Component switching method for a vehicle, computer-readable storage medium, and program product
By establishing a mapping relationship between the main component and the spare component in the vehicle, and based on the disassembly results of functional safety objectives, quickly switching the spare component solves the blind spot problem of safety scenario coverage of the redundant system of autonomous driving vehicles, realizing effective response to complex working conditions and seamless switching of functions.
Patent Information
- Application Number
- CN202510362545.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2045-03-26
AI Technical Summary
The existing redundant systems of autonomous driving vehicles lack complete architectural standards, making it difficult to effectively deal with the failure risk under complex operating conditions, and there are blind spots in safety scenarios.
By establishing a mapping relationship between the main component and the backup component in the vehicle, based on the disassembly results of the preset functional safety target, the target backup component is quickly positioned and switched to replace the abnormal main component to ensure the continuity and reliability of the vehicle function.
It achieves comprehensive coverage of different safety scenarios, avoids the risk of failure of vehicles under complex working conditions, and ensures seamless switching of vehicle functions and safe operation.
Smart Images

Figure CN119872589B_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the technical field of vehicle control, and particularly to a method for switching components of a vehicle, a computer-readable storage medium, and a program product. Background Art
[0002] In the context of autonomous driving, a redundant system refers to a technical architecture in which multiple backup components replace corresponding primary components in the event of failure to maintain the safe operation of the vehicle. Its role is to eliminate the risk of single-point failures and ensure the minimum safe operating capabilities. Taking the current mainstream autonomous driving levels L3 and L4 as examples, the former basically only implements basic redundancies such as braking and steering. Although the latter lists power redundancy as a necessary redundancy due to the safety requirements of highly autonomous driving, there is actually still a lack of a complete architecture standard for the redundant systems of vehicles in the industry. As a result, existing redundant systems have blind spots in covering safety scenarios and are difficult to effectively cope with failure risks under complex working conditions. Summary of the Invention
[0003] In view of this, this specification provides a method for switching components of a vehicle, a computer-readable storage medium, and a program product to address the deficiencies in the related art.
[0004] Specifically, this specification is implemented through the following technical solutions:
[0005] According to a first aspect of this specification, there is provided a method for switching components of a vehicle. The vehicle is deployed with a primary system and a backup system. The primary components in the primary system and / or the backup components in the backup system maintain a mapping relationship between the primary components and the backup components with the same function. The mapping relationship is created based on the decomposition results of preset functional safety objectives. The method includes:
[0006] In the case where it is determined that the working state of any primary component is abnormal, determine the target backup component in the backup system corresponding to the any primary component according to the mapping relationship;
[0007] Switch any primary component to the target backup component so that the target backup component replaces the any primary component to work.
[0008] According to a second aspect of this specification, there is provided a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, the steps of the method described in the first aspect are implemented.
[0009] According to a third aspect of this specification, a computer program product includes computer program / instructions. When the computer program / instructions are executed by a processor, the steps of the method described in the first aspect are implemented.
[0010] The vehicle in this application can be deployed with a primary system and a backup system. The primary components in the primary system and / or the backup components in the backup system can maintain the mapping relationship between the primary components and the backup components with the same functions. In the case where the operating state of any primary component is abnormal, the target backup component corresponding to the abnormal primary component can be quickly located from the backup system according to this mapping relationship, and then the abnormal primary component and the target backup component can be switched so that the target backup component can replace the abnormal primary component and continue to work properly. Among them, the above mapping relationship is created based on the decomposition results of the preset functional safety objectives. In other words, which components in the vehicle are used as primary components and which components are used as corresponding backup components can be uniformly determined by the pre-determined functional safety objectives, and then a complete architecture standard is specified around the functional safety objective to cover the scenario blind spots caused by the lack of systematic architecture design in the traditional solutions and avoid the failure risks under complex working conditions. Brief Description of the Drawings
[0011] In order to more clearly illustrate the technical solutions of this specification, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of this specification. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0012] Figure 1 is a schematic diagram of the architecture of a component switching system of a vehicle shown in the disclosed embodiments of this specification;
[0013] Figure 2 is a flowchart of a component switching method of a vehicle shown in the disclosed embodiments of this specification;
[0014] Figures 3a to 3c is a schematic diagram of the architecture of a communication system between redundant components of a vehicle shown in the disclosed embodiments of this specification;
[0015] Figure 4 is a schematic diagram of the architecture of redundant components of a vehicle shown in the disclosed embodiments of this specification;
[0016] Figure 5 is a schematic structural diagram of an electronic device shown in the embodiments of this specification;
[0017] Figure 6 is a block diagram of a component switching device of a vehicle shown in the embodiments of this specification. Detailed Description of the Embodiments
[0018] Exemplary embodiments will be described in detail herein, and examples thereof are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this specification. On the contrary, they are merely examples of devices and methods consistent with some aspects of this specification.
[0019] The terms used in this specification are for the purpose of describing specific embodiments only and are not intended to limit this specification. The singular forms "a", "the", and "said" used in this specification and the appended claims are also intended to include the plural forms unless the context clearly dictates otherwise. It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items.
[0020] It should be understood that although the terms first, second, third, etc. may be used in this specification to describe various information, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of this specification, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "when" or "while" or "in response to determining".
[0021] The following describes in detail an embodiment of the component switching method for a vehicle in this specification with reference to the accompanying drawings.
[0022] Figure 1 is a schematic diagram of the architecture of a component switching system for a vehicle shown in the disclosed embodiments of this specification. As Figure 1 shown, the system may include a vehicle 10, a main system 11, and an auxiliary system 12.
[0023] The vehicle 10 is a carrier for implementing the component switching function in this specification. It constructs a redundant architecture through the main system 11 and the auxiliary system 12 deployed thereon to ensure the achievement of the vehicle functional safety goal. Specifically, the vehicle 10 is actually configured with main system components for performing preset functions and corresponding standby components. The components form a switchable logical link based on the mapping relationship established for the decomposed functional safety goal. When a main system component fails, the vehicle 10 can execute a corresponding switching mechanism to call the standby components of the auxiliary system 12 for function substitution, thereby ensuring the continuity and reliability of the vehicle operation function. Among them, the above vehicle 10 may be a fuel vehicle, a hybrid vehicle, an electric vehicle, etc., based on different power types and having the ability of autonomous driving, and this specification does not limit this.
[0024] The main system 11 is the core execution unit for implementing vehicle functions, which may include m main components, where m is a positive integer. Specifically, the main components may store mapping relationship data of standby components equivalent to their functions according to the actual situation. When the working state of any main component is abnormal, the corresponding target standby component in the auxiliary system 12 can be quickly located based on the preset mapping relationship data, and the abnormal main component can be switched with the backup component to achieve seamless replacement of the faulty component.
