second timeout period exceeds the second preset duration, determine that the heartbeat message reception fails, and execute step S212; if the second timeout period does not exceed the second preset duration, return to step S209.
[0115] S212: If the handshake time exceeds a preset time threshold, or if both the PWM message reception and the heartbeat message reception fail, determine that the first controller has failed. It should be understood that the failure to receive the PWM message can also be understood as the PWM message meeting the first failure condition; and the failure to receive the heartbeat message can also be understood as the heartbeat message meeting the second failure condition.
[0116] In one example, step S212 further includes: determining that the first controller is faulty when the handshake time exceeds a preset time threshold and the PWM message reception fails (not shown in the figure). Figure 5 In the example shown, if the handshake time exceeds the preset time threshold, it means that the heartbeat message will fail to be received.
[0117] It should be noted that steps S201 to S206 can be performed simultaneously with steps S207 to S211, before steps S207 to S211, or after steps S207 to S211. Furthermore, steps S207 and S208 are optional steps. For example, if the first controller and the second controller have successfully established a connection, steps S207 and S208 may not be performed. It should be understood that this disclosure does not impose any specific limitations on this.
[0118] S102: The second controller implements a safety control function.
[0119] That is, the second controller implements the safety control function when it is confirmed that the first controller has failed.
[0120] In some embodiments, after the second controller is powered on or awakened from sleep mode for the first time, the second controller determines control instructions related to the security control function but does not issue such control instructions. That is, if the first controller is still functioning, the second controller and the first controller simultaneously implement the application logic for the security control function, but the second controller does not issue control instructions related to the security control function. It only issues control instructions if the first controller fails.
[0121] Based on this, in the event that the first controller fails, the second controller can quickly send out the determined control instructions, reduce the instruction delay caused by controller switching, achieve smooth migration of safety control functions, and improve the safety and reliability of vehicle control.
[0122] The vehicle control method provided by the embodiments of the present disclosure, on the one hand, can implement vehicle safety control functions through a first controller. If the first controller fails, a second controller can replace the first controller to continue implementing the safety control functions. This ensures that vehicle control is not interrupted even if the first controller fails, thereby improving the safety and reliability of vehicle control. On the other hand, it can support or integrate a wider range of safety control functions, not limited to single safety functions such as the electric parking brake (EPB) or the vehicle control unit (VCU), thereby improving vehicle control safety. Furthermore, by focusing fault detection on the second controller, even if the first controller cannot accurately communicate its own fault status, the second controller can accurately determine whether the first controller has failed and implement safety control functions in the event of the first controller failure. Furthermore, considering that electronic and electrical architectures typically have a central domain controller and multiple regional controllers, the method provided by the present disclosure redundantly implements safety control functions on top of the vehicle's original controller (for example, deploying the safety control functions on a second controller). This eliminates the need to add new controllers, improves vehicle operation safety and reliability, and saves cost and storage space.
[0123] In addition, an embodiment of the present disclosure also provides a vehicle control method, which is applied to the electronic and electrical system of the above-mentioned vehicle. The vehicle's electronic and electrical system includes a first controller and a second controller connected to the first controller. The second controller is used to implement the vehicle's safety control function in the event that the first controller fails. The method includes: when the first controller is working normally, the first controller implements the safety control function.
[0124] In some embodiments, the second controller is further configured to monitor the status of the first controller.
[0125] In some embodiments, the first controller further implements the following steps: sending an indication message to the second controller, so that the second controller can monitor the status of the first controller based on receipt of the indication message, thereby determining whether the first controller is in a failed state. Exemplarily, the indication message includes one or more of a PWM message and a heartbeat message.
[0126] In some embodiments, the above-mentioned sending of an indication message to the second controller includes: initialization after the first controller is powered on for the first time or awakened from sleep; if the initialization is successful, the first controller implements the vehicle's safety control function and sends a PWM message and a heartbeat message to the second controller; if the initialization fails, the first controller continues to attempt initialization.
[0127] In some embodiments, the first controller sends a heartbeat message to the second controller only after the Ethernet chip of the first controller is successfully initialized.
[0128] In some embodiments, the target parameter of the PWM message sent by the first controller is within a preset parameter range. For example, the first controller sends a PWM message with a fixed frequency and duty cycle to the second controller.
