Power-off method, vehicle domain controller, vehicle and readable storage medium

Through the shared memory mechanism and exit priority management, the problem of chips in intelligent driving domain controllers is solved, and a safe and fast power-off process and quick restart capability are achieved.

CN120255407APending Publication Date: 2025-07-04IMOTION AUTOMOTIVE TECH (SUZHOU) CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510472787.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

In existing intelligent driving domain controllers, chips with multi-core heterogeneous architectures are difficult to respond to power-down commands at the same time, resulting in improper resource release, affecting safe power-down and rapid restart.

Method used

Through the shared memory mechanism, the local application and the functional applications of the acceleration processing unit are triggered to exit the process simultaneously, and the functional applications are closed based on the order of exit priority. Finally, after confirming that all applications are exited, the system power-down process is triggered, including uninstalling the partition, synchronizing the file system and turning off the power.

Benefits of technology

It realizes that each chip responds to power-off commands at the same time, and is safe and fast underground power-off, ensuring that the previous state can be quickly restored during restart, improving the robustness and startup efficiency of the device.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120255407A_ABST
    Figure CN120255407A_ABST
Patent Text Reader

Abstract

The invention discloses a power-off method, a vehicle domain controller, a vehicle and a readable storage medium, and the method comprises the steps: a microcontroller in the vehicle domain controller receives a power-off command; wherein the vehicle domain controller comprises a microcontroller and an acceleration processing unit; triggering a local application exit process and a function application exit process of the acceleration processing unit by utilizing the shared memory; when it is determined that both the local application and the function application exit, a system power-off process is triggered; and turning off the power supply of the vehicle domain controller under the condition of determining that the system is successfully powered off. According to the method and the device, each chip can respond to the power-off command at the same time, and chip resources can be normally released, so that quick and safe power-off is realized, and the technical effect that the previous state can be quickly recovered when restarting is carried out is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of automobiles, and particularly to a power-off method, a vehicle domain controller, a vehicle, and a readable storage medium. Background Art

[0002] With the popularization of new types of vehicles such as electric vehicles, autonomous driving vehicles, and intelligent network-connected vehicles, the complexity of vehicle electronic systems has increased significantly, and the application of safe power-off technology has become increasingly important.

[0003] However, most current intelligent driving domain controllers (DCUs) adopt a multi-core heterogeneous architecture design, that is, multiple chips are deployed on one domain controller, and one chip operates independently to be responsible for a part of the functions.

[0004] How to make each chip be able to respond to the power-off command simultaneously and correctly release the resources of the chip has become a key issue in safe power-off technology. Summary of the Invention

[0005] The purpose of the present application is to provide a power-off method, a vehicle domain controller, a vehicle, and a readable storage medium, which can enable each chip to respond to the power-off command simultaneously and normally release the chip resources, so as to achieve fast and safe power-off, so that when restarting again, the previous state can be quickly restored.

[0006] To solve the above technical problems, the present application provides the following technical solutions:

[0007] A power-off method, including:

[0008] A microcontroller in a vehicle domain controller receives a power-off command; wherein, the vehicle domain controller includes the microcontroller and an acceleration processing unit;

[0009] By using a shared memory, trigger the local application exit process and the function application exit process of the acceleration processing unit;

[0010] When it is determined that both the local application and the function application have exited, trigger the system power-off process;

[0011] When it is determined that the system has successfully powered off, turn off the power of the vehicle domain controller.

[0012] Preferably, by using a shared memory, triggering the local application exit process and the function application exit process of the acceleration processing unit includes:

[0013] Set the power-off flag bit in the shared memory to power off;

[0014] When the power-off flag bit indicates power-off, trigger the local application exit process and the functional application exit process.

[0015] Preferably, the functional application exit process includes:

[0016] The acceleration processing unit detects the power-off flag bit;

[0017] When it is detected that the power-off flag bit indicates power-off, obtain the exit priorities corresponding to several functional applications respectively;

[0018] Close the several functional applications respectively in the order of the exit priorities.

[0019] Preferably, determining the exit priority includes:

[0020] Obtain the real-time index, functionality index, and activity index corresponding to the functional application;

[0021] Perform weighted summation on the real-time index, the functionality index, and the activity index to obtain a summation result;

[0022] Use the summation result to determine the exit priority of the functional application.

