Control right switching method, domain controller, storage medium and vehicle
By automatically switching control rights in the domain controller, using the second SoC and MCU to take over control rights when the first SoC is abnormal, the problem of SoC abnormality affecting the normal driving of the vehicle is solved, and the reliability and stability of the domain controller are improved.
Patent Information
- Application Number
- CN202510163478.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-14
- Publication Date
- 2025-05-16
AI Technical Summary
In autonomous driving mode, system-level chip (SoC) experiences abnormal power failure, downtime or frequent restarts, which seriously affects the normal driving of the vehicle and may cause safety problems.
A control right switching method is provided, using the second SoC to take over the control right when the first SoC is abnormal, and the control right is taken over by a microcontroller unit (MCU) when both the first SoC and the second SoC are abnormal, thereby ensuring normal driving of the vehicle.
By automatically switching control rights, we ensure that the vehicle can continue to drive normally in the case of abnormal main SoC, avoiding driving abnormalities caused by abnormal SoC, and greatly improving the reliability and stability of the domain controller.
Smart Images

Figure CN120010556A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a control right switching method, a domain controller, a storage medium and a vehicle. Background Art
[0002] Domain controllers are essential in vehicle intelligence and autonomous driving technology. The main functions of domain controllers include environmental perception and positioning, decision-making planning, and execution control. The application of domain controllers is not limited to the field of autonomous driving, but is also widely used in intelligent transportation systems, intelligent public transportation systems and other fields.
[0003] At present, domain controllers mainly include system-on-chip (SoC), microcontroller unit (MCU) and components connected to peripheral sensors. SoC is mainly responsible for the calculation, positioning, decision-making and execution control related to autonomous driving. However, if the vehicle is in autonomous driving mode, the SoC has faults such as abnormal power failure, abnormal downtime, frequent restart, etc., which will seriously affect the normal driving of the vehicle and may cause safety problems. Summary of the invention
[0004] In view of this, the present disclosure provides a control authority switching method, a domain controller, a storage medium and a vehicle to improve the reliability and stability of the domain controller under abnormal conditions of the SoC.
[0005] According to a first aspect of the present disclosure, a control right switching method is provided, the method being applied to a domain controller, the domain controller comprising a first SoC, a second SoC and a microcontroller unit MCU; the method comprising:
[0006] The first SoC sends a first message, where the first message carries first status information, where the first status information is used to indicate whether the first SoC is currently abnormal;
[0007] The second SoC receives and parses the first message to obtain the first status information;
[0008] If the first status information indicates that the first SoC is abnormal, the second SoC takes over control and sends a second message to the MCU, where the second message carries second status information, where the second status information is used to indicate whether the second SoC is currently abnormal and whether the takeover is successful;
[0009] The MCU receives and parses the first message and the second message to obtain the first status information and the second status information;
[0010] If the first status information indicates that the first SoC is abnormal and the second status information indicates that the second SoC is abnormal or fails to take over, the MCU takes over control.
[0011] In some implementations of the first aspect of the present disclosure, the method further includes: if the second SoC fails to parse the first message, the second SoC sends a second message to the MCU, and the second status information carried in the second message indicates that the second SoC fails to take over.
[0012] In some implementations of the first aspect of the present disclosure, the method further includes: the second SoC detects its own status in real time and sends the second message to the MCU, the second message carries second status information indicating whether the second SoC is currently normal or abnormal.
[0013] In some implementations of the first aspect of the present disclosure, the method further comprises:
[0014] The second SoC returns a first response to the first SoC, where the first response carries first feedback information, where the first feedback information is used to indicate whether the second SoC succeeds or fails in parsing the first message;
[0015] The MCU returns a second response to the first SoC, where the second response carries second feedback information, where the second feedback information is used to indicate whether the MCU succeeds or fails in parsing the first message;
[0016] The first SoC receives and parses the first response and the second response to obtain the first feedback information and the second feedback information;
[0017] When the first feedback information indicates that the second SoC fails to parse the first message and the second feedback information indicates that the MCU fails to parse the first message, the first SoC issues an abnormal alarm.
[0018] In some implementations of the first aspect of the present disclosure, the method also includes: the MCU returns a third response to the second SoC, the third response carries third feedback information, and the third feedback information is used to indicate whether the MCU's parsing of the second message is successful or failed; the second SoC receives and parses the third response to obtain the third feedback information, and the second SoC issues an abnormal alarm when the third feedback information indicates that the MCU fails to parse the second message.
[0019] In some implementations of the first aspect of the present disclosure, the method further includes: the MCU detecting its own state in real time, and issuing an abnormal alarm when detecting that its own state is abnormal.
[0020] In some implementations of the first aspect of the present disclosure, the method further includes one of the following:
[0021] If the second status information indicates that the second SoC has taken over successfully, the MCU sends a control right switching message to the host computer, where the control right switching message carries information indicating that the second SoC has taken over control;
[0022] If the MCU successfully takes over the control right, the MCU sends a control right switching message to the host computer, and the control right switching message carries information indicating that the MCU has taken over the control right.
