Multi-sensor domain controller dynamic management method and domain controller system
By using the master-slip clock switching and dynamic compensation technology of external Ethernet gateway and internal GNSS/IMU modules in the on-board domain controller, combined with hardware-level timestamp and software-level error correction algorithm, the problems of clock redundancy, error compensation and synchronization accuracy in the on-board domain controller are solved, and high-precision time synchronization and multi-sensor data fusion are achieved, meeting the real-time requirements of autonomous driving.
Patent Information
- Application Number
- CN202510363908.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2025-06-24
AI Technical Summary
The prior art has shortcomings in clock redundancy, error compensation, synchronization accuracy and heterogeneous data alignment in the field of on-board domain controllers, which affects the accuracy and effectiveness of multi-sensor data fusion.
Through the external Ethernet gateway as the main clock source, the MCU module is timed based on the GPTP protocol, and the internal GNSS module and IMU module are used as the backup clock source to realize automatic switching of the main and backup clocks and dynamic compensation. At the same time, hardware-level timestamp marking and software-level error correction algorithm are used to control the global time synchronization error of less than 150 microseconds, and time-stamp alignment and fusion of multi-sensor data.
The synchronization interrupt recovery time is less than 10ms, and the global time synchronization error is controlled within 150 microseconds, which improves the time stamp alignment accuracy, reduces the error rate of obstacle recognition, and meets the real-time requirements of autonomous driving decisions.
Smart Images

Figure CN120200700A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of vehicle domain controllers, and particularly to a dynamic management method for a multi-sensor domain controller and a domain controller system. Background Art
[0002] In the field of vehicle domain controllers, high-precision time synchronization is crucial for multi-sensor data fusion. However, there are many defects in the existing technologies in this regard, severely restricting the improvement of system performance.
[0003] In terms of clock redundancy, the current technology mainly relies on a single master clock source, such as GPS or an Ethernet gateway. However, in practical applications, the GPS signal is vulnerable to building blockage and fails, and the Ethernet gateway may also cause unstable clock signals due to hardware failures. Once the master clock source has problems, the system lacks the ability to switch to a backup clock, which will seriously affect the continuity and reliability of time synchronization.
[0004] In the error compensation mechanism, the existing technologies do not fully utilize historical clock deviation data for dynamic modeling. For example, the sliding window algorithm is not used to predict clock drift, which causes the clock deviation between the MCU and the SOC module to gradually increase during long-term operation, even exceeding 500 microseconds, greatly reducing the accuracy of time synchronization.
[0005] In terms of synchronization accuracy, the traditional GPTP protocol can only achieve a synchronization accuracy of 250 microseconds, and does not combine hardware-level timestamp marking, such as not using the nanosecond-level timing unit of Xilinx FPGA. In the scenario of multi-sensor fusion, this accuracy cannot meet the sub-millisecond-level time synchronization requirements, resulting in inconsistent time bases for sensor data.
[0006] In addition, heterogeneous data alignment is also a difficult problem. The data transmission delays of different sensors vary greatly. For example, the middle exposure moment of a camera and the point cloud generation moment of a lidar are often not aligned, which causes the time base deviation of the fusion model to exceed 200 microseconds, further affecting the accuracy and effectiveness of multi-sensor data fusion.
[0007] In summary, the existing technologies have obvious deficiencies in clock redundancy, error compensation, synchronization accuracy, and heterogeneous data alignment, and there is an urgent need for an innovative dynamic management method for a multi-sensor domain controller to solve these problems. Summary of the Invention
[0008] The purpose of the present invention is to provide a dynamic management method for a multi-sensor domain controller and a domain controller system, so as to solve the problems of deficiencies in clock redundancy, error compensation, and synchronization accuracy in the existing technologies.
[0009] To achieve the above object of the present invention, an embodiment of the present invention provides a method for dynamically managing a multi-sensor domain controller, which includes the following steps: S1. Use an external Ethernet gateway as the primary clock source to provide timing to the MCU module inside the domain controller based on the GPTP protocol; S2. The MCU module serves as a secondary clock source to distribute synchronous clock signals to the SOC module and external sensors, and collect clock deviation data in real time; S3. When the primary clock source fails, automatically switch to the internal GNSS module and IMU module as the backup clock source, and dynamically compensate for timing errors based on historical clock deviation data; S4. Control the global time synchronization error to be less than 150 microseconds through hardware-level timestamp marking and software-level error correction algorithms; S5. Based on the synchronized timing data, perform timestamp alignment and fusion on the heterogeneous data input by multiple sensors, generate a unified environment model and output it to the decision-making module.
