Dual-redundancy control method and device, chassis power system and vehicle

Through the dual-redundant control method and independent power supply design, the problem of reduced driver controllability caused by domain controller failure is solved, and the reliable operation and safety of the chassis power system in the event of a failure are achieved.

CN120652881APending Publication Date: 2025-09-16CHONGQING SELIS PHOENIX INTELLIGENT INNOVATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510809619.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-17
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

In existing technologies, functional failures caused by domain controller failures may significantly reduce the driver's controllability of the vehicle. Especially when integrating functions with high functional safety levels, there is a risk that the actuator will stop working during the failure, especially in wire-controlled steering and wire-controlled brake systems, which may cause danger.

Method used

A dual-redundant control method is adopted. Through the mutual checking mechanism and independent power supply design of the first and second control units, a control strategy is generated to ensure that the third control unit can still maintain system functions when any unit fails. This includes end-to-end verification and a hierarchical fault prompt mechanism to ensure the redundancy and reliability of the system.

Benefits of technology

It improves the control reliability and driver controllability of the chassis power system, ensures that the system can still operate normally when the control unit fails, reduces the danger caused by failure, and improves system safety and fault tolerance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120652881A_ABST
    Figure CN120652881A_ABST
Patent Text Reader

Abstract

The invention discloses a dual-redundancy control method. The dual-redundancy control method comprises the steps of receiving a first control main body judgment result of a first control unit and a second control main body judgment result of a second control unit; the first control main body judgment result is determined according to the operation state of the second control unit, and the second control main body judgment result is determined according to the operation state of the first control unit; and generating a control strategy based on the judgment result of the first control main body and the judgment result of the second control main body, so that a third control unit controls an actuator based on the control strategy. According to the chassis power control system, the running state judgment results of the two control units are received, the dynamic control strategy is generated, and the third control unit realizes redundancy decision, so that the whole chassis power control system can still ensure that basic functions are available under the condition that one control unit fails to work to the greatest extent; the method has the advantages of improving the control reliability of a chassis power system, improving the controllability of a driver on a vehicle and improving the safety of the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of dual-redundancy control technology, and in particular to a dual-redundancy control method, device, chassis power system and vehicle. Background Art

[0002] With the improvement of chip computing power and the level of automotive intelligence, the integration of domain controller functions has become an industry development trend. However, when a domain controller fails and its functions fail, the higher the degree of integration, the more likely the driver's controllability of the vehicle will be significantly reduced, thereby increasing the risk of personal injury. In particular, when high functional safety level functions such as wire-controlled steering, wire-controlled braking, and power control are integrated into a single domain controller, the driver will completely lose control of the vehicle in the event of a failure. The current mainstream solution uses a safety MCU to monitor the operating status of the main MCU and take over the control signal output when the main MCU experiences an abnormality. However, this solution has limitations in the output bus signal scenario: there is a time delay from the main MCU failure to the safety MCU completing the takeover, and the actuator may stop working during this period. For high-real-time systems such as wire-controlled braking and wire-controlled steering, execution interruptions may cause danger. Summary of the Invention

[0003] In view of the above-mentioned shortcomings of the prior art, the present application provides a dual-redundancy control method, device, chassis power system and vehicle to solve at least one defect in the prior art.

[0004] To achieve the above and other objectives, the present application provides a dual-redundancy control method, which is applied to a chassis power system, wherein the chassis power system includes a first control unit, a second control unit, and a third control unit; the dual-redundancy control method includes:

[0005] receiving a first control subject judgment result of the first control unit and a second control subject judgment result of the second control unit; the first control subject judgment result is determined according to the operating state of the second control unit, and the second control subject judgment result is determined according to the operating state of the first control unit;

[0006] A control strategy is generated based on the first control subject judgment result and the second control subject judgment result, so that the third control unit controls the actuator based on the control strategy.

[0007] In one embodiment of the present application, generating a control strategy based on the judgment result of the first control subject and the judgment result of the second control subject includes:

[0008] If the first control subject determines that the control unit is the first control unit and the second control subject determines that the control unit is the first control unit, the control strategy is to execute the first control signal output by the first control unit.

[0009] In one embodiment of the present application, the method further includes:

[0010] A control strategy is generated based on the judgment result of the first control subject, the judgment result of the second control subject, and the operating state of the second control unit.

[0011] In one embodiment of the present application, generating a control strategy based on the judgment result of the first control subject, the judgment result of the second control subject, and the operating state of the second control unit includes:

[0012] If the judgment result of the first control subject is the first control unit, the judgment result of the second control subject is the first control unit, and the operating state of the second control unit is an abnormal state, the control strategy is to execute the first control signal output by the first control unit and generate a first level fault prompt.

