Vehicle domain control system and vehicle

By introducing safety monitoring, fault diagnosis, and safety degradation modules into the vehicle domain control system, the system can monitor and respond to faults in real time, thus solving the problem of insufficient safety performance of the domain controller, achieving high reliability and functional safety, and meeting ASIL D level.

CN119428728BActive Publication Date: 2025-11-04CHENGDU TIANFU INVO TECHNOLOGY CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202411845291.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-13
Publication Date
2025-11-04
Estimated Expiration
2044-12-13

AI Technical Summary

Technical Problem

Traditional distributed automotive electronic controllers cannot meet the needs of vehicle intelligence. Domain controller chips have a high error rate, and the security performance of vehicle domain control systems is insufficient. There is an urgent need to improve functional safety and reliability.

Method used

Design a vehicle domain control system that includes a safety monitoring module, a fault diagnosis module, and a safety degradation module. The system monitors operating parameters in real time, determines the severity level of faults, and takes corresponding degradation measures to reduce potential safety risks. The system adopts a modular and hierarchical design to isolate safety and non-safety domains to ensure functional safety.

Benefits of technology

It improves the functional safety and reliability of the vehicle domain control system, enabling timely response and reduction of safety risks in the event of a fault, and meets the highest safety level requirement ASIL D.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119428728B_ABST
    Figure CN119428728B_ABST
Patent Text Reader

Abstract

The present disclosure provides a vehicle domain control system and a vehicle, and relates to the technical field of domain controller. The vehicle domain control system comprises a safety monitoring module, a fault diagnosis module and a safety degradation module. The safety monitoring module is configured to monitor operating parameters of the vehicle domain control system, and generate first fault information in the case of monitoring abnormal operating parameters; the fault diagnosis module is configured to determine a first fault severity level of the vehicle domain control system based on the first fault information, and the first fault severity level is positively correlated with the fault severity of the vehicle domain control system; and the safety degradation module is configured to determine a target safety state matched with the first fault severity level and a current safety state in which the vehicle domain control system currently locates, and control the vehicle domain control system to change from the current safety state to the target safety state in the case that the fault severity level corresponding to the current safety state is lower than the first fault severity level, so as to improve the functional safety and reliability of the vehicle domain control system.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of domain controller, in particular to a vehicle domain control system and a vehicle. BACKGROUND

[0002] With the increasing degree of electronicization and the diversification of functions of vehicles, the application of automatic driving and other intelligent modules makes vehicles need more sensors and processors. The traditional distributed automobile electronic controller has been insufficient to meet the intelligent needs of vehicles, and the more integrated and intelligent solution-domain controller has emerged as the times require.

[0003] The domain controller needs to process data from various sensors in real time and implement complex intelligent functions, which undoubtedly increases the error rate of domain controller chip operation. As the core of the automatic driving system, the safety performance of the domain controller has become a problem that must be paid attention to. At present, the design of the vehicle domain control system is more inclined to consider the implementation of functions and performance improvement, therefore, there is an urgent need for a vehicle domain control system that meets the functional safety requirements. SUMMARY

[0004] Therefore, the embodiments of the present disclosure provide a vehicle domain control system and a vehicle to improve the functional safety and reliability of the vehicle domain control system.

[0005] In a first aspect, a vehicle domain control system is provided, comprising a safety monitoring module, a fault diagnosis module and a safety degradation module. The safety monitoring module is configured to monitor operating parameters of the vehicle domain control system, and generate first fault information in the case of monitoring abnormal operating parameters; the fault diagnosis module is configured to determine a first fault severity level of the vehicle domain control system based on the first fault information, the first fault severity level being positively correlated with the fault severity of the vehicle domain control system; and the safety degradation module is configured to determine a target safety state matched with the first fault severity level and a current safety state in which the vehicle domain control system currently locates, and control the vehicle domain control system to change from the current safety state to the target safety state in the case that the fault severity level corresponding to the current safety state is lower than the first fault severity level.

[0006] In combination with the first aspect, in some implementations of the first aspect, the safety monitoring module is further configured to monitor a fault module corresponding to the abnormal operating parameters; and generate second fault information corresponding to the current operating parameters of the fault module in the case that the current operating parameters of the fault module change compared with the abnormal operating parameters; and the fault diagnosis module is further configured to determine a second fault severity level of the vehicle domain control system based on the second fault information.

[0007] With reference to the first aspect, in some implementations of the first aspect, the safety degradation module is further configured to: in a case where the second fault severity level characterizes that the vehicle domain control system is normally operating, control the vehicle domain control system to transit from the target safety state to a normal operating state.

[0008] With reference to the first aspect, in some implementations of the first aspect, the safety monitoring module is further configured to: monitor other operating parameters in the vehicle domain control system in addition to the abnormal operating parameter; in a case where the other operating parameters are abnormal, generate third fault information; and the fault diagnosis module is further configured to generate a third fault severity level of the vehicle domain control system based on the first fault information and the third fault information.

[0009] With reference to the first aspect, in some implementations of the first aspect, the vehicle domain control system comprises a functional safety domain and a non-functional safety domain, the safety monitoring module, the fault diagnosis module and the safety degradation module are deployed in the functional safety domain, and the fault module corresponding to the abnormal operating parameter is deployed in the non-functional safety domain; wherein the functional safety domain and the non-functional safety domain are decoupled to ensure that the operation of the safety monitoring module, the fault diagnosis module and the safety degradation module is not interfered by the non-functional safety domain.

[0010] With reference to the first aspect, in some implementations of the first aspect, the target safety state comprises any one of a first degradation state, a second degradation state, a third degradation state and a fourth degradation state, and the fault severity levels corresponding to the first degradation state, the second degradation state, the third degradation state and the fourth degradation state are sequentially increased; wherein in a case where the vehicle domain control system is in the first degradation state, the vehicle domain control system is normally operating; in a case where the vehicle domain control system is in the second degradation state, the vehicle domain control system is normally operating, and the safety degradation module generates fault reminder information corresponding to the first fault information; in a case where the vehicle domain control system is in the third degradation state, the safety degradation module generates a first communication management request, and generates fault reminder information corresponding to the first fault information and a first takeover request, and the first communication management request comprises a request to cut off external communication of the fault module corresponding to the abnormal operating parameter; and in a case where the vehicle domain control system is in the fourth degradation state, the safety degradation module generates a second communication management request, and generates fault reminder information corresponding to the first fault information and a second takeover request, and the second communication management request comprises a request to cut off external communication of all functional implementation modules in the vehicle domain control system.

