Control method and device for vehicle operation, vehicle and storage medium
By employing a redundant control method using master-slave control chips and buses in the vehicle chassis domain, multiple controllers are integrated into a single domain controller, solving the problems of high security and cost of chassis domain controllers and achieving improvements in stability and security.
Patent Information
- Application Number
- CN202411408709.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-10
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2044-10-10
AI Technical Summary
In the existing technology, the vehicle chassis domain control is connected by multiple controllers, which makes it difficult to ensure system safety, and the increased number of controllers leads to high costs.
A dual-control chip redundancy control method with master and slave control chips, and a dual-control bus transmission method with master and slave control buses, are adopted to integrate multiple controllers in the chassis domain into a single domain controller. By determining and switching the status of the master and slave chips and buses, the domain controller can be made stable in the event of a fault.
While reducing controller costs, it improves the security and stability of domain controllers, ensuring safe and stable operation even in the event of controller chip or bus failure.
Smart Images

Figure CN119370110B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of vehicle technology, and in particular to a method, apparatus, vehicle, and storage medium for controlling vehicle operation. Background Technology
[0002] With the popularization and development of vehicles, the mainstream architecture of new energy vehicles is currently a distributed architecture. That is, the central gateway is responsible for the signal interaction between the power domain, chassis domain, body domain, entertainment domain, and autonomous driving domain. Under each domain, the corresponding functions are realized by the various controllers connected to each other through signal transmission. Therefore, the functions corresponding to each domain of the vehicle are realized by the coordination of multiple controllers under that domain.
[0003] Among them, the vehicle's chassis area is equipped with a steering controller responsible for steer-by-wire, a brake controller responsible for brake-by-wire, and a suspension controller responsible for suspension-by-wire. Based on this, the steering controller realizes lateral functions, the brake controller realizes longitudinal functions, and the suspension controller realizes vertical functions.
[0004] However, since the current chassis domain control is obtained by connecting multiple controllers, it is difficult to guarantee system safety, and the total cost of multiple controllers is high. With the increasing computing power required by controller software, the number of controllers is increasing, which in turn leads to higher costs. Summary of the Invention
[0005] This application provides a vehicle operation control method, device, vehicle, and storage medium to solve the technical problems in the prior art where the current chassis domain control is obtained by connecting multiple controllers, which makes it difficult to ensure system safety and the total cost of multiple controllers is high. In the context of the increasing computing power required by controller software, the number of controllers is increasing, which leads to higher costs.
[0006] In a first aspect, this application provides a vehicle operation control method applied to a vehicle domain controller. The domain controller includes a master control chip and a slave control chip. The master control chip is connected to multiple different master function buses, and the slave control chip is connected to multiple different slave function buses. The master control chip and the slave control chip are connected. The method includes:
[0007] When both the master control chip and the slave control chip generate corresponding control commands based on the received sensor signals, the control states of the master control chip and the slave control chip are determined, as well as the operating states of the master functional bus and the slave functional bus are determined.
[0008] Based on the control state, the target control chip is determined from the master control chip and the slave control chip;
[0009] Based on the operating status, the target function bus is determined from the master function bus and the slave function bus;
[0010] The control commands generated by the target control chip are sent to the target function bus so that the vehicle operates according to the control commands output by the target function bus.
[0011] As one possible implementation, the main control chip and the slave control chip are connected through a preset communication interface;
[0012] Determining the control states of the master control chip and the slave control chip includes:
[0013] Obtain the verification result between the main control chip and the slave control chip;
[0014] Based on the verification results, the control states of the master control chip and the slave control chip are determined.
[0015] As one possible implementation, the method further includes:
[0016] When the verification result cannot be obtained, both the master control chip and the slave control chip are identified as the target control chip, and both the master function bus and the slave function bus are identified as the target function bus.
[0017] Sending the control commands generated by the target control chip to the target functional bus includes:
[0018] The control commands generated by the main control chip are sent to the main function bus, and the control commands generated by the slave control chip are sent to the slave function bus.
[0019] As one possible implementation, determining the target control chip from the master control chip and the slave control chip based on the control state includes:
[0020] If the control state indicates that the main control chip has not malfunctioned, the main control chip is identified as the target control chip.
[0021] If the control state indicates that the main control chip has failed and the slave control chip has not failed, the slave control chip is identified as the target control chip.
[0022] As one possible implementation, determining the target function bus from the master function bus and the slave function bus based on the operating state includes:
[0023] If the operating state indicates that the main functional bus has not failed, the main functional bus is identified as the target functional bus.
[0024] If the operating state indicates that the master functional bus has failed and the slave functional bus has not failed, the slave functional bus is identified as the target functional bus.
[0025] As one possible implementation, sending the control commands generated by the target control chip to the target function bus includes:
[0026] If the target control chip is determined to be a slave control chip, the slave control identifier of the slave control chip is obtained;
[0027] The control command generated from the control chip and the slave control identifier are sent to the target function bus, so that the target function bus sends the control command and the slave control identifier outward;
[0028] And / or,
[0029] If the target functional bus is determined to be a slave functional bus, the slave bus identifier of the slave functional bus is obtained;
[0030] The control command of the target control chip and the slave bus identifier are sent to the slave function bus, so that the slave function bus sends the control command and the slave bus identifier outward.
[0031] As one possible implementation, the method further includes:
[0032] If the verification result is not obtained, determine the time point at which the communication interface malfunctioned;
[0033] If the fault time point is within the current operating cycle of the domain controller, then if the main control chip does not fail, the main control chip is identified as the target control chip, and if the main function bus does not fail, the main function bus is identified as the target function bus.
[0034] If the fault time point is before the current operating cycle of the domain controller, then if the slave control chip does not fail, the slave control chip is identified as the target control chip, and if the slave function bus does not fail, the slave function bus is identified as the target function bus.
[0035] In one possible implementation, both the main control chip and the slave control chip include a functional fault detection module and a hardware fault detection module. The main control chip is powered by a main power supply module, and the slave control chip is powered by a slave power supply module. The functional fault detection module is used to detect whether there is a fault in the functional module of the main control chip or the slave control chip, and the hardware fault detection module is used to detect whether there is a hardware fault in the main control chip or the slave control chip. The method further includes:
[0036] When the main control chip's functional fault detection module detects a functional fault in the main control chip, and the hardware fault detection module detects a hardware fault in the main control chip, a preset fault signal is sent to the main power module so that the main power module updates the main control chip's operating state to a preset mode. When the main control chip is in the preset mode, the main control chip no longer processes the received sensor signals.
[0037] When the functional fault detection module of the slave control chip detects a fault in the functional module of the slave control chip, and the hardware fault detection module detects a hardware fault in the slave control chip, a preset fault signal is sent to the slave power supply module so that the slave power supply module updates the operating state of the slave control chip to a preset mode. When the slave control chip is in the preset mode, the slave control chip no longer processes the received sensor signals.