[0023] Preferably, the local application exit process includes:

[0024] The microcontroller sends a power-off message to the serial communication service so that the serial communication service closes the local applications that have registered power-off messages through the system management program.

[0025] Preferably, the system power-off process includes:

[0026] Exit the system process;

[0027] Unmount the mounted partitions and remount the root directory file in read-only mode;

[0028] Unmount the system devices;

[0029] Synchronize the file system and the block device;

[0030] Power off the system.

[0031] Preferably, when it is determined that both the local application and the functional application have exited, triggering the system power-off process includes:

[0032] Read the power-off flag bit in the shared memory;

[0033] When the power-off flag bit indicates application closed, determine that the functional application has exited;

[0034] When it is read that the status flag corresponding to the local application is stopped, it is determined that the local application has exited;

[0035] When it is determined that both the local application and the function application have exited, trigger the system power-down process.

[0036] A vehicle domain controller, the vehicle domain controller includes the microcontroller and the acceleration processing unit; the microcontroller includes:

[0037] A command receiving module, configured to receive a power-down command;

[0038] A power-down triggering module, configured to use shared memory to trigger the local application exit process and the function application exit process of the acceleration processing unit;

[0039] A system power-down module, configured to trigger the system power-down process when it is determined that both the local application and the function application have exited;

[0040] A power-off module, configured to turn off the power of the vehicle domain controller when it is determined that the system has successfully powered down.

[0041] A vehicle, including: the vehicle domain controller as described above.

[0042] A readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above power-down method are implemented.

[0043] Applying the method provided by the embodiments of the present application, the microcontroller in the vehicle domain controller receives a power-down command; wherein, the vehicle domain controller includes a microcontroller and an acceleration processing unit; uses shared memory to trigger the local application exit process and the function application exit process of the acceleration processing unit; triggers the system power-down process when it is determined that both the local application and the function application have exited; turns off the power of the vehicle domain controller when it is determined that the system has successfully powered down.

[0044] In order to enable the system to save the current state during the power-down process, correctly handle the release of device handles, clean up memory, stack data, etc., and ensure that it can quickly return to the previous working state when power is restored. In this application, the applications in each chip are first exited, and then the system is powered down. Specifically, the shared memory in the vehicle domain controller allows the microcontroller and the acceleration processing unit in the vehicle domain controller to access it jointly. Therefore, in this application, when the microcontroller in the vehicle domain controller receives a power-down command, the shared memory can be used to trigger the local application exit process and the function application exit process of the acceleration processing unit simultaneously. That is, based on the shared memory, multiple chips can respond to the power-down instruction simultaneously. Then, when it is clear that both the local application and the function application have exited, the system power-down process is triggered. When it is obvious that the system has been successfully powered down, the power supply of the vehicle domain controller is turned off.

[0045] This application can enable each chip to respond to the power-down command simultaneously and release the chip resources properly, thus achieving a fast and safe power-down so that when restarted again, it can quickly resume the previous state.

[0046] Correspondingly, the embodiments of this application also provide a vehicle domain controller, a vehicle, and a readable storage medium corresponding to the above power-down method, which have the above technical effects and will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] In order to more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments or related technologies. Obviously, the drawings in the following description are only some embodiments of this application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0048] Figure 1 It is the flowchart of the implementation of a power-down method in the embodiments of this application;

[0049] Figure 2 It is the schematic diagram of the implementation of a power-down method in the embodiments of this application;

[0050] Figure 3 It is the schematic diagram of the implementation details of a power-down method in the embodiments of this application;

[0051] Figure 4 It is the schematic diagram of the structure of a vehicle domain controller in the embodiments of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0052] To enable those skilled in the art to better understand the solution of this application, the following provides a further detailed description of this application in conjunction with the accompanying drawings and specific embodiments. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts shall fall within the scope of protection of this application.

[0053] Please refer to Figure 1 , Figure 1 which is a flowchart of a power-off method in an embodiment of this application. The method includes the following steps:

[0054] S101. The microcontroller in the vehicle domain controller receives a power-off command.

