Dual-redundancy AD control system based on SOC architecture
Through the dual-redundancy AD control system based on the SOC architecture, heartbeat monitoring and fault classification models are used to achieve rapid fault detection and switching, solving the crash problem of traditional AD systems in the event of faults and improving the system reliability and continuity of data collection.
Patent Information
- Application Number
- CN202510923042.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-04
- Publication Date
- 2025-09-12
AI Technical Summary
Traditional single-redundancy AD systems are prone to system crashes when the main control chip or AD module fails. Existing redundant designs have problems such as large switching delays, high logic complexity, and increased costs, making it difficult to meet the needs of high-reliability scenarios.
A dual-redundant AD control system based on the SOC architecture is adopted, with two SOC chips connected to the AD chip respectively. The heartbeat monitoring module and fault classification model are used to achieve rapid fault detection and seamless switching, reducing the fault rate.
It achieves seamless switching in the event of a fault, ensures the continuity of data collection and system reliability, reduces the occurrence of faults, and avoids data loss.
Smart Images

Figure CN120630639A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of electronic control, and in particular to an AD control system based on a dual-redundancy SOC architecture. Background Art
[0002] Processing reliability requirements are becoming increasingly stringent. Traditional single-redundancy AD systems have the following problems: once the main control chip or AD module fails, the entire system may lose its data acquisition function, resulting in system crash or data loss, seriously affecting system stability and security.
[0003] To improve system reliability, existing solutions often employ redundant designs, such as dual AD module backup. However, the switching logic for redundant AD modules in existing technologies often relies on external controllers or complex communication protocols, resulting in significant switching delays, high logic complexity, and increased costs. Furthermore, existing systems also lack robustness in fault detection and data storage, making them difficult to meet the demands of high-reliability scenarios.
[0004] Therefore, how to design a dual-redundancy AD control system based on the SOC chip architecture to achieve rapid fault detection and seamless switching, while ensuring data integrity and continuous system operation, is a technical problem that needs to be solved urgently. For example, Chinese Patent Publication No. CN116890770A discloses a vehicle control system, method, and vehicle. This application discloses a dual central platform of Tianxuan and Tianji that backs up each other, with functional domains connected by independent communication links, active and standby processor verification and independent storage devices to achieve dual redundancy of information and energy. However, the disadvantage is that it consumes resources, is costly, and is not suitable for small-scale engineering applications. Summary of the Invention
[0005] In view of this, the present application provides an AD control system based on dual redundancy of SOC architecture, which solves the shortcomings of low AD acquisition accuracy and poor integration in the existing technology and reduces the failure rate of the AD acquisition system.
[0006] The present application provides an AD control system based on dual redundancy of SOC architecture, which adopts the following technical solutions: An AD control system based on dual redundancy of SOC architecture, comprising: Two SOC chips, each connected to an AD chip; Both SOC chips are equipped with a heartbeat monitoring module. The two SOC chips are directly connected through IO hardware. The two SOC chips monitor each other's heartbeat line through the heartbeat monitoring module. Both SOC chips are equipped with a fault classification model, which receives AD sampling deviation, heartbeat response deviation, chip temperature and AD chip fault word feature value, and outputs the fault level; the SOC chip responds accordingly.
[0007] Optionally, the SOC chip calculates the actual AD sampling rate and compares it with the set AD sampling rate to determine whether data is lost. If a packet loss fault occurs, the fault classification model defines the fault as a level 1 fault. The SOC chip obtains the data sampled from the AD and compares the AD sampled data with the preset value. If the difference exceeds the preset range, the fault classification model defines the fault as a secondary fault. If one of the SOC chips determines that the other SOC chip cannot respond or the SOC chip monitors that the AD chip is working abnormally, the fault classification model will identify the fault as a level 3 fault.
[0008] Optionally, when a level 1 fault or a level 2 fault occurs, the SOC chip will latch the fault information and attempt to reconfigure AD parameters or reset the corresponding module to restore normal operation. If the fault recurs more than a threshold number of times, it will be upgraded to a level 3 fault.