[0010] As a further improvement of an embodiment of the present invention, the MCU module and the SOC module are integrated into a single Horizon J6E chip, where: The MCU module uses an ASIL-D level R52+ core, and exclusively accesses the secure memory area through the Arm TrustZone hardware isolation technology, and is responsible for processing real-time vehicle control signals with a cycle ≤ 1ms, and the task jitter is less than ±50μs; The SOC module integrates an A78AE core and a BPU Nash engine, and executes non-real-time image recognition and AI computing tasks with a delay ≥ 5ms through the non-secure memory area; The MCU and the SOC perform data interaction through a shared memory and a DMA engine based on MMU permission control. When transmitting a 128-byte data packet and the bus load rate ≤ 50%, the end-to-end communication delay is less than 10 microseconds.
[0011] As a further improvement of an embodiment of the present invention, in S1, the external Ethernet gateway is connected to the domain controller through two 10G Ethernet, and the following fields are defined in the GPTP protocol: Primary clock source priority identifier, clock deviation compensation coefficient, clock source health status flag bit; The MCU module sends a clock calibration request to the primary clock source every 100 milliseconds.
[0012] As a further improvement of an embodiment of the present invention, the specific method for dynamically compensating for timing errors in S3 is: Record the deviation data between the primary clock source and the backup clock source in the most recent 10 cycles, and calculate the average deviation value through a sliding window algorithm; When switching to the backup clock source, the current system time is superimposed with the average deviation value to ensure continuous and non-jumping time.
[0013] As a further improvement of an embodiment of the present invention, wherein the multi-sensor domain controller dynamic management method further includes a dynamic power management strategy: Define the operating mode, low-power mode, sleep mode, and power-off mode, and trigger mode switching based on the KL15 hardwired signal and the CAN FD wake-up message; In the sleep mode, the power supply to the SOC module and non-critical peripherals is turned off, and only the MCU module remains in standby, with a static current less than 200 microamps; In the operating mode, start in the order of "MCU wakes up first → SOC powers on → cameras or radars are powered on in batches", and the response time of the first frame of CAN message is less than 400 milliseconds.
[0014] As a further improvement of an embodiment of the present invention, wherein the dynamic power management strategy includes an anomaly detection mechanism: Real-time monitor the temperature of the PCB board through the temperature sensor. When the temperature exceeds 85 °C, trigger the SOC module to downclock or turn off some computing units; When it is detected that the power fluctuation exceeds ±15%, automatically cut off the power supply to non-safety-related peripherals and record the fault code.
[0015] As a further improvement of an embodiment of the present invention, wherein the multi-sensors include GMSL cameras, lidars, millimeter-wave radars, and ultrasonic radars, and their data fusion methods include: Design a hot-swap protocol for the GMSL camera. After detecting a link interruption, perform register reconfiguration and data stream recovery, and the disconnection reconnection time is less than 500 milliseconds; Perform timestamp alignment and coordinate system unified conversion on the lidar Ethernet data, millimeter-wave radar CAN FD data, and ultrasonic radar SPI data respectively; Dynamically allocate SOC computing resources according to the scenario requirements. In the parking scenario, give priority to processing surround-view camera data, and in the highway NOA scenario, give priority to processing front-view camera and lidar data.
[0016] As a further improvement of an embodiment of the present invention, wherein it further includes a modular OTA collaborative upgrade process: Perform digital signature verification, hardware compatibility check, and block CRC check on the firmware package; Adopt an incremental upgrade strategy, only transmit the differential data blocks, and ensure integrity in a weak network environment through the breakpoint resume mechanism; Upgrade in the order of "MCU firmware → SOC components → switch → sensors". If any node fails, the whole will roll back to the previous version.