[0055] Among them, the vehicle domain controller includes a microcontroller and an acceleration processing unit.

[0056] On a vehicle domain controller, an APU (Accelerated Processing Unit) and an RPU (a microcontroller that usually runs a real-time operating system) are deployed simultaneously. Among them, the acceleration processing unit is a processor that combines a central processing unit (CPU) and a graphics processing unit (GPU). The APU is designed to provide more powerful computing capabilities by integrating the CPU and GPU, while optimizing power consumption and space efficiency.

[0057] Among them, the microcontroller can be used as a chip for managing power, and the power-off command can be received by this microcontroller.

[0058] Specifically, the power-off command can be generated when the system fails or encounters an emergency, or, during normal use, when the user chooses to stop and cut off the power after using the vehicle.

[0059] S102. Utilize shared memory to trigger the local application exit process and the function application exit process of the acceleration processing unit.

[0060] In this embodiment, a local application exit process can be set for the APU in advance, and a function application exit process can be set for the APU. The trigger conditions for these two types of application exit processes can be exactly the same. In this way, multiple chips (APU and RPU) can respond to the power-off process simultaneously.

[0061] The shared memory can be accessed by both the RPU and the APU. Therefore, after the RPU receives the power-off command, it can utilize the shared memory to trigger the local application exit process and the function application exit process of the acceleration processing unit simultaneously.

[0062] In this embodiment, the local application of the RPU is an APP that runs on the RPU and has registered a power-down message. The specific functions and roles of the local application are not specifically limited; the functional application of the APU is an APP that runs on the APU and needs to exit before power-off. The specific functions and roles of the functional application are not specifically limited.

[0063] In a specific implementation manner of the present application, by using shared memory, the local application exit process and the functional application exit process of the acceleration processing unit are triggered, including:

[0064] Set the power-down flag bit in the shared memory to power-down;

[0065] When the power-down flag bit is power-down, trigger the local application exit process and the functional application exit process.

[0066] For ease of description, the above steps will be combined and described below.

[0067] In the embodiment of the present application, a power-down flag bit can be set in the shared memory. After the RPU receives a power-down command, the power-down flag bit can be set to power-down.

[0068] Correspondingly, the trigger conditions for both the local application exit process and the functional application exit process are that the power-down flag bit is power-down.

[0069] In this way, after the RPU sets the power-down flag bit to power-down, the local application exit process and the functional application exit process can be triggered. That is, multiple chips are simultaneously triggered to respond to the power-down command through the shared memory.

[0070] After triggering the local application exit process and the functional application exit process, the RPU executes the local application exit process, and the APU executes the functional application exit process.

[0071] In a specific implementation manner of the present application, the functional application exit process includes:

[0072] The acceleration processing unit detects the power-down flag bit;

[0073] When it is detected that the power-down flag bit is power-down, obtain the exit priorities corresponding to several functional applications;

[0074] Close several functional applications in the order of the exit priorities.

[0075] Among them, determining the exit priority includes:

[0076] Obtain the real-time index, functional index, and activity index corresponding to the functional application;

[0077] Perform a weighted sum of the real-time index, functionality index, and activity index to obtain the sum result;

[0078] Use the sum result to determine the exit priority of the function application.

[0079] For ease of explanation, the above steps will be combined and explained below.

[0080] It should be noted that for different function applications, there will be differences in the types and quantities of the hardware units involved. Therefore, exiting different function applications will have different degrees of impact on the magnitude of the hardware current. And excessive current differences will affect the service life of the hardware, especially the service life of storage and computing devices. The service life of the hardware is closely related to the recovery state after restart.

[0081] Therefore, in this embodiment, when exiting a function application, an orderly exit can be performed based on the exit priority, thereby avoiding excessive current differences.

[0082] Specifically, corresponding exit priorities can be set in advance for different function applications. Then, when it is detected that the power-down flag bit is for power-down, the exit priorities corresponding to different function applications can be obtained from the storage medium. Then, the function applications are closed in the order of the exit priorities.

[0083] Among them, the setting of the exit priority can be based on the least impact on the current, the higher the priority, and the higher the priority, the earlier the exit; or the setting of the exit priority can be based on the greatest impact on the current, the lower the priority, and the lower the priority, the earlier the exit. That is to say, the smaller the current impact caused by the exit of the function application, the earlier the exit.