[0038] As one possible implementation, the functional fault detection module detects each function of the control chip in the following way:
[0039] For each function of the control chip, the functional logic for generating control instructions corresponding to the function is determined, and the control chip is either a master control chip or a slave control chip.
[0040] Obtain the analog sensor signals corresponding to the functions generated by the simulator;
[0041] The analog sensor signal is processed according to the functional logic to obtain the control command range corresponding to the function;
[0042] Determine whether the control commands actually generated by the control chip are within the range of control commands;
[0043] If it is determined that the control commands actually generated by the control chip are within the range of the control commands, it is determined that the function is not faulty;
[0044] If it is determined that the control command actually generated by the control chip is not within the range of control commands, then the function is deemed to be faulty.
[0045] Secondly, this application provides a vehicle operation control device applied to a vehicle domain controller. The domain controller includes a master control chip and a slave control chip. The master control chip is connected to multiple different master function buses, and the slave control chip is connected to multiple different slave function buses. The master control chip and the slave control chip are connected. The device includes:
[0046] The first determining module is used to determine the control state of the main control chip and the slave control chip, and the operating state of the main functional bus and the slave functional bus, when both the main control chip and the slave control chip generate corresponding control commands based on the received sensor signals.
[0047] The second determining module is used to determine the target control chip from the main control chip and the slave control chip according to the control state;
[0048] The third determining module is used to determine the target function bus from the main function bus and the slave function bus according to the operating state;
[0049] The transmitting module is used to send the control commands generated by the target control chip to the target function bus, so that the vehicle can operate according to the control commands output by the target function bus.
[0050] Thirdly, this application provides a vehicle, including: a domain controller and a memory.
[0051] The domain controller includes a master control chip and a slave control chip. The master control chip is connected to multiple different master function buses, and the slave control chip is connected to multiple different slave function buses. The master control chip and the slave control chip are connected.
[0052] The domain controller is used to execute the vehicle operation control program stored in the memory to implement the vehicle operation control method described in any one of the first aspects.
[0053] Fourthly, this application provides a storage medium storing one or more programs that can be executed by one or more processors to implement the vehicle operation control method described in any one aspect.
[0054] The technical solution provided in this application includes a vehicle domain controller comprising a master control chip and a slave control chip. The master control chip is connected to multiple different master function buses, and the slave control chip is connected to multiple different slave function buses. When the master control chip and the slave control chip are connected, and both the master control chip and the slave control chip generate corresponding control commands based on received sensor signals, the control state of the master control chip and the slave control chip, as well as the operating state of the master function buses and the slave function buses, are determined. Based on the control state, a target control chip is determined from the master control chip and the slave control chip. Based on the operating state, a target function bus is determined from the master function buses and the slave function buses. The control commands generated by the target control chip are sent to the target function bus, so that the vehicle operates according to the control commands output by the target function bus. This technical solution integrates multiple controllers in the vehicle's chassis domain into a single domain controller. Furthermore, to enhance the domain controller's security, it employs a dual-control chip redundancy control method with a master control chip and a slave control chip, as well as a dual-control bus transmission method with a master control bus and a slave control bus. This ensures that the domain controller can still operate safely and stably even if the control chip or control bus fails, thereby reducing controller costs while improving the domain controller's security and stability. Attached Figure Description
[0055] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.
[0056] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the embodiments or the prior art will be briefly introduced below. Obviously, those skilled in the art can obtain other drawings based on these drawings without creative effort.
[0057] One or more embodiments are illustrated by way of example with reference numerals in the accompanying drawings. These illustrations do not constitute a limitation on the embodiments. Elements with the same reference numerals in the drawings are denoted as similar elements. Unless otherwise stated, the figures in the drawings are not to be limited by scale.
[0058] Figure 1 This application provides a schematic diagram of the structure of a domain controller according to an embodiment of the present application.
[0059] Figure 2 A flowchart illustrating an embodiment of a vehicle operation control method provided in this application;
[0060] Figure 3A flowchart illustrating an embodiment of another vehicle operation control method provided in this application;
[0061] Figure 4 A flowchart illustrating an embodiment of another vehicle operation control method provided in this application;
[0062] Figure 5 A flowchart illustrating another embodiment of a vehicle operation control method provided in this application;
[0063] Figure 6 This is a schematic diagram of another domain controller provided in an embodiment of this application;
[0064] Figure 7 A block diagram illustrating an embodiment of a vehicle operation control device provided in this application;
[0065] Figure 8 This is a structural schematic diagram of a vehicle provided in an embodiment of this application. Detailed Implementation
[0066] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the embodiments described below are only some, not all, of the embodiments of this application. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0067] The following disclosure provides numerous different embodiments or examples for implementing various structures of the invention. To simplify the disclosure, specific examples of components and arrangements are described below. These are merely examples and are not intended to limit the scope of the invention. Furthermore, reference numerals and / or letters may be repeated in different examples. Such repetition is for simplification and clarity and does not in itself indicate a relationship between the various embodiments and / or arrangements discussed.
[0068] To address the challenges of existing chassis domain control technologies, which rely on interconnected controllers, making system safety difficult and resulting in high overall costs, and further exacerbating the increasing computational demands of controller software and the resulting rise in controller numbers and costs, this application provides a vehicle operation control method, apparatus, vehicle, and storage medium. This method integrates multiple controllers within the vehicle's chassis domain into a single domain controller. Furthermore, to enhance the domain controller's security, it employs a dual-control chip redundancy control method (master and slave control chips) and a dual-control bus transmission method (master and slave control buses). This ensures that even in the event of a controller chip or bus failure, the domain controller can still operate safely and stably, thereby reducing controller costs while simultaneously improving its security and stability.
[0069] To facilitate understanding of the vehicle operation control method provided in this application, the vehicle's domain controller will be explained below.
[0070] See Figure 1 This is a schematic diagram of the structure of a domain controller provided in an embodiment of this application. Figure 1 As shown, the domain controller 10 may include a master control chip 11 and a slave control chip 12. The master control chip 11 may be connected to multiple different master function buses 111, and the slave control chip 12 may be connected to multiple different slave function buses 121.
[0071] In this embodiment, there are no restrictions on the model and type of the main control chip 11 and the slave control chip 12, as well as the main function bus 111 and the slave function bus 121.
[0072] Furthermore, to enhance the security of the domain controller, the security level of the master control chip 11 and the slave control chip 12 can be ASILD level.
[0073] Furthermore, the aforementioned main control chip 11 and the aforementioned slave control chip 12 can be connected through a preset communication interface.
[0074] The aforementioned main function bus 111 can be the function bus corresponding to the functions implemented in the daily operation of the vehicle, which may include, but is not limited to: hand-feel analog TV (three-phase) drive axle bus, brake bus, steering bus, CN bus (serial communication protocol bus), drive bus, suspension bus, and EP bus, etc.