[0129] In some embodiments, the above method further includes: in the event of a fault, the first controller sends an auxiliary control request message to the second controller, where the auxiliary control request message is used to request the second controller to implement a safety control function.
[0130] Exemplarily, when a failure of a controller area network (CAN) transceiver of a safety function system in a first controller is detected, an auxiliary control request message is sent to a second controller.
[0131] For example, the auxiliary control request message may be sent to the second controller only when the first controller fails to reset and fails. Based on this, the accuracy of failure judgment can be improved.
[0132] In some embodiments, the first controller is connected to a reset device, and the method further includes resetting the first controller upon receipt of a reset signal from the reset device. The reset device may include a hardware reset device and / or a software reset device. It should be noted that the first controller and the second controller may each be equipped with a different reset device to ensure that the first controller and the second controller can be reset independently of each other.
[0133] For example, if the reset device is a hardware watchdog, and if the first controller is not failed, the first controller performs a watchdog feeding operation on the hardware watchdog at a preset interval. For example, the first controller resets a timer built into the hardware watchdog at a preset interval. In response to the first controller not performing the watchdog feeding operation within the preset time, the hardware watchdog determines that the first controller has failed and sends a reset signal to the first controller, causing the first controller to reset based on the reset signal.
[0134] Exemplarily, a maximum number of reset times of the first controller may be set to avoid frequent resets of the first controller.
[0135] The vehicle control method provided by the embodiment of the present disclosure, on the one hand, can realize the safety control function of the vehicle through the first controller, and in the event of failure of the first controller, the second controller can replace the first controller to continue to realize the safety control function; thereby, it is ensured that the vehicle control will not be interrupted in the event of failure of the first controller, thereby improving the safety and reliability of vehicle control. On the other hand, it can support or integrate more types of safety control functions, not limited to a single electric parking brake EPB or vehicle control unit VCU and other safety functions, thereby improving the safety of vehicle control. On the other hand, the focus of fault detection is placed on the second controller, so that even if the first controller cannot accurately convey its own fault condition, the second controller can accurately monitor whether the first controller has failed, and realize the safety control function in the event of failure of the first controller.
[0136] It is understandable that, in order to implement the above functions, the above-mentioned devices include hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should easily realize that, in combination with the algorithm steps of each example described in the embodiments disclosed herein, the present disclosure can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this disclosure.
[0137] The embodiment of the present disclosure further provides a second controller for implementing the above-mentioned vehicle control method, wherein the second controller includes a state monitoring module and a redundant safety module.
[0138] The state monitoring module is used to monitor the state of the first controller during the process of the first controller realizing the safety control function of the vehicle.
[0139] The redundant safety module is used to implement safety control functions in the event that the first controller fails.
[0140] In some embodiments, the safety control function includes at least one of the following: a power steering EPS function, an integrated powertrain braking IPB function, a vehicle control unit VCU function, and a body control module BCM function.
[0141] In some embodiments, the status monitoring module is specifically configured to receive an instruction message sent by the first controller; and determine the status of the first controller according to a reception status of the instruction message.
[0142] In some embodiments, the indication message includes one or more of a pulse width modulation (PWM) message and a heartbeat message.
[0143] In some embodiments, the indication message includes a pulse width modulation (PWM) message, and the status monitoring module is specifically configured to determine that the first controller has failed if the PWM message meets a first failure condition; and / or the indication message includes a heartbeat message, and the status monitoring module is specifically configured to determine that the first controller has failed if the heartbeat message meets a second failure condition. The first failure condition and the second failure condition can be described above.
[0144] In some embodiments, the status monitoring module is specifically configured to determine that the first controller has failed when a handshake time of a handshake process between the first controller and the second controller exceeds a preset time threshold.
[0145] In some embodiments, the status monitoring module is specifically used to determine that the first controller has failed when receiving an auxiliary control request message sent by the first controller, where the auxiliary control request message is used to request the second controller to implement a safety control function.
[0146] In some embodiments, the second controller includes multiple cores, a first core among the multiple cores is configured to implement safety control functions in the event of a failure of the first controller, and a second core among the multiple cores is configured to implement control functions of the second controller itself. In one specific example, the redundant safety module is the core responsible for implementing the safety control functions, or the redundant safety module is integrated into the core responsible for implementing the safety control functions.