[0025] The auxiliary system 12 is a redundant backup unit for the main system 11, which may include n standby components with the same functions as the main components in the main system 11, where n is a positive integer greater than or equal to m. Each standby component forms a one-to-one or many-to-one logical association with the main component through a predefined mapping relationship. For example, standby component A only corresponds to main component B, and standby components C and D both correspond to main component E.
[0026] It is worth mentioning that in addition to the main components, there may be other components in the main system, and there are no standby components with the same functions as them in the above-mentioned standby system. Of course, the above-mentioned other components can be regarded as having met the above-mentioned functional safety objectives, so there is no need to additionally adopt the non-redundant design of the above-mentioned standby components.
[0027] For the convenience of subsequent introduction, this specification pre-explains the related technologies around the concept of functional safety objectives here:
[0028] Functional safety goals, as a core safety criterion developed based on systematic risk assessment and hazard analysis, aim to ensure that the vehicle's electrical and electronic systems can still maintain an acceptable safety level in case of failures. Specifically, taking the international standard ISO 26262 as an example, after an automotive manufacturer designs and defines the functional boundaries, operating environment, and interaction relationships with other systems of a system or component, it can list the possible failure modes of the system and the resulting hazardous events based on Hazard Analysis and Risk Assessment (HARA). For example, a failure in the steering system may cause the vehicle to lose control. Then, the above-mentioned hazardous events are quantified and scored from three dimensions: Severity (S), Exposure (E), and Controllability (C). Furthermore, the corresponding Automotive Safety Integrity Level (ASIL) is obtained according to the scores of each dimension. The ASIL levels are specifically divided into QM (Quality Management), A, B, C, and D, and the strictness of the safety requirements increases in this order. For example, if a brake failure leads to a fatal accident and is difficult to control, ASIL D needs to be assigned. Or, if the failure of the in-vehicle lighting system or window control has a minor impact on safety, ASIL A can be assigned.
[0029] After determining the ASIL level of a hazardous event, corresponding quantitative indicators such as the fault tolerance rate, failure probability, and response time can be formulated, thus forming a true functional safety goal. For example, "Prevent unexpected brake failure, ensure that the parking braking force ≥ 500 N·m, and the switching time ≤ 300 ms". However, functional safety goals such as "Prevent unexpected brake failure" and "Avoid unexpected loss of lateral motion control" are too abstract to directly guide the engineering design of vehicles. Therefore, they can be broken down step by step until the concrete minimum functional safety goals, which are uniformly referred to as the decomposition results of functional safety goals for the convenience of describing the following text. For example, the redundancy requirements at the chip level of a circuit board. Of course, the embodiments in this specification focus on the redundancy architecture design at the Bill of Materials (BOM) layer of the whole vehicle, mainly considering whether aspects such as the selection, layout, and interfaces of parts meet the safety requirements of the whole vehicle, and do not need to delve into details such as the specific design inside the chip. For example, there is an original functional safety goal of "When the main controller of the braking system fails, it is necessary to switch to the standby controller within 10 ms, maintain a braking force ≥ 50%, and ASIL D". Then, the main controller and the standby controller can be designed as independent heterogeneous units. Although the ASIL level of the functional safety goal corresponding to each controller is reduced to ASIL C, the two can meet the ASIL D requirement when coordinated, and finally achieve the effect of decomposing ASIL D into ASIL C + ASIL C. On this basis, the main controller, which belongs to the decomposition result of the original functional safety goal in the above example, can be used as the main component in the main system, and the standby controller can be used as the standby component in the standby system, and a mapping relationship between the two can be established, so that the main component and the standby component can achieve the above original functional safety goal according to this mapping relationship.
[0030] Those skilled in the art can understand that, from the perspective of functional redundancy, although the main component and the standby component with a mapping relationship have the same function, the performance of each component when implementing the same function can be set according to actual requirements. For example, in the L3 autonomous driving level, it is required that the standby system only takes over driving in specific scenarios such as highways, but the driver still needs to take over manually within a certain response time. Therefore, the standby component used to replace the main component only needs to provide the minimum safe operation ability, such as maintaining vehicle stability until the driver takes over, and the standby component does not need to achieve exactly the same performance as the main component. Another example is that in the L4 autonomous driving level, it is required that the system can independently handle all faults in specific scenarios such as urban roads without human takeover. Therefore, the above-mentioned standby component must exactly reproduce the performance of the main component to ensure that the system can still operate according to the original design after the fault switch. In particular, when the performance of the main component and the standby component in implementing the same function is also the same, the two can be used interchangeably without distinguishing between the main system and the standby system. For the convenience of description, in this specification, L3 is taken as the autonomous driving level that the vehicle defaults to follow, that is, the standby component is allowed to achieve the same function as the main component with lower performance.
[0031] In summary, in this specification, based on the functional safety goal, the originally abstract safety requirements can be transformed into executable technical specifications, and then the vehicle redundancy system designed based on the above functional safety goal can comprehensively cover different safety scenarios and avoid the failure risk of vehicle functions under complex working conditions.
[0032] Figure 2 It is a schematic flow chart of a component switching method for a vehicle provided by an exemplary embodiment; wherein, the above vehicle is deployed with a main system and a standby system, and the main component in the above main system and / or the standby component in the above standby system maintain a mapping relationship between the above main component and the above standby component with the same function, and the above mapping relationship is created based on the decomposition result of a preset functional safety goal; the method may include the following steps:
[0033] Step S202, in the case of determining that the working state of any main component is abnormal, determine the target standby component in the standby system corresponding to the any main component according to the mapping relationship.
[0034] Based on the above mapping relationship that has characterized the corresponding logic between the main components and the spare components with the same functions, once it is determined that the working state of any main component in the main system is abnormal, the corresponding spare component in the spare system can be determined according to this mapping relationship for function substitution in subsequent steps. Among them, the abnormality of the working state can be further divided into hardware physical failures, such as the pressure sensor of the hydraulic valve detecting that the actual pressure is greater than the preset pressure threshold, resulting in abnormal braking force output; software logic failures, such as the automatic driving path planning algorithm continuously generating an error trajectory with an offset greater than the preset offset value within a preset time due to memory overflow; and performance degradation, such as the lens of the vehicle camera being soiled, resulting in a decrease in the signal-to-noise ratio of the captured image and the target detection confidence of the object recognized based on this image being less than the preset confidence. Of course, regardless of the type of abnormality, the operation of determining the above target spare component can be triggered according to the mapping relationship.