[0011] With reference to the first aspect, in some implementations of the first aspect, the vehicle domain control system comprises a functional safety domain and a non-functional safety domain, the functional safety domain is decoupled from the non-functional safety domain, the safety monitoring module, the fault diagnosis module and the safety degradation module are deployed in the functional safety domain, and the fault module and the function implementation module are deployed in the non-functional safety domain; wherein the functional safety domain further comprises: a communication management module configured to, in response to a first communication management request, cut off external communication of the fault module; and / or, in response to a second communication management request, cut off external communication of all function implementation modules in the vehicle domain control system.

[0012] With reference to the first aspect, in some implementations of the first aspect, the vehicle domain control system comprises a functional safety domain and a non-functional safety domain, the functional safety domain is decoupled from the non-functional safety domain, the safety monitoring module, the fault diagnosis module and the safety degradation module are deployed in the functional safety domain; wherein the safety monitoring module comprises a system monitoring submodule, and the non-functional safety domain comprises a function implementation module; the system monitoring submodule is configured to monitor the function implementation module, reset the function implementation module in the case that the function implementation module has a fault, and generate fault information corresponding to the function implementation module having the fault; and / or the system monitoring submodule is further configured to periodically generate a running state signal, and stop generating the running state signal in the case that the function implementation module having the fault is still faulty after being reset, so that an external monitoring module outside the vehicle domain control system resets the vehicle domain control system when the generation of the running state signal is stopped.

[0013] With reference to the first aspect, in some implementations of the first aspect, the safety monitoring module comprises: a power supply monitoring submodule configured to monitor whether a power supply of the vehicle domain control system has an abnormality by sampling and calculating a power supply voltage of the power supply, and generate fault information corresponding to the power supply in the case that the power supply has the abnormality; and / or a temperature monitoring submodule configured to monitor whether an ambient temperature of the vehicle domain control system has an abnormality by sampling and calculating the ambient temperature, and generate fault information corresponding to the ambient temperature in the case that the ambient temperature has the abnormality.

[0014] The second aspect provides a vehicle comprising the vehicle domain control system provided in the first aspect.

[0015] In the vehicle domain control system provided in this disclosure, the security monitoring module monitors the operating parameters of the vehicle domain control system in real time; the fault diagnosis module determines the first fault severity level of the vehicle domain control system based on the first fault information determined by the security monitoring module; and the security degradation module enables the vehicle domain control system to take corresponding fault response measures based on the first fault severity level, thereby reducing the potential security risks to the vehicle domain control system caused by the fault indicated by the first fault information, and enabling the software architecture of the vehicle domain control system to have functional security. Attached Figure Description

[0016] Figure 1 The diagram shown is a structural schematic of a vehicle domain control system provided in an embodiment of this disclosure.

[0017] Figure 2 The diagram shown is a structural schematic of a vehicle domain control system provided in another embodiment of this disclosure.

[0018] Figure 3 The diagram shown is a structural schematic of a vehicle domain control system provided in another embodiment of this disclosure. Detailed Implementation

[0019] The technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this disclosure, and not all embodiments. Based on the embodiments of this disclosure, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this disclosure.

[0020] Figure 1 The diagram shown is a structural schematic of a vehicle domain control system provided in an embodiment of this disclosure. Figure 1 As shown, in this embodiment, the vehicle domain control system 100 includes a safety monitoring module 111, a fault diagnosis module 112, and a safety degradation module 113. The safety monitoring module 111 is communicatively connected to the fault diagnosis module 112, and the fault diagnosis module 112 is communicatively connected to the safety degradation module 113.

[0021] In addition to the aforementioned safety monitoring module 111, fault diagnosis module 112, and safety degradation module 113, the vehicle domain control system 100 may also include a function implementation module 121, a middleware module 122, etc.

[0022] The function implementation module 121 is configured to implement various auxiliary driving functions of the vehicle, which can be customized according to actual needs. For example, the function implementation module 121 can include a fusion perception module, a positioning module, a prediction module, a regulation and control module, a state machine management module, and the like. For example, the fusion perception module can perceive the environment around the vehicle by integrating data of various sensors (such as lidar, camera, etc.), and provide a comprehensive understanding of the surrounding environment; the positioning module can determine the accurate position coordinates of the vehicle based on positioning signals.

[0023] The middleware module 122 can provide standardized interfaces and services for different function implementation modules 121. The main function of the middleware module 122 is to shield the complexity of the underlying hardware of the domain controller, and help various function implementation modules 121 to run on different hardware platforms without the need to adjust for specific hardware. For example, the middleware module 122 can include a database middleware module, a message queue middleware module, and the like.

[0024] The safety monitoring module 111 is configured to monitor the operating parameters of the vehicle domain control system 100, and generate first fault information when an abnormal operating parameter is monitored.

[0025] The operating parameters of the vehicle domain control system 100 include power voltage signals, environmental temperature, clock signals, available space of memory, read and write operations of stored data, and the like of the vehicle domain control system 100. In an embodiment, the operating parameters of the vehicle domain control system 100 can be the operating parameters of each module included in the vehicle domain control system 100. For example, the operating parameters also include the operating parameters of the function implementation module 121 and the middleware module 122, such as operating cycle parameters, operating time parameters, data flow, control flow and execution flow parameters during operation, and the like.

[0026] During the process of monitoring the operating parameters by the safety monitoring module 111, if a certain operating parameter exceeds the normal threshold range corresponding to the operating parameter, the operating parameter is an abnormal operating parameter; for example, when the power voltage signal is monitored to be out of the rated voltage range, the power voltage signal is an abnormal operating parameter. Alternatively, the operating parameter can be processed to determine whether the operating parameter is abnormal; for example, the clock frequency is calculated according to the clock signal, and when the calculated clock frequency does not match the normal clock frequency, the clock signal is an abnormal operating parameter. Alternatively, when the operating parameters of the function implementation module 121 or the middleware module 122 represent that the function implementation module 121 or the middleware module 122 has a running failure, it is determined that the operating parameter is an abnormal operating parameter; for example, when the operating time parameter exceeds the normal time range, the operating time parameter is an abnormal operating parameter.