[0023] According to a second aspect of the present disclosure, a domain controller is provided, comprising: a first SoC, a second SoC, an MCU and a memory storing a program, wherein the program comprises instructions, and the instructions implement the above method when executed by the first SoC, the second SoC and the MCU.
[0024] According to a third aspect of the present disclosure, a computer-readable storage medium storing a program is provided, wherein the program includes instructions, and when the instructions are executed by one or more processors of a computing device, the computing device executes the above method.
[0025] According to a fourth aspect of the present disclosure, a vehicle is provided, comprising the above-mentioned domain controller.
[0026] It can be seen from the above technical solution that in the embodiment of the present disclosure, when the first SoC is abnormal, the second SoC takes over the control, and when both the first SoC and the second SoC are abnormal, the MCU takes over the control. Therefore, when the master SoC is abnormal, the control can be automatically switched to the slave SoC. In the case of an abnormality in the main SoC, the control can be automatically switched to ensure the normal operation of the automatic driving mode, prevent the abnormality of the main SoC from affecting normal driving, and avoid driving abnormalities caused by the failure of functions such as automatic driving to proceed normally in driverless scenarios. When both the master SoC and the slave SoC are abnormal, the control is automatically switched to the MCU, which effectively prevents driving abnormalities caused by abnormalities in the master SoC and the slave SoC, and greatly improves the reliability and stability of the domain controller. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] In order to more clearly illustrate the embodiments of the present disclosure or the technical solutions in the prior art, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0028] Figure 1 A schematic diagram of the structure of a domain controller provided in an embodiment of the present disclosure;
[0029] Figure 2 A flow chart of a control right switching method provided in an embodiment of the present disclosure;
[0030] Figure 3 This is a schematic diagram of periodic sending of a first message involved in an embodiment of the present disclosure;
[0031] Figure 4 This is a schematic diagram of the structure of a first message involved in an embodiment of the present disclosure;
[0032] Figure 5 A schematic diagram of a specific implementation process of the control right switching involved in the embodiment of the present disclosure;
[0033] Figure 6 A schematic diagram of a port scene involved in an embodiment of the present disclosure;
[0034] Figure 7 A schematic structural block diagram of an electronic device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION
[0035] The following will be combined with the drawings in the embodiments of the present disclosure to clearly and completely describe the technical solutions in the embodiments of the present disclosure. Obviously, the described embodiments are only part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present disclosure.
[0036] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments, and are not intended to limit the present disclosure. The singular forms "a", "said" and "the" used in the embodiments of the present disclosure and the appended claims are also intended to include plural forms, unless the context clearly indicates other meanings.
[0037] As used herein, the words "if," "if," and the like may be interpreted as "at the time of" or "when" or "in response to determining" or "in response to detecting," depending on the context. Similarly, the phrases "if it is determined" or "if (stated condition or event) is detected" may be interpreted as "when it is determined" or "in response to determining" or "when detecting (stated condition or event)" or "in response to detecting (stated condition or event)," depending on the context.
[0038] As mentioned above, if the main SoC has abnormalities such as abnormal power failure, abnormal downtime, frequent restart, etc. during vehicle driving, it will not only affect the normal driving of the vehicle, but also may cause safety problems. In view of this, the embodiment of the present disclosure provides the following control right switching method, domain controller, storage medium and vehicle. The first SoC, the second SoC and the MCU in the domain controller realize multi-level backup control right switching, which effectively improves the reliability of the domain controller and prevents the abnormality of the main SoC in the domain controller from affecting the normal driving of vehicles and other equipment.
[0039] The embodiments of the present disclosure can be applied to scenes such as ports, highways, logistics, mines, farms, closed parks, urban transportation, etc., and can be applied to many aspects such as logistics distribution, unmanned transportation, terminal distribution, car travel, automated agricultural operations, automated sanitation, etc. Of course, the embodiments of the present disclosure can also be applied to any other intelligent control scenes involving equipment such as vehicles, and the present disclosure does not limit the application scenes and applicable fields of the embodiments of the present disclosure.
[0040] The disclosed embodiments can be applied to the control of various types of equipment such as multiple wheeled mobile robots, wheeled mobile robots, mobile robots, vehicles, aircraft, ships, and intelligent rail rapid transit systems (ART, Autonomous rail Rapid Transit). The vehicles can be, but are not limited to, passenger cars, commercial vehicles (e.g., trucks, buses, vans, etc.), special-purpose vehicles (e.g., ambulances, fire trucks, engineering vehicles, rescue vehicles, etc.), agricultural and industrial vehicles (e.g., harvesters, forklifts, etc.), transportation and logistics vehicles (e.g., container trucks, refrigerated trucks, etc.), new energy vehicles (e.g., electric vehicles, hybrid electric vehicles), and special vehicles (e.g., garbage trucks, sprinkler trucks, etc.). In other words, the "vehicles", "container trucks", etc. involved in the disclosed embodiments can be replaced by any of the aforementioned equipment.