[0075] Accordingly, the aforementioned secondary function bus 121 corresponds to the aforementioned primary function bus 111, and may include, but is not limited to: haptic analog TV (three-phase) drive axle bus, brake bus, steering bus, CN bus (serial communication protocol bus), drive bus, suspension bus, and EP bus, etc.
[0076] In one embodiment, both the master control chip 11 and the slave control chip 12 are connected to other sensors in the vehicle. Therefore, both the master control chip 11 and the slave control chip 12 can receive sensor signals sent by other sensors in the vehicle and generate corresponding control commands based on the received sensor signals. For example, when the domain controller 10 is the chassis domain controller of the vehicle, the control commands generated by the master control chip 11 and the slave control chip 12 may include, but are not limited to, control commands for the vehicle's driving, steering, braking, and suspension control. The other sensors may include, but are not limited to, height sensors, acceleration sensors, accelerator pedal signal sensors, IMU (Inertial Measurement Unit) sensors, WSS (Windows SharePoint Services, an engine for creating websites that enable information sharing and document collaboration) sensors, TAS (Tool-Assisted Speedrun) sensors, and PTS (Predetermined time system) sensors.
[0077] Furthermore, after generating the corresponding control command, the domain controller 10 can send the control command to the main function bus 111 or the slave function bus 121 to transmit the control command outward through the main function bus 111 or the slave function bus 121 so that the vehicle can operate according to the control command.
[0078] In addition, the main control chip 11 and the slave control chip 12 can share the IGN power supply (wake-up power supply), which can ensure the synchronization of the two control chips.
[0079] Based on this, this application provides a vehicle operation control method, which can be applied to the above-mentioned... Figure 1 The domain controller shown can ensure that it can still operate safely and stably when the control chip or control bus fails, thereby reducing the cost of the controller while improving its security and stability.
[0080] The vehicle operation control method provided in this application will be further explained and described below with reference to the accompanying drawings and specific embodiments. The embodiments do not constitute a limitation on the embodiments of the present invention.
[0081] See Figure 2This is a flowchart illustrating an embodiment of a vehicle operation control method provided in this application. As one embodiment, Figure 2 The illustrated process can be applied to a vehicle's domain controller, which may include a master control chip and slave control chips. The master control chip is connected to multiple different master function buses, and the slave control chips are connected to multiple different slave function buses. The master control chip and slave control chips are connected, for example... Figure 1 Domain controller 10 is shown. (As shown) Figure 2 As shown, the process may include the following steps:
[0082] Step 201: When both the master control chip and the slave control chip generate corresponding control commands based on the received sensor signals, determine the control status of the master control chip and the slave control chip, as well as the operating status of the master function bus and the slave function bus.
[0083] The aforementioned sensor signals refer to the sensor signals sent by multiple sensors of the vehicle to the aforementioned domain controller. These sensors may include, but are not limited to, height sensors, acceleration sensors, accelerator pedal signal sensors, IMU sensors, WSS sensors, TAS sensors, and PTS sensors.
[0084] The aforementioned control commands refer to the control commands generated by the main controller chip or slave control chip in the domain controller based on the received sensor signals. These control commands may include, but are not limited to, control commands for vehicle driving, steering, braking, suspension control, etc.
[0085] The aforementioned control status refers to the operating status of the master control chip and the slave control chip, which can characterize whether the master control chip and the slave control chip have malfunctioned, that is, whether the master control chip and the slave control chip can transmit control commands normally.
[0086] The above operating status refers to the current operating status of the master function bus and the slave function bus, which can indicate whether there is a fault in the master function bus or the slave function bus, that is, whether the master function bus or the slave function bus can transmit control commands normally.
[0087] In this embodiment of the application, from Figure 1 As shown in the structure of the domain controller, both the master control chip and the slave control chip are connected to vehicle-related sensors and can receive sensor signals sent by the connected sensors.
[0088] Furthermore, the master control chip and slave control chip included in the above-mentioned domain controller are master and slave chips, and they perform the same functions. Therefore, both the master control chip and the slave control chip can generate corresponding control commands based on the received sensor signals.
[0089] Based on this, in order to ensure the normal operation of the domain controller, the execution entity of this application embodiment can determine the control status of the master control chip and the slave control chip, as well as the operating status of the master function bus and the slave function bus.
[0090] As an optional implementation, the master control chip and slave control chip can be connected via a preset communication interface, such as an SPI (Serial Peripheral interface). Based on this, the master control chip and slave control chip can perform fault verification and obtain the verification results through the aforementioned communication interface.
[0091] Based on this, the execution subject of this application embodiment can obtain the verification result of the above-mentioned verification between the main control chip and the slave control chip, and determine the control state of the main control chip and the slave control chip according to the above-mentioned verification result.
[0092] Optionally, if the above verification results indicate that the main control chip has a fault, and the slave control chip does not have a fault, the control state of the main control chip can be determined to be a fault state, and the control state of the slave control chip can be determined to be a normal control state.
[0093] Optionally, if the above verification results indicate that the main control chip is not faulty, but the slave control chip is faulty, the control state of the main control chip can be determined to be normal control state, and the control state of the slave control chip can be determined to be faulty state.
[0094] Optionally, if the above verification results indicate that neither the master control chip nor the slave control chip is faulty, it can be determined that the control states of both the master control chip and the slave control chip are in normal control states.
[0095] Optionally, if the above verification results indicate that both the master control chip and the slave control chip are faulty, it can be determined that the control states of both the master control chip and the slave control chip are faulty.
[0096] Furthermore, when it is determined that both the master control chip and the slave control chip are in a fault state, both the master control chip and the slave control chip are unavailable. At this time, the domain controller is faulty, so alarm information can be generated to characterize the fault of the domain controller and output to the outside through the master function bus or the slave function bus.
[0097] Step 202: Based on the above control status, determine the target control chip from the main control chip and the slave control chip.
[0098] Step 203: Based on the above operating status, determine the target function bus from the master function bus and slave function bus.
[0099] Step 204: Send the control commands generated by the target control chip to the target function bus, so that the vehicle runs according to the control commands output by the target function bus.
[0100] The following provides a unified explanation of steps 202 to 204:
[0101] The aforementioned target control chip is a control chip used in a domain controller to transmit control commands to the function bus. It can be a master control chip, a slave control chip, or both.
[0102] The aforementioned target function bus is a function bus in the domain controller used to transmit control commands to the outside world. It can be a master function bus, a slave function bus, or both.
[0103] In this embodiment, before transmitting control commands externally, the domain controller can first determine the target control chip from the master control chip and slave control chips based on the acquired control state, and determine the target functional bus from the master functional bus and slave functional buses based on the operating state. Then, the control commands generated by the target control chip can be sent to the target functional bus, thereby sending the control commands to the corresponding functional components of the vehicle via the target functional bus, so that the vehicle operates according to the control commands output by the target functional bus. The aforementioned functional components may include, but are not limited to, a motor, steering system, braking system, and suspension system.
