Safety control method, device and system based on vehicle-mounted video cross-domain sharing

By alternately acting as the main nodes of the communication bus, the problem of resource waste and control conflicts in traditional automotive electronic and electrical architectures is solved, and the cost reduction and safety control effects are achieved.

CN120567490APending Publication Date: 2025-08-29ECARX (HUBEI) TECHCO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510694643.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-08-29

AI Technical Summary

Technical Problem

In traditional automotive electronic and electrical architectures, the repeated configuration of camera modules and video processing chips of each functional domain controller leads to an increase in production costs, and multiple independent video streaming transmission causes waste of on-board network bandwidth resources, and the control rights of different domain controllers over video streams are prone to conflicts, making it difficult to achieve on-board security control.

Method used

Through the cockpit domain chip and the driving domain chip alternately as the master node of the communication bus, the permissions are configured according to different scenarios, the fault information of the slave node module is obtained in real time, and the on-board safety control is carried out to avoid control rights conflicts.

Benefits of technology

Reduce production costs, reduce resource waste, ensure the security and real-time nature of video streaming data communication, and realize on-board safety control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120567490A_ABST
    Figure CN120567490A_ABST
Patent Text Reader

Abstract

The invention provides a safety control method, device and system based on vehicle-mounted video cross-domain sharing. The method comprises the following steps: configuring a cabin domain chip or a driving domain chip as a main node according to different scenes to obtain the authority of accessing a communication link; controlling the cabin domain chip and the driving domain chip to access a slave node module on the communication link according to the authority so as to obtain fault information of the slave node module in real time; and correspondingly controlling a cabin domain chip or a driving domain chip to carry out vehicle-mounted safety control according to the fault information. The cabin domain and the control domain share the same video stream data, so that the production cost is reduced, the waste of resources occupied in the video stream data transmission process is reduced, and meanwhile, the cabin domain chip and the control domain chip are used for carrying out time-sharing alternate control on the authority of accessing the communication link, so that the conflict of the control authority is avoided, and the vehicle-mounted safety control is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of video stream transmission, and in particular relates to a security control method, device and system based on cross-domain sharing of vehicle-mounted videos. Background Art

[0002] In traditional automotive electrical and electronic architectures, a distributed domain controller solution is commonly used. Each functional domain controller is designed based on an independent security architecture and is equipped with dedicated sensors and processing units. For example, the ADCU domain has a built-in video processing module that uses a dedicated camera to achieve autonomous driving visual perception; the DHU domain is equipped with an independent camera module for functions such as sentry mode monitoring. Each domain controller adopts a vertical design at the functional safety level and only needs to meet the functional safety requirements of its own domain. However, the repeated configuration of hardware resources such as camera modules and video processing chips for each functional domain leads to a significant increase in production costs. The transmission of multiple independent video streams wastes on-board network bandwidth resources, making it difficult to meet the real-time requirements of high-resolution multi-camera systems. When the same video stream is shared across domains, different domain controllers are prone to conflicting control rights over the video stream, making it difficult to achieve on-board safety control. Summary of the Invention

[0003] The purpose of the present invention is to propose a security control method, device and system based on cross-domain sharing of in-vehicle video, which solves the problem in the related art that when the same video stream is shared across domains, different domain controllers are prone to conflict in control of the video stream, making it difficult to achieve in-vehicle security control.

[0004] To this end, in a first aspect, the present invention provides a security control method based on cross-domain sharing of in-vehicle video, comprising the following steps:

[0005] Configure the cockpit domain chip or driving domain chip as the master node according to different scenarios to obtain access to the communication link;

[0006] Controlling the cockpit domain chip and the driving domain chip to access the slave node module on the communication link according to the authority, so as to obtain fault information of the slave node module in real time;

[0007] According to the fault information, the cockpit domain chip or the driving domain chip is controlled to perform vehicle safety control.

[0008] Optionally, configuring the cockpit domain chip or the driving domain chip as the master node to obtain access to the communication link according to different scenarios includes:

[0009] When in the intelligent driving state, the driving domain chip serves as the master node of the communication link; when in the non-intelligent driving state, the cockpit domain chip serves as the master node of the communication link.

[0010] Optionally, controlling the cockpit domain chip and the driving domain chip to access the slave node module on the communication link according to the authority to obtain fault information of the slave node module in real time includes:

[0011] The cockpit domain chip is controlled as the master node of the communication bus, and a communication link is established with the deserializer corresponding to the cockpit domain as the slave node module. The driving domain chip is disconnected from the communication bus, and the cockpit domain chip accesses and detects the fault information of the deserializer corresponding to the cockpit domain.