[0013] In one embodiment of the present application, generating a control strategy based on the judgment result of the first control subject and the judgment result of the second control subject includes:

[0014] When the first control subject determines that the signal is the first control unit and the second control subject determines that the signal is the second control unit, performing a first end-to-end check on the first control signal;

[0015] If the first end-to-end verification passes, the control strategy is to execute the first control signal output by the first control unit and generate a second-level fault prompt;

[0016] If the first end-to-end verification fails, the control strategy is to execute the second control signal output by the second control unit and generate a third level fault prompt.

[0017] In one embodiment of the present application, generating a control strategy based on the judgment result of the first control subject, the judgment result of the second control subject, and the operating state of the second control unit includes:

[0018] When the first control subject determines that the first control unit is the first control unit, the second control subject determines that the second control unit is the second control unit, and the operating state of the second control unit is abnormal, performing a second end-to-end check on the first control signal output by the first control unit;

[0019] If the second end-to-end check passes, performing a third end-to-end check on the second control signal output by the second control unit;

[0020] If the third end-to-end verification passes, the control strategy is: execute the first control signal and generate a second-level fault prompt; if the third end-to-end verification fails, the control strategy is: execute the first control signal and generate a first-level fault prompt;

[0021] If the second end-to-end verification fails, a fourth end-to-end verification is performed on the second control signal output by the second control unit; if the fourth end-to-end verification passes, the control strategy is: execute the second control signal output by the second control unit and generate a third-level fault prompt; if the fourth end-to-end verification fails, the control strategy is: the actuator stops execution and generates a fourth-level fault prompt; wherein, the levels of the second-level fault prompt, the first-level fault prompt, the third-level fault prompt, and the fourth-level fault prompt increase in sequence.

[0022] To achieve the above and other objectives, the present application provides a dual-redundant control device, which is applied to a chassis power system. The chassis power system includes a first control unit, a second control unit, and a third control unit. The dual-redundant control device includes:

[0023] a data receiving module, configured to receive a first control subject judgment result of the first control unit and a second control subject judgment result of the second control unit; the first control subject judgment result is determined according to an operating state of the second control unit, and the second control subject judgment result is determined according to an operating state of the first control unit;

[0024] A strategy generation module is used to generate a control strategy based on the judgment result of the first control subject and the judgment result of the second control subject, so that the actuator executes the control strategy.

[0025] To achieve the above and other objectives, the present application provides a chassis power system, comprising:

[0026] The first control unit is configured to obtain an operating state of the second control unit and generate a first control subject judgment result according to the operating state of the second control unit;

[0027] The second control unit is used to obtain the operating status of the first control unit and generate a second control subject judgment result according to the operating status of the first control unit;

[0028] The third control unit is used to receive the first control subject judgment result of the first control unit and the second control subject judgment result of the second control unit, and generate a control strategy based on the first control subject judgment result and the second control subject judgment result so that the actuator executes the control strategy.

[0029] In one embodiment of the present application, the chassis power system further includes: a first power chip, a second power chip, a first CAN chip, a second CAN chip, and a CAN bus;

[0030] The first power chip is used to power the first control unit and the first CAN chip; the second power chip is used to power the second control unit and the second CAN chip; the first CAN chip communicates with the first control unit; the second CAN chip communicates with the second control unit; the first control unit exchanges data with the third control unit through the CAN bus; the second control unit exchanges data with the third control unit through the CAN bus.

[0031] To achieve the above objectives and other objectives, the present application provides a vehicle, including: the above-mentioned chassis power system.

[0032] Beneficial effects of this application:

[0033] The present application discloses a dual-redundant control method, which is applied to a chassis power system, wherein the chassis power system includes a first control unit, a second control unit, and a third control unit; the dual-redundant control method includes: receiving a first control subject judgment result of the first control unit and a second control subject judgment result of the second control unit; the first control subject judgment result is determined according to the operating state of the second control unit, and the second control subject judgment result is determined according to the operating state of the first control unit; generating a control strategy based on the first control subject judgment result and the second control subject judgment result, so that the third control unit controls the actuator based on the control strategy. The present application receives the operating state judgment results of the two control units and generates a dynamic control strategy, and the third control unit implements redundant decision-making, which can maximize the guarantee that the entire chassis power control system can still ensure the basic functions are available when one of the control units fails, and has the advantages of improving the control reliability of the chassis power system, improving the driver's controllability of the vehicle, and improving system safety.

[0034] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] The accompanying drawings are incorporated into and constitute a part of the specification, illustrating embodiments consistent with the present application and, together with the specification, serving to explain the principles of the present application. It is obvious that the drawings described below are merely some embodiments of the present application, and a person of ordinary skill in the art can derive other drawings based on these drawings without inventive effort. In the drawings:

[0036] Figure 1 This is a functional block diagram of the chassis power system according to one embodiment of the present application;

[0037] Figure 2 This is a flow chart of a dual-redundancy control method according to an embodiment of the present application;

[0038] Figure 3 This is a data flow diagram of a chassis power system according to an embodiment of the present application;

[0039] Figure 4 This is a principle block diagram of a dual-redundant control device according to an embodiment of the present application;

[0040] Figure 5 This is a functional block diagram of the chassis power system according to one embodiment of the present application;

[0041] Figure 6 A schematic diagram of the structure of a computer system suitable for implementing the memory of an embodiment of the present application is shown. DETAILED DESCRIPTION

[0042] The following describes the embodiments of the present application through specific examples. Those skilled in the art can easily understand the other advantages and effects of the present application from the content disclosed in this specification. The present application can also be implemented or applied through other different specific embodiments. The details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present application. It should be noted that the following embodiments and features in the embodiments can be combined with each other unless they conflict.

