Method and system for implementing a multi-redundant central controller system control

By building a multi-redundant central controller system and utilizing priority switching and data arbitration mechanisms, the vehicle control system failure problem caused by a single controller architecture is solved, ensuring the stable operation and safety of the vehicle in the event of a fault.

CN119218235BActive Publication Date: 2025-10-10JIANGLING MOTORS
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411347919.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-26
Publication Date
2025-10-10
Estimated Expiration
2044-09-26

AI Technical Summary

Technical Problem

The existing single central controller architecture may cause the vehicle control system to fail in the event of hardware or software failure, affecting driving safety and making maintenance inconvenient.

Method used

Build a multi-redundant central controller system, including multiple central controllers, obtain synchronous data through internal communication modules, perform fault switching and data arbitration based on priority levels, and ensure system stability and security.

Benefits of technology

It maintains the necessary control functions of the vehicle under any circumstances, improves the stability and safety of the vehicle control system, ensures driving safety, and supports hot plugging and remote diagnosis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119218235B_ABST
    Figure CN119218235B_ABST
Patent Text Reader

Abstract

The application relates to vehicle control system technology and provides a multi-redundancy central controller system control implementation method and system. The method comprises the following steps: constructing a multi-redundancy central controller system, the multi-redundancy central controller system comprising a plurality of central controllers, the plurality of central controllers respectively having different priority levels and being in communication connection with each other; acquiring synchronization data through interactive communication of the plurality of central controllers; and based on the synchronization data, controlling the switching of a vehicle communication module of different central controllers according to the priority level to enable a strategy. Through multi-redundancy design of a set of high-reliability central controller systems, automatic switching of the multi-redundancy central controllers is realized based on the synchronization data according to the priority level, the stability and safety of the vehicle control system are improved, and driving safety is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of vehicle control systems, and in particular to a method and system for implementing control of a multi-redundant central controller system. Background Art

[0002] In modern cars, especially autonomous vehicles, the central controller assumes important responsibilities such as vehicle status monitoring, decision making, and power system control.

[0003] If the existing single controller architecture encounters hardware failure or external extreme working conditions, it may cause the vehicle control system to fail, program abnormalities, and endanger driving safety.

[0004] Although there are methods on the market to improve the security of central controllers through fault detection and fault warning, and to prevent program errors or crashes through watchdog mechanisms and controller software restart, the limitations of a single controller architecture still lead to possible problems such as system failure or untimely response.

[0005] The existing single controller architecture has the following disadvantages:

[0006] 1. Single-point hardware risk: Once the controller hardware fails due to external temperature and humidity, aging, etc., it may cause the entire vehicle control system to fail, endangering driving safety;

[0007] 2. Single-point software risk: Due to certain scenarios or operating conditions, the controller software may crash or restart, causing the program to fail. This may cause the entire vehicle control logic to become abnormal or respond in a delayed manner, endangering driving safety.

[0008] 3. Inconvenient maintenance: Controller failure often requires on-site inspection and repair by professionals, affecting the availability and efficiency of the vehicle. Summary of the Invention

[0009] The present application provides a multi-redundant central controller system control implementation method and system, which can solve the technical problems of the limitations of the single central controller architecture in the existing technology and the failure or untimely response of the vehicle control system.

[0010] In a first aspect, the present application provides a method for implementing control of a multi-redundant central controller system, comprising the following steps:

[0011] Construct a multi-redundant central controller system, which includes multiple central controllers, each of which has a different priority level and is connected to each other in communication;

[0012] In the step of constructing a multi-redundant central controller system, the central controller includes:

[0013] A central computing module, configured to execute vehicle control operations;

[0014] A vehicle communication module, which is in communication with the central computing module and other controllers and is used to distribute data to other controllers based on the calculation results of the central computing module;

[0015] A fault detection module, in communication with the central computing module, for detecting the software and hardware operating status of its own central controller;

[0016] An internal communication module, which communicates data with the fault detection modules of all central controllers and is used for communication and interaction between multiple central controllers to obtain synchronous data, including the online status and self-test status of the central controllers and vehicle data that needs to be arbitrated;

[0017] The synchronization data is obtained through interactive communication between multiple central controllers. Based on the synchronization data, the switching enable strategy of the vehicle communication modules of different central controllers is controlled according to the priority level.