[0104] As an optional implementation, when determining the target control chip, corresponding priorities can be set for the aforementioned master control chip and slave control chip. Furthermore, the priority of the master control chip can be set to be higher than that of the slave control chip.
[0105] Based on this, if the main control chip does not malfunction as indicated by the above control state, the main control chip can be identified as the target control chip.
[0106] Optionally, if the above control state indicates that the main control chip has failed, but the slave control chip has not failed, then the slave control chip is identified as the target control chip.
[0107] Meanwhile, as an optional implementation, priorities can be assigned to the master and slave functional buses separately. Furthermore, the priority of the master functional bus can be set to be higher than that of the slave functional bus.
[0108] Based on this, if the above-mentioned operating status indicates that the main functional bus has not failed, the above-mentioned main functional bus can be identified as the target functional bus.
[0109] Optionally, if the above operating state indicates that the master function bus has failed and the slave function bus has not failed, the slave function bus shall be identified as the target function bus.
[0110] In one embodiment, when sending control commands generated by the target control chip to the target function bus, in order for the functional component receiving the control commands to distinguish between the control chip and the function bus that sent the control commands, when the target control chip is the main control chip and the target function bus is the main function bus, the control commands generated by the main control chip can be directly sent out through the target function bus.
[0111] As an optional implementation, if the target control chip is determined to be a slave control chip, the slave control chip's slave control identifier can be obtained. This slave control identifier is an identifier used to characterize the slave control chip; it can be a unique identification code for the slave control chip, or any identifier used to characterize the slave control chip, such as characters, numbers, or symbols.
[0112] Based on this, the control commands generated from the control chip and the aforementioned slave control identifier can be sent to the aforementioned target function bus, so that the target function bus can send the control commands and slave control identifier outward.
[0113] Furthermore, if the target functional bus is determined to be a slave functional bus, the slave bus identifier of the slave functional bus can be obtained. The slave bus identifier is an identifier used to identify the slave functional bus. It can be a unique identifier for the slave functional bus, or other pre-set identifiers used to uniquely identify the slave functional bus, such as characters, numbers, or letters.
[0114] Then, the control commands, control identifiers, and bus identifiers from the control chip can be sent to the function bus, so that the function bus can send the aforementioned control commands, control identifiers, and bus identifiers outward.
[0115] As another optional implementation, when the target control chip is the master control chip, and the target functional bus is a slave functional bus, the slave bus identifier of the aforementioned slave functional bus can be obtained. Then, the control commands from the target control chip and the slave bus identifier can be sent to the slave functional bus, enabling the slave functional bus to send control commands and the slave bus identifier outwards.
[0116] Furthermore, when determining the control states of the master and slave control chips by obtaining their verification results, there may be instances where the results cannot be obtained. Therefore, if no verification results are obtained, it indicates that the control states of the master and slave control chips cannot be determined at this time. To ensure the safe operation of the domain controller, both the master and slave control chips can be designated as target control chips, and both the master and slave function buses can be designated as target function buses.
[0117] Based on this, when sending the control commands generated by the target control chip to the target function bus, the control commands of the master control chip can be sent to the master function bus, and the control commands generated by the slave control chip can be sent to the slave function bus.
[0118] Furthermore, if the verification results of the master and slave control chips cannot be obtained, it indicates that the communication interface between the master and slave control chips has failed. In this case, to ensure the safe operation of the domain controller, the time point of the communication interface failure can be determined, and the target control chip and target function bus can be identified based on the time point of the failure.
[0119] Optionally, if the above-mentioned fault time point is within the current operating cycle of the domain controller (i.e., the ignition cycle of the domain controller), then if the main control chip does not fail, the main control chip will be identified as the target control chip, and if the main function bus does not fail, the main function bus will be identified as the target function bus.
[0120] Optionally, if the fault occurs before the current operating cycle of the domain controller, the slave controller will be identified as the target controller if no fault occurs in the slave controller chip, and the slave function bus will be identified as the target function bus if no fault occurs in the slave function bus.
[0121] The technical solution provided in this application includes a vehicle domain controller comprising a master control chip and a slave control chip. The master control chip is connected to multiple different master function buses, and the slave control chip is connected to multiple different slave function buses. When the master control chip and the slave control chip are connected, and both the master control chip and the slave control chip generate corresponding control commands based on received sensor signals, the control state of the master control chip and the slave control chip, as well as the operating state of the master function buses and the slave function buses, are determined. Based on the control state, a target control chip is determined from the master control chip and the slave control chip. Based on the operating state, a target function bus is determined from the master function buses and the slave function buses. The control commands generated by the target control chip are sent to the target function bus, so that the vehicle operates according to the control commands output by the target function bus. This technical solution integrates multiple controllers in the vehicle's chassis domain into a single domain controller. Furthermore, to enhance the domain controller's security, it employs a dual-control chip redundancy control method with a master control chip and a slave control chip, as well as a dual-control bus transmission method with a master control bus and a slave control bus. This ensures that the domain controller can still operate safely and stably even if the control chip or control bus fails, thereby reducing controller costs while improving the domain controller's security and stability.
[0122] See Figure 3 This is a flowchart illustrating an embodiment of another vehicle operation control method provided in this application. Figure 3 The process shown is in Figure 1 Based on the illustrated process, this paper describes how fault detection and handling are specifically performed when the main control chip includes a functional failure detection module and a hardware fault detection module, and the main control chip is powered by the main power supply module. For example... Figure 3 As shown, the process may include the following steps:
[0123] Step 301: Detect whether there is a functional fault in the main control chip through the main control chip's functional fault detection module, and detect whether there is a hardware fault in the main control chip through the main control chip's hardware fault detection module.
[0124] The aforementioned functional fault detection module refers to the functional fault detection layer in the main control chip, which is used to detect whether there is a fault in the functional module of the main control chip.
[0125] The aforementioned hardware fault detection module refers to the hardware fault detection layer in the main control chip, which is used to detect whether there is a hardware fault in the main control chip.
[0126] In this embodiment, the main control chip may include a functional fault detection module and a hardware fault detection module. Based on this, in order to ensure that the main control chip can operate normally, the domain controller can detect the main control chip through the aforementioned functional fault detection module and hardware fault detection module, thereby determining whether there is a fault in the functional components of the main control chip and whether there is a fault in the hardware of the main control chip.
[0127] As an optional implementation, the domain controller can periodically detect whether the functional modules of the main control chip are faulty through the aforementioned functional fault detection module, and detect whether the main control chip has hardware faults through the hardware fault detection module.
[0128] As another optional implementation, the domain controller can detect whether the functional modules of the main control chip are faulty in real time through the aforementioned functional fault detection module, and detect whether the hardware of the main control chip is faulty through the hardware fault detection module.