[0043] It should be noted that the illustrations provided in the following embodiments are only schematic illustrations of the basic concept of the present application. Therefore, the illustrations only show components related to the present application and are not drawn according to the number, shape and size of components in actual implementation. In actual implementation, the type, quantity and proportion of each component can be changed at will, and the component layout type may also be more complicated.

[0044] Although the terms "first," "second," "A," and "B," etc. may be used herein to describe various elements, these elements should not be limited by these terms and are merely used to distinguish one element from another. For example, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element without departing from the scope of the technology described below. The term "and / or" includes a combination of a plurality of related items or any of the plurality of related items.

[0045] As used herein, unless the context indicates otherwise, the singular form is intended to include the plural form, and it will be understood that the term "comprising" means the presence of stated features, quantities, steps, operations, elements, or combinations thereof, but does not preclude the presence or addition of one or more other features, quantities, steps, operations, elements, components, or combinations thereof.

[0046] Before describing the components in detail, it is intended to clarify that the components in this specification are divided only by the primary function of each component. That is, two or more components described below may be combined into one component, or may be divided into two or more components based on more detailed functions. In addition to the primary function of the component, each component described below may also perform some or all of the functions of other components, and some of the primary functions of each component may be exclusively performed by other components.

[0047] The embodiments of the present application respectively propose a dual-redundancy control method, a dual-redundancy control device, a chassis power system, and a vehicle, which will be described in detail below.

[0048] The dual redundant control method of this application is applied to the chassis power system, wherein, please refer to Figure 1 , Figure 1 This is a principle block diagram of the chassis power system of an embodiment of the present application. Figure 1 As shown, a chassis power system includes but is not limited to a first power supply S101, a second power supply S102, a domain controller S103, a CAN bus S104, and a third control unit (execution controller) S105. The domain controller S103 includes but is not limited to a first power supply chip S131, a first control unit S132, a first CAN chip S133, a second power supply chip S141, a second control unit S142, and a second CAN chip S143.

[0049] The first control unit and the second control unit may be a microcontroller unit MCU (Microcontroller Unit, MCU).

[0050] The first power supply S101 and the second power supply S102 may be 12V power supplies.

[0051] The first power supply S101 supplies power to the first power chip S131 in the domain controller S103.

[0052] The second power supply S102 supplies power to the second power chip S141 in the domain controller S103.

[0053] The first power supply S101 and the second power supply S102 are separate power sources for the vehicle. The first and second power sources are independent of each other, meaning that failure of one will not affect the power supply function of the other. This ensures power supply independence for the first and second control units, improving system reliability and fault tolerance. Even if one power supply fails, the other MCU will continue to operate normally, avoiding the risk of a single point of failure causing complete system failure. This design enhances system redundancy and improves the safety of the vehicle's electrical system.

[0054] For the first power chip S131, power is supplied to the first control unit S132 and the first CAN chip S133 in the domain controller S103. At the same time, the first power chip S131 includes but is not limited to voltage monitoring functions and watchdog functions. When the first power chip S131 detects that its own input and output voltages are abnormal, it will stop supplying power to the first control unit S132 and the first CAN chip S133. There is a communication link between the first power chip S131 and the first control unit S132, so that the watchdog in the first power chip S131 monitors the survival status of the first control unit S132. If the first control unit S132 stops feeding the watchdog in the first power chip S131, the first power chip S131 will restart the first control unit S132 through the restart pin.

[0055] The second power supply chip S141 supplies power to the second control unit S142 and the second CAN chip S143 in the domain controller S103. The second power supply chip S141 also includes, but is not limited to, voltage monitoring and watchdog functions. When the second power supply chip S141 detects abnormalities in its input and output voltages, it will stop supplying power to the second control unit S142 and the second CAN chip S143. A communication link exists between the second power supply chip S141 and the second control unit S142, enabling the watchdog in the second power supply chip S141 to monitor the survival status of the second control unit S142. If the second control unit S142 stops feeding the watchdog in the second power supply chip S141, the second power supply chip S141 will restart the second control unit S142 via the restart pin.

[0056] When the first power chip S131 detects abnormal input or output voltages, or restarts the first control unit S132 via the restart pin, the functions of the second power chip S141, the second control unit S142, and the second CAN chip S143 will not be affected. Similarly, when the second power chip S141 detects abnormal input or output voltages, or restarts the second control unit S142 via the restart pin, the functions of the first power chip S131, the first control unit S132, and the first CAN chip S133 will not be affected. By monitoring voltages and the operating status of the MCU in real time, potential faults can be quickly detected and responded to, preventing system errors caused by voltage anomalies or MCU crashes. Furthermore, by proactively cutting off power, the fault can be prevented from spreading, protecting other hardware components.