[0147] In addition, the embodiment of the present disclosure further provides a first controller for implementing the above-mentioned vehicle control method. The first controller is used to implement vehicle control, and the control function of the first controller includes a safety control function.
[0148] The first controller includes a safety control module, which is used to implement a safety control function of the vehicle when the first controller operates normally.
[0149] In some embodiments, the first controller further includes a status indication module and / or a function reset module.
[0150] In some embodiments, the status indication module is configured to send an indication message to the second controller.
[0151] In some embodiments, the indication message includes one or more of a pulse width modulation (PWM) message and a heartbeat message.
[0152] In some embodiments, the status indication module is further configured to send an auxiliary control request message to the second controller when a failure occurs in the first controller, where the auxiliary control request message is configured to request the second controller to implement a safety control function.
[0153] In some embodiments, the function reset module is configured to reset the first controller upon receiving a reset signal sent by the reset device.
[0154] It should be noted that the module divisions described above in the first and second controllers are schematic and represent only one logical functional division. In actual implementation, other divisions may be employed. For example, two or more functions may be integrated into a single processing module. These integrated modules may be implemented in either hardware or software functional modules.
[0155] In the case of implementing the functions of the above-mentioned integrated modules in the form of hardware, the embodiments of the present disclosure also provide a possible structure of an electronic device for executing the vehicle control method provided by the embodiments of the present disclosure. Similarly, the electronic device and the vehicle control method described above can be referenced in correspondence with each other.
[0156] like Figure 6 As shown, the electronic device includes a processor 602 and a communication interface 603. In some examples, the electronic device may further include at least one of a bus 604 and a memory 601.
[0157] Processor 602 may implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the embodiments of this disclosure. Processor 602 may be a central processing unit, a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field-programmable gate array, or other programmable logic device, a transistor logic device, a hardware component, or any combination thereof. It may implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the embodiments of this disclosure. Processor 602 may also be a combination that implements computing functions, such as a combination of one or more microprocessors, or a combination of a DSP and a microprocessor.
[0158] The communication interface 603 is used to connect to other devices via a communication network, such as Ethernet, wireless access network, or wireless local area network (WLAN).
[0159] The memory 601 may be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, an electrically erasable programmable read-only memory (EEPROM), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.
[0160] As a possible implementation, memory 601 may exist independently of processor 602. Memory 601 may be connected to processor 602 via bus 604 and used to store instructions or program codes executable by processor 602, such as computer program instructions. When processor 602 calls and executes the instructions or program codes stored in memory 601, the vehicle control method provided in the embodiments of the present disclosure can be implemented.
[0161] In another possible implementation, the memory 601 may also be integrated with the processor 602 .
[0162] The bus 604 may be an extended industry standard architecture (EISA) bus, etc. The bus 604 may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 6 Only one thick line is used in the diagram, but this does not mean that there is only one bus or one type of bus.
[0163] Some embodiments of the present disclosure provide a computer-readable storage medium (e.g., a non-transitory computer-readable storage medium) storing computer program instructions. When executed on a computer, the computer program instructions cause the computer to execute the vehicle control method described in any of the above embodiments. It should be understood that the present disclosure is not limited to the specific form of the computer.
[0164] In some examples, the computer-readable storage media described above may include, but are not limited to, magnetic storage devices (e.g., hard disks, floppy disks, or magnetic tapes), optical disks (e.g., compact disks (CDs), digital versatile disks (DVDs), etc.), smart cards, and flash memory devices (e.g., erasable programmable read-only memories (EPROMs), cards, sticks, or key drives). The various computer-readable storage media described herein may represent one or more devices and / or other machine-readable storage media for storing information. The term "machine-readable storage medium" may include, but is not limited to, wireless channels and various other media capable of storing, containing, and / or carrying instructions and / or data.
[0165] An embodiment of the present disclosure provides a computer program product comprising instructions, which, when executed on a computer, enables the computer to execute the vehicle control method described in any one of the above embodiments.