[0012] Optionally, controlling the cockpit domain chip or the driving domain chip to perform vehicle safety control according to the fault information includes:

[0013] When the cockpit domain chip acts as the master node of the communication bus and initiates video stream data transmission, the cockpit domain chip periodically detects fault information of the slave node module on the communication link through the communication bus. When fault information is detected, the fault information is transmitted to the cockpit domain controller, and the cockpit domain controller records the fault information.

[0014] Optionally, controlling the cockpit domain chip and the driving domain chip to access the slave node module on the communication link according to the authority to obtain fault information of the slave node module in real time includes:

[0015] The driving domain chip is controlled as the master node of the communication bus, and a communication link is established with the deserializer, serializer corresponding to the cockpit domain and the deserializer corresponding to the driving domain as slave node modules. The cockpit domain chip is disconnected from the communication bus, and the driving domain chip detects fault information of the deserializer, serializer corresponding to the cockpit domain and the deserializer corresponding to the driving domain.

[0016] Optionally, controlling the cockpit domain chip or the driving domain chip to perform vehicle safety control according to the fault information includes:

[0017] When the driving domain chip initiates video stream data transmission as the master node of the communication bus, the driving domain chip periodically detects fault information of the slave node module on the communication link through the communication bus. When fault information is detected, the fault information is transmitted to the driving domain controller, and the driving domain controller adopts a safety mechanism and enters a safe state.

[0018] Optionally, when the cockpit domain chip or the driving domain chip stops serving as the master node, the cockpit domain chip and the driving domain chip exchange permissions to access the communication link and serve as the master node alternately in a time-sharing manner.

[0019] Optionally, when the cockpit domain chip or the driving domain chip stops serving as the master node, the cockpit domain chip and the driving domain chip exchange permissions to access the communication link and alternately serve as the master node in a time-sharing manner, including:

[0020] When the cockpit domain chip stops serving as the master node of the communication link, it sends an end signal to the driving domain chip via Ethernet, and the driving domain chip restores the connection with the communication link. The driving domain chip, as the master node, obtains the permission to access the communication link.

[0021] When the driving domain chip stops serving as the master node of the communication link, it sends an end signal to the cockpit domain chip via Ethernet, and the cockpit domain chip restores the connection with the communication link. The cockpit domain chip obtains the right to access the communication link as the master node.

[0022] In a second aspect, a security control device based on cross-domain sharing of vehicle-mounted video is provided, comprising:

[0023] The permission configuration module is used to configure the cockpit domain chip or the driving domain chip as the master node to obtain the permission to access the communication link according to different scenarios;

[0024] a fault information acquisition module, configured to control the cockpit domain chip and the driving domain chip to access the slave node module on the communication link according to the authority, so as to obtain fault information of the slave node module in real time;

[0025] The safety control module is used to control the cockpit domain chip or the driving domain chip according to the fault information to perform vehicle safety control.

[0026] Thirdly, a security control system based on cross-domain sharing of vehicle-mounted video is provided, including:

[0027] A cockpit domain chip located in the cockpit domain and a driving domain chip located in the driving domain, wherein the cockpit domain chip or the driving domain chip is used to respectively serve as a master node to obtain access to the communication link according to different scenarios; and

[0028] The cockpit domain chip and the driving domain chip access the slave node module on the communication link according to the authority to obtain fault information of the slave node module in real time. The fault information is used by the corresponding cockpit domain chip or driving domain chip for vehicle safety control.

[0029] Optionally, the slave node module includes:

[0030] When the cockpit domain chip serves as the master node, the slave node modules on the corresponding communication link include a deserializer, a serializer, and a power module corresponding to the cockpit domain; or

[0031] When the driving domain chip serves as the master node, the slave node modules on the corresponding communication link include a deserializer, a serializer and a power supply module corresponding to the cockpit domain, and a deserializer corresponding to the driving domain.

[0032] Beneficial effects:

[0033] (1) The present disclosure provides a security control method, device and system based on cross-domain sharing of vehicle-mounted video. By sharing the same video stream data in the cockpit domain and the control domain, production costs are reduced and the waste of resources occupied during the transmission of video stream data is reduced. At the same time, the cockpit domain chip and the control domain chip perform time-sharing and alternating control over the access rights to the communication link to avoid conflicts in control rights and achieve vehicle-mounted safety control.

[0034] (2) In the present disclosure, the cockpit domain chip and the driving domain chip alternately serve as the master node of the communication bus to initiate video stream data transmission. When the cockpit domain chip serves as the master node of the communication bus, the cockpit domain chip initiates video stream data communication, and the driving domain chip is disconnected from the driving domain deserializer; when the driving domain chip serves as the master node of the communication bus, the driving domain chip initiates video stream data communication, and the cockpit domain chip is disconnected from the serializer and the cockpit domain deserializer, ensuring that the cockpit domain chip or the driving domain chip independently initiates video stream data communication at the same time, thereby ensuring the security of video stream data communication.