[0018] In conjunction with the first aspect, in one embodiment, the step of acquiring synchronization data through interactive communication between multiple central controllers and controlling the switching enabling strategy of the vehicle communication modules of different central controllers according to priority levels based on the synchronization data specifically includes the following steps:

[0019] Acquire synchronization data through interactive communication between multiple central controllers. When a failure of the currently enabled central controller is detected, different failover operations are controlled based on the synchronization data and according to the priority level.

[0020] Synchronous data is acquired through interactive communication between multiple central controllers. When data processed by central computing modules of multiple valid central controllers is acquired, different redundant data arbitration operations are controlled and executed based on the synchronous data and in accordance with the priority levels.

[0021] In conjunction with the first aspect, in one embodiment, the method of acquiring synchronization data through interactive communication between multiple central controllers, and when a failure of a currently enabled central controller is detected, controlling execution of different failover operations based on the synchronization data and according to priority levels, specifically includes the following steps:

[0022] After the multi-redundant central controller system is powered on, set the central controller status with no errors in self-test to be valid;

[0023] After each central controller is started, it sends an activation message through the internal communication module;

[0024] Priority ring building is performed according to the priority preset by each central controller;

[0025] According to the effective status and activation messages of each central controller, when the currently enabled central controller fails, a ring is established based on the priority and different failover operations are controlled.

[0026] In conjunction with the first aspect, in one embodiment, according to the valid status and activation message of each central controller, when a failure of the currently enabled central controller is obtained, a ring is established based on priority and different failover operations are controlled, specifically including the following steps:

[0027] When a higher priority central controller is online and valid, it controls the higher priority central controller to be enabled;

[0028] When a higher-level central controller is online and in an invalid state, a ring is established based on priority to synchronize the data of the higher-level central controller to the second-highest-level central controller that is online and in a valid state and control its vehicle communication module to be enabled.

[0029] In conjunction with the first aspect, in one embodiment, the central controller further includes:

[0030] The arbitration decision module is connected to the internal communication modules of all central controllers, and is used to obtain data from all central controllers and integrate all data to make arbitration decisions to obtain the safest and most reliable data.

[0031] In conjunction with the first aspect, in one embodiment, the method of acquiring synchronization data through interactive communication between multiple central controllers, when data processed by central computing modules of multiple valid central controllers is acquired, controls execution of different redundancy data arbitration operations based on the synchronization data and according to priority levels, specifically including the following steps:

[0032] After the multi-redundant central controller system is powered on, the central controller status is set to valid if there are no errors in the self-test;

[0033] Priority ring building is performed according to the priority preset by each central controller;

[0034] When data processed by central computing modules of multiple valid central controllers is obtained, each central controller obtains data processed by central computing modules in other valid central controllers, performs comparison, and obtains comparison conditions;

[0035] According to the comparison conditions and priority levels, different redundant data arbitration operations are controlled and executed.

[0036] In conjunction with the first aspect, in one embodiment, controlling and executing different redundancy data arbitration operations according to the comparison working conditions and priority levels specifically includes the following steps:

[0037] If the data processed by the central computing modules of all the effective central controllers are consistent, the vehicle communication module of the central controller with the highest priority among the effective central controllers is enabled;

[0038] If the data processed by the central computing modules of all the effective central controllers are inconsistent, the arbitration decision module is controlled to make a decision according to an arbitration algorithm to obtain the most reliable central controller, update the most reliable central controller to the highest priority, control other central controllers to stop working, and set the states of the other central controllers to be invalid until the number of the effective central controllers is one.

[0039] In a second aspect, the application provides a multi-redundancy central controller system control implementation system, comprising:

[0040] A control system construction module is configured to construct a multi-redundancy central controller system, the multi-redundancy central controller system comprising a plurality of central controllers, the plurality of central controllers having different priority levels respectively and being communicatively connected with each other;

[0041] The central controller comprises:

[0042] A central computing module is configured to perform vehicle control operations;

[0043] A vehicle communication module is communicatively connected with the central computing module and other controllers, and is configured to distribute data to the other controllers according to the calculation result of the central computing module;

[0044] A fault detection module is communicatively connected with the central computing module, and is configured to detect the software and hardware running states of the central controller itself;

[0045] An internal communication module is configured to communicate with the fault detection modules of all the central controllers to obtain synchronization data through communication interaction among the plurality of central controllers, the synchronization data comprising the online states, self-checking states and vehicle data requiring arbitration of the central controllers;

[0046] A controller switching module is communicatively connected with the internal communication module, and is configured to obtain the synchronization data through communication interaction among the plurality of central controllers, and control the switching of the vehicle communication modules of different central controllers according to the synchronization data and the priority levels.