[0084] The more core the functionality of the function application, the higher the real-time performance, the higher the activity, the more hardware units are used correspondingly, and the greater the current difference caused by exiting the application.

[0085] When determining the exit priority, it can be determined according to the real-time index, functionality index, and activity index. Specifically, it can be determined based on the weighted sum method.

[0086] For example: The APU can first evaluate and tag the running app (function application) in multiple dimensions, and calculate the activity of each unit (CPU core, GPU core, DSP, AI accelerator) it uses, such as the occupancy rate of the instruction pipeline and the cache access frequency.

[0087] Functional division: key application units: cores responsible for state preservation and communication interfaces (such as main CPU core, RPU communication module); non-key application units: GPU core, auxiliary computing units (such as AI inference engine), and unused DSPs.

[0088] Application real-time requirements are divided into high real-time applications, such as sensor data processing applications, medium real-time applications, such as navigation path planning, and low real-time applications, such as OTA updates.

[0089] Through the above three indicators, apps (functional applications) are divided into multiple exit priority apps. When considering exit priority, functionality and real-time performance can be given higher weights, and activity can be given lower weights.

[0090] When shutting down functional applications, applications can be shut down separately from low exit priority to high exit priority, thereby reducing the instantaneous rate of change of current and more smoothly powering off the domain controller.

[0091] In a specific implementation of the present application, the local application exit process includes: the microcontroller sends a power-off message to the serial communication service so that the serial communication service closes the local application that has registered the power-off message through the system management program.

[0092] Specifically, when exiting the local application, the RPU first sends a power-off message (such as a power-off message supported by the SIP protocol) to a serial communication service (SPI service, SPI is Serial Peripheral Interface, a serial communication protocol used for data transmission between the microcontroller (RPU) and external devices).

[0093] After receiving the power-off message, the SPI service sends a power-off message (i.e., a power-off SPI message) to sysmgr (system management program, running on the RPU) and sets the state of the local application to after-run.

[0094] After receiving the power-off message, Sysmgr sends it to the apps that have registered the power-off message, and enters the shutdown method of each app to exit the app.

[0095] When sysmgr receives the confirm message from all applications (APP), it sets the state to stop. In this way, the RPU can determine that all local applications have successfully exited.

[0096] S103: When it is determined that both the local application and the functional application have exited, a system power-off process is triggered.

[0097] If the system is powered off while the application is still running, the running data and status information of the application will be lost, which is not conducive to restarting and restoring the previous running state. Therefore, in this embodiment, after the RPU determines that both the application on the RPU local and the functional application on the APU have exited, the system power-off process is triggered to avoid data loss.

[0098] In a specific implementation manner of this application, when it is determined that both the local application and the functional application have exited, triggering the system power-off process includes:

[0099] Read the power-off flag bit in the shared memory;

[0100] When the power-off flag bit indicates that the application is closed, determine that the functional application has exited;

[0101] When the status flag corresponding to the local application read is stopped, determine that the local application has exited;

[0102] When it is determined that both the local application and the functional application have exited, trigger the system power-off process.

[0103] For ease of description, the above steps will be combined and described below.

[0104] After the APU executes the functional application exit process, the power-off flag bit in the shared memory will be set to indicate that the application is closed. Therefore, by reading the power-off flag bit, the RPU can determine that the functional application has exited when the read power-off flag bit indicates that the application is closed.

[0105] After the RPU executes the local application exit process, the sysmgr (system management program, running on the RPU) sets the state of the local application to after-run (exited from running). Therefore, the RPU directly reads the status flag corresponding to the local application, and when the read status flag bit is stopped, it can be determined that the local application has exited.

[0106] When it is clear that both the local application and the functional application have exited, the system power-off process can be triggered.

[0107] In a specific implementation manner of this application, the system power-off process includes:

[0108] Exit the system process;

[0109] Unmount the mounted partitions and remount the root directory file in read-only mode;

[0110] Unmount the system devices;

[0111] Synchronize the file system and block devices;

[0112] Power off the system.

[0113] For ease of description, the above steps will be combined and described below.