[0035] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0037] Figure 1 This is a method flow chart of a security control method based on cross-domain sharing of in-vehicle video in the present disclosure;

[0038] Figure 2 This is a method flow chart of an embodiment of a security control method based on cross-domain sharing of in-vehicle video in the present disclosure;

[0039] Figure 3 This is a schematic structural diagram of a security control device based on cross-domain sharing of vehicle-mounted video in the present disclosure;

[0040] Figure 4 This is a system structure diagram of a cross-domain sharing system for in-vehicle video streams disclosed in the present invention;

[0041] Figure 5 This is a flowchart of a working method of an embodiment of a vehicle-mounted video stream cross-domain sharing system disclosed in the present invention;

[0042] Figure 6 This is a flowchart of a non-intelligent driving state method of an embodiment of a vehicle-mounted video stream cross-domain sharing system in the present disclosure;

[0043] Figure 7 This is a flow chart of an intelligent driving state method according to an embodiment of a vehicle-mounted video stream cross-domain sharing system disclosed herein;

[0044] In the figure, 101-authority configuration module, 102-fault information acquisition module, 103-safety control module, 210-cockpit domain, 211-cockpit domain chip, 212-cockpit domain deserializer, 213-serializer, 214-cockpit domain Ethernet switch, 215-cockpit domain controller, 216-power module, 220-control domain, 221-driving domain chip, 222-driving domain deserializer, 223-driving domain Ethernet switch, 224-driving domain controller, 230-AVM camera component. DETAILED DESCRIPTION

[0045] To make the objectives, technical solutions, and advantages of this application more clear, the technical solutions in this application will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0046] Throughout the specification and claims of this application, as well as in the accompanying drawings, the terms "first," "second," "third," and "fourth," etc., are used to distinguish similar objects and are not necessarily intended to describe a particular order or precedence. It should be understood that these terms are interchangeable where appropriate. For example, cockpit domain information could also be referred to as driving domain information, and similarly, driving domain information could also be referred to as cockpit domain information, without departing from the scope of this disclosure.

[0047] The word "if" as used herein may be interpreted as "when" or "when" or "in response to determining," depending on the context.

[0048] Furthermore, as used herein, the singular forms "a," "an" and "the" are intended to include the plural forms as well, unless the context indicates otherwise.

[0049] It should be further understood that the terms “comprises” and “includes” indicate the existence of features, steps, operations, elements, components, items, types, and / or groups, but do not preclude the existence, occurrence, or addition of one or more other features, steps, operations, elements, components, items, types, and / or groups.

[0050] The terms "or" and "and / or" as used herein are to be interpreted as inclusive, or mean any one or any combination. Thus, "A, B, or C" or "A, B, and / or C" means "any one of the following: A; B; C; A and B; A and C; B and C; A, B, and C." An exception to this definition occurs only when a combination of elements, functions, steps, or operations are inherently mutually exclusive in some manner.

[0051] In traditional automotive electrical and electronic architectures, a distributed domain controller solution is commonly used. Each functional domain controller is designed based on an independent security architecture and is equipped with dedicated sensors and processing units. For example, the ADCU domain has a built-in video processing module that uses dedicated cameras to achieve autonomous driving visual perception; the DHU domain is equipped with an independent camera module for functions such as sentry mode monitoring. Each domain controller adopts a vertical design for functional safety and only needs to meet the functional safety requirements of its own domain. However, the repeated configuration of hardware resources such as camera modules and video processing chips for each functional domain leads to a significant increase in production costs. The transmission of multiple independent video streams wastes onboard network bandwidth resources, making it difficult to meet the real-time requirements of high-resolution multi-camera systems.

[0052] To this end, firstly, Figure 1 As shown, a security control method based on cross-domain sharing of vehicle-mounted video is provided, including the following steps:

[0053] S101. Configure the cockpit domain chip or the driving domain chip as the master node according to different scenarios to obtain access to the communication link;

[0054] The scenarios include intelligent driving state and non-intelligent driving state. When in the intelligent driving state, the driving domain chip serves as the master node of the communication bus; when in the non-intelligent driving state, the cockpit domain chip serves as the master node of the communication bus.

[0055] When in intelligent driving mode, such as automated parking or highway navigation, the driving domain chip needs to implement autonomous driving visual perception based on video stream data. When in non-intelligent driving mode, such as parking monitoring or multimedia interaction, the cockpit domain chip needs to implement functions such as sentry mode monitoring based on video stream data. The master node of the communication bus is the dominant node in the communication network, responsible for determining which node can use the bus for data transmission at a given moment and arranging the order and timing of data transmission based on system requirements and the status of each node. When the driving domain chip serves as the master node of the communication bus, it can establish a communication link to initiate video stream data communication. When the cockpit domain chip serves as the master node of the communication bus, it can also establish a communication link to initiate video stream data communication.