[0047] In combination with the second aspect, in an implementation manner, the controller switching module comprises:

[0048] A fault switching unit is communicatively connected with the internal communication module, and is configured to obtain the synchronization data through communication interaction among the plurality of central controllers, and control the execution of different fault switching operations according to the synchronization data and the priority levels when the currently enabled central controller fails.

[0049] The redundancy arbitration unit is communicatively connected to the internal communication module and is used to obtain synchronization data through interactive communication between multiple central controllers. When data processed by the central computing modules of multiple valid central controllers is obtained, different redundancy data arbitration operations are controlled and executed based on the synchronization data according to the priority level.

[0050] In a third aspect, the present application provides a computer-readable storage medium, on which a multi-redundant central controller system control implementation program is stored, wherein when the multi-redundant central controller system control implementation program is executed by a processor, the steps of the multi-redundant central controller system control implementation method as described above are implemented.

[0051] The beneficial effects of the technical solutions provided in the embodiments of the present application include at least:

[0052] A highly reliable central controller system is designed with multiple redundancy. Based on synchronized data and according to priority, automatic switching of multiple redundant central controllers is achieved to ensure that the vehicle can maintain necessary control functions and guarantee driving safety under any circumstances. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] Figure 1 A flowchart of a method for implementing a multi-redundant central controller system control method provided in an embodiment of the present application;

[0054] Figure 2 A diagram of the architecture of a multi-redundant central controller system provided in an embodiment of the present application;

[0055] Figure 3 A flowchart of a system failure switching of a multi-redundant central controller provided in an embodiment of the present application;

[0056] Figure 4 A block diagram of the functional modules of the multi-redundant central controller system provided in an embodiment of the present application;

[0057] Figure 5 This is a flowchart of redundancy data arbitration in a multi-redundant central controller system provided in an embodiment of the present application. DETAILED DESCRIPTION

[0058] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0059] The terms "including" and "having" and any variations thereof in the specification and claims of this application and the above-mentioned drawings are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally includes steps or units that are not listed, or optionally includes other steps or units inherent to these processes, methods, products or devices. The terms "first", "second" and "third" are used to distinguish different objects, etc., and do not represent a sequence, nor do they limit the "first", "second" and "third" to different types.

[0060] In the description of the embodiments of this application, the words "exemplary," "for example," or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary," "for example," or "for example" in the embodiments of this application should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary," "for example," or "for example" is intended to present the relevant concepts in a concrete manner.

[0061] In the description of the embodiments of the present application, unless otherwise specified, “ / ” means or, for example, A / B can mean A or B; “and / or” in the text is merely a description of the association relationship of associated objects, indicating that three relationships may exist, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in the description of the embodiments of the present application, “multiple” refers to two or more than two.

[0062] In some processes described in the embodiments of the present application, multiple operations or steps are included that appear in a specific order. However, it should be understood that these operations or steps may not be performed in the order in which they appear in the embodiments of the present application or may be performed in parallel. The sequence numbers of the operations are only used to distinguish between different operations, and the sequence numbers themselves do not represent any order of execution. In addition, these processes may include more or fewer operations, and these operations or steps may be performed in sequence or in parallel, and these operations or steps may be combined.

[0063] First, some technical terms in this application are explained to facilitate those skilled in the art to understand this application.

[0064] CCU: Communication Control Unit central controller.

[0065] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.

[0066] First, as Figure 1 As shown, the present application provides a multi-redundant central controller system control implementation method, comprising the following steps:

[0067] Step S1: Constructing a multi-redundant central controller system, which includes multiple central controllers. The multiple central controllers have the same vehicle control function and can operate independently. The multiple central controllers have different priority levels and are communicated with each other.