[0114] First, exit the system process; then, umount the mounted partitions and remount the rootfs in read-only mode; unmount Linux system devices such as loop devices and DM devices; Sync the file system and block devices; power off, and the shutdown ends. After the APU is completely powered off, the kernel sets the power-off flag to system shutdown through shared memory.

[0115] S104. When it is determined that the system has been successfully powered off, turn off the power of the vehicle domain controller.

[0116] In the system exit process, after the APU is powered off, the kernel can set the power-off flag to system shutdown through shared memory. Therefore, the RPU can detect the power-off flag. After detecting that the system has been powered off, it can be determined that the system has been successfully powered off. At this time, the power of the vehicle domain controller can be directly turned off.

[0117] In addition, after shutdown is completed, the gpio (abbreviation for General Purpose Input / Output, a hardware interface used on microcontrollers, embedded systems, or single-board computers) output becomes low level. Therefore, it is also possible to detect whether the gpio output interface has become low level. If it is low level, it can be determined that the system has been successfully powered off. At this time, power-off can also be performed, that is, turn off the power of the domain controller.

[0118] That is to say, by executing the above S101 to S104, when a system failure or an emergency occurs, the power can be safely and quickly disconnected to ensure the safety of the vehicle and its occupants. Also, during normal use, when the user chooses to power off the vehicle after use, the domain controller can release all resources before powering off, so that it can quickly resume the previous working state after restarting.

[0119] Initiate the power-off process through the RPU, and transfer the hierarchical power-off flag through SPI or shared memory to reduce the impact caused by sudden changes in current. The power-off process of the APU introduces a hierarchical strategy of dynamically shutting down unnecessary computing units of the APU, which can dynamically adjust the power-off order of the apps and further reduce the impact caused by sudden changes in power. The RPU and the APU jointly complete the power-off process, unify the power-off logic of the multi-core heterogeneous domain controller, and can improve the robustness of the device.

[0120] When the method provided by the embodiment of the present application is applied, the microcontroller in the vehicle domain controller receives a power-off command; wherein, the vehicle domain controller includes a microcontroller and an acceleration processing unit; by using shared memory, the local application exit process and the function application exit process of the acceleration processing unit are triggered; when it is determined that both the local application and the function application have exited, the system power-off process is triggered; when it is determined that the system has been successfully powered off, the power supply of the vehicle domain controller is turned off.

[0121] In order to enable the system to save the current state during the power-off process, correctly handle the release of device handles, clean up memory, stack data, etc., and ensure that it can quickly return to the previous working state when power is restored. In the present application, the applications in each chip are first exited, and then the system is powered off. Specifically, the shared memory in the vehicle domain controller allows the microcontroller and the acceleration processing unit in the vehicle domain controller to access it jointly. Therefore, in the present application, when the microcontroller in the vehicle domain controller receives a power-off command, by using the shared memory, the local application exit process and the function application exit process of the acceleration processing unit can be triggered simultaneously. That is, based on the shared memory, multiple chips can respond to the power-off instruction simultaneously. Then, when it is clear that both the local application and the function application have exited, the system power-off process is triggered. When it is obvious that the system has been successfully powered off, the power supply of the vehicle domain controller is turned off.

[0122] The present application can enable each chip to respond to the power-off command simultaneously and can normally release the chip resources, thereby achieving a fast and safe power-off so that when restarted again, the previous state can be quickly restored.

[0123] To facilitate those skilled in the art to better understand and implement the power-off method provided by the embodiment of the present application, the following takes a specific scenario as an example to detail the power-off method.

[0124] Taking a domain control chip including an APU and an RPU as an example, the power-off method is detailed. Among them, the RPU is the chip for managing the power supply. The RPU, as the initiator of the safe power-off process, sets the power-off flag bit to power-off through the shared memory and simultaneously starts the safe power-off process of the RPU (including the local application exit process). After receiving this flag bit, the APU starts to initiate the safe power-off process (and the function application exit process).

[0125] Please refer to Figure 2 , the RPU power-off process is as follows:

[0126] 1. The RPU sends a power-off SPI (Serial Peripheral Interface, a commonly used serial communication protocol for data transmission between a microcontroller (RPU) and external devices) message;

[0127] 2. The SPI service (hardware and communication protocol, connecting the APU and RPU) sends a power-off message (power-off SPI message) to the sysmgr (system management program), and sets the state to after-run (exit operation).