[0017] As a further improvement of an embodiment of the present invention, it further includes performing dual-backup partition management on the MCU firmware in the modular OTA collaborative upgrade process, specifically: Divide A / B dual-backup partitions for the MCU firmware, and each partition contains a complete firmware image and a version identifier; And optimize the upgrade protocol for sensors in the modular OTA collaborative upgrade process, specifically including: Design a DoIP-over-CAN conversion protocol for lidar and millimeter-wave radar, encapsulate the upgrade package as a UDS service instruction, and each frame of CAN FD data contains an 8-byte header and a 48-byte payload; If the reception confirmation is not received after 3 consecutive retransmissions, terminate the current upgrade and trigger a rollback; And perform timeout control in the modular OTA collaborative upgrade process, specifically: Set the MCU upgrade timeout threshold to 60 seconds, the SOC upgrade timeout threshold to 120 seconds, and the sensor upgrade timeout threshold to 180 seconds; If any module in the MCU, SOC, and sensors times out, interrupt the overall process and record the faulty module ID and the position of the last valid data block.
[0018] An embodiment of the present invention also provides a domain controller system, wherein the domain controller system can implement the multi-sensor domain controller dynamic management method as described in any one of the above and includes: Horizon J6E chip, integrating an SOC module, an ASIL-D level MCU module, and a hardware codec unit; Multiple GMSL deserializers, supporting the access of 12 cameras and the expansion of 4 Ethernet sensors; Dynamic power management circuit, including a KL15 wake-up interface, a CAN FD wake-up module, and a hierarchical power supply controller; OTA management engine, built-in with an incremental upgrade algorithm, a rollback strategy, and a multi-node collaborative control logic.
[0019] Compared with the prior art, the beneficial effects of the present invention are as follows: Through the automatic switching of the master and backup clocks and the dynamic compensation algorithm, the synchronous interrupt recovery time is less than 10 ms; the global time synchronization error is controlled within 150 microseconds, which is better than the traditional GPTP protocol benchmark value, meeting the real-time requirements of autonomous driving decision-making; the timestamp alignment accuracy is improved by more than 50%, optimized from 300 microseconds to 150 microseconds, reducing the misjudgment rate of obstacle recognition. Description of the Drawings
[0020] Figure 1Flowchart of a dynamic management method for a multi - sensor domain controller provided by an embodiment of the present invention. Detailed implementation manners
[0021] It should be noted that, without conflict, the embodiments in this application and the features in the embodiments may be combined with each other. The present invention will be described in detail below with reference to the drawings and in conjunction with the embodiments.
[0022] It should be pointed out that, unless otherwise specified, all technical and scientific terms used in this application have the same meaning as commonly understood by those of ordinary skill in the technical field to which this application belongs.
[0023] In the present invention, unless otherwise stated, the orientation words such as "upper, lower, top, bottom" are usually in the direction shown in the drawings, or in the vertical, perpendicular or gravitational direction of the component itself; similarly, for the sake of easy understanding and description, "inner, outer" refer to the inner and outer of the contour of each component itself, but the above orientation words do not limit the present invention.
[0024] In order to solve the problems existing in the multi - sensor domain controller in terms of clock redundancy, error compensation, and synchronization accuracy in the prior art.
[0025] The present invention will be further described in detail below with reference to the drawings and specific embodiments. Embodiment 1
[0026] As Figure 1 shown, a dynamic management method for a multi - sensor domain controller provided in this embodiment includes the following steps: S1. Use the external Ethernet gateway as the primary clock source to provide timing to the MCU module inside the domain controller based on the GPTP protocol; S2. The MCU module serves as a secondary clock source to distribute synchronous clock signals to the SOC module and external sensors, and collect clock deviation data in real time; S3. When the primary clock source fails, automatically switch to the internal GNSS module and IMU module as the backup clock source, and dynamically compensate the timing error based on the historical clock deviation data; S4. Control the global time synchronization error to be less than 150 microseconds through hardware - level timestamp marking and software - level error correction algorithms; S5. Based on the synchronized timing data, perform timestamp alignment and fusion on the heterogeneous data input by multiple sensors, generate a unified environment model and output it to the decision - making module.