[0041] For ease of understanding, the domain controller provided in the embodiment of the present disclosure is first described in detail below.
[0042] Figure 1 FIG. 1 shows a schematic diagram of the structure of a domain controller provided by an embodiment of the present disclosure. Figure 1 The domain controller 100 provided in the embodiment of the present disclosure may include: a first SoC 110, a second SoC 120 and an MCU 130, and the first SoC 110, the second SoC 120 and the MCU 130 communicate with each other.
[0043] In some implementations, the domain controller 100 may further include a buffer integrated circuit (BUFFER IC) 140 , through which the first SoC 110 , the second SoC 120 , and the MCU 130 are connected to achieve two-to-two communication.
[0044] Specifically, the first SoC 110, the second SoC 120 and the MCU 130 can be communicatively connected and / or electrically connected via a buffer integrated circuit. The first SoC 110, the second SoC 120 and the MCU 130 communicate via the BUFFER IC, which not only increases the driving capability, but also the buffer integrated circuit 140 has an enable pin, which facilitates the individual control of any communication path.
[0045] In some embodiments, the first SoC 110, the second SoC 120 and the MCU 130 can communicate through a universal asynchronous receiver / transmitter (UART). UART is a serial, asynchronous, full-duplex communication protocol widely used in the embedded field. UART communication does not rely on a clock signal, which makes it very flexible in asynchronous communication and can adapt to different data transmission rates and clock domains. UART supports full-duplex communication, that is, data can be sent and received at the same time, which is very useful for application scenarios such as vehicle control that require real-time two-way communication. UART communication usually consumes less power than parallel communication, which is particularly applicable to battery-powered devices (such as electric vehicles, etc.). In addition, UART also has the advantages of easy implementation, easy expansion, convenient debugging, good data integrity, easy integration, low hardware cost, etc., and is particularly suitable for flexible control of devices such as vehicles in the disclosed embodiments.
[0046] It should be noted that the communication method among the first SoC 110, the second SoC 120 and the MCU 130 in the domain controller 100 is not limited to the above-mentioned UART, and various other applicable communication methods may also be adopted, and the embodiments of the present disclosure do not limit this.
[0047] In the disclosed embodiment, the first SoC 110 and the second SoC 120 may adopt SoCs of different architectures or SoCs of the same architecture. Since the SoC integrates multiple processing cores, such as CPU, GPU, DSP, etc., it can process a large amount of data and complex computing tasks, which enables the first SoC 110 and the second SoC 120 to respectively perform complex tasks such as perception, positioning, path planning, decision-making, lane keeping, automatic speed adjustment, automatic joining of formations, automatic driving, etc., and manage electronic control units (ECUs) in specific fields.
[0048] The first SoC 110 and the second SoC 120 can be respectively connected to the peripheral sensor component 200 to obtain sensor data from the peripheral sensor component 200 and perform complex tasks such as perception and path planning based on the data, thereby realizing autonomous driving of the vehicle.
[0049] MCU 130 may be responsible for managing the electronic control unit (ECU) in a specific domain, controlling the components in the domain controller, and powering on and off the components to which the MCU is communicatively connected and / or electrically connected. In some examples, MCU 130 may be used to perform control tasks that require low computing resources and do not require sensor data from peripheral sensor components, such as turning on and off flashers, driving at low speeds, and driving to emergency lanes.
[0050] MCU 130 can also be responsible for interacting with the external host computer 300. The host computer 300 can be used as a remote control terminal, a user control terminal, or a cloud control terminal of the vehicle, and can be used to implement remote control, user control, cloud control, etc. of all vehicles or certain specified ones in a closed environment. MCU130 can interact with the host computer 300 through, for example, Ethernet, a mobile communication network, a local area network, or other wireless communication networks. In some examples, MCU130 can be used to report vehicle conditions to the host computer 300, such as the owner of the vehicle control right, the vehicle working status, etc. For example, when the vehicle control right is switched, the vehicle is working in the automatic driving mode, etc., MCU130 can report relevant information to the host computer 300 so that the control terminal can understand the vehicle condition in real time.
[0051] The domain controller 100 is connected to the power system, chassis system, body system, electrical system, safety system, fuel system, emission control system, smart cockpit system, etc. through the controller area network (CAN) bus. Specifically, the first SoC 110, the second SoC 120 and the MCU 130 are connected to the vehicle systems such as the power system, chassis system, body system, electrical system, safety system, fuel system, emission control system, smart cockpit system, etc. through the CAN bus.
[0052] In specific applications, the functions of the first SoC 110, the second SoC 120 and the MCU 130 and the vehicle control tasks that can be executed can be flexibly adjusted as needed. The embodiments of the present disclosure do not limit the specific functions of the first SoC 110, the second SoC 120 and the MCU 130 and the specific control tasks that they execute.
