Method for automatically evaluating the correct functionality of a computing system configured as a

By assigning characteristics and required attributes to hardware entities and computer programs on the vehicle computing platform and automatically evaluating their matching, the problems of resource contention and poor performance in the computing system are solved, and flexible evaluation and efficient operation of the computing system are achieved.

CN120712554APending Publication Date: 2025-09-26VOLKSWAGEN AG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380095149.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-04-05
Filing Date
2023-07-28
Publication Date
2025-09-26

AI Technical Summary

Technical Problem

The computing systems in existing vehicles based on centralized computing architectures find it difficult to efficiently evaluate whether the hardware requirements of multiple computer programs for the computing platform match, leading to resource contention and poor performance.

Method used

By assigning characteristic attributes and requirement attributes to hardware entities and computer programs on the computing platform, it automatically evaluates whether these attributes match the technical characteristics of the computing platform to ensure that the computing system can meet the hardware requirements.

Benefits of technology

It enables flexible evaluation of computing systems, ensures that the computing platform can meet hardware requirements, improves the scalability, flexibility and efficiency of computing systems, and reduces resource contention and poor performance problems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120712554A_ABST
    Figure CN120712554A_ABST
Patent Text Reader

Abstract

There is provided a method of automatically evaluating correct functionality of a computing system configured as a centralized in-vehicle computing system for a vehicle (800) to centrally control a variety of different functionality of the vehicle (800), the computing system comprising: a computing platform (700) having a plurality of hardware entities; and a plurality of different computer programs (700) configured for execution individually or concurrently on the computing platform; and the method comprising: assigning or accessing a set of associated one or more individual characteristic attributes (1005) for one or more of the hardware entities, the characteristic attributes individually or jointly representing one or more technical characteristics of the respective hardware entity; assigning or accessing a set of associated one or more demand attributes (1010) individually for one or more of the computer programs or jointly for a subset comprising two or more of the computer programs, the demand attributes independently or jointly represent one or more specific hardware requirements respectively required for correct execution of the computer program or a subset of computer programs on the computing platform (700); and comparing the respective individual hardware requirements of the one or more computer programs or the combined hardware requirements of a subset of the computer programs to the technical characteristics of the computing system defined by the characteristic attributes (1005), respectively, to determine an evaluation result (1365) indicating whether the computing system is able to meet the respective hardware requirements.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The present invention relates to the field of vehicle electronics, such as, but not limited to, automotive electronics. Specifically, the present invention relates to a method for automatically evaluating the correct functionality of a computing system configured as a centralized onboard computing system for a vehicle, such as an automobile, for centrally controlling various functions of the vehicle. The present invention also relates to an evaluation system for evaluating the correct functionality of such a computing system, a computer program for executing the method or a computer program product for executing the method, and a vehicle including such an evaluation system for evaluating such a computing system.

[0002] Modern vehicles, such as automobiles, typically include a number of different electronic components, including in particular so-called electronic control units (ECUs), which are interconnected using one or more communication links or entire networks, such as bus systems, for example the well-known CAN or LIN types. Furthermore, Ethernet-based networks are becoming increasingly relevant in this context. It should be noted that, while the acronym "ECU" is often also used in the automotive technology field to specifically refer to an engine control unit, this acronym is used herein in a broader sense to refer to any electronic controller or control unit for a vehicle, with the engine control unit being only one possible example of such a control unit.

[0003] In reality, many ECUs are embedded systems, comprising hardware such as a processing platform and associated software running on the processing platform. Thus, such ECUs form an embedded system, and when multiple ECUs are interconnected via a communications network, such a network can be designated as a distributed embedded system (network). While this "embedded" setup is particularly useful in its ability to provide real-time processing and optimally match a given ECU's software to its corresponding processing platform, it is often difficult to expand or scale such embedded systems or add new functionality.

[0004] The alternative approach as presented in this article is based on the idea that instead of or using dedicated software running on dedicated hardware to provide certain specific functionalities, i.e. the functions of a specific ECU, a central computing architecture is used, in which the different desired functionalities are provided by multiple different computer programs, in particular applications, running on the same CCU, which is therefore a shared computing resource.