[0027] In a case where the safety monitoring module 111 monitors an abnormal running parameter, first fault information is generated based on the abnormal running parameter, and the first fault information is sent to the fault diagnosis module 112. The first fault information records the abnormal running parameter and related information of the abnormal running parameter, such as the generation time of the abnormal running parameter, the description information of the abnormal running parameter, the fault module corresponding to the abnormal running parameter, and the like.

[0028] The fault diagnosis module 112 is configured to determine a first fault severity level of the vehicle domain control system 100 based on the first fault information.

[0029] Specifically, when the safety monitoring module 111 monitors an abnormal running parameter, it indicates that the vehicle domain control system 100 has a fault. At this time, the fault diagnosis module 112 can analyze the fault occurrence position, fault duration, and the impact of the fault on the functional safety of the vehicle domain control system 100 according to the first fault information, and comprehensively determine the first fault severity level of the vehicle domain control system 100.

[0030] The first fault severity level is positively correlated with the fault severity of the vehicle domain control system 100. The higher the first fault severity level, the more severe the current fault severity of the vehicle domain control system 100. Illustratively, a plurality of fault severity levels can be set according to different fault types or the impact of the fault on the functional safety. For example, when the first fault severity level is the lowest fault severity level, the vehicle domain control system 100 can operate normally; when the first fault severity level is the highest fault severity level, the vehicle domain control system 100 is completely disabled and cannot work.

[0031] The first fault severity level is determined based on the first fault information. For example, in determining the first fault severity level, the duration of the fault can be considered. Illustratively, the duration of the fault is determined based on the first fault information, and the fault is divided into “instantaneous fault” or “continuous fault” based on the duration of the fault, and the fault severity level corresponding to the “instantaneous fault” is lower than the fault severity level corresponding to the “continuous fault”.

[0032] Alternatively, in determining the first fault severity level, the impact range of the fault on the vehicle domain control system 100 can be considered. Illustratively, the affected auxiliary driving function of the fault is determined based on the first fault information, and the more auxiliary driving functions affected by the fault, the higher the fault severity level. If the fault is very serious, so that the fault diagnosis module 112 cannot accurately determine the affected auxiliary driving function of the vehicle domain control system 100, the first fault severity level is determined to be the highest fault severity level.

[0033] It can be understood that the above-mentioned enumerated manner of determining the first fault severity level based on the fault duration and / or the influence range is only illustrative, and those skilled in the art can design it according to actual needs. In addition to the fault duration and the influence range on the auxiliary driving function, the first fault severity level can also be determined based on other influencing factors, as long as the first fault information and the first fault severity level have a corresponding relationship, and the present disclosure does not make specific limitations thereto.

[0034] After determining the first fault severity level, the fault diagnosis module 112 sends the first fault severity level to the safety degradation module 113.

[0035] The safety degradation module 113 is configured to determine a target safety state matched with the first fault severity level, and a current safety state in which the vehicle domain control system currently locates. In the case that the fault severity level corresponding to the current safety state is lower than the first fault severity level, the vehicle domain control system is controlled to change from the current safety state to the target safety state. The vehicle domain control system 100 sets multiple safety states respectively for different levels of fault severity levels. Among them, the safety state is a safe operation mode adopted by the vehicle domain control system 100 to cope with faults, so as to reduce the safety risk caused by the fault to the vehicle domain control system 100.

[0036] There is a corresponding relationship between the fault severity level and the safety state of the vehicle domain control system 100. Based on this, after receiving the first fault severity level, the safety degradation module 113 can determine the safety state matched with the first fault severity level as the target safety state based on the first fault severity level.

[0037] The safety degradation module 113 can also determine the current safety state in which the vehicle domain control system 100 currently locates. The current safety state refers to the safety state in which the vehicle domain control system 100 locates before the corresponding fault response measure is taken for the first fault information.

[0038] The current safety state is also one of the multiple safety states preset by the vehicle domain control system 100, so the fault severity level corresponding to the current safety state can be determined. By comparing the fault severity level corresponding to the current safety state with the first fault severity level, if the fault severity level corresponding to the current safety state is lower than the first fault severity level, it indicates that the fault shown by the first fault information will have a greater impact on the functional safety of the vehicle domain control system 100, and the current safety state in which the vehicle domain control system 100 currently locates is insufficient to cope with. At this time, the safety degradation module 113 needs to control the vehicle domain control system 100 to change from the current safety state to the target safety state, so as to reduce the safety risk faced by the vehicle domain control system 100.

[0039] If the fault severity level corresponding to the current safety state is higher than or equal to the first fault severity level, the current safety state of the vehicle domain control system 100 is sufficient to cope with the fault shown by the first fault information, and the safety degradation module 113 does not need to control the vehicle domain control system 100 to change from the current safety state to the target safety state.

[0040] In the embodiments of the present disclosure, the safety monitoring module monitors the running parameters of the vehicle domain control system in real time; the fault diagnosis module determines the first fault severity level of the vehicle domain control system according to the first fault information determined by the safety monitoring module; and the safety degradation module causes the vehicle domain control system to take corresponding fault response measures according to the first fault severity level based on the first fault severity level, so as to reduce the potential safety risk caused by the fault shown by the first fault information to the vehicle domain control system, and make the software architecture of the vehicle domain control system have functional safety.

[0041] In addition, the safety monitoring module, the fault diagnosis module and the safety degradation module are independently arranged, and such modular design is convenient for development and maintenance. Through different designs of the safety monitoring module, the fault diagnosis module and the safety degradation module, in cooperation with the hardware design of the vehicle domain controller, different functional safety level (Automotive Safety Integrity Level, ASIL) requirements of the vehicle domain controller can be met, and the highest ASIL D level, i.e., the highest safety level, can be realized.

[0042] After monitoring the abnormal running parameters, the safety monitoring module 111 continues to monitor the running parameters of the vehicle domain control system 100, and after perceiving that the fault condition of the vehicle domain control system 100 has a new change, the safety monitoring module 111 continues to generate fault information corresponding to the new fault condition, so that the fault diagnosis module 112 and the safety degradation module 113 take corresponding fault response measures for the new fault condition. The following will continue to introduce several change modes of the fault condition of the vehicle domain control system 100 and the corresponding measures.