[0128] 3. The sysmgr sends to the apps registered with the power-off message and enters the shutdown method of each app to perform the exit process.

[0129] 4. After the sysmgr receives the confirm messages of all applications (APPs), it sets the state to stop.

[0130] 5. After all local applications of the RPU and functional applications in the APU have exited, the system shutdown process is executed. After the shutdown is completed, the gpio output becomes low level.

[0131] 6. The RPU detects that the gpio is low and performs a power-off, that is, shuts down the power of the domain controller. Of course, in actual applications, in order to ensure a quick power-off, a waiting duration can also be set after the power-off process is started, such as 6 seconds (this value can also be determined according to the consumption duration statistically obtained from multiple normal power-offs, such as taking the average or median), and then directly shut down the power of the domain controller after the waiting duration.

[0132] Please refer to Figure 3 (in Figure 3 , the EM and functional applications are carried on the APU), the APU power-off process is as follows:

[0133] After the EM (Execution Management Module) receives the power-off request of the RPU through the power-off flag bit in the shared memory, it exits the APP-related applications. During the exit process, the hierarchical strategy of unnecessary computing units of the APU can be dynamically closed. The specific implementation includes:

[0134] 1. First, evaluate and tag the running apps in multiple dimensions, and calculate the activity of each unit (CPU core, GPU core, DSP, AI accelerator) used by it, such as the instruction pipeline occupancy rate and cache access frequency.

[0135] 2. Divide the priorities according to functionality: Key application units: responsible for state saving and the core of the communication interface (such as the main CPU core, RPU communication module); Non-key application units: GPU core, auxiliary computing units (such as AI inference engine), unused DSP.

[0136] 3. Classified according to the real-time requirements of the application, high real-time applications, such as sensor data processing applications, medium real-time applications, such as navigation path planning, and low real-time applications, such as OTA updates.

[0137] Through the above three steps, the exit priorities are assigned to each app.

[0138] Then, the apps can be closed from low to high to reduce the instantaneous change rate of the current and more smoothly achieve the power-off of the domain controller.

[0139] Hierarchical shutdown process to reduce the impact of sudden current changes.

[0140] In the APU power-off process, the control of the power-off process is refined. After the app is closed, the power-off flag is set to app shutdown through the shared memory. When the RPU detects this power-off flag, it controls the power module to reduce the power output to the APU and can also reduce the working frequency of its own tasks. Further smoothly reduce the working current.

[0141] The system detects that the power-off flag in the shared memory is set to app shutdown and executes steps A - E (i.e., triggers the system power-off process):

[0142] A. System process exits

[0143] B. Umount the mounted partitions and remount the rootfs in read-only mode

[0144] C. Uninstall Linux system devices, such as loop device, DM device, etc.

[0145] D. Sync the file system and block devices

[0146] E. Power off

[0147] At the end of shutdown, after the APU is completely powered off, the kernel sets the flag to system shutdown through the shared memory so that the RPU can confirm the completion of system power-off when it detects this flag.

[0148] It can be seen that through the hierarchical strategy of dynamically closing unnecessary computing units of the APU, this application can adjust the closing order of apps in real time, ensuring the reliability of tasks and reducing the impact of sudden current changes.

[0149] The domain controller with multi-domain integration uses an inter-chip communication tool, such as SPI, to achieve synchronous sharing of the power-down signal, enabling the domain control to power down safely and correctly release resources. By the method of hierarchically reducing the power of the domain control, the impact of current change can be further reduced. The benefits brought by this are that the life cycle of the reading and writing devices can be extended, the probability of hardware damage can be reduced, and the robustness of the product can be improved.

[0150] When the domain control is restarted, it can quickly return to the powered-on state, reduce the startup time, and optimize the startup tasks.

[0151] Corresponding to the above method embodiments, the embodiment of the present application also provides a vehicle domain controller. The vehicle domain controller described below can be mutually referred to with the power-down method described above.