[0035] In this specification, the execution entity for determining the above abnormality and the above target spare component can be adjusted according to the actual situation. For this purpose, the above main components and the above spare components can be further refined. That is, the main components can include a main control component and a first controlled component controlled by the main control component, and the above spare components can also include a sub-control component, which can be used to control the second controlled component of the spare system. In the scenario of autonomous driving, the above main control component can specifically refer to the Highly Automated Driving (HAD) controller in the vehicle, which is responsible for collecting data from various sensors of the vehicle, performing complex operations and processing, and then sending instructions to actuators such as steering, braking, and power systems in the vehicle according to preset algorithms and strategies to achieve autonomous driving operations such as automatic following, lane keeping, and automatic lane change. Among them, the above sensors and actuators can both be regarded as the first controlled components. Except for the different systems in which the above sub-control component and the above main control component, the first controlled component and the second controlled component are located, they are basically the same in specific implementation, so this specification will not elaborate further here.
[0036] In one embodiment, when the main control component determines that the first controlled component meets the component abnormality condition, the main control component may determine that the operating state of the first controlled component is abnormal. Among them, the main control component establishes a communication connection with the first controlled component to determine the operating state of the first controlled component in an active monitoring or passive reception manner. Specifically, the main control component may actively poll the status register in the first controlled component through communication protocols such as Controller Area Network with Flexible Data Rate (CAN FD) / Controller Area Network eXtended Large Frames (CAN XL), or receive the self-check status reported by the first controlled component at a fixed period. The component abnormality condition may be a preset multi-dimensional determination rule set for determining whether the operating state of the first controlled component is abnormal. For example, when the first controlled component is a current sensor of a motor and the current exceeds the maximum current threshold set in the component abnormality condition, it may be determined that the operating state is abnormal. Another example is that if the communication between the main control component and the first controlled component times out, it may also be determined that the operating state is abnormal. Similarly, a communication connection may also be established between the secondary control component in the standby system and the second controlled component, thereby achieving the same effect as that of the main control component and the first controlled component in the above text, which will not be elaborated in this specification.
[0037] In another embodiment, when the secondary control component determines that the main control component meets the component abnormality condition, the secondary control component may determine that the operating state of the main control component is abnormal. In this embodiment, the secondary control component may serve as the execution entity for determining the abnormality of the main component to solve the special situation in the previous embodiment where the main control component of the main component itself is abnormal, resulting in the inability to timely determine the abnormality of the first controlled component or the main control component. Specifically, a communication connection may be established between the secondary control component and the main control component, thereby realizing the communication between the main system and the standby system.
[0038] Those skilled in the art can understand that the above two embodiments can be implemented simultaneously to ensure that whether it is the main control component or the first controlled component in the main system can be timely detected for abnormalities, improving the accuracy of abnormality determination for the main component.
[0039] When it is determined that the operating state of any main component is abnormal, in this specification, the execution entity for determining the target standby component corresponding to any main component may be further classified, so as to realize the dynamic selection of the determination path of the target standby component, and accelerate the efficiency of performing subsequent switching operations. Among them, the above classification basis may be associated with the maintenance location of the above mapping relationship.
[0040] In one embodiment, when it is determined that the working state of the first controlled component is abnormal, and the above-mentioned mapping relationship is maintained between the above-mentioned main control component and any one of the above-mentioned sub-control components, the above-mentioned any one of the components can determine the second controlled component corresponding to the above-mentioned first controlled component in the above-mentioned backup system as the above-mentioned target backup component according to the above-mentioned mapping relationship. In this embodiment, for the first controlled component, the first situation is: after the main control component determines that it is abnormal, it can directly determine the target backup component corresponding to any main component, and the second situation is: after the main control component synchronizes the determined abnormal result to the sub-control component, the sub-control component determines the target backup component corresponding to any main component. The execution of the above two situations depends on the maintenance position of the mapping relationship. When only the main control component maintains the above-mentioned mapping relationship, the first situation must be realized; when only the sub-control component maintains the above-mentioned mapping relationship, the second situation must be realized; when both the main control component and the sub-control component maintain the above-mentioned mapping relationship, any of the above situations can be realized. The difference is that the first situation omits the synchronization process of the abnormal result compared with the second situation, so it has a higher efficiency in determining the target backup component.
[0041] In another embodiment, when it is determined that the working state of the main control component is abnormal and the sub-control component maintains the mapping relationship, the sub-control component determines the sub-control component as the target standby component according to the mapping relationship. Since the main control component itself is abnormal, even if the main control component maintains the mapping relationship, it cannot be guaranteed that the main control component can successfully determine the sub-control component corresponding to it in the standby system as the target standby component, so it needs to rely on the sub-control component and the mapping relationship maintained in the sub-control component to determine itself as the target standby component.
[0042] It is worth mentioning that the sub-control component and the second controlled component can reduce the probability of common cause failure through heterogeneous design and physical isolation, so that the probability of synchronous abnormality between the main control component and the sub-control component, and the first controlled component and the second controlled component corresponding to the same mapping relationship is extremely low. Of course, even in extreme cases, the main control component and the sub-control component, or the first controlled component and the second controlled component are abnormal at the same time, and the full redundant link failure is triggered at the same time, the system can be forced to enter the static safety mode based on the underlying hardware and the preset failure safety logic, and perform basic safety operations such as electronic parking and double flash warnings.
[0043] Among them, the so-called physical isolation can be understood as isolating the main power supply component and the backup power supply component in the case where the main component includes the main power supply component and the backup component includes the backup power supply component, so that other main components depend on the main power supply component and other backup components depend on the backup power supply component. Specifically, the purpose of the above isolation operation is to construct independent power distribution networks and grounding circuits for the main system and the backup system. For example, the main power supply component uses a 12V lead-acid battery with the negative pole connected to the vehicle body ground, and the backup power supply component uses a 48V lithium battery with an independent negative pole circuit. The two can achieve electrical decoupling through devices such as optocouplers to avoid the situation where both the main component and the backup component cannot work properly due to the failure of the dual power supply. In addition, the so-called heterogeneous design can be understood from two aspects: software and hardware. The first aspect: the software of the main component and the backup component adopts a heterogeneous architecture design, that is, avoid using system code for the design of the main component and the backup component to prevent the same software exception in the exactly the same architecture from causing the main component and the corresponding backup component to fail together. The second aspect: the hardware platforms of the main component and the backup component are deployed heterogeneously, that is, avoid using the same underlying chip to prevent defects in quality and production process of the hardware with the same circuit architecture or the same production batch from causing the main component and the corresponding backup component to fail together.