[0068] In the step of constructing a multi-redundant central controller system, the central controller includes:

[0069] A central computing module, configured to execute vehicle control operations;

[0070] A vehicle communication module, which is in communication with the central computing module and other controllers and is used to distribute data to other controllers based on the calculation results of the central computing module;

[0071] a fault detection module, in communication with the central computing module, for detecting the software and hardware operating status of its own central controller, wherein the hardware status includes the power supply voltage and external sensors, and the software operating status includes whether the program is running normally, that is, detecting whether there are any software or hardware operating faults in the software and hardware of its own central controller, and performing switching operations between multiple central controllers based on this information;

[0072] An internal communication module, which communicates data with the fault detection modules of all central controllers and is used for communication and interaction between multiple central controllers to obtain synchronous data, including the online status and self-test status of the central controllers and vehicle data that needs to be arbitrated;

[0073] Step S2: Acquire synchronization data through interactive communication between multiple central controllers, and based on the synchronization data, control the switching enable strategy of the vehicle communication modules of different central controllers according to the priority level. The synchronization data includes online status, self-test status and / or vehicle control data that needs to be arbitrated.

[0074] This application provides a high-reliability central controller system through multi-redundancy design, realizes automatic switching of multi-redundant central controllers, ensures that the vehicle can maintain necessary control functions under any circumstances, improves the stability and safety of the vehicle control system, and ensures driving safety.

[0075] In this application, the vehicle communication module of the central controller is enabled, that is, the central controller is controlled to start bus communication. The vehicle communication module of the central controller exchanges information with other controllers in the vehicle, and the central controller performs the control operation of the vehicle.

[0076] In a specific embodiment, step S1: constructing a system architecture of a multi-redundant central controller system as follows: Figure 2 As shown, there are four central controllers, namely CCU_1, CCU_2, CCU_3, and CCU_4. The highest-level central controller is the main controller, and the central controllers at other levels are redundant controllers with redundant design, serving as failover backup controllers and realizing redundant data arbitration functions.

[0077] In one embodiment, step S2: acquiring synchronization data through interactive communication between multiple central controllers, and controlling the switching enabling strategy of the vehicle communication modules of different central controllers according to the priority levels based on the synchronization data, specifically includes the following steps:

[0078] Step S2A: Acquire synchronization data through interactive communication between multiple central controllers. When a failure of a currently enabled central controller is detected, control execution of different failover operations based on the synchronization data and according to priority levels.

[0079] Step S2B: Acquire synchronization data through interactive communication between multiple central controllers. When data processed by central computing modules of multiple valid central controllers are acquired, control execution of different redundancy data arbitration operations based on the synchronization data and according to priority levels.

[0080] In step S2A, the redundant central controller system and fault detection function ensure that in the event of a single central controller failure, the redundant central controller system can seamlessly switch to another online and valid central controller, thereby ensuring the normal operation of the vehicle and improving vehicle safety.

[0081] Through step S2B, accurate backup of real-time redundant data is achieved through the multi-redundant central controller system and arbitration switching function, ensuring the high reliability operation function of the central controller.

[0082] In one embodiment, if Figure 3 As shown, step S2A: acquiring synchronization data through interactive communication between multiple central controllers, and when a failure of the currently enabled central controller is obtained, controlling the execution of different failure switching operations based on the synchronization data and according to the priority level, specifically includes the following steps:

[0083] Step S2A1: After the multi-redundant central controller system is powered on, the central controller status is set to valid if no errors are found in the self-test.

[0084] Step S2A2: After each central controller is started, it sends an activation (Alive) message through the internal communication module. The activation message serves as judgment information whether the central controller is online;

[0085] Step S2A3: Priority ring establishment is performed based on the preset priorities of each central controller. Specifically, each central controller sends a Ring message, i.e., CCU1 points to CCU2, CCU2 points to CCU3, CCU3 points to CCU4, and CCU4 points to CCU1. The purpose of priority ring establishment is to allow the four controllers to clearly know which controller is online.

[0086] Step S2A4: According to the valid status and activation message of each central controller, when it is obtained that the currently enabled central controller fails, a ring is established based on the priority, and different failover operations are controlled and executed.

[0087] In one embodiment, step S2A4: based on the valid status and activation message of each central controller, when a failure of the currently enabled central controller is obtained, establishing a ring based on priority and controlling the execution of different failover operations specifically includes the following steps:

[0088] When the central controller with a higher priority is online and valid, it controls the central controller with a higher priority to be enabled, and other redundant controllers are always on standby and enter the startup or sleep state according to the synchronization data of all central controllers;

[0089] When a higher-level central controller is online and in an invalid state, a ring is established based on priority to synchronize the data of the higher-level central controller to the second-highest-level central controller that is online and in a valid state and control its vehicle communication module to be enabled.