[0129] As to how the aforementioned functional fault detection module specifically detects each function of the main control chip, it can be explained below. Figure 5 The process shown will be explained in detail here.
[0130] Step 302: When the main control chip's functional fault detection module detects a functional fault in the main control chip, and the hardware fault detection module detects a hardware fault in the main control chip, a preset fault signal is sent to the main power supply module so that the main power supply module updates the main control chip's operating state to a preset mode. When the main control chip is in the preset mode, the main control chip no longer processes the received sensor signals.
[0131] The aforementioned main power module refers to the power module that supplies power to the main control chip. It can be an SBC (System Basis Chip) power chip or other power chips; this application embodiment does not impose any limitations on this. In this application embodiment, the main power module not only supplies power to the main control chip but also serves as a monitoring module. When the main control chip sends a fault signal, it can promptly control the main control chip to enter a preset mode. When the main control chip is in the preset mode, it no longer processes the received sensor signals, meaning it no longer generates control commands.
[0132] In this embodiment, when the main control chip's functional failure detection module detects a functional failure in the main control chip, and the hardware failure detection module detects a hardware failure in the main control chip, it indicates that the main control chip is no longer able to execute safety-related logic normally. Therefore, in order to ensure the security of the domain controller, a preset fault signal can be sent to the main power module of the main control chip, so that the main power module updates the operating state of the main control chip to a preset mode, thereby ensuring that the main control chip no longer processes the received sensor signals.
[0133] The technical solution provided in this application uses a functional fault detection module to detect whether the main control chip has a functional fault, and a hardware fault detection module to detect whether the main control chip has a hardware fault. When both the functional fault detection module and the hardware fault detection module detect a functional fault, a preset fault signal is sent to the main power module. This causes the main power module to update the main control chip's operating state to a preset mode. When the main control chip is in this preset mode, it no longer processes received sensor signals. This technical solution uses the main power module of the main control chip as a monitoring module. When both the functional fault detection module and the hardware fault detection module detect faults in the main control chip's functional components and hardware, the main power module can update the main control chip's operating state to a preset mode, thereby preventing the main control chip from processing received sensor signals and ensuring the security of the domain controller.
[0134] See Figure 4 This is a flowchart illustrating another embodiment of a vehicle operation control method provided in this application. Figure 4 The process shown is in Figure 3 Based on the illustrated process, this paper describes how fault detection and handling are specifically performed when the control chip includes a functional fault detection module and a hardware fault detection module, and the control chip is powered by a power supply module. Figure 4 As shown, the process may include the following steps:
[0135] Step 401: Detect whether there is a functional fault in the control chip by using the functional fault detection module of the control chip, and detect whether there is a hardware fault in the control chip by using the hardware fault detection module of the control chip.
[0136] The aforementioned functional fault detection module refers to the functional fault detection layer in the control chip, which is used to detect whether there is a fault in the functional module of the control chip.
[0137] The aforementioned hardware fault detection module refers to the hardware fault detection layer in the control chip, which is used to detect whether there is a fault in the hardware of the control chip.
[0138] In this embodiment, the slave control chip may include a functional fault detection module and a hardware fault detection module. Based on this, in order to ensure that the slave control chip can operate normally, the domain controller can detect the slave control chip through the aforementioned functional fault detection module and hardware fault detection module, thereby determining whether there is a fault in the functional components of the slave control chip and whether there is a fault in the hardware of the slave control chip.
[0139] As an optional implementation, the domain controller can periodically detect whether the functional modules of the slave control chip are faulty through the aforementioned functional fault detection module, and detect whether there is a hardware fault in the slave control chip through the hardware fault detection module.
[0140] As another optional implementation, the domain controller can detect in real time whether the functional modules of the control chip are faulty through the aforementioned functional fault detection module, and detect whether there is a hardware fault in the control chip through the hardware fault detection module.
[0141] As to how the aforementioned functional fault detection module specifically detects each function of the control chip, it can be explained below. Figure 5 The process shown will be explained in detail here.
[0142] Step 402: When the functional fault detection module of the control chip detects a functional fault in the control chip and the hardware fault detection module detects a hardware fault in the control chip, a preset fault signal is sent to the power supply module so that the power supply module updates the operating state of the control chip to a preset mode. When the control chip is in the preset mode, the control chip no longer processes the received sensor signals.
[0143] The aforementioned power supply module refers to the power supply module that supplies power to the slave control chip. It can be an SBC power chip or other power chips, and this application embodiment does not impose any limitations on this. In this application embodiment, the slave power supply module not only supplies power to the slave control chip but also functions as a monitoring module. When the slave control chip sends a fault signal, it can promptly control the slave control chip to enter a preset mode. When the slave control chip is in the preset mode, it no longer processes the received sensor signals, meaning it no longer generates control commands.
[0144] In this embodiment, when the functional failure detection module of the slave control chip detects a functional failure of the slave control chip, and the hardware failure detection module detects a hardware failure of the slave control chip, it indicates that the slave control chip can no longer execute the safety-related logic normally. Therefore, in order to ensure the security of the domain controller, a preset fault signal can be sent to the slave power supply module of the slave control chip so that the slave power supply module updates the operating state of the slave control chip to a preset mode, so as to ensure that the slave control chip no longer processes the received sensor signals.
[0145] The technical solution provided in this application detects whether there is a functional fault in the control chip through a functional fault detection module and whether there is a hardware fault in the control chip through a hardware fault detection module. When both the functional and hardware fault detection modules detect a functional fault, a preset fault signal is sent to the power supply module. This causes the power supply module to update the operating state of the control chip to a preset mode. When the control chip is in this preset mode, it no longer processes received sensor signals. This technical solution uses the power supply module of the control chip as a monitoring module. When both the functional and hardware fault detection modules detect faults in the control chip's functional components and hardware, the power supply module can update the operating state of the control chip to a preset mode, thereby preventing the control chip from processing received sensor signals and ensuring the security of the domain controller.
[0146] See Figure 5 This is a flowchart illustrating another embodiment of a vehicle operation control method provided in this application. Figure 5 The process shown is in Figure 3 and Figure 4 Based on the illustrated process, this section describes how the main control chip's functional fault detection module specifically detects each function of the main control chip, and how the slave control chip's functional fault detection module specifically detects each function of the slave control chip. For example... Figure 5 As shown, the process may include the following steps:
[0147] Step 501: For each function of the control chip, determine the functional logic for generating control instructions corresponding to that function. The control chip mentioned above is either a master control chip or a slave control chip.
[0148] The aforementioned control chip refers to the master control chip or slave control chip in the domain controller, and Figure 5The process shown can be applied to both the detection of functional faults in the main control chip and the detection of functional faults in the slave control chip.