[0057] For the first control unit S132, external data is obtained from the first CAN chip S133 for its own logical calculations. After the logical calculations are completed inside the first control unit S132, a control signal is sent through the first CAN chip S133. The control signal sent will be E2E (end-to-end) protected. The first control unit S132 has but is not limited to the ability to detect its own hardware faults and system faults. When the detected fault directly affects its normal operation, the first control unit S132 will inform the first power chip S131. The first power chip S131 will restart the first control unit S132 and cut off the power supply to the first CAN chip S133; when the first control unit S132 restarts, it detects that its own fault has been cleared, and then notifies the first power chip S131 to power the first CAN chip S133.

[0058] For the second control unit S142, external data is obtained from, including but not limited to, the second CAN chip S143 for its own logical calculations. After the logical calculations are completed inside the second control unit S142, a control signal is sent through the second CAN chip S143. The control signal sent will be E2E protected. The second control unit S142 has, but is not limited to, the ability to detect its own hardware faults and system faults. When the detected fault directly affects its normal operation, the second control unit S142 will inform the second power chip S141. The second power chip S141 will restart the second control unit S142 and cut off the power supply to the second CAN chip S143; when the second control unit S143 restarts, it detects that its own fault has been cleared, and then notifies the second power chip S141 to supply power to the second CAN chip S143.

[0059] The first control unit S132 deploys full-function software components to implement all functions in the product definition; the second control unit S142 deploys basic software components to implement the basic functions of the driver controlling the entire vehicle. The first control unit S132 and the second control unit S142 have a communication link. The first control unit S132 uses this communication link to detect the heartbeat signal of the second control unit S142 and transmits the detection result to the CAN bus S104 via the first CAN chip S133. The second control unit S142 uses this communication link to detect the heartbeat signal of the first control unit S132 and transmit the detection result to the CAN bus S104 via the second CAN chip S43.

[0060] The first CAN chip S133 obtains data from the CAN bus S104 and sends the data to the first control unit S132; and the first CAN chip S133 receives the signal of the first control unit S132 and sends the signal to the CAN bus S104.

[0061] The second CAN chip S143 obtains data from the CAN bus S104 and sends the data to the second control unit S142; and the second CAN chip S143 receives the signal of the second control unit S142 and sends the signal to the CAN bus S104.

[0062] The execution controller S105 obtains the execution control instruction from the CAN bus S104, drives the actuator to perform the corresponding action, and feeds back the actuator status to the CAN bus S104.

[0063] See also Figure 2 , Figure 2 This is a flow chart of a dual-redundancy control method according to an embodiment of the present application. The dual-redundancy control method is applied to Figure 1 The chassis power system shown in Figure 2 is as follows. Figure 2 As shown, the dual-redundancy control method includes steps S210 to S220:

[0064] Step S210, receiving a first control subject judgment result of the first control unit and a second control subject judgment result of the second control unit; the first control subject judgment result is determined according to the operating state of the second control unit, and the second control subject judgment result is determined according to the operating state of the first control unit;

[0065] The first control unit refers to a core processor with a main control function, which is used to monitor the operating status of itself and the second control unit in real time and output a judgment result. The second control unit refers to a processor with the same function as the first control unit. The first control subject judgment result is the decision data generated by the first control unit by monitoring the operating status of the second control unit, which is used to determine the control subject, that is, whether the current main control unit is the first control unit or the second control unit; the second control subject judgment result is the decision data generated by the second control unit by monitoring the operating status of the first control unit, which is used to determine the control subject, that is, whether the current main control unit is the first control unit or the second control unit.

[0066] See also Figure 3 , Figure 3 This is a data flow diagram of the chassis power system of one embodiment of the present application. When the first control unit detects that the heartbeat of the second control unit is normal, the first control unit outputs a first control subject signal, indicating that the first control subject's judgment result is the first control unit, and the first control unit outputs a first control signal; when the first control unit detects that the heartbeat of the second control unit is abnormal, the operating state of the second control unit is abnormal, and the first control unit outputs the first control subject judgment result, indicating that the control subject is the first control unit but the second control unit is abnormal. When the second control unit detects that the heartbeat of the first control unit is normal, the second control unit outputs a second control subject signal, indicating that the second control subject's judgment result is the first control unit; when the second control unit detects that the heartbeat of the first control unit is abnormal, the operating state of the first control unit is abnormal, the second control unit outputs a second control subject signal, indicating that the second control subject's judgment result is the second control unit, and the second control unit outputs a second control signal.

[0067] Step S220 : generating a control strategy based on the judgment result of the first control subject and the judgment result of the second control subject, so that the third control unit controls the actuator based on the control strategy.