[0043] In some embodiments, the safety monitoring module 111 is further configured to monitor a fault module corresponding to the abnormal running parameter, and generate second fault information corresponding to a current running parameter of the fault module when the current running parameter of the fault module changes compared to the abnormal running parameter. The fault module corresponding to the abnormal running parameter refers to the function implementation module 121 or the middleware module 122 generating the abnormal running parameter. For example, in the process of monitoring the function implementation module 121, when the safety monitoring module 111 determines that the fusion perception module cannot correctly acquire the data collected by the left sensor of the vehicle by monitoring the running parameter of the fusion perception module, the running parameter of the fusion perception module is determined as the abnormal running parameter, and the fusion perception module is the fault module corresponding to the abnormal running parameter. The safety monitoring module 111 monitors the current running parameter of the fault module in real time, and if the current running parameter changes compared to the abnormal running parameter, it indicates that the fault condition of the fault module has changed. At this time, the safety monitoring module 111 generates second fault information corresponding to the current running parameter of the fault module. The second fault information can reflect the new fault condition of the fault module. After generating the second fault information, the safety monitoring module 111 sends the second fault information to the fault diagnosis module 112.

[0044] The fault diagnosis module 112 is further configured to determine a second fault severity level of the vehicle domain control system 100 based on the second fault information. The determination of the second fault severity level is similar to the determination of the first fault severity level, which will not be described here.

[0045] After determining the second fault severity level, the fault diagnosis module 112 sends the second fault severity level to the safety degradation module 113, so that the safety degradation module 113 takes corresponding fault response measures based on the second fault severity level.

[0046] In the embodiments of the present disclosure, the safety monitoring module monitors the current running parameter of the fault module in real time to determine whether the fault condition has changed, so that the safety degradation module can timely adjust the fault response measures of the vehicle domain control system according to the changed fault condition, thereby improving the functional safety and reliability of the vehicle domain control system.

[0047] Then, the safety degradation module 113 receives the second fault severity level and determines a target safety state matching the second fault severity level.

[0048] In some embodiments, the fault condition of the fault module develops more seriously over time, and then the second fault severity level should be equal to or higher than the first fault severity level.

[0049] If the second fault severity level is equal to the first fault severity level, it indicates that the target safety state, which the vehicle domain control system 100 currently locates in and which matches the first fault severity level, is sufficient to cope with the new fault condition, and thus the safety degradation module 113 does not need to control the vehicle domain control system 100 to change the safety state.

[0050] If the second fault severity level is higher than the first fault severity level, it indicates that the target safety state, which the vehicle domain control system 100 currently locates in and which matches the first fault severity level, is insufficient to cope with the new fault condition, and thus the safety degradation module 113 controls the vehicle domain control system 100 to change from the target safety state matching the first fault severity level to the target safety state matching the second fault severity level.

[0051] In some other embodiments, the fault of the fault module can be repaired by resetting or the like. After the fault module is repaired, the current running parameter of the fault module changes accordingly.

[0052] In this case, the safety degradation module 113 is further configured to control the vehicle domain control system 100 to change from the target safety state to the normal running state when the second fault severity level indicates that the vehicle domain control system 100 is in normal running.

[0053] For example, if the second fault severity level is the lowest fault severity level, it indicates that the vehicle domain control system 100 can run normally. In this case, the safety degradation module 113 controls the vehicle domain control system 100 to change from the target safety state matching the first fault severity level to the normal running state.

[0054] In the embodiments of the present disclosure, the safety degradation module controls the vehicle domain control system to take corresponding fault response measures according to the second fault severity level, so as to reduce the potential safety risk of the vehicle domain control system. In addition, when the safety degradation module detects that the fault of the fault module is repaired and the vehicle domain control system runs normally based on the second fault severity level, the safety degradation module controls the vehicle domain control system to change to the normal running state, so as to improve the overall performance and running efficiency of the vehicle domain control system.

[0055] The above embodiments introduce that the safety monitoring module 111 can continue to monitor the fault module so as to timely detect the change of the fault of the fault module. However, during the running of the function implementation module 121 and the middleware module 122, there is a dependency relationship between the modules. When a fault occurs in a certain module of the function implementation module 121 and the middleware module 122, the fault can spread to other modules through the dependency relationship and cause a cascading failure. In addition, other modules in the function implementation module 121 and the middleware module 122 except the fault module can also be faulty due to other reasons.

[0056] Therefore, in some embodiments, the safety monitoring module 111 is further configured to monitor other operating parameters in the vehicle domain control system in addition to the abnormal operating parameter; and generate third fault information in the case that the other operating parameters are abnormal.

[0057] Specifically, the safety monitoring module 111, in the case that the abnormal operating parameter is monitored, will continue to monitor other operating parameters in the vehicle domain control system 100 in addition to the abnormal operating parameter. In other words, in combination with the above-mentioned embodiments, the safety monitoring module 111 will monitor the operating parameters of the other modules in the function implementation module 121 and the middleware module 122 in addition to the fault module, as well as the operating parameters of the vehicle domain control system 100, such as the power voltage signal, the environmental temperature, the clock signal, the available space of the memory, the read and write operations of the stored data, etc.

[0058] If it is monitored that the other operating parameters are abnormal, it means that in addition to the fault shown in the first fault information, a new fault has occurred in the vehicle domain control system 100. At this time, the safety monitoring module 111 generates third fault information according to the abnormal operating parameters, and sends the third fault information to the fault diagnosis module 112.

[0059] The fault diagnosis module 112 is further configured to generate a third fault severity level of the vehicle domain control system 100 based on the first fault information and the third fault information.

[0060] The fault shown in the third fault information is different from the fault shown in the first fault information, so in the process of determining the fault severity level of the vehicle domain control system, the fault diagnosis module 112 needs to consider the influence of the faults shown in the first fault information and the third fault information on the functional safety of the vehicle domain control system 100, and obtain the third fault severity level.

[0061] In the embodiments of the present disclosure, the safety monitoring module monitors other operating parameters in addition to the abnormal operating parameter in real time, and timely detects other faults of the vehicle domain control system in addition to the fault shown in the first fault information, so that the fault diagnosis module can comprehensively consider the influence of multiple faults on the functional safety of the vehicle domain control system, so that the safety degradation module can timely adjust the fault response measures of the vehicle domain control system according to the fault condition, and the functional safety and reliability of the vehicle domain control system are improved.