[0056] S102: Control the cockpit domain chip and the driving domain chip to access the slave node module on the communication link according to the authority, so as to obtain fault information of the slave node module in real time;

[0057] The cockpit domain chip is controlled as the master node of the communication bus, and a communication link is established with the deserializer corresponding to the cockpit domain as the slave node module. The driving domain chip is disconnected from the communication bus, and the cockpit domain chip accesses and detects the fault information of the deserializer corresponding to the cockpit domain.

[0058] S103: Control the cockpit domain chip or the driving domain chip according to the fault information to perform vehicle safety control.

[0059] When the cockpit domain chip acts as the master node of the communication bus and initiates video stream data transmission, the cockpit domain chip periodically detects fault information of the slave node module on the communication link through the communication bus. When fault information is detected, the fault information is transmitted to the cockpit domain controller, and the cockpit domain controller records the fault information.

[0060] The driving domain chip is controlled as the master node of the communication bus, and a communication link is established with the deserializer, serializer corresponding to the cockpit domain and the deserializer corresponding to the driving domain as slave node modules. The cockpit domain chip is disconnected from the communication bus, and the driving domain chip detects fault information of the deserializer, serializer corresponding to the cockpit domain and the deserializer corresponding to the driving domain.

[0061] When the driving domain chip initiates video stream data transmission as the master node of the communication bus, the driving domain chip periodically detects fault information of the slave node module on the communication link through the communication bus. When fault information is detected, the fault information is transmitted to the driving domain controller, and the driving domain controller adopts a safety mechanism and enters a safe state.

[0062] S104. When the cockpit domain chip or the driving domain chip stops serving as the master node, the cockpit domain chip and the driving domain chip exchange the authority to access the communication link and serve as the master node alternately in a time-sharing manner.

[0063] When the cockpit domain chip stops serving as the master node of the communication link, it sends an end signal to the driving domain chip via Ethernet, and the driving domain chip restores the connection with the communication link. The driving domain chip, as the master node, obtains the permission to access the communication link.

[0064] When the driving domain chip stops serving as the master node of the communication link, it sends an end signal to the cockpit domain chip via Ethernet, and the cockpit domain chip restores the connection with the communication link. The cockpit domain chip obtains the right to access the communication link as the master node.

[0065] Since conflicts will occur when both the cockpit domain chip and the driving domain chip serve as the master node of the communication bus, leading to video stream transmission errors, only one of the cockpit domain chip and the driving domain chip can serve as the master node of the communication bus at the same time, and the other chip is disconnected from the communication bus to ensure the security of video stream data transmission.

[0066] When the driving domain chip establishes a communication link, it provides visual support for intelligent driving based on video stream data, such as lane line recognition, pedestrian detection and collision warning, to ensure the safety of vehicle intelligent driving.

[0067] When the cockpit domain chip establishes a communication link, it provides visual support for parking monitoring or multimedia interaction based on the video stream data. For example, in sentry mode, it performs real-time monitoring of the vehicle's surroundings.

[0068] like Figure 2 FIG. 1 is a specific implementation of a security control method based on cross-domain sharing of vehicle-mounted video, comprising the following steps:

[0069] S201: In a non-intelligent driving state, the cockpit domain chip serves as the master node of the communication bus and obtains permission to access the communication link;

[0070] Non-intelligent driving states include parking monitoring, multimedia interaction, and driver monitoring. The cockpit domain chip establishes master node authority via the communication bus. During this time, the driving domain chip disconnects from the communication bus to avoid bus conflicts. As the master node, the cockpit domain chip is responsible for initiating video stream data communications, such as using external cameras for real-time monitoring in sentry mode or using internal cameras for driver fatigue detection.

[0071] S202: Control the cockpit domain chip to access the slave node module on the communication link according to the authority to obtain fault information of the slave node module in real time;

[0072] The cockpit domain deserializer serves as the core slave node, responsible for parsing the video stream data transmitted by the camera. The cockpit domain chip periodically checks the status of the slave node module via the communication bus, including fault types such as signal interruption, data verification errors, and module overheating. If a fault is detected, the cockpit domain chip transmits this information via the bus to the cockpit domain controller, which then logs the fault type, occurrence time, and module address.

[0073] S203: Control the cockpit domain chip to perform vehicle safety control based on the fault information;

[0074] When the cockpit domain chip acts as the master node of the communication bus, the cockpit domain chip periodically detects fault information of the slave node module on the communication link through the communication bus. When fault information is detected, the fault information is transmitted to the cockpit domain controller, and the cockpit domain controller records the fault information.

[0075] S204: The scene switches to the intelligent driving state. The cockpit domain chip and the driving domain chip exchange access rights to the communication link, and the driving domain chip serves as the master node of the communication bus.