[0068] The third control unit is an arbitration controller independent of the first control unit and the second control unit, and can specifically be an actuator controller, which is responsible for comprehensively evaluating the judgment results of the two control entities and selecting an effective control signal.

[0069] Control strategy, the third control unit triggers the preset execution logic based on the judgment results of the first control subject and the second control subject.

[0070] The first and second control units exchange operating status data in real time, independently analyzing their respective operating states and determining the principal judgment based on these states. These principal judgment results are transmitted via independent communication channels (CAN buses) to the third control unit for logical analysis. Ultimately, a control strategy is generated based on these logical analysis results and output to the actuator.

[0071] This application constructs a two-way mutual inspection mechanism so that the two control units monitor each other, effectively eliminating the blind spot of one-way monitoring; at the same time, by setting up a third control unit with independent power supply, a physically isolated arbitration execution layer is realized to ensure that the system decision-making ability can be maintained when any control unit fails completely.

[0072] In one embodiment, generating a control strategy based on the judgment result of the first control subject and the judgment result of the second control subject includes:

[0073] If the first control subject determines that the control unit is the first control unit and the second control subject determines that the control unit is the first control unit, the control strategy is to execute the first control signal output by the first control unit.

[0074] When the judgment results of the first control subject and the judgment results of the second control subject both point to the first control unit, that is, when the judgment results of the control subjects are the same and there is no disagreement, the third control unit receives the control signal output by the first control unit and executes the control signal output by the first control unit.

[0075] This application uses a synchronous dual judgment mechanism to establish a deterministic execution strategy when both control units are operating normally, avoiding the problem of signal jitter during the control switching process. When both control units confirm the validity of the first control unit through independent detection mechanisms, its control signal is directly executed, avoiding the invalid arbitration process of the redundant control unit in the absence of abnormalities.

[0076] In one embodiment, the method further includes: generating a control strategy based on the judgment result of the first control subject, the judgment result of the second control subject, and the operating state of the second control unit.

[0077] In the process of generating the control strategy, in addition to receiving the judgment results of the first control subject and the second control subject, the actual operating parameters of the first control unit and the second control unit are also obtained synchronously. When the judgment results of the first control subject and the second control subject both determine that the first control unit is the main control, further check whether the operating status of the second control unit is normal, and generate the control strategy in combination with the operating status of the second control unit. For example, when the judgment results of the first control subject and the second control subject both determine that the first control unit is the main control, the control strategy is to execute the first control signal output by the first control unit; when the judgment results of the first control subject and the second control subject both determine that the first control unit is the main control, determine whether the communication response delay of the second control unit exceeds the threshold and whether the power supply voltage exceeds the allowable range, and identify whether it is in an abnormal state. If the second control unit is in an abnormal state, the control strategy is to execute the first control signal output by the first control unit and output a fault prompt message.

[0078] In one embodiment, generating a control strategy based on the judgment result of the first control subject, the judgment result of the second control subject, and the operating state of the second control unit includes:

[0079] If the judgment result of the first control subject is the first control unit, the judgment result of the second control subject is the first control unit, and the operating state of the second control unit is abnormal, the control strategy is to execute the first control signal output by the first control unit and generate a first level fault prompt.

[0080] The first level fault prompt refers to an alarm signal in a preset fault classification system, which can be implemented through a fault code mapping table, for example, using binary coding to distinguish different fault levels. The first level fault prompt can be a medium level fault prompt.

[0081] Specifically, when both the first and second control units determine that the first control unit should be the control subject, the system continuously monitors the operating status of the second control unit to identify whether it is in an abnormal state. For example, a communication response delay exceeding a threshold or a power supply voltage exceeding an allowable range indicates an abnormal operating state. If an abnormality is detected in the second control unit but has not yet affected the control subject determination, the decision path for the first control unit to output the control signal is maintained, and a fault prompt matching the abnormality type is triggered.

[0082] In one embodiment, generating a control strategy based on the judgment result of the first control subject and the judgment result of the second control subject includes:

[0083] When the first control subject determines that the signal is the first control unit and the second control subject determines that the signal is the second control unit, performing a first end-to-end check on the first control signal;

[0084] If the first end-to-end verification passes, the control strategy is to execute the first control signal output by the first control unit and generate a second-level fault prompt;

[0085] If the first end-to-end verification fails, the control strategy is to execute the second control signal output by the second control unit and generate a third level fault prompt.

[0086] The first end-to-end check is a check of the first control signal, which refers to the verification of data integrity and logical consistency in the control signal transmission path. Specifically, it can be implemented by combining a CRC cyclic redundancy check with an instruction sequence number comparison to detect whether data loss or logical errors occur during signal transmission. The second-level fault prompt and the third-level fault prompt belong to a graded alarm mechanism, which can be implemented through a preset fault code mapping table. The second-level fault prompt can be a low-level fault prompt, and the third-level fault prompt can be a high-level fault prompt.