Claims
1. An electrical and electronic system for a vehicle, characterized in that: It includes a first controller and a second controller, wherein the first controller is connected to the second controller; wherein, The first controller includes a plurality of cores, a fourth core among the plurality of cores is used to implement a safety control function, and the other cores among the plurality of cores are used to implement control functions other than the safety control function; The second controller is used to perform regional control. The second controller includes multiple cores. A first core among the multiple cores replicates the content of a fourth core of the first controller to implement the security control function in the event that the first controller fails. The other cores among the multiple cores are used to implement the regional control function of the second controller. When the first controller is not failed, the first core of the second controller determines a control instruction based on vehicle operating parameters; when the first controller fails, the first core of the second controller implements the safety control function based on the determined control instruction; The first controller is further configured to send an instruction message to the second controller; The second controller is further configured to determine whether the state of the first controller is an invalid state according to the reception status of the indication message; The indication message includes a pulse width modulation (PWM) message, and the second controller is further configured to determine that the first controller has failed if the PWM message meets a first failure condition; wherein the first failure condition includes at least one of the following: the PWM message is not received within a first preset time period, or a target parameter of the received PWM message exceeds a preset parameter range, the target parameter including frequency and / or duty cycle; The indication message includes a heartbeat message, and the second controller is also used to determine that the first controller has failed when the heartbeat message meets a second failure condition, and the second failure condition includes at least one of the following: the heartbeat message is not received within a second preset time period; the handshake time during the handshake process with the first controller before receiving the heartbeat message exceeds a preset time threshold.
2. The electronic and electrical system according to claim 1, wherein: The safety control function includes at least one of the following: power steering EPS function, integrated powertrain braking IPB function, vehicle control unit VCU function, and body control module BCM function.
3. The electronic and electrical system according to claim 1, wherein: The electronic and electrical system includes a plurality of zone controllers, the first controller is a first zone controller among the plurality of zone controllers, and the second controller is a second zone controller among the plurality of zone controllers.
4. The electronic and electrical system according to claim 3, characterized in that: The first regional controller is deployed with the function of a central domain controller.
5. The electronic and electrical system according to claim 1, wherein: The first controller is a central domain controller of the electronic and electrical system.
6. The electronic and electrical system according to claim 1, characterized in that The indication message includes one or more of a pulse width modulation (PWM) message and a heartbeat message.
7. The electronic and electrical system according to claim 1, characterized in that: The second controller is further configured to determine that the first controller is invalid when a handshake time of a handshake process between the first controller and the second controller exceeds a preset time threshold.
8. The electronic and electrical system according to claim 1, wherein: The first controller is further configured to send an auxiliary control request message to the second controller in the event of a fault, wherein the auxiliary control request message is used to request the second controller to implement the safety control function; The second controller is further configured to implement the safety control function upon receiving the auxiliary control request message.
9. The electronic and electrical system according to claim 1, characterized in that: Also includes: A reset device is connected to the first controller and is used to output a reset signal to the first controller when it is detected that the first controller fails.
10. The electronic and electrical system according to claim 1, wherein: One of the first controller and the second controller is a left domain controller of the electronic and electrical system, and the other is a right domain controller of the electronic and electrical system.
11. A vehicle control method, characterized in that: Applicable to the electronic and electrical system according to any one of claims 1 to 10, the electronic and electrical system comprising a first controller and a second controller; the first controller comprising a plurality of cores, a fourth core among the plurality of cores being used to implement a safety control function, and the other cores among the plurality of cores being used to implement control functions other than the safety control function; the second controller comprising a plurality of cores, a first core among the plurality of cores replicating the contents of the fourth core of the first controller to implement the safety control function in the event that the first controller fails; The other cores in the plurality of cores are used to implement the regional control function of the second controller; and the method includes: In a case where the first controller is not failed, the first core in the second controller determines a control instruction based on vehicle operating parameters; The second controller confirms that the first controller fails; The first core of the second controller implements the security control function based on the determined control instruction; receiving an instruction message sent by the first controller; Determining a state of the first controller based on a receipt of the indication message; The second controller confirms that the first controller has failed, including: the indication message includes a pulse width modulation (PWM) message, and the first controller is determined to have failed if the PWM message meets a first failure condition; wherein the first failure condition includes at least one of the following: the PWM message is not received within a first preset time period; a target parameter of the received PWM message exceeds a preset parameter range, the target parameter including frequency and / or duty cycle; The indication message includes a heartbeat message. When the heartbeat message meets the second failure condition, the first controller is determined to be failed; the second failure condition includes at least one of the following: the heartbeat message is not received within a second preset time period; the handshake time during the handshake process with the first controller before receiving the heartbeat message exceeds a preset time threshold.