[0027] In the multi-sensor domain controller dynamic management method of this embodiment, through the automatic switching of the primary and backup clocks (Ethernet gateway + GNSS / IMU redundancy) and the dynamic compensation algorithm, it is ensured that the synchronization interruption recovery time is less than 10 ms; the global time synchronization error is controlled within 150 microseconds (superior to the benchmark value of 250 microseconds of the traditional GPTP protocol), meeting the real-time requirements of autonomous driving decision-making; the timestamp alignment accuracy is improved by more than 50% (optimized from the traditional 300 microseconds to 150 microseconds), reducing the misjudgment rate of obstacle recognition.
[0028] Furthermore, the MCU module and the SOC module are integrated into a single Horizon J6E chip. This highly integrated design helps to reduce the system volume, lower the power consumption and improve the overall performance. Among them, The MCU module adopts an ASIL-D level R52 + core.
[0029] "ASIL-D level" is the highest level in the Automotive Safety Integrity Level, representing the classification with the most stringent functional safety requirements in the ISO26262 standard. This standard is an international standard for the functional safety of the electronic and electrical systems of road vehicles, aiming to reduce the risk of personal injury caused by system or component failures through a systematic approach. The determination of ASIL-D is based on a comprehensive hazard analysis and risk assessment (HARA), which includes evaluating the risks and hazards that each component, module or system may fail. When the HARA assessment result of a system shows the highest risk level, that is, the severity is S3 (life-threatening to fatal injury), the exposure is E4 (high probability), and the controllability is C0 (generally controllable), the system will be classified as ASIL-D level. This means that for a system at the ASIL-D level, the highest level of safety measures must be implemented, including strict design, verification and validation processes, as well as high standards for fault prevention, detection and response.
[0030] "R52+" is an upgraded R-core processor based on the ARMv8-R architecture. As an upgraded version based on the Cortex-R52 architecture, R52+ inherits the high performance, high reliability and high flexibility of Cortex-R52, and may be optimized or enhanced in some aspects. Cortex-R52 is a 32-bit high-performance real-time processor with extremely high functional safety standards and great flexibility. Its 4 cores can either operate independently or be configured as up to 4-core lockstep or split-lock.
[0031] Adopting the ASIL-D level R52+ core, it can possess high reliability and security, and can meet the high requirements for functional safety in the automotive field. Through the Arm TrustZone hardware isolation technology, the MCU module can exclusively access the secure memory area, effectively preventing external interference and illegal access, and ensuring the stability and security of real-time vehicle control signal processing. It is responsible for processing real-time vehicle control signals with a cycle ≤ 1ms, and the task jitter is less than ±50μs, which can provide accurate and timely control instructions for the vehicle.
[0032] The SOC module integrates the A78AE core and the BPU Nash engine. The A78AE core is a high-performance general-purpose processing core, while the BPU Nash engine focuses on AI computing acceleration. The SOC module executes non-real-time image recognition and AI computing tasks with a delay ≥ 5ms through the non-secure memory area, and can efficiently process complex images and AI algorithms, providing strong perception and decision-making support for autonomous driving.
[0033] The MCU and the SOC perform data interaction through the shared memory and the DMA engine based on MMU permission control. This interaction method realizes efficient data transmission on the premise of ensuring data security. When transmitting a 128-byte data packet and the bus load rate ≤ 50%, the end-to-end communication delay is less than 10 microseconds, ensuring the real-time and efficient data interaction between the MCU and the SOC, and further improving the performance of the entire domain controller system.
[0034] Furthermore, in step S1, the external Ethernet gateway is connected to the domain controller through two 10G Ethernet connections. This connection method can provide a high-speed and stable data transmission channel to ensure the accurate transmission of clock signals. In the GPTP protocol, the following fields are specifically defined: the primary clock source priority identifier, which is used to clarify the priority order between different clock sources. When there are multiple clock sources, the system can select the optimal clock source for time synchronization according to this identifier; the clock deviation compensation coefficient, which can be dynamically adjusted according to the actual clock deviation situation to more accurately compensate for the clock deviation and improve the accuracy of time synchronization; the clock source health status flag bit, which is used to monitor the operating status of the clock source in real time. When the clock source fails or is abnormal, the system can detect it in time and take corresponding measures.
[0035] The MCU module sends a clock calibration request to the primary clock source every 100 milliseconds. By regularly sending calibration requests, the MCU module can timely obtain the latest clock information of the primary clock source and adjust and calibrate its own clock according to this information, so as to ensure the time synchronization between the MCU module and the primary clock source, providing a basis for the high-precision time synchronization of the entire domain controller system.