[0044] For the process of determining that the operating state of the first controlled component is abnormal for the above-mentioned main control component, this specification can be implemented based on Figures 3a to 3c the different communication systems between the components shown, so as to support multiple anomaly detections.
[0045] In an embodiment, the main control component determines that the operating state of the first controlled component is abnormal based on the first connection between the main control component and the first controlled component. At this time, the first connection can correspond to Figure 3a the communication connection of the centralized architecture between the main control component and x first controlled components in [], and can also correspond to the communication connection between the secondary control component and x second controlled components. In short, when the main control component communicates with any first controlled component through the first connection, the communication content can carry control information from the main control component, status information from any first controlled component, and other information such as handshake information, so that the main control component can quickly locate the first controlled component with an abnormality according to the above status information, and issue corresponding control information to the abnormal first controlled component and the secondary control component to indicate the switching operation of the target backup component in the subsequent steps.
[0046] Among them, a Figure 3aThe special first connection shown, and the communication content corresponding to this connection only needs to include battery status information. The reason is that the core control right of the vehicle power supply is usually in the hands of a dedicated power management module. For example, main control components such as HAD controllers cannot directly control the power on / off or voltage regulation of the power supply. Therefore, the main control components cannot carry control information for the main power supply components in the communication with the main power supply components. Of course, the main control components can interact with the power management system through communication protocols to indirectly affect the power supply strategy. For example, adjusting the load priorities of different first controlled components, so as to meet the flexibility requirements of the autonomous driving system while ensuring the safety and reliability of power management. The same is true for the secondary control component and the backup power supply component in the backup system, which will not be elaborated here in this specification.
[0047] In another embodiment, the above-mentioned main control component can determine that the working state of the above-mentioned first controlled component is abnormal based on the second connection between the above-mentioned main control component and other first controlled components. The above-mentioned other first controlled components are the controlled components in the above-mentioned main components that are different from the above-mentioned first controlled component. For example Figure 3b the first controlled components 2 to y in Figure 3b and the above-mentioned other first controlled components are connected to the above-mentioned first controlled component by a third connection. For example Figure 3b the connection between the first controlled component 1 and each of the first controlled components 2 to y in Figure 3b The same is true for the secondary control component and the y second controlled components in
[0048] Specifically, based on the above-mentioned second connection and third connection, the following can also be derived Figure 3cThe special communication structure shown, in which, although the first controlled component 1 has established a third connection with other first controlled components 3, the first controlled component 3 has further established a communication connection with the first controlled component 2 (for the sake of distinction, this connection is called the fourth connection), so that the three form a hierarchical nested communication link of "master control component → (second connection) → first controlled component 1 → (third connection) → first controlled component 3 → (fourth connection) → first controlled component 2" with the master control component. That is, the first controlled component 3 can independently process the information of the first controlled component 2 through the fourth connection, and the processing result and its own status information of the first controlled component 3 are then independently processed by the first controlled component 1 through the third connection, and the processing result and the status information of the first controlled component 1 are then processed by the master control component 1 through the second connection, further sharing and reducing the calculation pressure of the master control component, thereby improving the determination efficiency of the overall abnormal component.
[0049] In addition, Figure 3c The first controlled component 3 that has already established a third connection with the first controlled component 1 can actually establish a special connection with the master control component (for the sake of distinction, this connection is called the fifth connection) to reduce the communication link between the master control component and the corresponding first controlled component. Specifically, for safety considerations, the time required for the master component to switch operations from detecting an abnormality to determining the target standby component and then to subsequent steps needs to be controlled within a short fixed time, such as 100 milliseconds. Therefore, simply performing hierarchical communication on the above-mentioned first controlled components is likely to consume a lot of time. Therefore, a fifth connection can be established between the first controlled components in these "inner layers" and the master control component, and the key messages that can prove the abnormality of the corresponding first controlled component can be transmitted to the master control component quickly through the above-mentioned fifth connection. As for the remaining non-key messages, they can be analyzed and processed by the first controlled components in the original hierarchical communication relationship in the outer layer. In short, this design effectively compresses the time-consuming of key abnormality determination and optimizes the bandwidth resources through heterogeneous communication links.
[0050] Taking the example of "the driver intervention module as the first controlled component 1, the vehicle driving angle module as the first controlled component 2, the steering component as the first controlled component 3, and the HAD main controller as the main control component", when the driver intervention module receives the real-time torque data of the steering component through the third connection and obtains the yaw rate information of the vehicle driving angle module through the fourth connection at the same time. When the steering component detects that the deviation between the angle command and the actual wheel rotation angle > 15% and lasts for 20 ms, it can directly send the corresponding abnormal emergency fault code to the HAD main controller through the fifth connection, and the HAD main controller triggers redundant switching within 5 ms; at the same time, the steering component still uploads detailed diagnostic logs (such as temperature, current waveform) through the hierarchical link (component 3 → component 1 → main control). This example ensures that when a single point of failure occurs in the steering system, the main control component can not only make quick decisions but also retain the ability for in-depth analysis, and can reduce the load of the main control component through the local preprocessing of the driver intervention module.
[0051] Step S204, switch any one of the main components to the target standby component so that the target standby component replaces the any one of the main components to work.
[0052] After determining the target standby component, any one of the above-mentioned main components that is performing the target task can be aborted, and the target standby component continues to execute the above-mentioned target task, so as to achieve the effect that the target standby component replaces any one of the above-mentioned main components to work.
[0053] Among them, the specific execution method between the main component and the target standby component can be adaptively adjusted according to the execution relationship between the two and the target task before switching, so as to expand the application scenarios of the solution in this specification.
[0054] In one embodiment, in the case where any one of the above-mentioned main components and the above-mentioned target standby component work independently, switch any one of the main components to the above-mentioned target standby component so that the above-mentioned target standby component completely replaces any one of the above-mentioned main components to work. Among them, any one of the above-mentioned main components executes the target task based on the independent working mode, and the corresponding target standby component only performs diagnostic monitoring and data transmission at most under normal conditions and does not participate in real-time control; only when the main component fails, the standby component will completely take over all its functions. For example, in the hydraulic braking system of a vehicle, the main braking component independently responds to the boost demand and controls the ABS system, and the standby braking component only monitors the pressure and fault status under normal conditions. If the main brake fails, the standby unit immediately takes over the brake boost and ABS control, and the main brake exits the working state.