[0062] The above introduces several coping measures taken by the safety monitoring module, the fault diagnosis module and the safety degradation module when the fault condition of the vehicle domain control system changes. As introduced in the above embodiments, if there is a dependency relationship between two modules, the failure of one module may cause the failure of the other module.

[0063] To avoid the influence of the failure in the function implementation module or the middleware module on the safety monitoring module, the fault diagnosis module and the safety degradation module, and thus the failure of the fault response measure of the vehicle domain control system, in some embodiments, the vehicle domain control system is divided into a functional safety domain and a non-functional safety domain to isolate the safety monitoring module, the fault diagnosis module and the safety degradation module from the function implementation module and the middleware module.

[0064] Specifically, Figure 2 As shown in the figure, the vehicle domain control system provided by another embodiment of the present disclosure is shown. As Figure 2 As shown in the figure, in this embodiment, the vehicle domain control system 100 includes a functional safety domain 110 and a non-functional safety domain 120. The safety monitoring module 111, the fault diagnosis module 112 and the safety degradation module 113 are deployed in the functional safety domain 110, and the function implementation module 121 and the middleware module 122 are deployed in the non-functional safety domain 120. The fault module corresponding to the abnormal operating parameter is the module that fails in the function implementation module 121 and the middleware module 122, in other words, the fault module corresponding to the abnormal operating parameter is deployed in the non-functional safety domain 120.

[0065] Among them, the functional safety domain 110 and the non-functional safety domain 120 are decoupled to ensure that the operation of the safety monitoring module 111, the fault diagnosis module 112 and the safety degradation module 113 is not disturbed by the non-functional safety domain 120. That is, when the module in the non-functional safety domain 120 fails, the failure will not affect the normal operation of the module in the functional safety domain 110.

[0066] In the embodiments of the present disclosure, the vehicle domain control system adopts a hierarchical and modular design scheme, and the functional safety domain and the non-functional safety domain are decoupled, which is helpful for the design and maintenance of the safety monitoring module, the fault diagnosis module and the safety degradation module. Moreover, the functional safety domain and the non-functional safety domain are isolated, which ensures that the modules in the functional safety domain will not be affected by the failure in the non-functional safety domain and thus fail, improving the reliability of the vehicle domain control system.

[0067] In some embodiments, the non-functional safety domain 120 can be further divided into an application software domain and a middleware domain. The function implementation module 121 is deployed in the application software domain, and the middleware module 122 is deployed in the middleware domain, to further improve the modular degree of the vehicle domain control system and make it easier to maintain and upgrade.

[0068] The above introduces that the safety degradation module can control the vehicle domain control system to enter a safety state matched with the fault severity level according to the fault severity level, to reduce the safety risk caused by the fault to the vehicle domain control system. Next, a fault severity level grading scheme and the setting of the safety state corresponding to the fault severity level are introduced.

[0069] In some embodiments, the fault severity level includes five levels. For the convenience of description, the five fault severity levels are named as follows in this embodiment: no fault, slight fault, general fault, relatively serious fault, and very serious fault. The fault severity levels represented by the five fault severity levels increase in turn. It can be understood that the naming of the above fault severity levels is only illustrative, and those skilled in the art can adjust it by themselves.

[0070] Each fault severity level corresponds to a different safety state. For different fault severity levels, five safety states are set in this embodiment, including: normal operation state, first degraded state, second degraded state, third degraded state, and fourth degraded state. Among them, the fault severity levels corresponding to the normal operation state, the first degraded state, the second degraded state, the third degraded state, and the fourth degraded state increase in turn.

[0071] Specifically, if the vehicle domain control system 100 does not have a fault, it means that the vehicle domain control system 100 can operate normally. That is, the safety state corresponding to the fault severity level "no fault" is "normal operation state".

[0072] In addition, the safety state corresponding to "slight fault" is "first degraded state", the safety state corresponding to "general fault" is "second degraded state", the safety state corresponding to "relatively serious fault" is "third degraded state", and the safety state corresponding to "very serious fault" is "fourth degraded state".

[0073] In the case where the safety monitoring module 111 monitors an abnormal operating parameter, it means that a fault occurs in the vehicle domain control system 100. At this time, the target safety state matched with the first fault severity level should be any one of the first degraded state, the second degraded state, the third degraded state, and the fourth degraded state. The current safety state of the vehicle domain control system 100 can be any one of the normal operation state, the first degraded state, the second degraded state, the third degraded state, and the fourth degraded state.

[0074] For different fault severity levels, the fault response measures of the vehicle domain control system 100 are different, and the specific fault response measures of the vehicle domain control system 100 for different fault severity levels will be introduced below.

[0075] The fault severity level is “minor fault”, which indicates that the fault shown by the first fault information does not significantly increase the probability of the vehicle domain control system 100 having a safety risk, and does not affect the normal operation of the auxiliary driving function of the vehicle domain control system 100. Therefore, when the vehicle domain control system 100 is in the first degraded state corresponding to the “minor fault”, the vehicle domain control system 100 operates normally. At this time, the safety degradation module 113 can record the first fault information in the system log of the vehicle domain control system 100 for subsequent maintenance.

[0076] The fault severity level is “general fault”, which indicates that the fault shown by the first fault information may affect the functional safety of the vehicle domain control system 100, but generally does not cause serious consequences. Therefore, when the vehicle domain control system 100 is in the second degraded state corresponding to the “general fault”, the vehicle domain control system 100 operates normally, and the safety degradation module 113 generates fault reminder information corresponding to the first fault information.

[0077] The fault reminder information can be output through a vehicle terminal or other output device to remind the driver or technician that the vehicle domain control system 100 has a fault, causing the driver or technician to be vigilant.

[0078] The fault severity level is “general fault”, which indicates that the fault shown by the first fault information may affect the functional safety of the vehicle domain control system 100, but generally does not cause serious consequences. Therefore, when the vehicle domain control system 100 is in the second degraded state corresponding to the “general fault”, the vehicle domain control system 100 operates normally, and the safety degradation module 113 generates fault reminder information corresponding to the first fault information.

[0079] The first communication management request includes a request to cut off the external communication of the fault module corresponding to the abnormal operating parameter. External communication refers to the sending and receiving of messages by the fault module. As introduced in the previous embodiment, the external communication of the fault module can trigger a cascade failure, and after cutting off the external communication of the fault module, the spread of the fault can be prevented, avoiding triggering more widespread system problems. Avoiding the auxiliary driving function related to the fault module from not operating normally.