[0005] In particular, as described above, this CCU-based approach allows for more flexibility than traditional decentralized approaches in terms of expanding, scaling, or reducing the functionality of the vehicle. However, this approach presents other challenges, such as the need to intelligently co-design and / or manage software and hardware resources to avoid or limit drawbacks such as resource contention or poor performance.

[0006] Therefore, the technical problem to be solved by the present invention is to provide an improved method for evaluating a CCU, which includes a computing platform and a plurality of computer programs that use the computing platform as a shared computing resource, in order to evaluate the correct functioning of the CCU. In particular, such an evaluation may include determining whether the overall computing requirements of the computer programs exceed the capabilities of the computing platform, or the extent to which they exceed the capabilities of the computing platform.

[0007] A first aspect of the present solution relates to a method of automatically evaluating the proper functionality of a computing system configured as a centralized onboard computing system for a vehicle to centrally control various functions of the vehicle.

[0008] The computing system includes:

[0009] a computing platform having multiple hardware entities, and

[0010] A plurality of different computer programs are configured for execution individually or concurrently on the computing platform to enable one or more of the described functions of the vehicle.

[0011] The method includes:

[0012] (i) assigning or accessing, for one or more of the hardware entities, a set of one or more associated individual characteristic attributes, said characteristic attributes individually or jointly representing one or more technical characteristics of the respective hardware entity;

[0013] (ii) allocating or accessing, for one or more of the computer programs, individually or jointly for a subset of two or more of the computer programs, a set of associated one or more requirement attributes, the requirement attributes individually or jointly representing one or more specific hardware requirements required for the computer program or subset of computer programs, respectively, to execute correctly on a computing platform; and

[0014] (iii) comparing the corresponding individual hardware requirements of the one or more computer programs or the combined hardware requirements of a subset of the computer programs with the technical characteristics of the computing platform defined by the characteristic attributes to determine an evaluation result indicating whether the computing system, or more specifically, its computing platform, is capable of meeting the corresponding hardware requirements.

[0015] Thus, the method of the first aspect provides an evaluation of a computing system based on matching, i.e., comparing, specific hardware requirements imposed on a computing platform by various computer programs, either individually or in combination, with the technical properties of the computing platform's hardware entities. If the match results in the technical properties of the hardware entities being found to be sufficient to meet the hardware requirements, the evaluation result indicates this; otherwise, it indicates a mismatch and / or the degree of mismatch. Thus, the evaluation determines whether the hardware requirements (i.e., the requirements of the computer programs) meet or exceed the capabilities of the computing system's hardware.

[0016] In particular, the method allows not only such an evaluation to be performed during the runtime of a program on a computing platform, but also, or alternatively, allows for a prior evaluation, in particular a virtual evaluation, based on a purely virtual model, once the hardware entities and their technical characteristics, as well as the computer programs and their requirements on the hardware, are known. Furthermore, potential mismatches can be detected even if no problem is detected at a given time during the execution of one or more computer programs. This is because problems may only occur when several computer programs are about to run simultaneously or if they start out out of sync.

[0017] As used herein, the term "hardware entity" of a computing platform is an entity, such as a unit or module of a computing platform, which includes hardware, such as active or passive electronic or optical devices, such as circuits. For example, a hardware entity may include a hardware circuit that includes a custom VLSI circuit or gate array, an off-the-shelf semiconductor, such as a basic logic chip, a transistor, or other discrete components. A hardware entity may also be implemented in a programmable hardware device, such as a field programmable gate array, programmable array logic, a programmable logic device, or the like. A hardware entity may also optionally include software, such as firmware. Without limitation, a processor, a circuit board (e.g., a printed circuit board, PCB), a power supply module, an RF circuit, a communication interface device, a storage medium, a sensor, an actuator, a camera, a cable, a cooling device, and the housing of the computing platform as a whole or part thereof are examples of hardware entities.