12. The method according to claim 11, characterized in that The safety control function includes at least one of the following: power steering EPS function, integrated powertrain braking IPB function, vehicle control unit VCU function, and body control module BCM function.
13. The method according to claim 11, characterized in that The indication message includes one or more of a pulse width modulation (PWM) message and a heartbeat message.
14. The method according to claim 11, characterized in that The second controller confirming that the first controller fails includes: When a handshake time of a handshake process between the second controller and the first controller exceeds a preset time threshold, the second controller determines that the first controller has failed.
15. The method according to claim 11, characterized in that The second controller confirming that the first controller fails includes: The second controller determines that the first controller has failed when receiving the auxiliary control request message sent by the first controller, where the auxiliary control request message is used to request the second controller to implement the safety control function.
16. A vehicle control method, characterized in that: Applicable to the electronic and electrical system according to any one of claims 1 to 10, the electronic and electrical system comprising a first controller and a second controller; the first controller comprising a plurality of cores, a fourth core among the plurality of cores being used to implement a safety control function, and the other cores among the plurality of cores being used to implement control functions other than the safety control function; the second controller comprising a plurality of cores, a first core among the plurality of cores replicating the contents of the fourth core of the first controller to implement the safety control function in the event that the first controller fails; The other cores in the plurality of cores are used to implement the regional control function of the second controller; and the method includes: When the first controller operates normally, the fourth core of the first controller implements a safety control function of the vehicle; The first controller sends an indication message to the second controller, so that the second controller determines whether the state of the first controller is an invalid state according to a reception condition of the indication message; The indication message includes a pulse width modulation (PWM) message, and the first controller is determined to be failed when the PWM message meets a first failure condition; wherein the first failure condition includes at least one of the following: the PWM message is not received within a first preset time period; a target parameter of the received PWM message exceeds a preset parameter range, and the target parameter includes a frequency and / or a duty cycle; the indication message includes a heartbeat message, and the first controller is determined to be failed when the heartbeat message meets a second failure condition; the second failure condition includes at least one of the following: the heartbeat message is not received within a second preset time period; a handshake time in a handshake process with the first controller before receiving the heartbeat message exceeds a preset time threshold; In the event that the first controller fails, the first controller sends an auxiliary control request message to the second controller, wherein the auxiliary control request message is used to request the first core among the multiple cores of the second controller to implement the safety control function based on a predetermined control instruction; the predetermined control instruction is a control instruction determined by the first core in the second controller based on the vehicle operating parameters when the first controller is not failed.
17. The method according to claim 16, characterized in that The indication message includes one or more of a pulse width modulation (PWM) message and a heartbeat message.
18. The method according to claim 16, characterized in that The safety control function includes at least one of the following: power steering EPS function, integrated powertrain braking IPB function, vehicle control unit VCU function, and body control module BCM function.
19. The method according to claim 16, wherein The first controller is connected to a reset device, and the method further includes: When the first controller receives the reset signal sent by the reset device, the first controller is reset.
20. A first controller, characterized in that: include: a processor and a memory for storing instructions executable by the processor; The processor is configured to execute the instructions so that the first controller executes the vehicle control method as described in any one of claims 16 to 19.
21. A second controller, characterized in that: include: a processor and a memory for storing instructions executable by the processor; The processor is configured to execute the instructions so that the second controller executes the vehicle control method according to any one of claims 11 to 15.
22. A vehicle, characterized in that: The electronic and electrical system comprises any one of claims 1 to 10; or, comprises the first controller according to claim 20 and the second controller according to claim 21.
23. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and when the computer instructions are executed on a computer, the computer is enabled to execute the vehicle control method according to any one of claims 11 to 19.
Citation Information
Patent Citations
Failure control method and system for remote power-on of vehicle
CN108650282A
Redundant backup method and device
CN111107572A
Modular redundancy control electronic parking brake system and brake method
CN112406842A
System detection method and device, equipment, storage medium, vehicle and cloud control platform
CN114844807A
Redundancy control system and method for autonomous vehicle and vehicle
CN115805964A