[0080] The first takeover request is used to remind the driver to take over part of the auxiliary driving function of the vehicle, which is the auxiliary driving function related to the fault module that cannot operate normally. For example, for the automatic lane changing function of the vehicle, if the fusion perception module fails to correctly obtain the data of the left sensor of the vehicle, the vehicle cannot perceive the environment on the left side of the vehicle, resulting in the function of the automatic lane changing function to change lanes to the left cannot operate normally. At this time, the first takeover request reminds the driver to take over the left lane changing operation of the vehicle.

[0081] The fault severity level is "very serious fault", which indicates that the fault shown by the first fault information has a serious impact on the functional safety of the vehicle domain control system 100, and it is uncertain whether the auxiliary driving function of the vehicle domain control system 100 can normally operate. Therefore, in the case where the vehicle domain control system 100 is in the fourth degraded state corresponding to the "very serious fault", the safety degradation module 113 generates a second communication management request, and generates fault reminder information and a second takeover request corresponding to the first fault information.

[0082] The second communication management request includes a request to cut off the external communication of all functional implementation modules in the vehicle domain control system. At this time, all auxiliary driving functions in the vehicle domain control system 100 stop running. The second takeover request is used to remind the driver to take over all functions of the vehicle.

[0083] In the embodiments of the present disclosure, for different fault severity levels, corresponding safety states are set, so that the vehicle domain control system can respond reasonably to different fault severity levels, and the functional safety of the vehicle domain control system is improved. In the case of more serious faults, the driver can be reminded in time to take over the vehicle, and the safety risk of the vehicle caused by the failure of the auxiliary driving function of the vehicle domain control system is reduced.

[0084] It can be understood that when the vehicle domain control system has a very serious fault, it cannot be restored by simple repair. Therefore, in the case where the vehicle domain control system enters the fourth degraded state, it is usually necessary to wait for the relevant technical personnel to handle, and the fourth degraded state generally will not change to other safety states.

[0085] When the vehicle domain control system has a more serious fault or a very serious fault, the external communication of the fault module or all functional implementation modules needs to be cut off. Based on this requirement, a communication management module is further deployed in the functional safety domain.

[0086] With reference to Figure 2 , the functional safety domain 110 further includes a communication management module 114. The communication management module 114 is configured to cut off the external communication of the fault module in response to the first communication management request, and / or cut off the external communication of all functional implementation modules 121 in the vehicle domain control system 100 in response to the second communication management request. For example, the communication management module 114 can cut off the connection between the fault module and the communication interface for data transmission to control the sending and receiving of information of the fault module.

[0087] Specifically, in the case that the vehicle domain control system 100 is in the third degraded state, the safety degradation module 113 sends a first communication management request to the communication management module 114, requesting to cut off the external communication of the faulty module. After receiving the first communication management request, the communication management module 114 cuts off the external communication of the faulty module.

[0088] In the case that the vehicle domain control system 100 is in the fourth degraded state, the safety degradation module 113 sends a second communication management request to the communication management module 114. After receiving the second communication management request, the communication management module 114 cuts off the external communication of all the functional implementation modules 121 in the vehicle domain control system 100.

[0089] In the embodiments of the present disclosure, the communication management module can receive and execute the first communication management request and the second communication management request generated by the safety degradation module, so that the faulty module can be quickly isolated after the vehicle domain control system enters the third degraded state, and all the functional implementation modules can be isolated from other modules in the non-functional safety domain after the vehicle domain control system enters the fourth degraded state, preventing the spread of faults and improving the functional safety of the vehicle domain control system.

[0090] Next, other modules in the functional safety domain will be introduced.

[0091] Figure 3 Fig. 1 shows a structural schematic diagram of a vehicle domain control system provided by another embodiment of the present disclosure. As shown in Fig. 1, the vehicle domain control system 100 includes a functional safety domain 110 and a non-functional safety domain 120, the functional safety domain 110 is decoupled from the non-functional safety domain 120, and a safety monitoring module 111, a fault diagnosis module 112, and a safety degradation module 113 are deployed in the functional safety domain 110. The non-functional safety domain 120 includes a functional implementation module 121 and a middleware module 122. Figure 3

[0092] The safety monitoring module 111 includes a system monitoring submodule 1111.

[0093] The system monitoring submodule 1111 is configured to monitor the functional implementation module 121, reset the faulty functional implementation module in the case that the functional implementation module 121 is monitored to have a fault, and generate fault information corresponding to the faulty functional implementation module.

[0094] ​Exemplarily, the system monitoring submodule 1111 determines whether the running parameters of the function implementation module 121 are abnormal and further determines whether the function implementation module 121 is faulty by performing program flow monitoring, Deadline monitoring or Alive monitoring on the function implementation module 121. In the case that the function implementation module 121 is monitored to be faulty, the fault information corresponding to the faulty function implementation module, i.e., the first fault information, is generated.

[0095] The program flow monitoring is used to monitor the dependency relationship and execution order between tasks of the function implementation module 121, the Deadline monitoring is used to monitor the execution time of event-type tasks, and the Alive monitoring is used to monitor whether the periodic tasks are running according to the expected periodicity, so as to comprehensively monitor whether the function implementation module 121 is running normally.

[0096] Resetting the faulty function implementation module refers to a process of restoring the state of the faulty function implementation module to an initial or predefined safe state. The resetting helps to clear the error state inside the faulty function implementation module and eliminate the error influence caused by the fault. Through the resetting process, it is expected that the faulty function implementation module can restore the normal working state and prevent the error from continuing to spread to other modules.

[0097] In some embodiments, the system monitoring submodule 1111 is further configured to periodically generate a running state signal and stop generating the running state signal in the case that the faulty function implementation module is still faulty after being reset, so that an external monitoring module outside the vehicle domain control system recognizes the stop of the generation of the running state signal and resets the vehicle domain control system.

[0098] The running state signal can include the running state, load condition, resource usage rate and the like of the vehicle domain control system 100.