[0087] This application solves the control right conflict problem of the dual redundant system by introducing a step-by-step verification mechanism. When the two control units disagree on the judgment of the master control right, the output signal of the first control unit is verified end-to-end integrity. If the verification passes, it means that there is no abnormality in the control right judgment of the first control unit. At this time, the control subject of the first control unit is maintained and a low-level fault prompt is generated. If the verification fails, it is determined that there is an abnormality in the control subject judgment of the first control unit, and the second control unit is automatically switched to output the second control signal. At the same time, the fault level is increased to trigger a higher level of diagnostic measures, such as generating a high-level fault prompt.

[0088] By adding an end-to-end verification link, this application can accurately identify effective control signals in control subject dispute scenarios. Combined with the hierarchical alarm mechanism, it not only ensures the continuous operation of the system, but also realizes the accurate identification of fault types, significantly improving the system's fault tolerance.

[0089] In one embodiment, generating a control strategy based on the judgment result of the first control subject, the judgment result of the second control subject, and the operating state of the first control unit or the operating state of the second control unit includes:

[0090] When the first control subject determines that the first control unit is the first control unit, the second control subject determines that the second control unit is the second control unit, and the operating state of the second control unit is abnormal, performing a second end-to-end check on the first control signal output by the first control unit;

[0091] If the second end-to-end check passes, performing a third end-to-end check on the second control signal output by the second control unit;

[0092] If the third end-to-end verification passes, the control strategy is: execute the first control signal and generate a second-level fault prompt; if the third end-to-end verification fails, the control strategy is: execute the first control signal and generate a first-level fault prompt;

[0093] If the second end-to-end verification fails, a fourth end-to-end verification is performed on the second control signal output by the second control unit; if the fourth end-to-end verification passes, the control strategy is: execute the second control signal output by the second control unit and generate a third-level fault prompt; if the fourth end-to-end verification fails, the control strategy is: the actuator stops execution and generates a fourth-level fault prompt; among them, the levels of the second-level fault prompt, the first-level fault prompt, the third-level fault prompt, and the fourth-level fault prompt increase in sequence.

[0094] When the first control unit and the second control unit disagree on the ownership of the control subject and the second control unit is detected to be in an abnormal operating state, an end-to-end verification is first performed on the first control signal output by the first control unit pointed to by the control subject judgment result. If the first control signal passes the verification, the second control signal output by the second control unit is further verified for the second time, forming a dual verification mechanism for the main and backup signals. When the secondary verification of the second control signal passes, the generated control strategy is to execute the first control signal and generate a second-level fault prompt message; when the secondary verification of the second control signal fails, the generated control strategy is to execute the first control signal and generate a first-level fault prompt message. When the first control signal fails to pass the verification, the second control signal is independently verified: when the second control signal passes the end-to-end verification, the system switches to the second control and triggers the third-level fault prompt; if the second control signal verification also fails, the actuator is directly cut off and the fourth-level fault prompt is triggered.

[0095] This application solves the real-time problem by simultaneously receiving signals from the first and second control units through an actuator and performing arbitration within the actuator. At the same time, this application introduces a hierarchical verification mechanism to maintain system operation through multiple signal verifications in scenarios where the control subject makes conflicting judgments, while also utilizing dynamic fault grading to achieve precise emergency response.

[0096] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0097] Figure 4 This is a block diagram of a dual redundant control device according to an embodiment of the present application. The dual redundant control device is applied to a dual redundant chassis power system. The dual redundant chassis power system includes a first control unit, a second control unit, and a third control unit. Figure 4 As shown, a dual redundant control device includes:

[0098] a data receiving module 410 configured to receive a first control subject judgment result of the first control unit and a second control subject judgment result of the second control unit; the first control subject judgment result is determined based on the operating state of the first control unit and the operating state of the second control unit, and the second control subject judgment result is determined based on the operating state of the first control unit and the operating state of the second control unit;

[0099] The strategy generation module 420 is configured to generate a control strategy based on the judgment result of the first control subject and the judgment result of the second control subject, so that the actuator executes the control strategy.

[0100] It should be noted that the dual-redundant control device provided in the above-described embodiment and the dual-redundant control method provided in the above-described embodiment are based on the same concept. The specific manner in which the various modules and units perform their operations has been described in detail in the method embodiments and will not be repeated here. In actual applications, the dual-redundant control device provided in the above-described embodiment can, as needed, allocate the aforementioned functions to different functional modules. That is, the internal structure of the device can be divided into different functional modules to perform all or part of the aforementioned functions, and this is not a limitation herein.

[0101] See also Figure 5 , Figure 5 This is a schematic diagram of a dual-redundant chassis power system according to an embodiment of the present application. Figure 5 As shown, the dual redundant chassis power system includes:

[0102] The first control unit is configured to obtain an operating state of the first control unit and an operating state of the second control unit, and generate a first control subject judgment result according to the operating state of the first control unit and the operating state of the second control unit;

[0103] A second control unit is configured to obtain an operating state of the first control unit and an operating state of the second control unit, and generate a second control subject judgment result according to the operating state of the first control unit and the operating state of the second control unit;

[0104] The third control unit is used to receive the first control subject judgment result of the first control unit and the second control subject judgment result of the second control unit, and generate a control strategy based on the first control subject judgment result and the second control subject judgment result so that the actuator executes the control strategy.