[0053] Figure 2 FIG. 1 is a flow chart of a control right switching method provided by an embodiment of the present disclosure, which method can be executed by the aforementioned domain controller 100. Figure 2 , the method of the embodiment of the present disclosure may include the following steps:
[0054] Step 201: The first SoC sends a first message, where the first message carries first status information, and the first status information is used to indicate whether the first SoC is currently abnormal.
[0055] Step 202, the second SoC receives and parses the first message to obtain first status information;
[0056] Step 203: If the first status information indicates that the first SoC is abnormal, the second SoC takes over control and sends a second message to the MCU, where the second message carries second status information, and the second status information is used to indicate whether the second SoC is currently abnormal and whether the takeover is successful.
[0057] Step 204, the MCU receives and parses the first message and the second message to obtain first status information and second status information;
[0058] Step 205 , if the first status information indicates that the first SoC is abnormal and the second status information indicates that the second SoC is abnormal or fails to take over, the MCU takes over control.
[0059] In the disclosed embodiment, when the first SoC is abnormal, the second SoC takes over the control, and when both the first SoC and the second SoC are abnormal, the MCU takes over the control. Therefore, when the master SoC is abnormal, the control right can be automatically switched to the slave SoC. In the case of an abnormality in the master SoC, the control right can be automatically switched to ensure the normal operation of the autonomous driving mode, prevent the abnormality of the main SoC from affecting normal driving, and avoid driving abnormalities caused by the failure of functions such as autonomous driving to operate normally in driverless scenarios. When both the master SoC and the slave SoC are abnormal, the control right is automatically switched to the MCU, effectively preventing driving abnormalities caused by abnormalities in the master SoC and the slave SoC, thereby greatly improving the reliability and stability of the domain controller.
[0060] In a specific application, abnormal states may be pre-configured for the first SoC, the second SoC, and the MCU, respectively. The first SoC, the second SoC, and the MCU determine whether they are abnormal by detecting whether their current working states conform to their pre-configured abnormal states.
[0061] In the embodiments of the present disclosure, the "abnormalities" of the first SoC, the second SoC, and the MCU can be flexibly set according to the application scenario and actual needs. In some examples, the "abnormality" may include, but is not limited to: internal process stuck, abnormal working voltage, abnormal power failure, and frequent restarts. Those skilled in the art should understand that the "abnormalities" of the first SoC, the second SoC, and the MCU are not limited to the above situations, and may also include other similar situations. As long as a situation that affects the normal operation of the SoC or MCU occurs, it can be regarded as an "abnormality". In this regard, the embodiments of the present disclosure are not limited.
[0062] In step 201, the first SoC may send the first message in a variety of ways. In some examples, the first SoC may send the first message when detecting an abnormality in itself. In some examples, the first SoC may detect its own state in real time and send the first message periodically, that is, the first message is sent regardless of whether the first SoC is abnormal or not, and the first state information carried in the first message indicates whether the first SoC is normal or abnormal.
[0063] In step 201, the first SoC may send a first message to the second SoC and the MCU. In some implementations, the first SoC may send the first message to the first SoC and the MCU in the form of message broadcasting. Figure 3An example diagram of periodic transmission of the first message is shown. Figure 3 , the first SoC continuously sends two frames at a certain interval (for example, 1 second), the first frame is sent to the first SoC, and the second frame is sent to the MCU, and the first frame and the second frame are both independent first messages. Therefore, the first SoC can notify the second SoC and the MCU of its own status in real time by periodically sending the first message.
[0064] In some examples, the first message may be a UART message, which may be Figure 4 See the data format shown in Figure 4 , the first message may include: a start bit, a data bit, a check bit and a stop bit. The start bit may be fixed to a low level of one bit, used to mark the beginning of the data frame; the data bit contains the valid data to be transmitted, which may be 5-9 bits; the check bit is an optional data bit, used for data verification, which may be odd, even or no check; the stop bit may be fixed to a high level of one or two bits, used to mark the end of the data frame. The second message, the third message, the first response, the second response and the third response below may respectively adopt the same format and structure as the first message.
[0065] Since UART messages have high reliability and security, they can provide reliable data transmission in different environments and prevent data leakage and tampering. At the same time, UART messages are also highly flexible and can adapt to different communication needs by changing the data transmission rate. Therefore, UART is better suitable for control switching scenarios.
[0066] In the first message and the second message, the data content (i.e., the content of the data bit part of the preceding text) may include, but is not limited to, a message identifier (e.g., a destination address, a receiver identifier, etc.) for indicating the message recipient, and information for indicating the status. In some examples, the data formats of the first message and the second message may be the same, and may include an idle bit, a start bit, and valid data, respectively. The idle bit is a high level, the start bit is a low level, and the valid data is 1 byte. The upper 4 bits of the 1 byte are the message identifier, which is used to distinguish the recipient of the message, and the lower 4 bits of the 1 byte are information indicating the working status.