[0018] As used herein, the term "access" may particularly refer to reading data stored in a memory or receiving data provided by another entity, such as a data stream provided by an entity external to the computing platform, eg, an external computer.

[0019] As used herein, the term "centrally controlling various functions" refers to a control scheme in which a centralized non-embedded computing system is used to perform control. The functions of the centralized non-embedded computing system can be flexibly adapted during runtime by different computer programs, which can be selectively executed alone or concurrently with one or more other computer programs on the computing system, depending on the one or more functions of the vehicle that the computing system currently needs to perform or control. Therefore, this computing system differs from a traditional distributed embedded system network in a vehicle, in which control functions are primarily divided across a set of dedicated electronic control units (ECUs), each of which is an embedded system with fixed, dedicated, limited functionality within a larger mechanical or electronic subsystem of the vehicle, such as an infotainment or lighting system or a driver assistance system.

[0020] The terms "first," "second," "third," and the like in the description and claims are used to distinguish between similar elements and not necessarily to describe a sequential or chronological order. It is understood that the terms so used are interchangeable under appropriate circumstances, and that the embodiments of the invention described herein are capable of operation in sequences other than those described or illustrated herein.

[0021] Unless the context requires otherwise, where the terms "comprises" or "includes" or variations thereof are used in this specification and claims, they do not exclude other elements or steps and are to be interpreted in an open, inclusive sense as "including but not limited to".

[0022] Where an indefinite or definite article is used when referring to a singular noun eg "a" or "an", "the", this includes a plural of that noun unless something else is specifically stated.

[0023] In the description, the appearances of the phrases "in some embodiments," "in one embodiment," or "in an embodiment," if any, are not necessarily all referring to the same embodiment. Furthermore, the particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0024] Furthermore, unless expressly stated otherwise, "or" refers to an inclusive or and not an exclusive or. For example, a condition A or B is satisfied by any one of the following: A is true (or exists) and B is false (or does not exist), A is false (or does not exist) and B is true (or exists), and both A and B are true (or exist).

[0025] In the following, preferred embodiments of the method are described, which can be arbitrarily combined with one another or with other aspects of the invention, unless such a combination is explicitly excluded or technically impossible.

[0026] According to some embodiments, a computing system includes a central computing unit (CCU) configured as a centralized onboard computing system for a vehicle to centrally control various functions of the vehicle, and the method is applied to automatically evaluate the correct functionality of the CCU. The CCU includes:

[0027] (i) a distributed computing system DCS comprising a plurality of co-located (e.g., in the same housing, such as a closed housing or an open housing, such as a rack) autonomous computing entities CE, each CE having its own separate memory, wherein the CEs are configured to communicate between each other by message passing via one or more communication networks to coordinate among themselves the distribution of computing tasks to be performed by the DCS as a whole;

[0028] (ii) a communication switch comprising a plurality of mutually independent switching fabrics (i.e., at least functionally independent switching fabrics), each switching fabric being configured to variably connect a subset of CEs of the DCS or each CE to one or more of a plurality of interfaces for exchanging information thereon with communication nodes external to the vehicle's computing system. Such nodes may in particular be or include network endpoints, such as actuators or sensors, or intermediate network nodes, such as hubs, for connecting a plurality of other network nodes. The communication switch may in particular include, but is not limited to, one or more PCI Express (PCIe) switches and / or Compute Express Link (CXL) as switching fabrics; and

[0029] (iii) A power supply system comprising a plurality of power supply subsystems for simultaneous operation, each power supply subsystem being capable of supplying power to the DCS and to at least two, in particular all, switching fabrics individually and independently of one another.

[0030] As used herein, the term "switch fabric" refers particularly to hardware used to variably connect multiple different nodes of a network, such as nodes of a computer network, to exchange data therebetween.

[0031] The term "switch" or "switch" as used herein (e.g., in the terms "switch fabric" and "communications switch") generally refers to variably connecting different nodes of a network to exchange data therebetween, and is not limited to any particular connection technology, such as circuit switching or packet switching, or any particular communication technology or protocol, such as Ethernet, PCIe, etc., unless otherwise expressly specified in a given context.