[0009] Optionally, in the event of a level 3 fault, if one SOC chip fails to receive the heartbeat signal from the other SOC chip, the normal SOC chip will dynamically increase the heartbeat frame frequency signal reading. If it fails to read again, the hardware triggers an automatic switching mechanism, and the normal working SOC chip and AD chip will perform subsequent processing; If the SOC chip keeps reading that the AD chip is faulty, it will try to reset the AD chip. If the fault persists, the hardware will trigger an automatic switching mechanism, and the normally functioning SOC chip and AD chip will perform subsequent processing.
[0010] Optionally, the SOC chip establishes multiple different time windows to predict faults at a preset clock frequency, and the time of the multiple time windows gradually increases. The standard value voltage of each sample in the first time window is subtracted from the standard voltage, and the average difference of all differences in the time window is recorded as A1. The time of the next time window increases, the standard value voltage of each sample in the second time window is subtracted from the standard voltage, and the average difference of all differences in the time window is recorded as A2. The standard value voltage of each sample in all remaining time windows is subtracted from the standard voltage in turn, and the average difference of all differences in the time window is recorded as A3, ..., An in turn; the differences between two adjacent time windows are subtracted in pairs, and the differences are compared. If they are constantly increasing or decreasing, sampling is stopped, and it is considered that the AD acquisition has failed at this time, and it is defined as a secondary fault.
[0011] Optionally, during the initialization phase of the PS side of the SOC chip, AD configuration parameters are pre-loaded into the dual-port RAM of the PL side of the SOC chip. The two SOC chips periodically poll and read the AD configuration information in the dual-port RAM and write the AD configuration information into their respective registers.
[0012] In summary, this application has the following beneficial technical effects: Compared with traditional AD control, dual SOC independent control can complete redundant switching without external intervention, thereby improving system reliability. Moreover, through fault prediction and rapid switching, data collection is ensured to be uninterrupted, and fault classification can be carried out, which can greatly reduce the occurrence rate of system failures. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0014] Figure 1 This is a principle block diagram of the SOC chip in the embodiment of this application; Figure 2 This is the operation flow chart of the control system for this application; Figure 3 This is the fault level classification diagram for this application. DETAILED DESCRIPTION
[0015] The embodiments of the present application are described in detail below with reference to the accompanying drawings.
[0016] The following describes the embodiments of the present application through specific examples, and those skilled in the art can easily understand other advantages and effects of the present application from the contents disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. The present application can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present application. It should be noted that, in the absence of conflict, the features in the following embodiments and embodiments can be combined with each other. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without making creative work are within the scope of protection of this application.
[0017] It should be noted that various aspects of the embodiments within the scope of the appended claims are described below. It should be apparent that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is merely illustrative. Based on this application, it should be understood by those skilled in the art that an aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects described herein can be used to implement an apparatus and / or practice a method. In addition, other structures and / or functionalities other than one or more of the aspects described herein can be used to implement this apparatus and / or practice this method.
[0018] It should also be noted that the illustrations provided in the following embodiments are only schematic illustrations of the basic concept of the present application. The illustrations only show components related to the present application and are not drawn according to the number, shape and size of components in actual implementation. In actual implementation, the type, quantity and proportion of each component can be changed at will, and the component layout type may also be more complicated.
[0019] Additionally, in the following description, specific details are provided to provide a thorough understanding of the examples. However, one skilled in the art will appreciate that the aspects described can be practiced without these specific details.
[0020] The embodiment of the present application provides an AD control system based on dual redundancy of SOC architecture.
[0021] like Figures 1 to 3 As shown, an AD control system based on dual redundancy of SOC architecture includes: Two SOC chips are connected to one AD chip respectively. The SOC chip is based on the ZYNQ architecture. ZYNQ integrates an ARM processor core and an FPGA, integrating a software-programmable hard-core processor and a hardware-programmable FPGA into one chip. The ARM processor in the SOC chip is called PS, which stands for Processing System, and the FPGA is called PL, which stands for Programmable Logic. The two independent SOC chips run the same control software and are responsible for AD control. Both SOC chips are equipped with a heartbeat monitoring module. The two SOC chips are directly connected through IO hardware, and the two SOC chips monitor each other's heartbeat line through the heartbeat monitoring module.
[0022] Both SOC chips are equipped with a fault classification model, which receives AD sampling deviation, heartbeat response deviation, chip temperature and AD chip fault word feature value, and outputs the fault level; the SOC chip responds accordingly.