[0055] In another embodiment, when any of the above-mentioned main components works in cooperation with the above-mentioned target standby component, any of the main components is switched to the above-mentioned target standby component so that the above-mentioned target standby component synchronously undertakes the work of any of the main components. Among them, the main component and the standby component cooperate to execute tasks under the cooperation mode in the normal state. The task can refer to the same task or different tasks that are interrelated under the same task. The main component dominates the control decision-making; when the main component fails, the standby component increases its own control weight to maintain the complete function of the system. For example, in the steering system of a vehicle, the main steering component controls 50% of the torque output of the motor assistance, and the standby steering component synchronously executes the remaining 50%. If the main unit fails, the standby unit automatically increases the output to 100% and takes over the function of parsing the steering instructions of the HAD main controller.
[0056] In this specification, different switching strategies can be provided for the abnormal situations of special main components to maintain the integrity of vehicle functions and their normal implementation.
[0057] In one embodiment, when the working state of the above-mentioned main control component or the above-mentioned main power component is abnormal, each main component in the above-mentioned main system can be separately switched to the corresponding standby component in the above-mentioned standby system. Different from other main components, the above-mentioned main control component and the above-mentioned main power component are the core components of the main system. The former is used to control the functions and behaviors of other first controlled components, and the latter provides power support for all main components. Therefore, even if none of the other first controlled components have abnormalities, the standby components used to replace the main components or the main power component may not be able to meet the normal operation requirements of all main components in the main system. For example, when the main power fails, the standby power actually only supports some key first controlled components such as braking and steering, and non-critical modules (such as the entertainment system) are powered off, resulting in abnormalities in related functions. It is necessary to separately switch each main component in the main system to the corresponding standby component in the standby system. Of course, this embodiment is applicable to the L3 autonomous driving level where the performance of the main component and the standby component is not required to be the same. In the case of the L4 autonomous driving level, the vehicle actually does not need to perform an overall switch on the main control component or the above-mentioned main power component, and only needs to separately replace it with the corresponding standby component.
[0058] The following combines Figure 4 to explain in detail the architecture design of vehicle redundant components. As Figure 4As shown, the drive power module 1, main brake 1, brake light 1, wheel speed sensing module 1, parking brake 1, data recorder 1, turn signal module 1, driver intervention module 1, vehicle driving angle module 1, main steering 1, vehicle attitude information 1, rear vehicle visible warning light 1, HMI alarm reminder 1, vehicle-mounted lighting 1, navigation / location 1, sensing redundancy 1, HAD main controller 1, and main power supply 1 in the main component can be sequentially and respectively mapped one-to-one with the drive power module 2, secondary brake 2, brake light 2, wheel speed sensing module 2, parking brake 2, data recorder 2, turn signal module 2, driver intervention module 2, vehicle driving angle module 2, secondary steering 2, vehicle attitude information 2, rear vehicle visible warning light 2, HMI alarm reminder 2, vehicle-mounted lighting 2, navigation / location 2, sensing redundancy 2, HAD secondary controller 2, and backup power supply 2 in the spare components. The above mapping relationship is created based on the breakdown result of the functional safety goal under the ISO 26262 standard. For example, the functional safety goal of "avoiding unexpected loss of lateral motion control" belongs to ASIL D. Therefore, the single-point failure risk can be reduced through redundant design, that is, the main steering 1 (ASIL B) and the secondary steering 2 (ASIL B) are independently designed to ensure that there is no common cause failure between them. Another example is that the functional safety goal of "avoiding unexpected loss of deceleration ability" belongs to ASIL D. Therefore, a braking redundancy system can be involved, that is, the main brake 1 (ASIL B) and the secondary brake 2 (ASIL B) control different hydraulic circuits respectively. For example, the main brake 1 uses traditional hydraulic control, and the secondary brake 2 integrates electro-mechanical braking. The creation process of the mapping relationship between other main components and secondary components is basically the same, so it will not be elaborated in this specification.
[0059] Specifically, looking at the functional safety goal of "avoiding unexpected loss of external lighting and indication of the vehicle itself during the operation of the autonomous driving function" independently, it belongs to ASIL A. Considering the vehicle level, non-redundant design is feasible. However, based on the breakdown result of the functional safety requirements, when the HAD main controller 1 is in control, if the vehicle's autonomous driving technology uses a pure vision solution, then after the lighting fails, the vehicle's duration of maintaining the lane line at night will not be continuous. Therefore, a complementary redundant design for the vehicle-mounted lighting is necessary, meeting the design requirements of the backup link at the ASIL B level of the sensing link. In other words, the lighting system needs to at least meet the total breakdown functional safety requirements of ASIL B and requires a redundant design solution, that is Figure 4 the vehicle-mounted lighting 1 and vehicle-mounted lighting 2 components in
[0060] In addition, if the vehicle corresponds to the L3 autonomous driving level, the redundant design of the drive power module 2 can be considered to save the vehicle's production cost and in-vehicle space without affecting the minimum safety requirements.
[0061] The following Figure 4 explains the minimum safety requirements corresponding to the main components and standby components associated with each mapping relationship in an embodiment of
[0062] 1. Drive power module 1 and drive power module 2: When drive power module 1 fails, drive power module 2 needs to provide a peak torque output of ≥8%, corresponding to an acceleration of 0.15g, and support full speed range from 0 - 150 km / h and cornering conditions with a curvature radius ≥30 m to ensure power continuity, and the switching delay ≤50 ms.
[0063] 2. Main brake 1 and secondary brake 2: When main brake 1 fails, secondary brake 2 needs to achieve a deceleration of ≥0.6g, for example, in the scenario of a dry road surface with an initial vehicle speed of 80 km / h, and activate the Antilock Brake System (ABS) function, with the wheel speed fluctuation control ≤±5% and the response time ≤100 ms.
[0064] 3. Brake light 1 and brake light 2: When brake light 1 fails, brake light 2 needs to activate the dual - light synchronous lighting mode (brightness ≥200 cd / m²) within 50 ms, covering the full - speed - range braking scenarios (including AEB emergency braking), ensuring that the recognition delay of the following vehicle ≤300 ms.
[0065] 4. Wheel speed sensing module 1 and wheel speed sensing module 2: Although the ABS of the braking system requires feedback on the status of each wheel, for some applications in the high - adhesion operation design domain (Operational Design Domain, ODD), non - redundant four - wheel sensors can be considered, and only two front - wheel redundancies are carried out. However, considering that when single wheel speed sensing module 1 fails in the architecture design, relying only on the estimation of the rear - wheel speed by the Inertial Measurement Unit (IMU) and the wheel speed status obtained from the redundancy of two front - wheel speeds by wheel speed sensing module 2 is unreliable. Therefore, wheel speed sensing module 2 needs to be designed with four - wheel independent redundancy, the IMU estimation error compensation threshold ≤2 km / h. When the main module fails, the standby module can provide four - wheel rotation speed data (accuracy ±0.5 km / h) within 20 ms to meet the full - function requirements of ABS / ESP.