[0076] If the driver activates intelligent driving functions such as automatic parking and high-speed navigation, the scene switches to the intelligent driving state. The cockpit domain chip sends an end signal to the driving domain chip via Ethernet. The cockpit domain chip is disconnected from the communication bus, and the driving domain chip restores the connection and obtains the master node authority.

[0077] S205: Control the driving domain chip to access the slave node module on the communication link according to the authority to obtain fault information of the slave node module in real time;

[0078] The core slave nodes, including the driver domain deserializer, serializer, and cockpit domain deserializer, are responsible for parsing the video stream data transmitted by the camera. Detection criteria include: video stream delay exceeding a threshold, sensor data verification failure, and module communication timeout.

[0079] S206: Control the driving domain chip to perform vehicle safety control based on the fault information;

[0080] If a critical fault that affects intelligent driving is detected, the driving domain chip will adopt a safety mechanism to enter a safe state to ensure the safe driving of the vehicle.

[0081] S207: The scene switches to the non-intelligent driving state and returns to step S201.

[0082] Second, as Figure 3 As shown, a security control device based on cross-domain sharing of vehicle-mounted video is provided, comprising:

[0083] The permission configuration module 101 is used to configure the cockpit domain chip or the driving domain chip as the master node to obtain the permission to access the communication link according to different scenarios;

[0084] a fault information acquisition module 102, configured to control the cockpit domain chip and the driving domain chip to access the slave node module on the communication link according to the authority, so as to obtain fault information of the slave node module in real time;

[0085] The safety control module 103 is used to control the cockpit domain chip or the driving domain chip according to the fault information to perform vehicle safety control.

[0086] In a third aspect, the present disclosure provides Figure 4 The illustrated system is an in-vehicle video stream cross-domain sharing system, comprising a cockpit domain 210 and a control domain 220. The cockpit domain 210 comprises a cockpit domain chip 211, a cockpit domain deserializer 212 and a serializer 213. The cockpit domain chip 211 is communicatively connected to the cockpit domain deserializer 212 and the serializer 213 via a communication bus. The control domain 220 comprises a driving domain chip 221 and a driving domain deserializer 222. The driving domain chip 221 is communicatively connected to the driving domain deserializer 222 via a communication bus. The cockpit domain deserializer 212 is used to receive video stream data and transmit the video stream data to the serializer 213 and the cockpit domain chip 211 respectively. The serializer 213 is used to convert the video stream data into serial data and transmit it to the driving domain deserializer 222. The driving domain deserializer 222 is used to restore the serial data to video stream data and transmit it to the driving domain chip 221. The cockpit domain chip 211 and the driving domain chip 221 alternately serve as the master node of the communication bus to initiate video stream data transmission.

[0087] The cockpit domain 210 (DHU, Digital Head Unit) is a controller for intelligent management of in-vehicle human-machine interaction and infotainment. It can perform sentry mode monitoring based on video streaming data. The control domain 220 (ADCU, Automated Driving Control Unit) is a controller for integrating and processing sensor data and executing autonomous driving decision-making and control logic. It can also provide the image foundation for intelligent driving based on video streaming data.

[0088] In one embodiment, video stream data is acquired by the AVM camera assembly 230 and output as a serialized video stream. This data is then transmitted to the cockpit domain deserializer 212 via a SerDes bus. The cockpit domain deserializer 212 converts the video stream data into a parallel format so that it can be read by the cockpit domain chip 211. The SerDes bus is a serial communication method that implements data transmission through a serializer and a deserializer, such as an FPD-Link line or a GMSL line.

[0089] In one embodiment, the cockpit domain chip 211 is a System on Chip (SOC). It accesses and controls the cockpit domain deserializer 212 and serializer 213 via an I2C communication bus. The cockpit domain deserializer 212 transmits video stream data to the cockpit domain chip 211 via the CSI interface. The serializer 213 and the driver domain deserializer 222 transmit serial video stream data via a SerDes bus.

[0090] In one embodiment, the driving domain chip 221 is an ORIN chip. The driving domain chip 221 accesses and controls the driving domain deserializer 222 via a communication bus, where the communication bus is an I2C bus. The driving domain deserializer 222 sends the video stream data to the driving domain chip 221 via a CSI interface.

[0091] Cockpit domain 210 also includes a cockpit domain Ethernet switch 214, which is communicatively connected to cockpit domain chip 211. Control domain 220 also includes a driving domain Ethernet switch 223, which is communicatively connected to driving domain chip 221. Cockpit domain Ethernet switch 214 and driving domain Ethernet switch 223 are connected via Ethernet. The Ethernet switch is used to connect cockpit domain 210 and control domain 220 via Ethernet, achieving efficient data forwarding and communication.