[0036] Further, the specific method for dynamically compensating the timing error in step S3 is as follows: The system will record in detail the deviation data between the main clock source and the backup clock source in the most recent 10 cycles. These data are important bases for subsequent error compensation. By collecting data from multiple cycles, the deviation situation between the clock sources can be understood more comprehensively. The sliding window algorithm is used to process these deviation data to calculate an average deviation value. The sliding window algorithm can continuously update the average deviation value as new data is added, making it better reflect the current deviation state.
[0037] When the main clock source fails and the system switches to the backup clock source, the current system time will be superimposed with the above calculated average deviation value. The purpose of this is to ensure continuous and non-jumping time, avoid sudden changes in time due to clock source switching, thereby ensuring the time synchronization and stability of the entire domain controller system, and enabling the system to operate continuously and accurately.
[0038] Further, the dynamic management method of the multi-sensor domain controller further includes a dynamic power management strategy, which aims to flexibly adjust the power supply mode according to the actual operation requirements of the system to reduce power consumption and improve energy utilization efficiency.
[0039] Specifically, four modes are defined: the operating mode, the low-power mode, the sleep mode, and the power-off mode. The mode switching is triggered based on the KL15 hardwired signal and the CAN FD wake-up message. The KL15 hardwired signal is a commonly used power control signal in the vehicle electrical system, and the CAN FD wake-up message is a specific message used to wake up the system transmitted through the CAN FD bus.
[0040] In the sleep mode, the system will cut off the power supply to the SOC module and non-critical peripherals, and only keep the MCU module in the standby state. At this time, the static current of the system is less than 200 microamps, greatly reducing the power consumption, which is suitable for when the vehicle is parked for a long time or in an inactive state.
[0041] In the operating mode, the system starts in the order of "MCU wakes up first → SOC powers on → cameras or radars are powered on batch by batch". This startup order ensures that the system can respond quickly and operate orderly. At the same time, it is required that the response time of the first-frame CAN message is less than 400 milliseconds, ensuring that the system can communicate with other in-vehicle devices in a timely manner after startup, meeting the real-time requirements of applications such as autonomous driving.
[0042] Furthermore, the dynamic power management strategy includes an anomaly detection mechanism, which is used to ensure the stable operation of the system under abnormal conditions. The temperature of the PCB board is monitored in real time through a temperature sensor, which can accurately sense the temperature change of the PCB board. Once the temperature exceeds 85°C, the system will respond quickly. At this time, the SOC module will be triggered to reduce its operating frequency to reduce heat generation; or some computing units will be turned off to avoid excessive concentrated heat generation, thus effectively preventing damage to the system caused by overheating.
[0043] When it is detected that the power fluctuation exceeds ±15%, the system will automatically cut off the power supply of non-safety-related peripherals to prevent the power fluctuation from impacting non-critical devices and ensure the stability of the core functions of the system. At the same time, the system will record the fault code, which contains key information such as the time and amplitude of the power fluctuation, facilitating subsequent analysis and troubleshooting of the fault and providing a strong basis for the maintenance and optimization of the system.
[0044] In this embodiment, the multi-sensor includes a GMSL camera, a lidar, a millimeter-wave radar, and an ultrasonic radar, and its data fusion method has pertinence and high efficiency.
[0045] For the GMSL camera, a hot-swap protocol is designed. During actual operation, when a link interruption is detected, this protocol will quickly execute register reconfiguration and data stream recovery operations. In this way, the normal operation of the camera can be restored within a short time, and the disconnection reconnection time is less than 500 milliseconds, effectively reducing data loss and system downtime caused by link interruption.
[0046] For lidar Ethernet data, millimeter-wave radar CAN FD data, and ultrasonic radar SPI data, timestamp alignment and coordinate system unified conversion will be performed respectively. Timestamp alignment ensures the consistency of different sensor data in the time dimension, and coordinate system unified conversion ensures the comparability of data in the space dimension, providing a basis for subsequent data fusion.