[0023] Through dual SOC collaboration and heartbeat detection, two independent SOCs, each running the same control software, are responsible for AD control. This incorporates fault prediction models and fault classification to predict and classify AD faults, providing differentiated processing for each fault level. This achieves dual SOC control of dual ADs. Furthermore, data backup is maintained for any faults, reducing the failure rate of the AD acquisition system.
[0024] After the SOC chip is powered on, it waits for the PL end to start working and begins mutual monitoring of heartbeat frames. This mainly involves the heartbeat monitoring module. The dual SOC chips are connected directly by hardware and adopt a dynamic adaptive heartbeat detection algorithm. The dynamic adaptive heartbeat detection algorithm is specifically implemented as follows: the SOC chips at both ends respectively send out frequency-adjustable PWM signals, and the SOC chip at the other end collects PWM waveforms; by detecting the amount of data collected by the AD and the chip temperature, the PWM sampling frequency and sampling interval are autonomously adjusted. During the initialization phase on the PS end, the AD configuration parameters are pre-loaded into the dual-port RAM on the PL end of the SOC chip. The two SOC chips periodically poll and read the AD configuration information in the dual-port RAM and write the AD configuration information into their respective registers. The configuration parameters include the AD operating mode, sampling rate, gain setting, etc. The two SOC chips periodically poll and read the AD configuration information in the dual-port RAM and write these configurations into their respective registers. In this way, both SOC chips maintain the latest configuration parameters.
[0025] After the configuration is read, AD collection begins. This part includes AD collection and fault classification modules. Figure 2 As shown in the figure, this part mainly adopts a real-time fault tree classification algorithm based on multi-feature fusion and hardware parallelism. This algorithm performs fault tree classification by fusion of feature values.
[0026] The SOC chip calculates the actual AD sampling rate and compares it with the set AD sampling rate to determine whether there is data packet loss. If a packet loss fault occurs, the fault classification model defines the fault as a level 1 fault. Specifically, the AD sampling process is monitored to see whether a small amount of data is lost, which may be caused by communication delays or transient interference, that is, occasional packet loss.
[0027] The SOC chip obtains the data sampled from the AD and compares the AD sampled data with the preset value. If the difference exceeds the preset range, the fault classification model defines the fault as a secondary fault. If one of the SOC chips determines that the other SOC chip cannot respond or the SOC chip monitors that the AD chip is working abnormally, the fault classification model will identify the fault as a level 3 fault.
[0028] The present application also includes fault prediction. The SOC chip establishes multiple different time windows with a preset clock frequency to predict faults. The time of multiple time windows gradually increases. The standard value voltage of each sample in the first time window is subtracted from the standard voltage, and the average difference of all differences in the time window is recorded as A1. The time of the next time window increases, the standard value voltage of each sample in the second time window is subtracted from the standard voltage, and the average difference of all differences in the time window is recorded as A2. The standard value voltage of each sample in all remaining time windows is subtracted from the standard voltage in turn, and the average difference of all differences in the time window is recorded as A3, ..., An; the differences between two adjacent time windows are subtracted in pairs, and the differences are compared. If they are constantly increasing or decreasing, sampling is stopped, and it is considered that the AD acquisition has failed at this time, and it is defined as a secondary fault.
[0029] AD chips usually set a reference source voltage to calibrate the sampling voltage. The SOC chip of this application will continuously collect standard value voltages. Taking a clock frequency of 50MHz as an example, different time windows are established to predict faults, namely 5us, 10us, 15us, etc. The standard value voltage sampled each time within the 5us period is subtracted from the standard voltage, and the final difference is retained and recorded as A1. The next time the time window becomes 10us, and the same operation as above is performed, and the final difference is retained and recorded as A2. And so on, in order, A2, A3, A4, A9, and the differences are made in pairs, A2-A1, A3-A2, etc. until A9-A8. The differences are compared. If they are constantly increasing or decreasing, sampling is stopped. It is considered that the AD acquisition has failed at this time, which corresponds to a secondary fault.
[0030] When a level 1 or level 2 fault occurs, the SOC chip will latch the fault information and try to reconfigure AD parameters or reset the corresponding module to restore normal operation. If the fault recurs more than a threshold number of times, it will be upgraded to a level 3 fault.