[0152] See Figure 4 As shown, the vehicle domain controller includes a microcontroller 100 and an acceleration processing unit 200; the microcontroller includes:

[0153] A command receiving module 101, configured to receive a power-down command;

[0154] A power-down triggering module 102, configured to use shared memory to trigger the local application exit process and the function application exit process of the acceleration processing unit;

[0155] A system power-down module 103, configured to trigger the system power-down process when it is determined that both the local application and the function application have exited;

[0156] A power-off module 104, configured to turn off the power of the vehicle domain controller when it is determined that the system has successfully powered down.

[0157] Applying the vehicle domain controller provided by the embodiment of the present application, the microcontroller in the vehicle domain controller receives a power-down command; wherein, the vehicle domain controller includes a microcontroller and an acceleration processing unit; uses shared memory to trigger the local application exit process and the function application exit process of the acceleration processing unit; triggers the system power-down process when it is determined that both the local application and the function application have exited; and turns off the power of the vehicle domain controller when it is determined that the system has successfully powered down.

[0158] In order to enable the system to save the current state during power-off, correctly handle the release of device handles, clean up memory, stack data, etc., and ensure that it can quickly return to the previous working state when power is restored. In this application, the applications in each chip are first exited, and then the system is powered off. Specifically, the shared memory in the vehicle domain controller allows the microcontroller and the acceleration processing unit in the vehicle domain controller to access it jointly. Therefore, in this application, when the microcontroller in the vehicle domain controller receives a power-off command, the shared memory can be used to trigger the local application exit process and the function application exit process of the acceleration processing unit simultaneously. That is, based on the shared memory, multiple chips can respond to the power-off instruction simultaneously. Then, when it is clear that both the local application and the function application have exited, the system power-off process is triggered. When it is obvious that the system has been successfully powered off, the power supply of the vehicle domain controller is turned off.

[0159] This application can enable each chip to respond to the power-off command simultaneously and can correctly release the chip resources, thereby achieving fast and safe power-off so that when restarted again, it can quickly restore the previous state.

[0160] In a specific embodiment of this application, the power-off trigger module is specifically used to set the power-off flag bit in the shared memory to power-off;

[0161] When the power-off flag bit is power-off, the local application exit process and the function application exit process are triggered.

[0162] In a specific embodiment of this application, the function application exit process includes:

[0163] The acceleration processing unit detects the power-off flag bit;

[0164] When it is detected that the power-off flag bit is power-off, obtain the exit priorities corresponding to several function applications;

[0165] Close several function applications in sequence according to the order of the exit priorities.

[0166] In a specific embodiment of this application, determining the exit priority includes:

[0167] Obtain the real-time index, functional index, and activity index corresponding to the function application;

[0168] Perform weighted summation on the real-time index, functional index, and activity index to obtain a summation result;

[0169] Use the summation result to determine the exit priority of the function application.

[0170] In a specific embodiment of this application, the local application exit process includes:

[0171] The microcontroller sends a power-down message to the serial communication service so that the serial communication service closes the local applications with registered power-down messages through the hypervisor.

[0172] In a specific embodiment of the present application, the system power-down process includes:

[0173] Exit the system process;

[0174] Unmount the mounted partitions and remount the root directory file in read-only mode;

[0175] Unmount the system devices;

[0176] Synchronize the file system and block devices;

[0177] Power down the system.

[0178] In a specific embodiment of the present application, the system power-down module is specifically used to read the power-down flag bit in the shared memory;

[0179] When the power-down flag bit is for application shutdown, it is determined that the functional application has exited;

[0180] When the status flag corresponding to the local application read is stopped, it is determined that the local application has exited;

[0181] When it is determined that both the local application and the functional application have exited, trigger the system power-down process.

[0182] Corresponding to the above method embodiment, an embodiment of the present application also provides a vehicle. A vehicle described below can be mutually corresponding and referred to with the vehicle domain controller and a power-down method described above.

[0183] The vehicle includes: a vehicle domain controller as provided in the above embodiment.

[0184] In the vehicle domain controller, the steps of the power-down method as provided in the above embodiment can be implemented. That is, the vehicle can achieve graceful power-down. Graceful power-down means that after the automotive operating system receives a power-down command, the system can save the current state, correctly handle the release of device handles, clean up the memory, stack data, etc., to ensure that it can quickly return to the previous working state when powering on again.