[0066] 5. Parking brake 1 and parking brake 2: In the case of the failure of the main control of parking brake 1, parking brake 2 requires that the secondary control can have a parking slope - holding ability of not less than 8% under the condition of maintaining pressure to a stationary vehicle, the hydraulic pressure holding leakage rate ≤0.5 bar / min, and the response time of the electronic parking brake instruction ≤200 ms.
[0067] 6. HAD Master Controller and HAD Slave Controller: In the event of the failure of the HAD Master Controller, for the L3 system, the HAD Slave Controller needs to maintain a 10-second control window provided that the vehicle speed ≤ 60 km / h, and trigger the driver takeover prompt synchronously through means such as "acoustic-optical + tactile warning". For the L4 system, the HAD Slave Controller can cooperate with power redundancy to perform the control of pulling over to the side of the road or the control of stopping in the current lane under non-highway conditions, relying on the high-precision map positioning error ≤ 30 cm.
[0068] 7. Data Record 1 and Data Record 2: The two can be divided into two recording methods. In the event of the failure of Data Record 1, Data Record 2 needs to support the dual-channel synchronous writing of cloud design and local storage, where the data loss rate ≤ 0.1% when a single channel fails, the recording frequency ≥ 100 Hz, and the pre-buffering time for key events (such as AEB triggering) ≥ 30 s. Data recording and extraction can be carried out for accident scenario reproduction or data verification.
[0069] 8. Turn Signal Module 1 and Turn Signal Module 2: In the L3 design, when the turn signal 1 module fails, the vehicle can directly brake to a stop in the current lane without turning, and thus there is no need to consider the redundancy of the turn signal 2 module. However, during the application of the turning function, if a failure occurs in the turn signal module and the turning indication is lost, it will bring the risk that the adjacent vehicle cannot be controllably avoided. The left and right turn signals can be respectively handed over to Turn Signal Module 1 and Turn Signal Module 2 (both modules can be regarded as main components at this time). However, when any one of the modules (assuming it is Turn Signal Module 1) is abnormal, the other turn signal module 2 can be determined as the standby component, which achieves the same effect as the warning light through rapid frequency flashing (flashing frequency 2 Hz, brightness ≥ 150 cd / m²). For L4, Turn Signal Module 1 can pursue a dual-channel redundancy design, that is, Turn Signal Module 2 provides independent redundancy for the left and right turn signals respectively, and when it fails, the lighting logic can be switched through CAN signal remapping.
[0070] 9. Driver Intervention Module 1 and Driver Intervention Module 2: For the functional safety objective of the driver smoothly taking over the autonomous driving state and the override takeover control in an emergency, the torque sensor of the steering wheel (torque detection sensitivity ±0.5 Nm) can be used as part of the driver intervention module for redundancy design without using a switch combination method; or a combination of an ASIL B-compliant autonomous driving function switch (switch response time ≤ 50 ms) and the torque sensor can be jointly used to form an ASIL D design, which can meet the safety objective.
[0071] 10. Vehicle Driving Angle Module 1 and Vehicle Driving Angle Module 2. Regarding the angle situation of vehicle direction steering, Vehicle Driving Angle Module 2 needs to provide redundant detection of the steering wheel rotation angle, with an angle resolution error ≤ 0.5°, a data fusion period with yaw rate ≤ 10 ms, and support for closed-loop correction of steering control. Among them, the vehicle driving angle is essentially obtained by converting the original data collected by the steering wheel rotation angle sensor (such as (dual potentiometer + Hall sensor)) and the algorithm of the vehicle steering system. Its result can be combined with vehicle attitude information, etc., and algorithm calculations are performed by the HAD main controller.
[0072] 11. Main Steering 1 and Auxiliary Steering 2: In the case of failure of Main Steering 1, Auxiliary Steering 2 is required to maintain steering assistance at a vehicle speed ≥ 5 km / h, that is, the output torque ≥ 30 Nm, the steering angle tracking error ≤ 2°, and support for a minimum turning radius ≤ 6 m.
[0073] 12. Vehicle Attitude Information 1 and Vehicle Attitude Information 2. First of all, any component corresponding to vehicle attitude information is required to be used for the vehicle state characteristics obtained by analyzing the collected chassis dynamic information through chassis dynamics algorithms. For example, information such as longitudinal acceleration ax, lateral acceleration ay, yaw rate, roll angle, slip rate, stability state, slope, etc. are used as the processing results of Vehicle Attitude Information 1 or Vehicle Attitude Information 2. Subsequently, they all need to rely on the HAD main controller and the HAD sub-controller for control and management respectively. Among them, the longitudinal / lateral acceleration detection accuracy is ±0.05g, the yaw rate accuracy is ±0.1° / s, and the data output frequency ≥ 100 Hz.
[0074] 13. Rear Vehicle Visible Warning Lights 1 and Rear Vehicle Visible Warning Lights 2: Similar to the above turn signal module, it can be classified and designed based on the left and right lights. In the case of an abnormality of Rear Vehicle Visible Warning Light 1, Rear Vehicle Visible Warning Light 2 achieves the same effect as the hazard warning lights through rapid frequency flashing (4 Hz, brightness ≥ 300 cd / m², night visibility distance ≥ 200 m).
[0075] 14. HMI Alarm Reminder 1 and HMI Alarm Reminder 2: HMI Alarm Reminder 1 can be presented in the form of voice + text; HMI Alarm Reminder 2 can adopt design schemes such as vibrating the seat (5 - 15 Hz) + interior lights (RGB ambient lights in the vehicle fade to red for warning) + light braking reminder (1 Hz, deceleration ≤ 0.1g), that is, alarm complementarity is achieved through diversified combination methods. Among them, voice backup broadcasting can be performed between HMI Alarm Reminder 1 and HMI Alarm Reminder 2 at the voice level, and the voice alarm delay is required to be ≤ 200 ms.