[0047] In addition, the SOC computing power resources are dynamically allocated according to the scenario requirements. In the parking scenario, the surround-view camera data is preferentially processed to meet the accurate perception requirements of the surrounding environment during parking; in the highway NOA scenario, the front-view camera and lidar data are preferentially processed to provide reliable environmental information for high-speed driving and automatic navigation.
[0048] The multi-sensor domain controller dynamic management method provided in this embodiment also includes a modular OTA collaborative upgrade process.
[0049] Before the upgrade, the firmware package will be strictly inspected, including digital signature verification to ensure the reliable source and integrity of the firmware package; hardware compatibility check to ensure that the firmware package matches the current hardware environment; and block CRC check to divide the firmware package into blocks and calculate the cyclic redundancy check code for each block to detect whether errors occur during data transmission or storage.
[0050] An incremental upgrade strategy is adopted to only transfer the differential data blocks, which can greatly reduce the data transmission volume and improve the upgrade efficiency. At the same time, through the breakpoint resume mechanism, the integrity of the upgrade can be ensured even in a weak network environment. Even if the network is interrupted during the upgrade process, it can resume transmission from the breakpoint after the network is restored.
[0051] The upgrade is carried out in the order of "MCU firmware → SOC components → switch → sensor". If the upgrade fails at any node, the whole system will roll back to the previous version to ensure the stability and reliability of the system and avoid abnormal operation of the system due to upgrade failure.
[0052] The multi-sensor domain controller dynamic management method provided in this embodiment also includes dual-backup partition management for the MCU firmware in the modular OTA collaborative upgrade process. Specifically, A / B dual-backup partitions are defined for the MCU firmware, and each partition contains a complete firmware image and a version identifier. In this way, when performing firmware upgrade, the new firmware can be first written into the standby partition, and then the partition switch can be performed after the upgrade is successful. If the upgrade fails, it can quickly roll back to the original partition to ensure the stable operation of the system.
[0053] At the same time, the upgrade protocol for sensors is optimized in the modular OTA collaborative upgrade process. For lidar and millimeter-wave radar, a DoIP - over - CAN conversion protocol is designed to encapsulate the upgrade package as a UDS service instruction. Each frame of CAN FD data contains an 8-byte header and 48 bytes of payload to improve the data transmission efficiency. If the reception confirmation is not received after 3 consecutive retransmissions, the current upgrade will be terminated and a rollback will be triggered to avoid the upgrade falling into an infinite loop.
[0054] In addition, timeout control is performed in the modular OTA collaborative upgrade process. The MCU upgrade timeout threshold is set to 60 seconds, the SOC upgrade timeout threshold is set to 120 seconds, and the sensor upgrade timeout threshold is set to 180 seconds. If any module among the MCU, SOC, and sensors times out, the overall process will be interrupted, and the fault module ID and the position of the last valid data block will be recorded for subsequent fault troubleshooting and recovery. Embodiment 2
[0055] In this embodiment, a domain controller system is provided. The domain controller system can implement the multi-sensor domain controller dynamic management method described above, and its overall architecture and functional design are aimed at meeting the requirements of modern automobiles for high performance, high security, and high reliability.
[0056] The system includes the Horizon J6E chip, which integrates an SOC module, an ASIL-D level MCU module, and a hardware codec unit. The SOC module has powerful computing capabilities, can process massive amounts of data from multiple sensors, and perform complex environmental perception and decision-making algorithm operations. The ASIL-D level MCU module focuses on safety-related control tasks, such as functional safety monitoring, fault diagnosis, etc. Its ASIL-D level certification ensures that the system can still maintain a high level of safety and reliability in the face of potential failures. The hardware codec unit can quickly encode and decode data such as images and videos, improve data processing efficiency, and reduce the CPU load.
[0057] The multi-channel GMSL deserializer is an important part of the system. It supports the access of 12 cameras and the expansion of 4 Ethernet sensors. The access of 12 cameras can meet the all-round environmental perception needs around the vehicle, such as front-view, rear-view, side-view, and surround-view cameras, etc., providing rich visual information for autonomous driving. The expansion of 4 Ethernet sensors enables the system to easily access Ethernet sensors such as lidar and millimeter-wave radar, further enhancing the system's perception ability.