[0185] Corresponding to the above method embodiment, an embodiment of the present application also provides a readable storage medium. A readable storage medium described below can be mutually corresponding and referred to with a power-down method described above.

[0186] A readable storage medium has a computer program stored thereon. When the computer program is executed by a processor, the steps of the power-down method in the above method embodiment are implemented.

[0187] Specifically, the readable storage medium may be a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, an optical disk, or any other readable storage medium capable of storing program codes.

[0188] In the present specification, the various embodiments are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the various embodiments, reference can be made to each other. For the domain controller disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple, and reference can be made to the description in the method part for relevant parts.

[0189] Those skilled in the art can further realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of the examples have been generally described according to functions in the above description. Whether these functions are executed in the form of hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0190] The steps of the method or algorithm described in combination with the embodiments disclosed in this article can be directly implemented by hardware, a software module executed by a processor, or a combination of the two. The software module can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, register, hard disk, removable disk, CD-ROM, or any other form of storage medium well-known in the technical field.

[0191] Finally, it should also be noted that in this article, relationships such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "including", "comprising", or any other variant is intended to cover non-exclusive inclusion, so that a process, method, article, or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or elements inherent to such process, method, article, or device.

[0192] In this article, specific examples are used to illustrate the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to this application.

Claims

1. A power-down method, characterized in that, including: The microcontroller in the vehicle domain controller receives a power-off command; wherein, the vehicle domain controller includes the microcontroller and an acceleration processing unit; Using shared memory, trigger the local application exit process and the function application exit process of the acceleration processing unit; When it is determined that both the local application and the function application have exited, trigger the system power-off process; When it is determined that the system has been successfully powered off, turn off the power of the vehicle domain controller.

2. The method according to claim 1, wherein Using shared memory, trigger the local application exit process and the function application exit process of the acceleration processing unit, including: Set the power-off flag bit in the shared memory to power off; When the power-off flag bit is power off, trigger the local application exit process and the function application exit process.

3. The method according to claim 2, wherein The function application exit process includes: The acceleration processing unit detects the power-off flag bit; When it is detected that the power-off flag bit is power off, obtain the exit priorities corresponding to several function applications; Close the several function applications in the order of the exit priorities.

4. The method according to claim 3, wherein Determining the exit priority includes: Obtain the real-time index, functional index, and activity index corresponding to the function application; Perform a weighted sum of the real-time index, the functional index, and the activity index to obtain a summation result; Use the summation result to determine the exit priority of the function application.

5. The method according to claim 1, characterized in that, The local application exit process includes: The microcontroller sends a power-off message to the serial communication service so that the serial communication service closes the local applications that have registered power-off messages through the system management program.

6. The method according to claim 1, wherein The system power-off process includes: Exit the system process; Unmount the mounted partitions and remount the root directory file in read-only mode; Unmount the system devices; Synchronize the file system and block devices; Power off the system.

7. The method according to any one of claims 1 to 6, characterized in that, When it is determined that both the local application and the function application have exited, trigger the system power-off process, including: Read the power-off flag bit in the shared memory; When the power-off flag bit is application closed, determine that the function application has exited; When it is read that the status flag corresponding to the local application is stopped, determine that the local application has exited; When it is determined that both the local application and the function application have exited, trigger the system power-off process.

8. A vehicle domain controller, characterized in that, The vehicle domain controller includes the microcontroller and an acceleration processing unit; the microcontroller includes: A command receiving module for receiving a power-off command; A power-off trigger module for triggering the local application exit process and the function application exit process of the acceleration processing unit using shared memory; A system power-off module for triggering the system power-off process when it is determined that both the local application and the function application have exited; A power-off module for turning off the power of the vehicle domain controller when it is determined that the system has been successfully powered off.

9. A vehicle, characterized in that, including: The vehicle domain controller according to claim 8.

10. A readable storage medium, characterized in that, The computer program is stored on the readable storage medium, and when the computer program is executed by a processor, it implements the steps of the power-off method according to any one of claims 1 to 7.

Citation Information

Cited By

  • Power-down control method, integrated controller, automobile, medium, and program

    CN121004949A