[0090] In this application, when the highest-level central controller is in an online and valid state, the vehicle communication module of the highest-level central controller is enabled first to perform control functions on the entire vehicle. When the highest-level central controller fails, a loop is established according to priority, and the vehicle communication module of the second-highest-level online and valid central controller is enabled in sequence. If the second-highest-level central controller fails, the vehicle communication module of the next-level online and valid central controller is enabled in sequence.

[0091] This application uses a built-in fault detection mechanism to quickly identify abnormalities in the main controller and automatically switch the redundant controller to take over control. The implementation of multiple redundancies makes the system more fault-tolerant.

[0092] In one embodiment, the central controller further includes:

[0093] The arbitration decision module is connected to the internal communication modules of all central controllers, and is used to obtain data from all central controllers and integrate all data to make arbitration decisions to obtain the safest and most reliable data.

[0094] In one embodiment, the multi-redundant control system provided by the present application is further configured with a redundant communication network in addition to the main communication link to ensure the reliability of data transmission, such as Figure 4 and Figure 5 As shown, step S2B: acquiring synchronization data through interactive communication between multiple central controllers, when data processed by central computing modules of multiple valid central controllers is acquired, based on the synchronization data, controlling and executing different redundancy data arbitration operations according to priority levels, specifically includes the following steps:

[0095] Step S2B1: After the multi-redundant central controller system is powered on, the central controller status is set to valid if no errors are found in the self-test;

[0096] Step S2B2: Establishing a priority ring according to the priority preset by each central controller;

[0097] Step S2B3: When data processed by the central computing modules of multiple valid central controllers is obtained, each central controller obtains data processed by the central computing modules of other valid central controllers, compares the data processed by the central computing modules of all valid central controllers, and obtains a comparison condition. Specifically, data synchronization and status comparison are continuously performed between the main controller and the redundant controller via a high-speed data bus to ensure consistency of data information and fault information.

[0098] Step S2B4: Based on the comparison conditions and priority levels, control the execution of different redundancy data arbitration operations.

[0099] In one embodiment, step S2B4: controlling and executing different redundancy data arbitration operations according to the comparison conditions and priority levels, specifically includes the following steps:

[0100] If the data processed by the central computing modules of all valid central controllers are consistent, the vehicle communication module of the central controller with the highest priority among the valid central controllers is enabled;

[0101] If the data processed by the central computing modules of all valid central controllers are inconsistent, the control arbitration decision module will determine the most reliable central controller according to the arbitration algorithm, update the most reliable central controller to the highest priority level, control other central controllers to stop working, and set the status of other central controllers to invalid until the number of valid central controllers is one. In this case, the vehicle will degenerate into a single redundant controller and wait for maintenance to repair or supplement the abnormal redundant controller.

[0102] The multi-redundancy central controller system provided in the application supports the hot-pluggable controller design, allows replacing the faulty components without shutdown, and has the remote diagnosis and software updating capabilities.

[0103] In a second aspect, the application provides a multi-redundancy central controller system control implementation system, comprising:

[0104] A control system construction module is configured to construct a multi-redundancy central controller system, the multi-redundancy central controller system comprising a plurality of central controllers, the plurality of central controllers having different priority levels respectively and being communicatively connected with each other;

[0105] The central controller comprises:

[0106] A central computing module is configured to perform whole-vehicle control operations;

[0107] A whole-vehicle communication module is communicatively connected with the central computing module and other controllers, and is configured to distribute data to the other controllers according to the computing results of the central computing module;

[0108] A fault detection module is communicatively connected with the central computing module, and is configured to detect the software and hardware running states of the central controller itself;

[0109] An internal communication module is in data communication with the fault detection modules of all the central controllers, and is configured to obtain synchronization data through communication interaction between the plurality of central controllers, the synchronization data comprising the online states, self-checking states and vehicle data requiring arbitration of the central controllers;

[0110] A controller switching module is communicatively connected with the internal communication module, and is configured to obtain the synchronization data through communication interaction between the plurality of central controllers, and based on the synchronization data, control the switching of the whole-vehicle communication modules of different central controllers according to the priority levels.