[0032] As used herein, the term "power supply" refers in particular to the delivery of electrical power to an entity to be powered, and may optionally also include first generating the electrical power and / or converting it to a suitable kind or level of power, for example by DC / DC, AC / DC or DC / AC conversion, or time-dependent conversion of the power signal (signal shaping).

[0033] As used herein, the term "computing entity," or its abbreviation "CE," refers to an autonomous computing unit capable of performing computing tasks on its own and, to that end, including at least one processor and at least one associated memory. In particular, each CE can be embodied separately from all other CEs. For example, it can be embodied in one or more circuits, such as in an integrated circuit (e.g., as a system-on-chip (SOC), system-in-package (SIP), multi-chip module (MCM), or chiplet) or in a chipset.

[0034] Specifically, the communication network used for communication between CEs can be a high-speed communication network, such as a PCI Express or Ethernet type, to coordinate the distribution of computing tasks to be executed by the DCS as a whole. In particular, in the case of multiple communication networks, these networks can be coupled in such a manner that messages can be transmitted between a sending CE and a receiving CE via communication links involving two or more of the multiple networks. For example, a given message can be sent from a sending CE to a gateway in PCI Express format via one or more first communication paths in a PCI Express network. The gateway then converts the message to Ethernet format and forwards the converted message to a receiving CE via one or more second communication paths in the Ethernet network. A collection of individual CEs of a DCS can be specifically configured to perform parallel task processing, such that the CEs in the collection simultaneously execute a collection of similar or different computing tasks, for example, such that each CE individually executes a proper subset of the collection of computing tasks to be executed by the DCS as a whole, where the computing tasks executed by different CEs can be different.

[0035] In particular, as further defined above, each of the CE, communication switch, switch fabric, and power supply system may be considered a "hardware entity."

[0036] A CCU according to the present scheme may provide several advantages, including one or more of the following:

[0037] (i) Easy scalability of computing power (additional CEs can be added or CEs can be removed and computing tasks can be optimally distributed among the available CEs).

[0038] (ii) High efficiency in executing many different kinds of computing tasks. For example, one or more CEs can be specifically adapted to perform certain specific tasks, such as machine learning, image rendering, real-time processing, general-purpose computing, etc., all with options for sequential as well as parallel processing, so that computing tasks can be selectively executed by one or more appropriately adapted dedicated CEs within the DCS. Furthermore, the total amount of computing power allocated by the DCS to specific computing tasks can be variably adapted "on the fly";

[0039] (iii) High flexibility in performing many different, even highly variable, computing tasks. In the conventional "world" of automotive ECUs, each ECU is typically designed to fulfill a small and limited number of specified, fixed, and specialized functions, implemented by the underlying ECU hardware and typically proprietary software written specifically for that hardware. Both the hardware and software are intended to remain virtually unchanged until the vehicle reaches its end-of-life state—perhaps with the exception of some minor software updates related to bug fixes or minor functionality expansions. The present solution overcomes these limitations and enables not only the flexible distribution of computing tasks among a group of CEs, but also the expansion or change of computing tasks, and therefore the functionality that the CCU can support. In particular, the software defining such functionality can be easily updated or upgraded (e.g., "over-the-air" or OTA) to implement such expansions or changes, and even new software can be easily added. Such changes at the software level can even be performed very frequently, as needed. Furthermore, even the underlying computing hardware can be easily adapted to support a changed or new set of functionality by adding, replacing, or removing individual CEs or groups of CEs.

[0040] (iv) High performance and power efficiency: Since the communication links between co-located CEs can be kept short, high-speed communication between them can be achieved with less power loss and higher signal quality. Therefore, high performance, power efficiency, and reliability of the DCS as a whole can be achieved.

[0041] (v) High reliability due to the flexible allocation of computing tasks to the selected CEs and highly flexible redundancy of redundant power supply.