[0076] 15. Vehicle-mounted lighting lamp 1 and vehicle-mounted lighting lamp 2: Vehicle-mounted lighting lamp 1 and vehicle-mounted lighting lamp 2 can be complementary to each other as high beam and low beam. For example, vehicle-mounted lighting lamp 1 is the high beam and vehicle-mounted lighting lamp 2 is the low beam. Specifically, corresponding requirements can be designed according to different recognition capabilities of visual perception. For example, in the scenario of autonomous driving, whether the forward objects and lane lines can be accurately recognized is used as the minimum requirement. Further, the maximum driving speed is used as the key basis. For example, if the vehicle speed is too fast, then the lighting distance of vehicle-mounted lighting lamp 2 as the low beam does not match the perception processing time and cannot be used for a long time. In short, for the complementarity of high beam or low beam, when the low beam fails, the high beam automatically reduces the power to 50% to maintain basic lighting (illumination distance ≥ 60m), which can achieve a low-cost solution selection. If higher requirements are needed, a redundant design of dual high beams can be carried out. When a single lamp fails, the brightness is maintained at ≥ 800 lumens, and the beam deflection compensation angle is ±1.5°.
[0077] 16. Navigation / Location 1 and Navigation / Location 2: Navigation / Location 1 can be the integrated positioning of an electronic map and IMU + Global Navigation Satellite System (GNSS), and Navigation / Location 2 can be the safe operation by using the map of Advanced Driving Assistance System (ADAS) and the self-built map of perception. The positioning data update frequency ≥ 10Hz, and the time synchronization error with the main system (i.e., GNSS + IMU) ≤ 10ms.
[0078] 17. Perception redundancy 1 and perception redundancy 2: It refers to a series of sensor devices used by the vehicle to perceive the surrounding environment. Considering the large number and variety, they are uniformly referred to as perception redundancy. In the case of the failure of perception redundancy 1, it is required that perception redundancy 2 maintains at least no less than 80% of the original perception coverage range, such as a 120° horizontal field of view angle, and the key target detection ability, such as the obstacle recognition accuracy within 50 meters ≥ 95%. And through a heterogeneous sensor combination, such as replacing the failed vision module in perception redundancy 2 with lidar + millimeter-wave radar in perception redundancy 2, to ensure the continuity of multi-source data fusion and at the same time meet the fault response time requirements of ASIL B-level functional safety.
[0079] Figure 5 is a schematic structural diagram of an electronic device in an exemplary embodiment. Please refer to Figure 5, at the hardware level, the electronic device includes a processor 502, an internal bus 510, a network interface 504, a memory 506, and a non-volatile memory 508. Of course, it may also include other required hardware. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it, forming a detection device for risk codes at the logical level. Of course, in addition to the software implementation method, this specification does not exclude other implementation methods, such as logic devices or a combination of software and hardware, etc. That is to say, the execution subject of the following processing flow is not limited to each logical unit, but can also be hardware or a logic device.
[0080] Figure 6 The block diagram of a component switching device for a vehicle shown in an embodiment of this specification. As Figure 6 shown, in this device, the vehicle is deployed with a main system and a standby system. The main component in the main system and / or the standby component in the standby system maintains a mapping relationship between the main component and the standby component with the same function. The mapping relationship is created based on the decomposition result of a preset functional safety target; this device may include:
[0081] A target standby component determination unit 602, configured to, when determining that the operating state of any main component is abnormal, determine the target standby component in the standby system corresponding to the any main component according to the mapping relationship;
[0082] A target standby component switching unit 604, configured to switch any main component to the target standby component so that the target standby component replaces the any main component to work.
[0083] Optionally, the main component includes a main control component and a first controlled component controlled by the main control component, and the standby component includes a secondary control component; this device further includes:
[0084] A first abnormality determination unit, when the main control component determines that the first controlled component meets the component abnormality condition, the main control component determines that the operating state of the first controlled component is abnormal;
[0085] A second abnormality determination unit, when the secondary control component determines that the main control component meets the component abnormality condition, the secondary control component determines that the operating state of the main control component is abnormal.
[0086] Optionally, the standby component further includes a second controlled component controlled by the secondary control component; the target standby component determination unit 602 is specifically configured to:
[0087] When it is determined that the operating state of the first controlled component is abnormal and any one of the main control component and the secondary control component maintains the mapping relationship, the said any one component determines the second controlled component corresponding to the first controlled component in the standby system as the target standby component according to the mapping relationship;
[0088] When it is determined that the operating state of the main control component is abnormal and the secondary control component maintains the mapping relationship, the secondary control component determines itself as the target standby component according to the mapping relationship.
[0089] Optionally, the first abnormality determination unit is specifically configured to:
[0090] The main control component determines that the operating state of the first controlled component is abnormal based on the first connection between the main control component and the first controlled component; or,
[0091] The main control component determines that the operating state of the first controlled component is abnormal based on the second connection between the main control component and other first controlled components, where the other first controlled components are the controlled components in the main component that are different from the first controlled component, and the other first controlled components are connected to the first controlled component by a third connection.
[0092] Optionally, the device further includes:
[0093] A power isolation unit, when the main component includes a main power component and the standby component includes a standby power component, isolates the main power component from the standby power component.
[0094] Optionally, the main component includes a main control component, and the device further includes:
[0095] An all-component switching unit, when the operating state of the main control component or the main power component is abnormal, switches each main component in the main system to the corresponding standby component in the standby system respectively.
[0096] Optionally, the target standby component switching unit 604 is specifically configured to:
[0097] When any main component and the target standby component work independently, switch any main component to the target standby component so that the target standby component completely replaces the work of any main component;
[0098] When any main component and the target standby component work in cooperation, switch any main component to the target standby component so that the target standby component synchronously undertakes the work of any main component.
[0099] For the implementation processes of the functions and roles of each unit in the above device, please refer to the implementation processes of the corresponding steps in the above method for details, which will not be elaborated here.
[0100] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to the partial descriptions of the method embodiments. The device embodiments described above are only illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution in this specification. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0101] Based on the same concept as the above method, this specification also provides an electronic device, including: a processor; a memory for storing processor-executable instructions; wherein, the processor realizes the steps of the method as described in any of the above embodiments by running the executable instructions.
[0102] Based on the same concept as the above method, this specification also provides a computer-readable storage medium, on which computer instructions are stored, and when the instructions are executed by a processor, the steps of the method as described in any of the above embodiments are realized.
[0103] Based on the same concept as the above method, this specification also provides a computer program product, including a computer program / instructions, and when the computer program / instructions are executed by a processor, the steps of the method as described in any of the above embodiments are realized.
[0104] The embodiments of the subject matter and functional operations described in this specification can be implemented in the following: digital electronic circuits, tangible computer software or firmware, computer hardware including the structures disclosed in this specification and their structural equivalents, or a combination of one or more of them. The embodiments of the subject matter described in this specification can be implemented as one or more computer programs, that is, one or more modules in computer program instructions encoded on a tangible non-transitory program carrier to be executed by a data processing device or to control the operation of a data processing device. Alternatively or additionally, the program instructions can be encoded on an artificially generated propagated signal, such as a machine-generated electrical, optical or electromagnetic signal, which is generated to encode information and transmit it to a suitable receiver device for execution by a data processing device. A computer storage medium can be a machine-readable storage device, a machine-readable storage substrate, a random or serial access memory device, or a combination of one or more of them.