[0099] The external monitoring module is independently arranged with the vehicle domain control system 100. The system monitoring submodule 1111 periodically sends the running state signal to the external monitoring module to indicate that the vehicle domain control system 100 is in the normal working state. If the external monitoring module does not receive the running state signal within a predetermined time, it is indicated that a fault may occur in the vehicle domain control system 100. At this time, the external monitoring module automatically triggers a preset safety response measure to reset the vehicle domain control system 100, so as to restore the vehicle domain control system 100 to the normal working state.

[0100] In the embodiments of the present disclosure, the system monitoring submodule can monitor whether the function implementation module fails in real time, and timely repair through resetting and the like. In the case that the resetting process cannot repair the failure, the vehicle domain control system as a whole can be reset through the external monitoring module outside the vehicle domain control system. The system monitoring submodule provides a repair means for the failure of the function implementation module, reduces the frequency of the vehicle domain control system entering the degraded state, and improves the reliability of the vehicle domain control system as a whole.

[0101] In some embodiments, continuing to refer to Figure 3 The safety monitoring module 111 further includes a power supply monitoring submodule 1112 and / or a temperature monitoring submodule 1113.

[0102] Specifically, the power supply monitoring submodule 1112 is configured to monitor whether the power supply is abnormal by sampling and calculating the power voltage of the power supply of the vehicle domain control system. For example, by sampling and calculating the power voltage, if it is determined that the input voltage of the power supply is not within the rated voltage range, it is determined that the power supply is abnormal. In the case that the power supply is monitored to be abnormal, the failure information corresponding to the power supply, i.e., the first failure information, is generated.

[0103] The temperature monitoring submodule 1113 is configured to monitor whether the environment temperature is abnormal by sampling and calculating the environment temperature of the vehicle domain control system. For example, if it is monitored that the environment temperature exceeds the preset normal working temperature range, it is determined that the environment temperature is abnormal. In the case that the environment temperature is monitored to be abnormal, the failure information corresponding to the environment temperature, i.e., the first failure information, is generated.

[0104] In the embodiments of the present disclosure, the power supply monitoring submodule and the temperature monitoring submodule can monitor the power supply and the environment temperature of the vehicle domain control system, prevent the failure of the vehicle domain control system caused by voltage or environmental factors, and ensure the stability and safety of the vehicle domain control system.

[0105] In some embodiments, the safety monitoring module 111 further includes a communication protection submodule.

[0106] The communication protection submodule is configured to perform communication verification on the communication data of the modules in the function safety domain. During the running of the vehicle domain control system, the safety monitoring module needs to interact with the monitored modules in the process of monitoring the modules in the non-function safety domain; and in the case that the abnormal running parameters are monitored, the safety monitoring module, the fault diagnosis module and the safety degradation module also need to interact, for example, the system monitoring submodule 1111 sends the first failure information to the fault diagnosis module 112. In this process, the communication protection submodule can perform communication verification on the communication data of the modules in the function safety domain.

[0107] In some embodiments, the communication protection submodule is further configured to perform communication verification on the security-related data input from outside the vehicle domain control system. Specifically, in the process of communication with the external device, the external device can input security-related data into the vehicle domain control system 100, such as configuration information for the security degradation module, etc. At this time, the communication verification needs to be performed on the security-related data input from outside the vehicle domain control system. In the case of communication verification failure, fault information corresponding to the communication failure is generated.

[0108] For example, the communication verification can be performed in the manner of cyclic redundancy check (CRC), checksum, rolling counter, etc.

[0109] In the embodiments of the present disclosure, the communication protection submodule can perform communication verification on the communication data between the modules inside the vehicle domain control system and the communication data between the vehicle domain control system and the external device, so as to ensure the integrity, authenticity and reliability of the communication data, and prevent communication data errors or loss caused by factors such as software and hardware faults, electromagnetic interference or external attacks.

[0110] In some embodiments, the security monitoring module 111 further includes a storage detection submodule. The storage detection submodule is configured to monitor the read and write operations of the data stored inside or outside the vehicle domain control system, and generate fault information corresponding to the storage error in the case of detecting the storage error.

[0111] In some embodiments, the security monitoring module 111 further includes a clock monitoring submodule. The clock monitoring submodule is configured to monitor the clock signal outside the vehicle domain control system and the clock signal inside the vehicle domain control system. For example, the clock frequency of the clock signal input can be calculated to determine whether the clock signal is abnormal. In the case of detecting the clock signal abnormality, fault information corresponding to the clock signal is generated.

[0112] In addition, the clock monitoring submodule can monitor and diagnose the time synchronization signal inside and outside the system by monitoring the clock signal inside and outside the vehicle domain control system. In the case of detecting the time synchronization signal abnormality, fault information corresponding to the time synchronization signal is generated.

[0113] In some embodiments, the security monitoring module 111 further includes an OTA monitoring submodule. When remote OTA software flashing is needed, the OTA monitoring submodule can judge the OTA flashing condition. In the case of meeting the flashing condition, the vehicle domain control system can safely enter the OTA state, and in the case of not meeting the flashing condition, fault information corresponding to the flashing condition abnormality is generated.

[0114] And, the OTA monitoring submodule can also perform security check on the received OTA software package, to prevent incorrect software from being written into the vehicle domain control system during the writing process; and in the case where it is detected that the OTA software package has errors, generate fault information corresponding to the OTA software package.

[0115] The above embodiments introduce a plurality of modules that can be included in the functional safety domain, the plurality of modules can monitor different operating parameters of the vehicle domain control system, and each module is independent of each other, which is helpful for the design and maintenance of each module.

[0116] Based on the same inventive concept, the disclosure also provides a vehicle comprising the vehicle domain control system described in any of the above embodiments. The vehicle embodiment solves the problem in a similar way to the above vehicle domain control system embodiment, and therefore the implementation of this embodiment can refer to the implementation of the above vehicle domain control system embodiment, and the repeated parts will not be described again.

[0117] The technical features of the above embodiments can be combined arbitrarily, and to make the description concise, not all possible combinations of the technical features in the above embodiments are described, however, as long as the combinations of the technical features do not exist contradictory, they should be considered as the scope of the disclosure.

[0118] Other embodiments of the disclosure will be apparent to those skilled in the art from consideration of the specification and practice of the disclosure disclosed herein. The disclosure is intended to cover any variations, uses or adaptations of the disclosure following the general principles thereof and including such departures from the present disclosure that come within known use or custom in the art to which the disclosure pertains. The specification and examples are to be regarded as illustrative only, and the true scope and spirit of the disclosure are indicated by the appended claims.