[0149] The aforementioned functional logic refers to the functional logic by which the control chip processes the sensor signal corresponding to the function when implementing the function. In other words, by processing the sensor signal through this functional logic, the control command corresponding to the function can be generated.
[0150] The aforementioned functions refer to the functions that the control chip can perform. The control chip may include a functional layer, which may include multiple functions implemented by the control chip, including but not limited to: service braking function, EPB (Electrical Park Brake) left and right functions, SBW (Steering By Wire) electric adjustment function, SBW hand-feel analog motor (three-phase) function, SBW steering actuator motor, air spring, CDC (Continuous Damping Control) system, and drive motor control command function, etc.
[0151] In this embodiment of the application, when the control chip is running, there may be a corresponding functional logic for each function. Based on this, when the function of the control chip is detected by the functional fault detection module, the functional logic corresponding to each function can be determined.
[0152] As an optional implementation, the main control chip can pre-store the correspondence between each function and its functional logic in a preset storage medium. Based on this, when determining the functional logic of each function, the functional logic of the function can be determined from the correspondence stored in the aforementioned storage medium.
[0153] Step 502: Obtain the analog sensor signals corresponding to the functions mentioned above generated by the simulator.
[0154] Step 503: Process the simulator sensor signals according to the above functional logic to obtain the control command range corresponding to the above functions.
[0155] The following provides a unified explanation of steps 502 and 503:
[0156] The aforementioned simulator is used to simulate various sensor signals inside a vehicle.
[0157] The aforementioned simulated sensor signals are sensor signals generated by the simulator, not sensor signals generated by actual sensors. There may be one or more simulated sensor signals; this embodiment does not impose any limitation on this.
[0158] In this embodiment of the application, for each function of the control chip, a simulator can be used to simulate the sensor signals required for that function (hereinafter referred to as "simulated sensor signals" for easy distinction), and then the simulated sensor signals can be processed according to the functional logic corresponding to that function to obtain the control command range corresponding to that function.
[0159] Furthermore, to ensure the accuracy of the defined range of control commands, the tree simulator can simulate all the analog sensor signals required for this function.
[0160] Step 504: Determine whether the control instructions actually generated by the control chip are within the range of the above control instructions. If yes, proceed to step 505; otherwise, proceed to step 506.
[0161] Step 505: Confirm that the above functions are not faulty.
[0162] Step 506: Determine if the above functions are faulty.
[0163] The following provides a unified explanation of steps 504 to 506:
[0164] The aforementioned control commands refer to the control commands generated by the control chip for this function based on the actual sensor signals received.
[0165] In this embodiment of the application, for each function of the control chip, it is determined whether the control instructions actually generated by the control chip for that function are within the range of the aforementioned control instructions.
[0166] Optionally, if the above control instructions are within the range of the above control instructions, it indicates that the control chip generates control instructions for this function relatively accurately, and therefore it can be determined that the above function is not faulty.
[0167] Conversely, if the control command is not within the range of control commands, it indicates that the control command generated by the control chip for this function is inaccurate, and therefore it can be determined that the function is faulty.
[0168] The technical solution provided in this application, for each function of the control chip, determines the functional logic corresponding to that function for generating control instructions. The control chip, either as a main control chip or a slave control chip, obtains the analog sensor signals corresponding to the function generated by the simulator. The simulator sensor signals are processed according to the functional logic to obtain the control instruction range corresponding to the function. It then determines whether the control instructions actually generated by the control chip fall within this range. If so, the function is determined to be fault-free; otherwise, a fault is determined to exist. This technical solution utilizes a simulator to simulate the analog sensor signals required for each function of the control chip, and uses the analog sensor signals and the corresponding functional logic to determine the control instruction range for each function. This allows for a comparison between the control instructions actually generated by the control chip for that function and the control instruction range, thus determining whether each function of the control chip is faulty. This achieves efficient and accurate fault detection of the control chip's functions.
[0169] Furthermore, to facilitate understanding of the domain controller provided in this application, the detailed architecture of the domain controller is described below:
[0170] See Figure 6 This is a schematic diagram of another domain controller provided in an embodiment of this application. Figure 6 As shown, the domain controller may include a master MCU (Microcontroller Unit) and a slave MCU, wherein both the master and slave chips and the power supply chip adopt the ASILD level and share the IGN power supply (wake-up power supply) to ensure the synchronization of the two chips.
[0171] The communication between the two MCUs uses high-speed SPI to ensure real-time control. The power chip can be used as a monitoring module to put the control chip into a preset mode when a functional or hardware failure occurs, so that the control chip no longer processes the received sensor signals and generates control commands.
[0172] Furthermore, to ensure that the entire controller system meets ASILD's functional safety requirements, the control strategy for the master and slave chips adopts a three-layer architecture to achieve functional monitoring, hardware monitoring, and program flow monitoring:
[0173] 1) The L1 layer is the function implementation layer, which completes the specific function implementation. For example, for the chassis domain controller, this layer implements the air suspension height adjustment function, shock absorber damping adjustment function, basic braking function, basic steering function, etc., which may include but are not limited to: service braking function, EPB left and right function, SBW electric adjustment function, SBW hand-feel analog motor (three-phase) function, SBW steering actuator motor, air spring, CDC, and drive motor control command function, etc.
[0174] 2) Layer L2 is the functional monitoring layer, used to monitor whether the L1 functions are operating normally. Layer L2 is designed with a set of functional logic to determine whether L1 is operating normally. The functional logic for determining whether L1 is operating normally is related to the monitored functions. Different monitored functions have different functional logic, such as through software diversity redundancy or rationality checks.
[0175] For example, in the basic braking function, when L2 uses the rationality verification method to determine whether the L1 function is operating normally, it first calculates the reasonable range of braking force output based on the signal input from the pedal displacement sensor on the brake pedal simulator, then calculates the actual output quantity fed back from the actuator, and finally determines whether the actual output braking force of L1 is within the allowable reasonable range. If it exceeds the reasonable range, the L1 function is determined to be abnormal, and error handling is performed.
[0176] 3) The L3 layer controller monitoring layer mainly consists of three functional parts:
[0177] Hardware diagnostics for electronic and electrical systems: This involves monitoring hardware faults in electronic and electrical systems. To achieve this, safety islands are defined on both the master and slave chips. When a functional safety fault occurs in the master chip, such as a CPU core fault, RAM fault, or ROM fault in the controller, the information is transmitted through the safety island to the slave chip's failback module. This enables the slave chip's backup control strategy to take over the vehicle's braking, steering, and drive systems. Simultaneously, the fault is reported, alerting the driver to danger and urging caution. A failure of the master chip does not directly lead to a violation of safety objectives; only a combined failure of both the master and slave chips directly violates functional safety objectives. When a functional safety fault occurs in the slave chip, the master chip continues to operate normally. The failback module receives the fault information, reports the fault, and alerts the driver to danger and urges caution.