[0067] Table 1 shows the data content of the first message. Among them, "1" in "10" is an idle bit, "0" indicates the start bit, the upper 4 bits "0001" indicate that the first message is sent to the second SoC, the upper 4 bits "0010" indicate that the first message is sent to the MCU, the lower 4 bits "0101" indicate that the current working state of the first SoC is normal, and the lower 4 bits "1010" indicate that the current working state of the first SoC is abnormal.
[0068] Data content Functional Description 10 0001 0101 Sent to second SoC, first SoC works fine 10 0001 1010 Sent to the second SoC, the first SoC works abnormally 10 0010 0101 Sent to MCU, the first SoC works fine 10 0010 1010 Sent to MCU, the first SoC works abnormally
[0069] Table 1
[0070] Table 2 shows the data content of the second message. Among them, "1" in "10" is an idle bit, "0" indicates the start bit, the upper 4 bits "1010" indicate that the recipient of the second message is the MCU, the lower 4 bits "0101" indicate that the current state of the second SoC is normal, the lower 4 bits "1010" indicate that the current state of the second SoC is abnormal, and the lower 4 bits "1111" indicate that the second SoC has successfully taken over control.
[0071]
[0072]
[0073] Table 2
[0074] In step 202, after receiving the first message, the second SoC parses the first message from the first SoC. If the first state information is obtained through parsing and the data verification of the first state information is correct, the parsing is successful. If the parsing is not completed or the data verification of the first state information obtained through parsing is wrong, the parsing fails, and the second SoC can directly discard the currently received first message.
[0075] In some implementations, the method of the embodiment of the present disclosure may further include: the second SoC sends a second message to the first SoC; when the second SOC is determined to be abnormal through the second message, the first SoC may take over the control and send control takeover success information (for example, it may be sent through the first message) to the second SoC and the MCU. Here, if the first SoC fails to take over the control, the control takeover failure information may be sent to the second SoC and the MCU, or if the first SoC is abnormal and cannot send messages normally, the control takeover failure information cannot be sent.
[0076] Furthermore, the method of the embodiment of the present disclosure may also include: the MCU waits for a predetermined period of time (for example, 100ms) after receiving the second message; if the MCU receives the controller takeover success information from the first SoC within the predetermined period of time, the control right takeover action is not performed; if the control right takeover failure information is received from the first SoC within the predetermined period of time, the control right is automatically taken over; if no message (for example, the controller takeover success information from the first SoC) is received within the predetermined period of time, the MCU automatically takes over the control right.
[0077] Taking into account that the second SoC may not be able to send and receive messages normally if it is abnormal, the method of the embodiment of the present disclosure may further include: the MCU waits for a predetermined period of time (for example, 100ms) after receiving the first message. If no message of successful takeover is received after the predetermined period of time, it proves that the current state of the second SoC may be abnormal, and the MCU can take over control.
[0078] Figure 5 A schematic diagram of a specific implementation process of control right switching according to an embodiment of the present disclosure is shown.
[0079] In some embodiments, see Figure 5 The above method of the embodiment of the present disclosure may further include: Step 206, if the second SoC fails to parse the first message, the second SoC may send a second message to the MCU, and the second status information carried in the second message indicates that the second SoC fails to take over. Therefore, when the second SoC cannot correctly identify the first message, the MCU is notified through the second message so that the MCU can take over the control in time.
[0080] In some embodiments, see Figure 5 The above method of the embodiment of the present disclosure may further include: Step 207, the second SoC may detect its own state in real time and send a second message to the MCU, the second message carrying second state information indicating whether the second SoC is currently normal or abnormal. Thus, the second SoC may notify the MCU of its own state in a timely manner, so that the MCU can take over the control right in a timely manner in combination with the real-time state of the first SoC and the real-time state of the second SoC.
[0081] In a specific application, the second message can be sent periodically or when the second SoC finds itself abnormal. The periodic sending method of the second message is the same as the sending method of the first message above, except that the second message only needs to be sent to the MCU.
[0082] In the above method of the embodiment of the present disclosure, if the first status information indicates that the first SoC is currently normal, the second SoC and MCU can maintain the current status unchanged, that is, do not take over the control, and the first SoC still takes over the control.
[0083] In step 203, when the first status information indicates that the first SoC is abnormal, if the second SoC detects that its own status is normal, the second SoC can take over control actively. After the second SoC successfully takes over control, the working mode of the domain controller can be kept unchanged. For example, if the vehicle is in automatic driving mode, after the second SoC takes over control, it continues to plan and control the vehicle using the intermediate data required for the current working mode of the vehicle provided by the first SoC, the data provided by each sensor component, etc., so that the vehicle remains in the current automatic driving mode. In this way, the control of the vehicle can be switched without external sensing and the driving state of the vehicle remains unchanged.