Claims

1. A vehicle domain control system, characterized in that, It includes a security monitoring module, a fault diagnosis module, and a security degradation module; The safety monitoring module is configured to monitor the operating parameters of the vehicle domain control system and generate first fault information when abnormal operating parameters are detected. The fault diagnosis module is configured to determine a first fault severity level of the vehicle domain control system based on the first fault information, wherein the first fault severity level is positively correlated with the fault severity of the vehicle domain control system. The security degradation module is configured to determine a target security state that matches the first fault severity level and the current security state of the vehicle domain control system. If the fault severity level corresponding to the current security state is lower than the first fault severity level, the module controls the vehicle domain control system to change from the current security state to the target security state. If the fault severity level corresponding to the current security state is higher than or equal to the first fault severity level, then there is no need to control the vehicle domain control system to change from the current security state to the target security state. Wherein, the first fault severity level is any one of no fault, minor fault, general fault, relatively serious fault, and very serious fault; the safety states corresponding to the five fault severity levels are normal operation state, first degraded state, second degraded state, third degraded state, and fourth degraded state, respectively; the target safety state is any one of the first degraded state, second degraded state, third degraded state, and fourth degraded state; the current safety state is any one of the normal operation state, first degraded state, second degraded state, third degraded state, and fourth degraded state; the fault severity levels corresponding to the normal operation state, first degraded state, second degraded state, third degraded state, and fourth degraded state increase sequentially; When the vehicle domain control system is in the first degraded state, the vehicle domain control system operates normally; When the vehicle domain control system is in the second degraded state, the vehicle domain control system operates normally, and the security degrade module generates a fault reminder message corresponding to the first fault information; When the vehicle domain control system is in the third degraded state, the security degrade module generates a first communication management request, and generates a fault reminder message and a first takeover request corresponding to the first fault information. The first communication management request includes a request to cut off the external communication of the fault module corresponding to the abnormal operating parameters. The first takeover request is used to remind the driver to take over some of the vehicle's assisted driving functions. The partial assisted driving functions are assisted driving functions related to the fault module that cannot operate normally. When the vehicle domain control system is in the fourth degraded state, the security degrade module generates a second communication management request, and generates a fault reminder message and a second takeover request corresponding to the first fault information. The second communication management request includes a request to cut off the external communication of all functional implementation modules in the vehicle domain control system. The second takeover request is used to remind the driver to take over all functions of the vehicle.

2. The vehicle domain control system according to claim 1, characterized in that, The security monitoring module is also configured to: Monitor the fault modules corresponding to the abnormal operating parameters; When the current operating parameters of the faulty module change compared to the abnormal operating parameters, a second fault information corresponding to the current operating parameters of the faulty module is generated. The fault diagnosis module is also configured to determine the second fault severity level of the vehicle domain control system based on the second fault information.

3. The vehicle domain control system according to claim 2, characterized in that, The security degradation module is also configured to: When the second fault severity level indicates that the vehicle domain control system is operating normally, the vehicle domain control system is controlled to change from the target safe state to the normal operating state.

4. The vehicle domain control system according to claim 1, characterized in that, The security monitoring module is also configured to: Monitor the vehicle domain control system for other operating parameters besides the abnormal operating parameters mentioned above. If the other operating parameters are abnormal, a third fault message is generated; The fault diagnosis module is further configured to generate a third fault severity level of the vehicle domain control system based on the first fault information and the third fault information.

5. The vehicle domain control system according to claim 1, characterized in that, The vehicle domain control system includes a functional safety domain and a non-functional safety domain. The safety monitoring module, the fault diagnosis module, and the safety degradation module are deployed in the functional safety domain, and the fault module corresponding to the abnormal operating parameters is deployed in the non-functional safety domain. The functional safety domain is decoupled from the non-functional safety domain to ensure that the operation of the safety monitoring module, the fault diagnosis module, and the safety degradation module is not affected by the non-functional safety domain.

6. The vehicle domain control system according to claim 1, characterized in that, The vehicle domain control system includes a functional safety domain and a non-functional safety domain. The functional safety domain is decoupled from the non-functional safety domain. The safety monitoring module, the fault diagnosis module, and the safety degradation module are deployed in the functional safety domain, while the fault module and the function implementation module are deployed in the non-functional safety domain. The functional safety domain further includes: The communication management module is configured to, in response to the first communication management request, cut off the external communication of the faulty module; and / or, in response to the second communication management request, cut off the external communication of all functional implementation modules in the vehicle domain control system.

7. The vehicle domain control system according to claim 1, characterized in that, The vehicle domain control system includes a functional safety domain and a non-functional safety domain. The functional safety domain is decoupled from the non-functional safety domain. The safety monitoring module, the fault diagnosis module, and the safety degradation module are deployed in the functional safety domain. The security monitoring module includes a system monitoring submodule, and the non-functional security domain includes a function implementation module. The system monitoring submodule is configured to monitor the function implementation module, and when a fault is detected in the function implementation module, to reset the faulty function implementation module and generate fault information corresponding to the faulty function implementation module; and / or The system monitoring submodule is also configured to periodically generate operating status signals, and to stop generating the operating status signals if the faulty functional implementation module still has a fault after being reset, so that the external monitoring module outside the vehicle domain control system can reset the vehicle domain control system when it detects that the operating status signals have stopped being generated.

8. The vehicle domain control system according to claim 1, characterized in that, The security monitoring module includes: The power monitoring submodule is configured to monitor whether there are any abnormalities in the power supply by sampling and calculating the power supply voltage of the vehicle domain control system, and to generate fault information corresponding to the power supply if an abnormality is detected; and / or The temperature monitoring submodule is configured to monitor whether there is an abnormality in the ambient temperature by sampling and calculating the ambient temperature of the vehicle domain control system, and generate fault information corresponding to the ambient temperature if an abnormality is detected.

9. A vehicle, characterized in that, Includes the vehicle domain control system as described in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Intelligent driving domain controller, vehicle control method and vehicle

    CN115384533A

  • Domain controller fault diagnosis system and method in automatic parking process, vehicle and storage medium

    CN118025210A

  • Vehicle fault processing method and device, vehicle-mounted equipment and storage medium

    CN118560507A

  • Vehicle control unit and electric automobile

    CN208344148U