[0178] Independent monitoring: When a controller-related fault occurs, the controller can no longer reliably execute safety-related logic. To ensure safety, the power chip is used as a monitoring MCU to ensure that even if the MCU experiences a serious fault, it can still enter a safe state.
[0179] Application Flow Check: Monitors whether the L1 and L2 monitoring programs are running normally. This is achieved by binding the application flow check to the watchdog timer. If the L1 and L2 related monitoring programs do not run in the set order or do not execute within the specified time, the application flow check fails, the watchdog timer cannot be fed normally, and the system enters a safe state.
[0180] In one embodiment, based on the above-described domain controller, a corresponding fail-safe mechanism may exist to ensure the security of the domain controller:
[0181] Optionally, when there are no failures (i.e., neither the master MCU nor the slave MCU is faulty), the master CAN on the master MCU (including private CANs of domain controller peripheral components such as control CAN1, steering CAN1, drive CAN1, and suspension CAN1, as well as common CANs such as CHCAN and EP CAN1) sends drive, steering, braking, and suspension control commands to the motor, steering system, braking system, and suspension system, and sends the control commands of the chassis domain controller to CH CAN and EP CAN1.
[0182] The MCU sends drive, steering, braking, and suspension control commands from the CAN (including private CANs of domain controller peripherals such as control CAN2, steering CAN2, drive CAN2, and suspension CAN2, as well as public CANs such as RNDT CAN and EP CAN2) to the motor, steering system, braking system, and suspension system, and sends the control commands of the chassis domain controller to RNDT CAN and EPCAN2.
[0183] The master and slave MCUs can perform fault verification via SPI, and then determine which controller will send control commands externally. Generally, both controllers are not allowed to send control commands simultaneously. Nor is it allowed for a single controller to send control commands to both the master and slave CAN buses simultaneously. The master and slave MCUs perform verification via two CAN buses; if one CAN bus fails, the master-slave verification can still be completed.
[0184] When the master MCU and slave MCU cannot determine each other's failure status for some reason, the master MCU and slave MCU need to send control commands to the domain controller peripheral components via master CAN and slave CAN respectively. The master MCU and slave MCU send requests through two CAN channels, which provides a higher degree of redundancy.
[0185] When there are no failures, the main MCU sends control commands to peripheral components via the main CAN bus. When the main CAN bus fails, the main MCU sends control commands to peripheral components via the CAN bus.
[0186] The slave MCU is only allowed to send braking requests when the master MCU fails completely.
[0187] In this process, the master MCU sends control commands via CAN and simultaneously sends a CAN takeover flag to the peripheral components. When the slave MCU sends control commands, it should send the slave takeover flag to the peripheral components. After taking over, the slave MCU needs to send a request via CAN, and should simultaneously send the CAN takeover flag. The peripheral components only use these flags to determine their response to the master and slave MCU control commands; no further arbitration is required.
[0188] Furthermore, the two redundant SPI communications are configured such that if a fault occurs in the current ignition cycle, the master MCU will control and record the SPI communication fault; if the fault occurs in the previous ignition cycle or at the ignition synchronization moment, the slave MCU will act as the master and execute the slave MCU control instructions.
[0189] The domain controller provided in this application embodiment is based on the functional safety objectives and the highest vehicle safety integrity level of the chassis domain controller, as well as the hardware resource deployment method for the chassis domain controller to implement the functions of the steer-by-wire suspension system, steer-by-wire system, and steer-by-wire system. This jointly confirms the functional safety architecture of the chassis domain controller, thereby reducing the controller cost while improving the safety and stability of the domain controller.
[0190] See Figure 7 This is a block diagram illustrating an embodiment of a vehicle operation control device provided in this application. As one embodiment, Figure 7 The illustrated device can be applied to a vehicle's domain controller, which includes a master control chip and slave control chips. The master control chip is connected to multiple different master function buses, and the slave control chips are connected to multiple different slave function buses. The master control chip and the slave control chips are interconnected. Figure 7 As shown, the device may include:
[0191] The first determining module 71 is used to determine the control state of the main control chip and the slave control chip, and to determine the operating state of the main functional bus and the slave functional bus, when both the main control chip and the slave control chip generate corresponding control commands based on the received sensor signals.
[0192] The second determining module 72 is used to determine the target control chip from the main control chip and the slave control chip according to the control state;
[0193] The third determining module 73 is used to determine the target function bus from the main function bus and the slave function bus according to the operating state;
[0194] The sending module 74 is used to send the control commands generated by the target control chip to the target function bus so that the vehicle runs according to the control commands output by the target function bus.
[0195] like Figure 8 The diagram shown is a structural schematic of a vehicle according to an embodiment of this application, including a processor 81, a communication interface 82, a memory 83, and a communication bus 84. The processor 81, communication interface 82, and memory 83 communicate with each other via the communication bus 84.
[0196] Memory 83 is used to store computer programs;
[0197] In one embodiment of this application, when the processor 81 executes the program stored in the memory 83, it implements the vehicle operation control method provided in any of the foregoing method embodiments. This method can be applied to... Figure 1 or Figure 6 The domain controller shown includes a master control chip and a slave control chip. The master control chip is connected to multiple different master function buses, and the slave control chip is connected to multiple different slave function buses. The master control chip and the slave control chip are connected, including:
[0198] When both the master control chip and the slave control chip generate corresponding control commands based on the received sensor signals, the control states of the master control chip and the slave control chip are determined, as well as the operating states of the master functional bus and the slave functional bus are determined.
[0199] Based on the control state, the target control chip is determined from the master control chip and the slave control chip;
[0200] Based on the operating status, the target function bus is determined from the master function bus and the slave function bus;
[0201] The control commands generated by the target control chip are sent to the target function bus so that the vehicle operates according to the control commands output by the target function bus.
[0202] This application also provides a storage medium storing a computer program thereon, which, when executed by a processor, implements the steps of the vehicle operation control method provided in any of the foregoing method embodiments.
[0203] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0204] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented using software and a general-purpose hardware platform, or of course, using hardware. Based on this understanding, the above technical solutions, in essence or the parts that contribute to the related technology, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0205] It should be understood that the terminology used herein is for the purpose of illustrating specific embodiments of the text only and is not intended to be limiting. Unless the context clearly indicates otherwise, the singular forms “a,” “an,” and “described” as used herein may also include the plural forms. The terms “comprising,” “including,” “containing,” and “having” are inclusive and therefore indicate the presence of the stated features, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, elements, components, and / or combinations thereof. The method steps, processes, and operations described herein are not construed as requiring them to be performed in the specific order described or illustrated unless the order is explicitly indicated. It should also be understood that additional or alternative steps may be used.
[0206] The above description is merely a specific embodiment of the present invention, enabling those skilled in the art to understand or implement the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the present invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features claimed herein.