[0058] The dynamic power management circuit includes a KL15 wake-up interface, a CAN FD wake-up module, and a hierarchical power supply controller. The KL15 wake-up interface can respond to the vehicle's power signal to achieve the wake-up and sleep control of the system. The CAN FD wake-up module receives wake-up messages through the CAN FD bus to quickly start the system when needed. The hierarchical power supply controller precisely controls the power supply of each module according to different operating modes of the system. For example, in the sleep mode, it turns off the power supply of non-critical modules to reduce power consumption.
[0059] The OTA management engine incorporates an incremental upgrade algorithm, a rollback strategy, and multi-node collaborative control logic. The incremental upgrade algorithm can only transmit the differential data blocks of the firmware package, reducing the data transmission volume and improving the upgrade efficiency. The rollback strategy ensures that the system can quickly recover to the previous stable version in case of upgrade failure. The multi-node collaborative control logic guarantees the collaborative work of nodes such as MCU firmware, SOC components, switches, and sensors during the upgrade process, ensuring the consistency and integrity of the upgrade.
[0060] In summary, through the collaborative work of each module, the domain controller system realizes the dynamic management of the multi-sensor domain controller, providing strong support for the intelligent development of automobiles.
[0061] In summary, the embodiments of the present invention achieve the following technical effects: Through the automatic switching between the primary and backup clocks and the dynamic compensation algorithm, the synchronization interruption recovery time is less than 10 ms; the global time synchronization error is controlled within 150 microseconds, which is better than the benchmark value of the traditional GPTP protocol, meeting the real-time requirements for autonomous driving decision-making; the timestamp alignment accuracy is improved by more than 50%, optimized from 300 microseconds to 150 microseconds, reducing the misjudgment rate of obstacle recognition.
[0062] Obviously, the above-described embodiments are only a part of the embodiments of the present invention, rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0063] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present application. As used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. In addition, it should be understood that when the terms "comprise" and / or "include" are used in this specification, they specify the presence of features, steps, operations, devices, components, and / or combinations thereof.
[0064] It should be noted that the terms "first", "second", etc. in the description, claims, and drawings of the present application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order different from those illustrated or described herein.
[0065] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A multi-sensor domain controller dynamic management method, characterized in that: The following steps are involved: S1, using an external Ethernet gateway as the main clock source, and providing time to the MCU module inside the domain controller based on the GPTP protocol; S2, the MCU module acts as a secondary clock source, distributes synchronous clock signals to the SOC module and external sensors, and collects clock deviation data in real time; S3: When the main clock source fails, it automatically switches to the internal GNSS module and IMU module as the backup clock source, and dynamically compensates for the timing error based on the historical clock deviation data; S4, through hardware-level timestamp marking and software-level error correction algorithm, control the global time synchronization error to less than 150 microseconds; S5. Based on the synchronized time series data, the heterogeneous data input by multiple sensors are timestamp aligned and fused to generate a unified environmental model and output it to the decision module.
2. The multi-sensor domain controller dynamic management method according to claim 1, characterized in that: The MCU module and SOC module are integrated into a single Horizon J6E chip, where: The MCU module adopts the ASIL-D R52+ core, has exclusive access to the secure memory area through the Arm TrustZone hardware isolation technology, is responsible for real-time vehicle control signal processing with a cycle of ≤1ms, and the task jitter is less than ±50μs; The SOC module integrates the A78AE core and the BPU Nash engine, and executes non-real-time image recognition and AI computing tasks with a delay of ≥5ms through the non-secure memory area; The MCU and SOC exchange data through a shared memory and a DMA engine based on MMU permission control. When a 128-byte data packet is transmitted and the bus load rate is ≤50%, the end-to-end communication delay is less than 10 microseconds.
3. The multi-sensor domain controller dynamic management method according to claim 1, characterized in that: The external Ethernet gateway described in S1 is connected to the domain controller via two 10 Gigabit Ethernets, and the following fields are defined in the GPTP protocol: Main clock source priority flag, clock deviation compensation coefficient, clock source health status flag; The MCU module sends a clock calibration request to the main clock source every 100 milliseconds.
4. The multi-sensor domain controller dynamic management method according to claim 1, characterized in that: The specific method of dynamically compensating the timing error described in S3 is: Record the deviation data between the main clock source and the backup clock source in the last 10 cycles, and calculate the average deviation value through the sliding window algorithm; When switching to the backup clock source, the average deviation value is added to the current system time to ensure time continuity without jumps.