[0084] In step 204, after receiving the first message, the MCU parses the first message from the first SoC. If the first state information is obtained through parsing and the data verification of the first state information is correct, the second message parsing is successful. If the parsing is not completed or the parsed first state information data verification is wrong, the second message parsing fails, and the MCU directly discards the currently received second message.
[0085] After receiving the second message, the MCU parses the second message from the second SoC. If the second state information is obtained through parsing and the second state information data is verified to be correct, the second message parsing is successful. If the parsing fails or the parsed second state information data is verified to be incorrect, the second message parsing fails, and the MCU directly discards the currently received second message.
[0086] In some embodiments, see Figure 5 The above method of the embodiment of the present disclosure may further include: Step 208, if the second status information indicates that the second SoC has taken over successfully, the MCU may send a control switching message to the host computer, and the control switching message carries information indicating that the second SoC has taken over control.
[0087] In some embodiments, see Figure 5 The above method of the embodiment of the present disclosure may further include: Step 209, if the MCU successfully takes over the control right, the MCU sends a control right switching message to the upper computer, and the control right switching message carries information indicating that the MCU has taken over the control right.
[0088] In some examples, in step 209, after the MCU successfully takes over the control right, an interrupt event may be triggered, and in response to the interrupt event, the MCU sends a control right switching message to the host computer.
[0089] In specific applications, the MCU can send a control right switching message to the host computer via Ethernet, 4G network or other wireless communication networks to convey to the host computer the message that the second SoC has taken over the control right.
[0090] From the above, after the MCU or the second SoC takes over the control, it can send a control right switching message to the host computer, so that the host computer can understand the switching status of the vehicle control right in real time.
[0091] Further, see Figure 5The above method of the embodiment of the present disclosure may further include: Step 210, the second SoC returns a first response to the first SoC, the first response carries first feedback information, and the first feedback information is used to indicate whether the second SoC successfully or failed to parse the first message. Thus, the first SoC can understand the parsing of the first message by the second SoC in real time, so as to perform protective measures such as abnormal alarm when the parsing of the first message fails, so as to further improve the reliability of the domain controller.
[0092] Further, see Figure 5 The method of the embodiment of the present disclosure may further include: step 211, the MCU returns a second response to the first SoC, the second response carries second feedback information, and the second feedback information is used to indicate whether the MCU successfully or failed to parse the first message. Thus, it is convenient for the first SoC to execute protective measures such as abnormal alarm when the parsing of the first message fails, so as to further improve the reliability of the domain controller.
[0093] Further, see Figure 5 , the above method of the embodiment of the present disclosure may also include: step 212, the first SoC receives and parses the first response and the second response to obtain the first feedback information and the second feedback information, and when the first feedback information indicates that the second SoC fails to parse the first message and the second feedback information indicates that the MCU fails to parse the first message, the first SoC issues an abnormal alarm. Thus, the first SoC can provide an alarm to the user side in a timely manner when it is abnormal and the second SoC and MCU cannot correctly parse the message, so that the operator can understand the status of the domain controller in real time, thereby further improving the reliability of the domain controller.
[0094] In some embodiments, see Figure 5 , the above method of the embodiment of the present disclosure may also include: step 213, the MCU returns a third response to the second SoC, the third response carries third feedback information, and the third feedback information is used to indicate whether the MCU succeeds or fails in parsing the second message; step 214, the second SoC receives and parses the third response to obtain the third feedback information, and the second SoC issues an abnormal alarm when the third feedback information indicates that the MCU fails to parse the second message. Therefore, the second SoC can execute protective measures such as abnormal alarm when the second message fails to be parsed, further improving the reliability of the domain controller.
[0095] In some implementations, the above method of the embodiment of the present disclosure may further include: the MCU detects its own state in real time, and when the MCU detects that its own state is abnormal, the MCU issues an abnormal alarm. Thus, the MCU can notify the user side by means of an abnormal alarm when it is abnormal, so that the operator can understand the status of the domain controller in real time, thereby further improving the reliability of the domain controller.
[0096] In specific applications, the specific methods of abnormal alarm may include but are not limited to one or more of the following: 1) sending an alarm message to the host computer so that the host computer can issue an alarm; 2) sending fault information to the chassis system, body system, electrical system, safety system, intelligent cockpit system, etc. through the CAN bus, so that the alarm system of the vehicle can issue an alarm to the user. It should be understood by those skilled in the art that the specific implementation method of abnormal alarm may also include any other applicable methods, and the embodiments of the present disclosure are not limited to this.
[0097] In some implementations, after step 205, the above method of the embodiment of the present disclosure may further include: after the MCU takes over control, exiting the automatic driving mode and controlling the vehicle to travel in a predetermined mode, and the predetermined mode may include one of the following: 1) controlling the vehicle to slow down and pull over to the side of the road so that staff can perform subsequent fault maintenance on the vehicle; 2) reminding the driver to take over the vehicle and controlling the vehicle to travel in response to the driver's operation.