[0111] In an embodiment, the controller switching module comprises:

[0112] A fault switching unit is communicatively connected with the internal communication module, and is configured to obtain the synchronization data through communication interaction between the plurality of central controllers, and when a fault of the currently enabled central controller is obtained, based on the synchronization data, control different fault switching operations according to the priority levels;

[0113] A redundancy arbitration unit is communicatively connected with the internal communication module, and is configured to obtain the synchronization data through communication interaction between the plurality of central controllers, and when the data processed by the central computing modules of the plurality of valid central controllers is obtained, based on the synchronization data, control different redundancy data arbitration operations according to the priority levels.

[0114] Among them, the functional implementation of each module in the above-mentioned multi-redundant central controller system control implementation system corresponds to the various steps in the above-mentioned multi-redundant central controller system control implementation method embodiment, and its functions and implementation processes are no longer repeated here.

[0115] In a third aspect, an embodiment of the present application provides a multi-redundant central controller system control implementation device, which can be a personal computer (PC), a laptop, a server, or other device with data processing capabilities.

[0116] Communication interfaces include input / output (I / O) interfaces, physical interfaces, and logical interfaces. These interfaces are used to interconnect components within a device, as well as to connect the device to other devices (such as other computing devices or user devices). Physical interfaces can include Ethernet, fiber, or ATM interfaces; user devices can include displays and keyboards.

[0117] The memory can be various types of storage media, such as random access memory (RAM), read-only memory (ROM), non-volatile RAM (NVRAM), flash memory, optical storage, hard disk, programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), etc.

[0118] The processor may be a general-purpose processor that can call a multi-redundant central controller system control implementation program stored in a memory and execute the multi-redundant central controller system control implementation method provided in the embodiments of the present application. For example, the general-purpose processor may be a central processing unit (CPU). The method executed when the multi-redundant central controller system control implementation program is called can be referred to in the various embodiments of the multi-redundant central controller system control implementation method of the present application, and will not be repeated here.

[0119] In a fourth aspect, an embodiment of the present application also provides a readable storage medium.

[0120] The readable storage medium of the present application stores a multi-redundant central controller system control implementation program, wherein when the multi-redundant central controller system control implementation program is executed by a processor, the steps of the multi-redundant central controller system control implementation method as described above are implemented.

[0121] Among them, the method implemented when the multi-redundant central controller system control implementation program is executed can refer to the various embodiments of the multi-redundant central controller system control implementation method of this application, and will not be repeated here.

[0122] It should be noted that the serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.

[0123] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, of course, it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes a number of instructions for enabling a terminal device to execute the methods described in each embodiment of the present application.

[0124] The above are only preferred embodiments of the present application and do not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made using the contents of the present application specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present application.

Claims

1. A method for implementing control of a multi-redundant central controller system, characterized in that: The following steps are involved: Construct a multi-redundant central controller system, which includes multiple central controllers, each of which has a different priority level and is connected to each other in communication; In the step of constructing a multi-redundant central controller system, the central controller includes: A central computing module, configured to execute vehicle control operations; A vehicle communication module, which is in communication with the central computing module and other controllers and is used to distribute data to other controllers based on the calculation results of the central computing module; A fault detection module, in communication with the central computing module, for detecting the software and hardware operating status of its own central controller; An internal communication module, which communicates data with the fault detection modules of all central controllers and is used for communication and interaction between multiple central controllers to obtain synchronous data, including the online status and self-test status of the central controllers and vehicle data that needs to be arbitrated; An arbitration decision module, which is connected to the internal communication modules of all central controllers, is used to obtain data from all central controllers and integrate all data to make arbitration decisions, thereby obtaining the most secure and reliable data; Acquire synchronization data through interactive communication between multiple central controllers, and control the switching enable strategy of the vehicle communication modules of different central controllers according to the priority level based on the synchronization data, which specifically includes the following steps: Acquire synchronization data through interactive communication between multiple central controllers. When a failure of the currently enabled central controller is detected, different failover operations are controlled based on the synchronization data and according to the priority level. When synchronous data is acquired through interactive communication between multiple central controllers and the data processed by the central computing modules of multiple valid central controllers is acquired, different redundant data arbitration operations are controlled and executed based on the synchronous data and in accordance with the priority levels. Specifically, the following steps are included: After the multi-redundant central controller system is powered on, the central controller status is set to valid if there are no errors in the self-test; Priority ring building is performed according to the priority preset by each central controller; When data processed by central computing modules of multiple valid central controllers is obtained, each central controller obtains data processed by central computing modules in other valid central controllers, performs comparison, and obtains comparison conditions; According to the comparison conditions and priority levels, different redundant data arbitration operations are controlled and executed.