[0105] In one embodiment, the dual-redundant chassis power system further includes: a first power chip, a second power chip, a first CAN chip, a second CAN chip, and a CAN bus;

[0106] The first power chip is used to power the first control unit and the first CAN chip; the second power chip is used to power the second control unit and the second CAN chip; the first CAN chip communicates with the first control unit; the second CAN chip communicates with the second control unit; the first control unit exchanges data with the third control unit through the CAN bus; the second control unit exchanges data with the third control unit through the CAN bus.

[0107] It should be noted that the dual-redundant chassis power system provided in the above-mentioned embodiments and the dual-redundant control method / device provided in the above-mentioned embodiments share the same concept. The specific manner in which each module and unit performs operations has been described in detail in the method embodiments and will not be repeated here. In actual applications, the dual-redundant chassis power system provided in the above-mentioned embodiments can, as needed, allocate the aforementioned functions to different functional modules. This means that the internal structure of the device can be divided into different functional modules to perform all or part of the functions described above. This is not a limitation herein.

[0108] An embodiment of the present application also provides a vehicle, comprising: the aforementioned chassis power system.

[0109] An embodiment of the present application also provides a device, comprising: one or more processors; and a memory for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the memory implements the dual-redundancy control method in the above embodiment.

[0110] The embodiments of the present application further provide one or more machine-readable media having instructions stored thereon, which, when executed by one or more processors, enable the processors to execute the dual-redundancy control method in the above embodiments.

[0111] Figure 6 FIG1 shows a schematic diagram of a computer system structure suitable for implementing a memory according to an embodiment of the present invention. It should be noted that Figure 6 The computer system of the memory shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present invention.

[0112] like Figure 6As shown, the computer system 600 includes a central processing unit (CPU) 601, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 602 or the program loaded from the storage portion into the random access memory (RAM) 603, such as executing the method in the above embodiment. Various programs and data required for system operation are also stored in the RAM. The CPU 601, ROM 602, and RAM 603 are connected to each other via a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.

[0113] The following components are connected to the I / O interface 605: an input section 606 including a keyboard, a mouse, and the like; an output section 607 including devices such as a cathode ray tube (CRT), a liquid crystal display (LCD), and a speaker; a storage section 608 including a hard disk; and a communication section 609 including a network interface card such as a LAN (Local Area Network) card or a modem. The communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the I / O interface 605 as needed. Removable media 611, such as a magnetic disk, an optical disk, a magneto-optical disk, or a semiconductor memory, is installed in the drive 610 as needed, so that computer programs read therefrom can be installed into the storage section 608 as needed.

[0114] In particular, according to an embodiment of the present invention, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present invention includes a computer program product comprising a computer program carried on a computer-readable medium, the computer program including a computer program for executing the aforementioned dual-redundancy control method. In such an embodiment, the computer program can be downloaded and installed from a network via a communication component and / or installed from removable media 611. When the computer program is executed by the central processing unit (CPU) 601, the various functions defined in the system of the present invention are performed.

[0115] It should be noted that the computer-readable medium shown in the embodiments of the present invention may be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. The computer-readable storage medium may, for example, be an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or component, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM) 603, a read-only memory (ROM) 602, an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present invention, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries a computer-readable computer program. Such a propagated data signal may take a variety of forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination thereof. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device. A computer program embodied on a computer-readable medium may be transmitted using any suitable medium, including but not limited to wireless, wired, or any suitable combination thereof.

[0116] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions and operations of the systems, methods and computer program products according to various embodiments of the present invention. Each box in the flowchart or block diagram can represent a module, program segment, or part of the code, and the above-mentioned module, program segment, or part of the code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the boxes can also occur in an order different from that marked in the accompanying drawings. For example, two boxes shown in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of boxes in the block diagram or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or can be implemented using a combination of dedicated hardware and computer instructions.

[0117] The units involved in the embodiments of the present invention may be implemented in software or hardware, and the units described may also be provided in a processor. In some cases, the names of these units do not limit the units themselves.

[0118] Another aspect of the present invention provides a computer-readable storage medium having a computer program stored thereon. When executed by a computer processor, the computer program causes the computer to perform the aforementioned dual-redundancy control method. The computer-readable storage medium may be included in the memory described in the above embodiments, or may exist independently and not be incorporated into the memory.

[0119] Another aspect of the present invention provides a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to implement the dual-redundancy control method provided in each of the above embodiments.