[0098] For example, in closed environments such as ports, vehicles usually do not have drivers, but are remotely controlled by the control terminal or operators. Most of these vehicles use autonomous driving mode. In similar scenarios, if the first SoC is abnormal and the second SoC fails to take over control, but the MCU takes over control, the autonomous driving mode may not be supported. The MCU can use the aforementioned 1) mode to control the vehicle to slow down and stop, so that the operator or tester can perform fault maintenance on the vehicle's domain controller, thereby effectively preventing the vehicle from being unable to drive normally due to the abnormality of the first SoC, resulting in abnormal vehicle driving and even accidents, thereby improving the reliability of the vehicle's autonomous driving mode in similar scenarios.
[0099] Figure 6 A schematic diagram of a port scenario is shown. In the port scenario, each container truck is deployed with a domain controller provided by an embodiment of the present disclosure. The container truck has no driver but works in an automatic driving mode under the control of an operator and / or a host computer. The above method of the embodiment of the present disclosure is applied to Figure 6In the scenario shown, when the first SoC (i.e., the main SoC) in the domain controller of the container truck is abnormal, the second SoC (i.e., the slave SoC) takes over the control and continues to control the container truck to travel in the automatic driving mode. If both the second SoC and the first SoC are abnormal, the MCU in the domain controller takes over the control. After the MCU takes over the control, the aforementioned predetermined mode 1) can be adopted to control the container truck to slow down and stop, so that relevant personnel can perform fault maintenance on the domain controller in the container truck. It can be seen that by applying the embodiment of the present disclosure to the port scenario, the container truck can be kept working normally in the automatic driving mode by automatically switching the control right to the slave SoC when the main SoC is abnormal. When both the main SoC and the slave SoC are abnormal, the control right is automatically switched to the MCU, and the MCU controls the container truck to stop in time, thereby effectively reducing the impact of the abnormality of the main SoC on the normal operation of the container truck, and at the same time reducing the abnormal driving of the container truck that may be caused by all SoC failures.
[0100] For example, when there is a driver in the vehicle, after the MCU takes over control, it can remind the driver to take over the vehicle and control the vehicle's driving in response to the driver's operation.
[0101] The domain controller and control switching method provided in the embodiments of the present disclosure adopt a multi-level backup control logic, that is, when the first SoC is abnormal, the second SoC actively takes over the control, and when the second SoC is abnormal, the MCU actively takes over the control. The second SoC serves as the preferred line of defense for the domain controller, and the MCU serves as the last line of defense for the domain controller, which effectively improves the reliability of the domain controller.
[0102] In addition, an embodiment of the present disclosure further provides a computer-readable storage medium on which a computer program is stored. The program includes instructions, and when the instructions are executed by one or more processors, the steps of the aforementioned control right switching method are executed.
[0103] In a specific application, the domain controller 100 provided in the embodiment of the present disclosure may be implemented as an electronic device. Figure 7 Schematic diagram of the structure of the electronic device is shown. Figure 7 The electronic device 700 may include: multiple processing units 701, and also include a memory 702 for storing one or more programs, which are executed by the above-mentioned multiple processing units 701 to implement the method flow shown in the above-mentioned embodiments of the present disclosure and / or the program units corresponding to each unit in the device.
[0104] The various components are interconnected using different buses and can be mounted on a common motherboard or in other ways as needed. The processing unit 701 can process instructions executed within the electronic device, including instructions stored in or on the memory to display graphical information of the user interface on an external input / output device (such as a display device coupled to the interface). In other embodiments, if desired, multiple processors and / or multiple buses can be used with multiple memories and multiple memories.
[0105] The processing unit 701 may include the aforementioned first SoC, second SoC, and MCU.
[0106] The memory 702 is a computer-readable storage medium provided by the present disclosure, which can be used to store non-transient software programs, non-transient computer executable programs and units, such as the following in the embodiments of the present disclosure: Figure 2 The processor 701 executes the non-transient software programs, instructions and units stored in the memory 702 to perform the above method embodiments. Figure 2 The program, instructions and units corresponding to the control right switching method shown.
[0107] The electronic device 700 may further include: an input device 703 and an output device 704. The processor 701, the memory 702, the input device 703 and the output device 704 may be connected via a bus or other means. Figure 7 The example of connecting through bus is taken in the following.
[0108] The input device 703 can receive input digital or character information, and generate signal input related to user settings and function control, such as a touch screen, a keypad, a mouse, a track pad, a touch pad, an indicator rod, one or more mouse buttons, a track ball, a joystick and other input devices. The output device 704 may include a display device, an auxiliary lighting device (e.g., an LED) and a tactile feedback device (e.g., a vibration motor), etc. The display device may include, but is not limited to, a liquid crystal display (LCD), a light emitting diode (LED) display and a plasma display. In some embodiments, the display device may be a touch screen.