5. The multi-sensor domain controller dynamic management method according to claim 1, characterized in that: The multi-sensor domain controller dynamic management method also includes a dynamic power management strategy: Defines operating mode, low power mode, sleep mode and power-off mode, and triggers mode switching based on KL15 hard-wired signals and CAN FD wake-up messages; In sleep mode, the SOC module and non-critical peripheral power supply are turned off, leaving only the MCU module in standby mode, and the static current is less than 200 microamperes; In the running mode, the system starts in the order of "MCU wake-up first → SOC power-on → camera or radar power supply in batches", and the response time of the first CAN message frame is less than 400 milliseconds.
6. The multi-sensor domain controller dynamic management method according to claim 5, characterized in that: The dynamic power management strategy includes an anomaly detection mechanism: The temperature of the PCB is monitored in real time through the temperature sensor. When the temperature exceeds 85°C, the SOC module is triggered to reduce the frequency or shut down some computing units. When a power supply fluctuation exceeding ±15% is detected, the power supply to non-safety-related peripherals is automatically cut off and a fault code is recorded.
7. The multi-sensor domain controller dynamic management method according to claim 1, characterized in that: The multi-sensor includes a GMSL camera, a laser radar, a millimeter-wave radar and an ultrasonic radar, and the data fusion method includes: Design a hot-swap protocol for GMSL cameras. After detecting a link interruption, perform register reconfiguration and data flow recovery. The disconnection reconnection time is less than 500 milliseconds. Perform timestamp alignment and coordinate system conversion on LiDAR Ethernet data, millimeter wave radar CAN FD data, and ultrasonic radar SPI data respectively; SOC computing resources are dynamically allocated according to scene requirements, with surround-view camera data being prioritized in parking scenarios and forward-view camera and lidar data being prioritized in high-speed NOA scenarios.
8. The multi-sensor domain controller dynamic management method according to claim 1, characterized in that: It also includes modular OTA collaborative upgrade process: Perform digital signature verification, hardware compatibility check and block CRC verification on the firmware package; Adopting an incremental upgrade strategy, only transmitting differential data blocks, and ensuring integrity in a weak network environment through a breakpoint-resume transmission mechanism; Upgrade in the order of "MCU firmware → SOC component → switch → sensor". If any node fails, the entire version will be rolled back to the previous version.
9. The multi-sensor domain controller dynamic management method according to claim 8, characterized in that: It also includes dual backup partition management of MCU firmware in the modular OTA collaborative upgrade process, specifically: Divide the MCU firmware into A / B dual backup partitions, each partition contains a complete firmware image and version identification; And optimize the upgrade protocol of sensors in the modular OTA collaborative upgrade process, including: Design DoIP-over-CAN conversion protocol for LiDAR and millimeter-wave radar, encapsulate the upgrade package into UDS service instructions, and each frame of CAN FD data contains an 8-byte header and a 48-byte payload; If no confirmation is received after three consecutive retransmissions, the current upgrade is terminated and a rollback is triggered; And perform timeout control in the modular OTA collaborative upgrade process, specifically: Set the MCU upgrade timeout threshold to 60 seconds, the SOC upgrade timeout threshold to 120 seconds, and the sensor upgrade timeout threshold to 180 seconds; If any module among MCU, SOC and sensor times out, the overall process will be interrupted and the faulty module ID and the location of the last valid data block will be recorded.
10. A domain controller system, characterized in that: The domain controller system can implement the multi-sensor domain controller dynamic management method as described in any one of claims 1 to 9 and includes: Horizon J6E chip integrates SOC module, ASIL-D level MCU module and hardware codec unit; Multi-channel GMSL deserializer, supporting 12-channel camera access and 4-channel Ethernet sensor expansion; Dynamic power management circuit, including KL15 wake-up interface, CAN FD wake-up module and hierarchical power supply controller; OTA management engine with built-in incremental upgrade algorithm, rollback strategy and multi-node collaborative control logic.
Citation Information
Cited By
Power and environment data monitoring method based on NB-IOT communication
CN120499617A
Intelligent vehicle-mounted system based on domain controller and application method thereof
CN121425264A