2. The method for implementing control of a multi-redundant central controller system according to claim 1, wherein: The method of acquiring synchronization data through interactive communication between multiple central controllers and, when a failure of the currently enabled central controller is detected, controlling and executing different failure switching operations based on the synchronization data and according to the priority level specifically includes the following steps: After the multi-redundant central controller system is powered on, set the central controller status with no errors in self-test to be valid; After each central controller is started, it sends an activation message through the internal communication module; Priority ring building is performed according to the priority preset by each central controller; According to the effective status and activation messages of each central controller, when the currently enabled central controller fails, a ring is established based on the priority and different failover operations are controlled.

3. The method for implementing control of a multi-redundant central controller system according to claim 2, wherein: According to the effective status and activation message of each central controller, when the currently enabled central controller fails, a ring is established based on the priority, and different failover operations are controlled and executed, which specifically includes the following steps: When a higher priority central controller is online and valid, it controls the higher priority central controller to be enabled; When a higher-level central controller is online and in an invalid state, a ring is established based on priority to synchronize the data of the higher-level central controller to the second-highest-level central controller that is online and in a valid state and control its vehicle communication module to be enabled.

4. The method for implementing control of a multi-redundant central controller system according to claim 3, wherein: The control of executing different redundancy data arbitration operations according to the comparison conditions and priority levels specifically includes the following steps: If the data processed by the central computing modules of all valid central controllers are consistent, the vehicle communication module of the central controller with the highest priority among the valid central controllers is enabled; If the data processed by the central computing modules of all valid central controllers are inconsistent, the control arbitration decision module will determine the most reliable central controller according to the arbitration algorithm, update the most reliable central controller to the highest priority level, control other central controllers to stop working, and set the status of other central controllers to invalid until the number of valid central controllers is one.

5. A multi-redundant central controller system control implementation system, characterized in that: include: A control system building module is used to build a multi-redundant central controller system, which includes multiple central controllers, each of which has a different priority level and is communicatively connected between each other; The central controller includes: A central computing module, configured to execute vehicle control operations; A vehicle communication module, which is in communication with the central computing module and other controllers and is used to distribute data to other controllers based on the calculation results of the central computing module; A fault detection module, in communication with the central computing module, for detecting the software and hardware operating status of its own central controller; An internal communication module, which communicates data with the fault detection modules of all central controllers and is used for communication and interaction between multiple central controllers to obtain synchronous data, including the online status and self-test status of the central controllers and vehicle data that needs to be arbitrated; An arbitration decision module, which is connected to the internal communication modules of all central controllers, is used to obtain data from all central controllers and integrate all data to make arbitration decisions, thereby obtaining the most secure and reliable data; A controller switching module is communicatively connected to the internal communication module and is used to acquire synchronization data through interactive communication between multiple central controllers, and based on the synchronization data, controls the switching enabling strategy of the vehicle communication modules of different central controllers according to the priority level; The method of acquiring synchronization data through interactive communication between multiple central controllers and controlling the switching enabling strategy of the vehicle communication modules of different central controllers according to the priority levels based on the synchronization data specifically includes: Acquire synchronization data through interactive communication between multiple central controllers. When a failure of the currently enabled central controller is detected, different failover operations are controlled based on the synchronization data and according to the priority level. Acquire synchronous data through interactive communication between multiple central controllers. When acquiring data processed by the central computing modules of multiple valid central controllers, control and execute different redundant data arbitration operations based on the synchronous data and according to the priority level, including: After the multi-redundant central controller system is powered on, the central controller status is set to valid if there are no errors in the self-test; Priority ring building is performed according to the priority preset by each central controller; When data processed by central computing modules of multiple valid central controllers are obtained, each central controller obtains data processed by central computing modules in other valid central controllers, performs comparison, and obtains comparison conditions.

6. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a multi-redundant central controller system control implementation program, wherein when the multi-redundant central controller system control implementation program is executed by the processor, the steps of the multi-redundant central controller system control implementation method according to any one of claims 1 to 4 are implemented.

Citation Information

Patent Citations

  • Communication device for a motor vehicle

    DE102011088020A1

  • Vehicle Controller Simulator

    KR102275506B1