[0092] The cockpit domain chip 211 and the driving domain chip 221 alternately serve as the master node of the communication bus to initiate video stream data transmission, including:

[0093] When the cockpit domain chip 211 serves as the master node of the communication bus, the cockpit domain chip 211 initiates video stream data communication, and the driving domain chip 221 is disconnected from the driving domain deserializer 222;

[0094] When the cockpit domain chip 221 serves as the master node of the communication bus, the cockpit domain chip 221 initiates video stream data communication, and the cockpit domain chip 211 is disconnected from the serializer 213 and the cockpit domain deserializer 212 .

[0095] When the cockpit domain chip 211 stops serving as the master node of the communication bus, it sends an end signal to the driving domain chip 221 via Ethernet, and the driving domain chip 221 and the driving domain deserializer 222 are restored to their connection.

[0096] When the driving domain chip 221 stops serving as the master node of the communication bus, it sends an end signal to the cockpit domain chip 211 via Ethernet, and the cockpit domain chip 211 resumes connection with the serializer 213 and the cockpit domain deserializer 212.

[0097] The master node of the communication bus is used to initiate and end video stream data communication. The communication bus is an I2C bus. When the cockpit domain chip 211 serves as the master node of the communication bus, the cockpit domain deserializer 212 and serializer 213 serve as slave nodes of the communication bus. The cockpit domain chip 211 sends a video stream data communication transmission signal to the cockpit domain deserializer 212 and simultaneously sends a start signal to the driving domain chip 221 via Ethernet. After receiving the start signal, the driving domain chip 221 disconnects from the driving domain deserializer 222, and the cockpit domain deserializer 212 sends video stream data to the cockpit domain chip 211. When the cockpit domain chip 211 needs to end video stream data communication, it sends a video stream data communication end signal to the cockpit domain deserializer 212 and simultaneously sends an end signal to the driving domain chip 221 via Ethernet. After receiving the end signal, the driving domain chip 221 restores the connection with the driving domain deserializer 222, and the cockpit domain deserializer 212 stops sending video stream data to the cockpit domain chip 211. When the driving domain chip 221 serves as the master node of the communication bus, the cockpit domain deserializer 212, serializer 213, and driving domain deserializer 222 serve as slave nodes of the communication bus. The driving domain chip 221 sends a video stream data communication transmission signal to the driving domain deserializer 222 and simultaneously sends a start signal to the cockpit domain chip 211 via Ethernet. After receiving the start signal, the cockpit domain chip 211 disconnects from the serializer 213 and cockpit domain deserializer 212, and the driving domain deserializer 222 sends video stream data to the driving domain chip 221. When the driving domain chip 221 needs to terminate video stream data communication, it sends a video stream data communication termination signal to the driving domain deserializer 222 and simultaneously sends an termination signal to the cockpit domain chip 211 via Ethernet. After receiving the termination signal, the cockpit domain chip 211 restores the connection with the cockpit domain deserializer 212, and the driving domain deserializer 222 stops sending video stream data to the driving domain chip 221.

[0098] In one embodiment, the serializer 213 and the driving domain deserializer 222 are configured in pass-through mode, allowing video stream data to pass directly without any processing. The master node can directly access the remote slave node, and the remote slave node may not be directly connected to the communication bus. This method can directly transmit the original data, so that the driving domain chip 221 of the control domain 220 can directly obtain the original video stream data, thereby ensuring the transmission efficiency of the video stream data.

[0099] A cockpit domain controller 215 is provided in the cockpit domain 210, and the cockpit domain controller 215 is communicatively connected to the cockpit domain chip 211 and the cockpit domain Ethernet switch 214. A driving domain controller 204 is provided in the control domain 220, and the driving domain controller 224 is communicatively connected to the driving domain chip 221 and the driving domain Ethernet switch 223. The cockpit domain controller 215 and the driving domain controller 224 are communicatively connected via the vehicle bus.

[0100] A power module 216 is provided in the cockpit domain 210 , and is used to provide power to the cockpit domain deserializer 212 and the serializer 213 . The power module 216 can also be used to provide power to the AVM camera assembly 230 .

[0101] When the cockpit domain chip 211 acts as the master node of the communication bus and initiates video stream data transmission, the cockpit domain chip 211 periodically detects fault information of the cockpit domain deserializer 212, serializer 213 and power module 216 through the communication bus. When fault information is detected, the fault information is transmitted to the cockpit domain controller 215, and the cockpit domain controller 215 records the diagnostic fault code.

[0102] When the driving domain chip 221 initiates video stream data transmission as the master node of the communication bus, the driving domain chip 221 periodically detects the fault information of the cockpit domain deserializer 212, serializer 213, driving domain deserializer 222 and power module 216 through the communication bus. When fault information is detected, the fault information is transmitted to the driving domain controller 224, and the driving domain controller 224 adopts a safety mechanism and enters a safe state.