[0120] The above embodiments are merely illustrative of the principles and effects of this application and are not intended to limit this application. Anyone skilled in the art may modify or alter the above embodiments without departing from the spirit and scope of this application. Therefore, any equivalent modifications or alterations accomplished by a person of ordinary skill in the art without departing from the spirit and technical concepts disclosed in this application shall be covered by the claims of this application.

Claims

1. A dual redundant control method, characterized in that: Applied to a chassis power system, the chassis power system includes a first control unit, a second control unit, and a third control unit; the dual-redundancy control method includes: receiving a first control subject judgment result of the first control unit and a second control subject judgment result of the second control unit; the first control subject judgment result is determined according to the operating state of the second control unit, and the second control subject judgment result is determined according to the operating state of the first control unit; A control strategy is generated based on the first control subject judgment result and the second control subject judgment result, so that the third control unit controls the actuator based on the control strategy.

2. The dual redundant control method according to claim 1, characterized in that: The generating of the control strategy based on the judgment result of the first control subject and the judgment result of the second control subject includes: If the first control subject determines that the control unit is the first control unit and the second control subject determines that the control unit is the first control unit, the control strategy is to execute the first control signal output by the first control unit.

3. The dual redundant control method according to claim 1, characterized in that: The method further comprises: A control strategy is generated based on the judgment result of the first control subject, the judgment result of the second control subject, and the operating state of the second control unit.

4. The dual redundant control method according to claim 3, characterized in that: The generating of the control strategy based on the judgment result of the first control subject, the judgment result of the second control subject and the operating state of the second control unit includes: If the judgment result of the first control subject is the first control unit, the judgment result of the second control subject is the first control unit, and the operating state of the second control unit is an abnormal state, the control strategy is to execute the first control signal output by the first control unit and generate a first level fault prompt.

5. The dual redundant control method according to claim 1, characterized in that: The generating of the control strategy based on the judgment result of the first control subject and the judgment result of the second control subject includes: When the first control subject determines that the signal is the first control unit and the second control subject determines that the signal is the second control unit, performing a first end-to-end check on the first control signal; If the first end-to-end verification passes, the control strategy is to execute the first control signal output by the first control unit and generate a second-level fault prompt; If the first end-to-end verification fails, the control strategy is to execute the second control signal output by the second control unit and generate a third level fault prompt.

6. The dual redundant control method according to claim 3, characterized in that: The generating of the control strategy based on the judgment result of the first control subject, the judgment result of the second control subject and the operating state of the second control unit includes: When the first control subject determines that the first control unit is the first control unit, the second control subject determines that the second control unit is the second control unit, and the operating state of the second control unit is abnormal, performing a second end-to-end check on the first control signal output by the first control unit; If the second end-to-end check passes, performing a third end-to-end check on the second control signal output by the second control unit; If the third end-to-end verification passes, the control strategy is: execute the first control signal and generate a second-level fault prompt; if the third end-to-end verification fails, the control strategy is: execute the first control signal and generate a first-level fault prompt; If the second end-to-end verification fails, a fourth end-to-end verification is performed on the second control signal output by the second control unit; if the fourth end-to-end verification passes, the control strategy is: execute the second control signal output by the second control unit and generate a third-level fault prompt; if the fourth end-to-end verification fails, the control strategy is: the actuator stops execution and generates a fourth-level fault prompt; wherein, the levels of the second-level fault prompt, the first-level fault prompt, the third-level fault prompt, and the fourth-level fault prompt increase in sequence.

7. A dual redundant control device, characterized in that: Applied to a chassis power system, the chassis power system includes a first control unit, a second control unit, and a third control unit; the dual redundant control device includes: a data receiving module, configured to receive a first control subject judgment result of the first control unit and a second control subject judgment result of the second control unit; the first control subject judgment result is determined according to an operating state of the second control unit, and the second control subject judgment result is determined according to an operating state of the first control unit; A strategy generation module is used to generate a control strategy based on the judgment result of the first control subject and the judgment result of the second control subject, so that the actuator executes the control strategy.

8. A chassis power system, characterized in that: The chassis power system includes: The first control unit is configured to obtain an operating state of the second control unit and generate a first control subject judgment result according to the operating state of the second control unit; The second control unit is used to obtain the operating status of the first control unit and generate a second control subject judgment result according to the operating status of the first control unit; The third control unit is used to receive the first control subject judgment result of the first control unit and the second control subject judgment result of the second control unit, and generate a control strategy based on the first control subject judgment result and the second control subject judgment result so that the actuator executes the control strategy.

9. The chassis power system according to claim 8, characterized in that: The chassis power system further includes: a first power chip, a second power chip, a first CAN chip, a second CAN chip, and a CAN bus; The first power chip is used to power the first control unit and the first CAN chip; the second power chip is used to power the second control unit and the second CAN chip; the first CAN chip communicates with the first control unit; the second CAN chip communicates with the second control unit; the first control unit exchanges data with the third control unit through the CAN bus; the second control unit exchanges data with the third control unit through the CAN bus.

10. A vehicle, characterized in that: include: The chassis power system as claimed in claim 8.