[0031] Specifically, under normal circumstances, only one SOC chip controls one AD. The SOC chip continuously reads the fault classification output module and switches between the ADs. It first receives first- and second-level fault processing signals. For occasional packet loss or data out-of-tolerance, the SOC chip latches the fault information and attempts to reconfigure AD parameters or reset related modules to restore normal operation. If the fault recurs or worsens, it is upgraded to a higher-level fault.
[0032] Level 3 fault handling: If one SOC chip fails to receive the heartbeat signal from the other, the healthy SOC chip dynamically increases the heartbeat frame frequency. If it fails again, the hardware triggers an automatic switching mechanism, and the normally functioning SOC and AD chips handle subsequent processing. If the SOC chip continues to detect an AD chip fault, it attempts to reset the AD chip. If the fault persists, the hardware triggers an automatic switching mechanism, and the normally functioning SOC and AD chips handle subsequent processing. During the AD switching, the data collected by the faulty AD is promptly written to the FLASH.
[0033] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.
Claims
1. An AD control system based on dual redundancy of SOC architecture, characterized in that: include: Two SOC chips, each connected to an AD chip; Both SOC chips are equipped with a heartbeat monitoring module. The two SOC chips are directly connected through IO hardware. The two SOC chips monitor each other's heartbeat line through the heartbeat monitoring module. Both SOC chips are equipped with a fault classification model, which receives AD sampling deviation, heartbeat response deviation, chip temperature and AD chip fault word feature value, and outputs the fault level; the SOC chip responds accordingly.
2. The AD control system based on SOC architecture dual redundancy according to claim 1 is characterized in that: The SOC chip calculates the actual AD sampling rate and compares it with the set AD sampling rate to determine whether data is lost. If a packet loss fault occurs, the fault classification model defines the fault as a level 1 fault. The SOC chip obtains the data sampled from the AD and compares the AD sampled data with the preset value. If the difference exceeds the preset range, the fault classification model defines the fault as a secondary fault. If one of the SOC chips determines that the other SOC chip cannot respond or the SOC chip monitors that the AD chip is working abnormally, the fault classification model will identify the fault as a level 3 fault.
3. The AD control system based on SOC architecture dual redundancy according to claim 2, characterized in that: When a level 1 or level 2 fault occurs, the SOC chip will latch the fault information and try to reconfigure AD parameters or reset the corresponding module to restore normal operation. If the fault recurs more than a threshold number of times, it will be upgraded to a level 3 fault.
4. The AD control system based on dual redundancy of SOC architecture according to claim 1, characterized in that: In the event of a level 3 fault, if one SOC chip fails to receive the heartbeat signal from the other SOC chip, the normal SOC chip will dynamically increase the heartbeat frame frequency signal reading. If it fails to read again, the hardware triggers an automatic switching mechanism, and the normal working SOC chip and AD chip will perform subsequent processing; If the SOC chip keeps reading that the AD chip is faulty, it will try to reset the AD chip. If the fault persists, the hardware will trigger an automatic switching mechanism, and the normally functioning SOC chip and AD chip will perform subsequent processing.
5. The AD control system based on dual redundancy of SOC architecture according to claim 1, characterized in that: The SOC chip establishes multiple different time windows to predict faults at a preset clock frequency. The time of multiple time windows gradually increases. The standard value voltage of each sample in the first time window is subtracted from the standard voltage, and the average difference of all differences in the time window is recorded as A1. The time of the next time window increases, the standard value voltage of each sample in the second time window is subtracted from the standard voltage, and the average difference of all differences in the time window is recorded as A2. The standard value voltage of each sample in all remaining time windows is subtracted from the standard voltage in turn, and the average difference of all differences in the time window is recorded as A3, ..., An in turn. The differences between two adjacent time windows are subtracted in pairs and the differences are compared. If they are constantly increasing or decreasing, sampling is stopped, and it is considered that the AD acquisition has failed at this time, and it is defined as a secondary fault.
6. The AD control system based on dual redundancy of SOC architecture according to claim 1, characterized in that: During the initialization phase of the PS side of the SOC chip, the AD configuration parameters are pre-loaded into the dual-port RAM of the PL side of the SOC chip. The two SOC chips periodically poll and read the AD configuration information in the dual-port RAM and write the AD configuration information into their respective registers.
Citation Information
Patent Citations
Vehicle control system and method and vehicle
CN116890770A