[0109] The above-mentioned programs (also referred to as software, software applications, or codes) include machine instructions for programmable processors, and these computer programs can be implemented using object-oriented programming languages, assembly or machine languages.
[0110] With the development of time and technology, the meaning of medium is becoming more and more extensive, and the propagation path of computer programs is no longer limited to tangible media, and can also be downloaded directly from the network, etc. Any combination of one or more computer-readable storage media can be used. Computer-readable storage media can be used but not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or devices, or any combination of the above. More specific examples (non-exhaustive list) of computer-readable storage media include: portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this document, computer-readable storage media can be any tangible medium containing or storing programs, which can be used by or in combination with instruction execution systems, devices or devices.
[0111] The embodiment of the present disclosure further provides a vehicle, which may include the aforementioned domain controller 100. The vehicle may implement, but is not limited to, the aforementioned various types of equipment such as multiple wheeled mobile robots, wheeled mobile robots, mobile robots, vehicles, aircraft, ships, and an autonomous rail rapid transit system (ART).
[0112] The technical solution provided by the present disclosure is described in detail above. The principles and implementation methods of the present disclosure are described in detail using specific examples. The description of the above embodiments is only used to help understand the method and core idea of the present disclosure. At the same time, for those skilled in the art, according to the idea of the present disclosure, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as limiting the present disclosure.
[0113] The above description is only a preferred embodiment of the present disclosure and is not intended to limit the present disclosure. Any modifications, equivalent substitutions, etc. made within the spirit and principles of the present disclosure should be included in the protection scope of the present disclosure.
Claims
1. A control right switching method, characterized in that: The method is applied to a domain controller, the domain controller includes a first SoC, a second SoC and a microcontroller unit MCU; the method includes: The first SoC sends a first message, where the first message carries first status information, where the first status information is used to indicate whether the first SoC is currently abnormal; The second SoC receives and parses the first message to obtain the first status information; If the first status information indicates that the first SoC is abnormal, the second SoC takes over control and sends a second message to the MCU, where the second message carries second status information, where the second status information is used to indicate whether the second SoC is currently abnormal and whether the takeover is successful; The MCU receives and parses the first message and the second message to obtain the first status information and the second status information; If the first status information indicates that the first SoC is abnormal and the second status information indicates that the second SoC is abnormal or fails to take over, the MCU takes over control.
2. The method according to claim 1, characterized in that The method further comprises: If the second SoC fails to parse the first message, the second SoC sends a second message to the MCU, and the second status information carried in the second message indicates that the second SoC fails to take over.
3. The method according to claim 1, characterized in that The method further comprises: The second SoC detects its own state in real time and sends the second message to the MCU, where the second message carries information indicating a second state, where the second state information is used to indicate whether the second SoC is currently normal or abnormal.
4. The method according to any one of claims 1 to 3, characterized in that: The method further comprises: The second SoC returns a first response to the first SoC, where the first response carries first feedback information, where the first feedback information is used to indicate whether the second SoC succeeds or fails in parsing the first message; The MCU returns a second response to the first SoC, where the second response carries second feedback information, where the second feedback information is used to indicate whether the MCU succeeds or fails in parsing the first message; The first SoC receives and parses the first response and the second response to obtain the first feedback information and the second feedback information; When the first feedback information indicates that the second SoC fails to parse the first message and the second feedback information indicates that the MCU fails to parse the first message, the first SoC issues an abnormal alarm.
5. The method according to any one of claims 1 to 3, characterized in that: The method further comprises: The MCU returns a third response to the second SoC, where the third response carries third feedback information, where the third feedback information is used to indicate whether the MCU succeeds or fails in parsing the second message; The second SoC receives and parses the third response to obtain the third feedback information, and the second SoC generates an abnormal alarm when the third feedback information indicates that the MCU fails to parse the second message.
6. The method according to any one of claims 1 to 3, characterized in that: The method further includes: the MCU detecting its own state in real time, and issuing an abnormal alarm when detecting that its own state is abnormal.
7. The method according to claim 1, characterized in that The method further comprises one of the following: If the second status information indicates that the second SoC has taken over successfully, the MCU sends a control right switching message to the host computer, where the control right switching message carries information indicating that the second SoC has taken over control; If the MCU successfully takes over the control right, the MCU sends a control right switching message to the host computer, and the control right switching message carries information indicating that the MCU has taken over the control right.
8. A domain controller, characterized in that: include: A first SoC, a second SoC, an MCU and a memory storing a program, wherein the program includes instructions, and the instructions implement the method according to any one of claims 1 to 7 when executed by the first SoC, the second SoC and the MCU.
9. A computer-readable storage medium storing a program, wherein the program comprises instructions, and when the instructions are executed by one or more processors of a computing device, the instructions cause the computing device to execute the method according to any one of claims 1 to 7.
10. A vehicle, characterized in that: The vehicle comprises the domain controller of claim 8.