[0103] Fault information includes the hardware fault type and level of verification for the cockpit domain deserializer 212, serializer 213, driver domain deserializer 222, and power module 216, such as video link overvoltage, undervoltage, or overcurrent. Safety mechanisms are proactive measures designed to address faults in the cockpit domain deserializer 212, serializer 213, driver domain deserializer 222, or power module 216, such as fault detection, fault diagnosis, fault isolation, or fault alarms, to ensure safety during intelligent driving.

[0104] When in the intelligent driving state, the driving domain chip 221 initiates video stream data transmission as the master node of the communication bus; when in the non-intelligent driving state, the cockpit domain chip 211 initiates video stream data transmission as the master node of the communication bus. The triggering condition for the conversion of the cockpit domain chip 211 and the driving domain chip 221 as the master node of the communication bus is that the current vehicle is in the intelligent driving state or the non-intelligent driving state. When the cockpit domain 210 is powered on and started, the driving domain chip 221 defaults to the master node of the communication bus. At this time, the vehicle is in the non-intelligent driving state, and the driving domain chip 221 initiates video stream data transmission when needed. When the vehicle is in the intelligent driving state, the driving domain chip 221 needs to use video stream data to assist in intelligent driving, while the cockpit domain chip 211 does not need video stream data.

[0105] In one embodiment, Figure 5 As shown, the working steps of a cross-domain sharing system of vehicle-mounted video streams include:

[0106] S310, the cockpit domain deserializer 212 receives video stream data;

[0107] S320: Determine whether the vehicle is currently in an intelligent driving state or a non-intelligent driving state;

[0108] S330: If the vehicle is in a non-intelligent driving state, the cockpit domain chip 211 initiates video stream data transmission as the master node of the communication bus; if the vehicle is in an intelligent driving state, the driving domain chip 221 initiates video stream data transmission as the master node of the communication bus.

[0109] These include:

[0110] like Figure 6 As shown, S331, if the current vehicle is in a non-intelligent driving state, the cockpit domain chip 211 serves as the master node of the communication bus, the cockpit domain deserializer 212 and the serializer 213 are the slave nodes of the communication bus, the cockpit domain chip 211 initiates video stream data transmission, and the driving domain chip 221 disconnects from the driving domain deserializer 222.

[0111] The cockpit domain chip 211 sends a video stream data communication transmission signal to the cockpit domain deserializer 212, and at the same time sends a startup signal to the driving domain chip 221 via Ethernet. After receiving the startup signal, the driving domain chip 221 disconnects from the driving domain deserializer 222, and the cockpit domain deserializer 212 sends video stream data to the cockpit domain chip 211.

[0112] When the cockpit domain chip 211 needs to end the video stream data communication, it sends a video stream data communication end signal to the cockpit domain deserializer 212, and at the same time sends an end signal to the driving domain chip 221 through Ethernet. After receiving the end signal, the driving domain chip 221 restores the connection with the driving domain deserializer 222, and the cockpit domain deserializer 212 stops sending video stream data to the cockpit domain chip 211.

[0113] like Figure 7 As shown, S332, if the current vehicle is in the intelligent driving state, the driving domain chip 221 serves as the master node of the communication bus, the cockpit domain deserializer 212, the serializer 213 and the driving domain deserializer 222 are the slave nodes of the communication bus, the driving domain chip 221 initiates video stream data transmission, and the cockpit domain chip 211 disconnects from the cockpit domain deserializer 212 and the serializer 213.

[0114] The driving domain chip 221 sends a video stream data communication transmission signal to the driving domain deserializer 222, and at the same time sends a startup signal to the cockpit domain chip 211 through Ethernet. After receiving the startup signal, the cockpit domain chip 211 disconnects from the serializer 213 and the cockpit domain deserializer 212. The cockpit domain deserializer 212 sends the video stream data to the serializer 103. The serializer 103 converts the video stream data into serial form and then sends it to the driving domain deserializer 222. The driving domain deserializer 222 restores the video stream data to parallel form and then sends the video stream data to the driving domain chip 221.

[0115] When the driving domain chip 221 needs to end the video stream data communication, it sends a video stream data communication end signal to the driving domain deserializer 222, and at the same time sends an end signal to the cockpit domain chip 211 through Ethernet. After receiving the end signal, the cockpit domain chip 211 restores the connection with the cockpit domain deserializer 212, and the driving domain deserializer 222 stops sending video stream data to the driving domain chip 221.

[0116] Finally, it should be noted that those skilled in the art will readily identify other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. The present invention is intended to cover any variations, uses, or adaptations of the present invention that follow the general principles of the present invention and include common knowledge or customary techniques in the art not disclosed herein. The present invention is not limited to the precise structure described above and illustrated in the accompanying drawings, and various modifications and variations may be made without departing from the scope thereof. The scope of the present invention is limited solely by the appended claims.