[0105] The processes and logical flows described in this specification can be performed by one or more programmable computers executing one or more computer programs to perform the corresponding functions by operating on input data and generating output. The processes and logical flows can also be performed by, for example, special logic circuitry such as an FPGA (Field Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit), and the apparatus can also be implemented as special logic circuitry.
[0106] Computers suitable for executing computer programs include, for example, general and / or special purpose microprocessors, or any other type of central processing unit. Generally, the central processing unit will receive instructions and data from a read-only memory and / or a random access memory. The basic components of a computer include a central processing unit for implementing or executing instructions and one or more memory devices for storing the instructions and data. Generally, a computer will also include one or more mass storage devices for storing data, such as magnetic disks, magneto-optical disks, or optical disks, etc., or the computer will be operatively coupled to such mass storage devices to receive data therefrom or transfer data thereto, or both. However, a computer is not necessarily required to have such devices. In addition, a computer may be embedded in another device, such as a mobile phone, a personal digital assistant (PDA), a mobile audio or video player, a game console, a global positioning system (GPS) receiver, or a portable storage device such as a universal serial bus (USB) flash drive, to name just a few.
[0107] Computer-readable media suitable for storing computer program instructions and data include all forms of non-volatile memory, media, and memory devices, such as including semiconductor memory devices (such as EPROM, EEPROM, and flash memory devices), magnetic disks (such as internal hard disks or removable disks), magneto-optical disks, and CD ROM and DVD-ROM disks. The processor and the memory may be supplemented by, or incorporated in, special logic circuitry.
[0108] Although this specification contains many specific implementation details, these should not be construed as limiting the scope of any invention or the scope of what is claimed, but rather as mainly describing the features of specific embodiments of a particular invention. Certain features described in multiple embodiments in this specification can also be implemented in combination in a single embodiment. On the other hand, the various features described in a single embodiment can also be implemented separately in multiple embodiments or in any suitable sub-combination. In addition, although features may operate in certain combinations as described above and even be initially claimed as such, one or more features from the claimed combination can in some cases be removed from the combination, and the claimed combination can be directed to a sub-combination or a variation of a sub-combination.
[0109] Similarly, although the operations are depicted in the drawings in a particular order, this should not be construed as requiring that the operations be performed in the particular order shown or sequentially, or that all illustrated operations be performed to achieve the desired result. In some cases, multitasking and parallel processing may be advantageous. Additionally, the separation of various system modules and components in the above-described embodiments should not be construed as required in all embodiments, and it should be understood that the program components and systems described can generally be integrated together in a single software product or packaged into multiple software products.
[0110] Thus, particular embodiments of the subject matter have been described. Additionally, the processing depicted in the drawings is not necessarily in the particular order or sequential order shown to achieve the desired result. In some implementations, multitasking and parallel processing may be advantageous.
[0111] The above description is only a preferred embodiment of this specification and is not intended to limit this specification. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of this specification shall be included within the scope of protection of this specification.
Claims
1. A component switching method for a vehicle, characterized in that, The vehicle is deployed with a main system and a backup system. The main components in the main system and / or the backup components in the backup system maintain a mapping relationship between the main components and the backup components with the same function. The mapping relationship is created based on the decomposition result of a preset functional safety goal. The main components include a main control component, a first controlled component controlled by the main control component, and other first controlled components. The first controlled component is a single physical unit. The backup components include a secondary control component. The method includes: When it is determined that the working state of any main component is abnormal, determine the target backup component in the backup system corresponding to the any main component according to the mapping relationship. Switch any main component to the target backup component so that the target backup component replaces the any main component to work. The determination that the working state of any main component is abnormal includes: When the main control component determines that the first controlled component meets the component abnormality condition, the main control component determines that the working state of the first controlled component is abnormal.
2. The method according to claim 1, characterized in that, The determination that the working state of any main component is abnormal includes: When the secondary control component determines that the main control component meets the component abnormality condition, the secondary control component determines that the working state of the main control component is abnormal.
3. The method according to claim 2, wherein The backup components further include a second controlled component controlled by the secondary control component. The determination of the target backup component in the backup system corresponding to the any main component according to the mapping relationship includes: When it is determined that the working state of the first controlled component is abnormal and any one of the main control component and the secondary control component maintains the mapping relationship, the any one of the components determines the second controlled component in the backup system corresponding to the first controlled component as the target backup component according to the mapping relationship. When it is determined that the working state of the main control component is abnormal and the secondary control component maintains the mapping relationship, the secondary control component determines the secondary control component as the target backup component according to the mapping relationship.
4. The method according to claim 2, wherein The main control component determines that the working state of the first controlled component is abnormal, including: The main control component determines that the working state of the first controlled component is abnormal based on the first connection between the main control component and the first controlled component; or, The main control component determines that the working state of the first controlled component is abnormal based on the second connection between the main control component and the other first controlled components, and the other first controlled components are connected to the first controlled component by a third connection.
5. The method according to claim 1, characterized in that, The method further includes: When the main component includes a main power component and the backup component includes a backup power component, isolate the main power component and the backup power component.
6. The method according to claim 5, wherein The main component includes a main control component. The method further includes: When the working state of the main control component or the main power component is abnormal, switch each main component in the main system to the corresponding backup component in the backup system respectively.
7. The method according to claim 1, wherein The switching of any main component to the target backup component includes: When any of the main components works independently of the target standby component, switch any of the main components to the target standby component so that the target standby component completely replaces any of the main components in working. When any of the main components works in cooperation with the target standby component, switch any of the main components to the target standby component so that the target standby component synchronously undertakes the work of any of the main components.
8. The method according to claim 1, wherein The software of the main component and the standby component is designed with a heterogeneous architecture, and the hardware platforms of the main component and the standby component are deployed in a heterogeneous manner.
9. A computer-readable storage medium, characterized in that, Stored thereon are computer instructions which, when executed by a processor, implement the steps of the method according to any one of claims 1 to 8.
10. A computer program product, characterized in that, It includes a computer program / instructions which, when executed by a processor, implement the steps of the method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Lighting system for vehicle and control method for lighting system
CN115742940A
Vehicle control method and device based on functional safety mechanism and central computing architecture
CN116494893A
Control system based on vehicle redundant power supply and method, device and equipment thereof
CN117394512A
Design method and device of vehicle headlamp, electronic equipment and storage medium
CN118981833A