Claims
1. A method for controlling vehicle operation, characterized in that, A domain controller for vehicles, the domain controller including a master control chip and a slave control chip, the master control chip being connected to multiple different master function buses, the slave control chip being connected to multiple different slave function buses, the master control chip and the slave control chip being connected, the method including: When both the master control chip and the slave control chip generate corresponding control commands based on the received sensor signals, the control states of the master control chip and the slave control chip are determined, as well as the operating states of the master functional bus and the slave functional bus are determined. Based on the control state, the target control chip is determined from the master control chip and the slave control chip; Based on the operating status, the target function bus is determined from the master function bus and the slave function bus; The control commands generated by the target control chip are sent to the target function bus so that the vehicle operates according to the control commands output by the target function bus. The master control chip and the slave control chip are connected through a preset communication interface; determining the control state of the master control chip and the slave control chip includes: obtaining the verification result of the verification between the master control chip and the slave control chip; and determining the control state of the master control chip and the slave control chip based on the verification result. If the verification result is not obtained, determine the time point at which the communication interface malfunctioned; If the fault time point is within the current operating cycle of the domain controller, then if the main control chip does not fail, the main control chip is identified as the target control chip, and if the main function bus does not fail, the main function bus is identified as the target function bus. If the fault time point is before the current operating cycle of the domain controller, then if the slave control chip does not fail, the slave control chip is identified as the target control chip, and if the slave function bus does not fail, the slave function bus is identified as the target function bus.
2. The method according to claim 1, characterized in that, The method further includes: When the verification result cannot be obtained, both the master control chip and the slave control chip are identified as the target control chip, and both the master function bus and the slave function bus are identified as the target function bus. Sending the control commands generated by the target control chip to the target functional bus includes: The control commands generated by the main control chip are sent to the main function bus, and the control commands generated by the slave control chip are sent to the slave function bus.
3. The method according to claim 1, characterized in that, The step of determining the target control chip from the master control chip and the slave control chip based on the control state includes: If the control state indicates that the main control chip has not malfunctioned, the main control chip is identified as the target control chip. If the control state indicates that the main control chip has failed and the slave control chip has not failed, the slave control chip is identified as the target control chip.
4. The method according to claim 1, characterized in that, The step of determining the target function bus from the master function bus and the slave function bus based on the operating state includes: If the operating state indicates that the main functional bus has not failed, the main functional bus is identified as the target functional bus. If the operating state indicates that the master functional bus has failed and the slave functional bus has not failed, the slave functional bus is identified as the target functional bus.
5. The method according to claim 1, characterized in that, Sending the control commands generated by the target control chip to the target functional bus includes: If the target control chip is determined to be a slave control chip, the slave control identifier of the slave control chip is obtained; The control command generated from the control chip and the slave control identifier are sent to the target function bus, so that the target function bus sends the control command and the slave control identifier outward; And / or, If the target functional bus is determined to be a slave functional bus, the slave bus identifier of the slave functional bus is obtained; The control command of the target control chip and the slave bus identifier are sent to the slave function bus, so that the slave function bus sends the control command and the slave bus identifier outward.
6. The method according to claim 1, characterized in that, Both the master control chip and the slave control chip include a functional fault detection module and a hardware fault detection module. The master control chip is powered by a master power supply module, and the slave control chip is powered by a slave power supply module. The functional fault detection module is used to detect whether there is a fault in the functional module of the master control chip or the slave control chip, and the hardware fault detection module is used to detect whether there is a hardware fault in the master control chip or the slave control chip. The method further includes: When the main control chip's functional fault detection module detects a functional fault in the main control chip, and the hardware fault detection module detects a hardware fault in the main control chip, a preset fault signal is sent to the main power module so that the main power module updates the main control chip's operating state to a preset mode. When the main control chip is in the preset mode, the main control chip no longer processes the received sensor signals. When the functional fault detection module of the slave control chip detects a fault in the functional module of the slave control chip, and the hardware fault detection module detects a hardware fault in the slave control chip, a preset fault signal is sent to the slave power supply module so that the slave power supply module updates the operating state of the slave control chip to a preset mode. When the slave control chip is in the preset mode, the slave control chip no longer processes the received sensor signals.
7. The method according to claim 6, characterized in that, The functional fault detection module detects each function of the control chip in the following ways: For each function of the control chip, the functional logic for generating control instructions corresponding to the function is determined, and the control chip is either a master control chip or a slave control chip. Obtain the analog sensor signals corresponding to the functions generated by the simulator; The analog sensor signal is processed according to the functional logic to obtain the control command range corresponding to the function; Determine whether the control commands actually generated by the control chip are within the range of control commands; If it is determined that the control commands actually generated by the control chip are within the range of the control commands, it is determined that the function is not faulty; If it is determined that the control command actually generated by the control chip is not within the range of control commands, then the function is deemed to be faulty.
8. A control device for vehicle operation, characterized in that, A domain controller for vehicles, the domain controller including a master control chip and a slave control chip, the master control chip being connected to multiple different master function buses, the slave control chip being connected to multiple different slave function buses, the master control chip and the slave chip being connected, the device comprising: The first determining module is used to determine the control state of the main control chip and the slave control chip, and the operating state of the main functional bus and the slave functional bus, when both the main control chip and the slave control chip generate corresponding control commands based on the received sensor signals. The second determining module is used to determine the target control chip from the main control chip and the slave control chip according to the control state; The third determining module is used to determine the target function bus from the main function bus and the slave function bus according to the operating state; The transmitting module is used to send the control commands generated by the target control chip to the target function bus, so that the vehicle runs according to the control commands output by the target function bus; The master control chip and the slave control chip are connected through a preset communication interface; determining the control state of the master control chip and the slave control chip includes: obtaining the verification result of the verification between the master control chip and the slave control chip; and determining the control state of the master control chip and the slave control chip based on the verification result. If the verification result is not obtained, determine the time point at which the communication interface malfunctioned; If the fault time point is within the current operating cycle of the domain controller, then if the main control chip does not fail, the main control chip is identified as the target control chip, and if the main function bus does not fail, the main function bus is identified as the target function bus. If the fault time point is before the current operating cycle of the domain controller, then if the slave control chip does not fail, the slave control chip is identified as the target control chip, and if the slave function bus does not fail, the slave function bus is identified as the target function bus.
9. A vehicle, characterized in that, include: Domain controllers and memory, The domain controller includes a master control chip and a slave control chip. The master control chip is connected to multiple different master function buses, and the slave control chip is connected to multiple different slave function buses. The master control chip and the slave control chip are connected. The domain controller is used to execute the vehicle operation control program stored in the memory to implement the vehicle operation control method according to any one of claims 1 to 7.
10. A storage medium, characterized in that, The storage medium stores one or more programs, which can be executed by one or more processors to implement the vehicle operation control method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Electric power steering control system
CN113120071A
Vehicle chassis, electric vehicle and control method
CN117657287A