Claims

1. A security control method based on cross-domain sharing of vehicle-mounted video, characterized in that: Configure the cockpit domain chip or driving domain chip as the master node according to different scenarios to obtain access to the communication link; Controlling the cockpit domain chip and the driving domain chip to access the slave node module on the communication link according to the authority, so as to obtain fault information of the slave node module in real time; According to the fault information, the cockpit domain chip or the driving domain chip is controlled to perform vehicle safety control.

2. The method according to claim 1, characterized in that The configuration of the cockpit domain chip or the driving domain chip as the master node to obtain access to the communication link according to different scenarios includes: When in the intelligent driving state, the driving domain chip serves as the master node of the communication link; when in the non-intelligent driving state, the cockpit domain chip serves as the master node of the communication link.

3. The method according to claim 2, characterized in that Controlling the cockpit domain chip and the driving domain chip to access the slave node module on the communication link according to the authority to obtain fault information of the slave node module in real time includes: The cockpit domain chip is controlled as the master node of the communication bus, and a communication link is established with the deserializer corresponding to the cockpit domain as the slave node module. The driving domain chip is disconnected from the communication bus, and the cockpit domain chip accesses and detects the fault information of the deserializer corresponding to the cockpit domain.

4. The method according to claim 3, characterized in that The controlling of the cockpit domain chip or the driving domain chip to perform vehicle safety control according to the fault information includes: When the cockpit domain chip acts as the master node of the communication bus and initiates video stream data transmission, the cockpit domain chip periodically detects fault information of the slave node module on the communication link through the communication bus. When fault information is detected, the fault information is transmitted to the cockpit domain controller, and the cockpit domain controller records the fault information.

5. The method according to claim 2, characterized in that Controlling the cockpit domain chip and the driving domain chip to access the slave node module on the communication link according to the authority to obtain fault information of the slave node module in real time includes: The driving domain chip is controlled as the master node of the communication bus, and a communication link is established with the deserializer, serializer corresponding to the cockpit domain and the deserializer corresponding to the driving domain as slave node modules. The cockpit domain chip is disconnected from the communication bus, and the driving domain chip detects fault information of the deserializer, serializer corresponding to the cockpit domain and the deserializer corresponding to the driving domain.

6. The method according to claim 5, characterized in that The controlling of the cockpit domain chip or the driving domain chip to perform vehicle safety control according to the fault information includes: When the driving domain chip initiates video stream data transmission as the master node of the communication bus, the driving domain chip periodically detects fault information of the slave node module on the communication link through the communication bus. When fault information is detected, the fault information is transmitted to the driving domain controller, and the driving domain controller adopts a safety mechanism and enters a safe state.

7. The method according to claim 1, characterized in that Also includes: When the cockpit domain chip or the driving domain chip stops serving as the master node, the cockpit domain chip and the driving domain chip exchange the rights to access the communication link and take turns serving as the master node in a time-sharing manner.

8. The method according to claim 7, characterized in that When the cockpit domain chip or the driving domain chip stops serving as the master node, the cockpit domain chip and the driving domain chip exchange permissions to access the communication link and alternately serve as the master node in a time-sharing manner, including: When the cockpit domain chip stops serving as the master node of the communication link, it sends an end signal to the driving domain chip via Ethernet, and the driving domain chip restores the connection with the communication link. The driving domain chip, as the master node, obtains the permission to access the communication link. When the driving domain chip stops serving as the master node of the communication link, it sends an end signal to the cockpit domain chip via Ethernet, and the cockpit domain chip restores the connection with the communication link. The cockpit domain chip obtains the right to access the communication link as the master node.

9. A security control device based on cross-domain sharing of vehicle-mounted video, characterized in that: include: The permission configuration module is used to configure the cockpit domain chip or the driving domain chip as the master node to obtain the permission to access the communication link according to different scenarios; a fault information acquisition module, configured to control the cockpit domain chip and the driving domain chip to access the slave node module on the communication link according to the authority, so as to obtain fault information of the slave node module in real time; The safety control module is used to control the cockpit domain chip or the driving domain chip according to the fault information to perform vehicle safety control.

10. A safety control system based on cross-domain sharing of vehicle-mounted video, characterized in that: include: A cockpit domain chip located in the cockpit domain and a driving domain chip located in the driving domain, each of which serves as a master node to obtain access to the communication link according to different scenarios; as well as The cockpit domain chip and the driving domain chip access the slave node module on the communication link according to the authority to obtain fault information of the slave node module in real time. The fault information is used by the corresponding cockpit domain chip or driving domain chip for vehicle safety control.

11. The system according to claim 11, wherein: The slave node module includes: When the cockpit domain chip serves as the master node, the slave node modules on the corresponding communication link include a deserializer, a serializer, and a power module corresponding to the cockpit domain; or When the driving domain chip serves as the master node, the slave node modules on the corresponding communication link include a deserializer, a serializer and a power supply module corresponding to the cockpit domain, and a deserializer corresponding to the driving domain.