[0042] In some embodiments, at least one of the computer programs, such as an application-level computer program, includes two or more program modules designed to be reused by multiple of the computer programs. Each program module has or is assigned one or more individual module-level requirement attributes, which, individually or in combination, represent one or more specific hardware requirements required for the corresponding program module to execute correctly on a computing platform. Assigning a set of the relevant one or more individual requirement attributes to each of these computer programs includes deriving its corresponding set of individual requirement attributes at least in part by combining, such as accumulating, the corresponding individual module-level requirement attributes assigned to its corresponding program module. Thus, the requirement attributes of one or more computer programs can be automatically derived "bottom-up" based at least in part on the requirement attributes of the modules incorporated into the computer program. This modular approach enables efficient and flexible determination of the requirement attributes of a computer program that includes such reusable program modules.

[0043] In some embodiments, the computing system includes two or more of the computer programs, and at least a subset of the reusable program modules is included as an element in a library of stock software modules, such that they can be individually integrated or accessed by different computer programs in the computer programs via the library. Assessing the correct functionality of the computing system includes performing an assessment based on the two or more computer programs, each of which includes the subset of reusable program modules integrated into or accessed by one or more of the computer programs. This library approach can be used specifically at the compiler and / or linker level, i.e., the relevant software modules are retrieved from the library in the object code and incorporated into the executable version of the computer program in question during its compilation, for example, by linking. However, it can alternatively be used at the interpreter level, i.e., if the computer program is available in some source code and is only interpreted, i.e., converted into executable code, during runtime. In the latter case, the software modules can also be specifically available in the source code so that they can be interpreted along with the rest of the computer program in question. In principle, even a combination of the two options (compiler / linker and interpreter) is possible. Thus, the efficiency of a software program may be improved in terms of one or more of reusability, code size, and reliability.

[0044] In some embodiments, defining the technical characteristics of a computing system by a set of characteristic attributes of one or more hardware entities includes defining one or more abstract hardware entities, each of which virtually represents a set of different possible real instantiations of such hardware entity by a corresponding set of individual characteristic attributes of each abstract hardware entity. Thus, the abstract hardware entity can be considered as a kind of abstract "layer" for hiding the working details of the subsystem from other hardware or software entities of the computing system, i.e., the differences between different individual instantiations of the hardware entity, such as hardware entities from different vendors. This approach can be particularly useful for enabling or supporting multi-source scenarios (e.g., second-source scenarios), in which a system integrator has different vendors for the hardware entity, all of which then need to meet the same or at least substantially similar specifications for the abstract hardware entity, in order to enable the multi-source scenario with minimal additional burden on the system integrator.

[0045] In some embodiments, at least one of the characteristic attributes is individually encoded by a corresponding unique, computer-readable characteristic identifier. When comparing the hardware requirements of one or more computer programs, or a combination of subsets of computer programs, such as the cumulative hardware requirements (particularly for their concurrent execution), with the technical attributes of a computing system, at least one characteristic identifier is decoded to determine the characteristic attribute encoded by the characteristic identifier as the basis for comparison. Thus, encoding with the identifier is used to represent the characteristic attribute within the computing system. Such encoding allows for efficient representation of the characteristic attribute, requiring minimal storage space and / or bandwidth for communication within the computing system, for example, and requiring relatively low processing effort.

[0046] In some embodiments, at least one of the requirement attributes is separately encoded by a corresponding unique and computer-readable requirement identifier. When comparing the individual hardware requirements of one or more computer programs or a combination of subsets of computer programs, such as the cumulative hardware requirements, with the technical attributes of the computing system, at least one requirement identifier is decoded to determine the requirement attribute encoded by the requirement identifier as the basis for the comparison. Thus, an encoding with a requirement identifier is used to represent the hardware requirements within the computing system. Such an encoding can achieve an efficient representation of the hardware requirements, which requires minimal storage space for storage and / or minimal bandwidth for communication, such as within the computing system, and requires only relatively low processing effort. In addition, if both the characteristic attributes and the hardware requirements are represented by corresponding identifiers, the comparison can even be performed in full or in part at the encoding level, which can further improve efficiency because only the identifiers need to be processed instead of more complex descriptions or parameters of the relevant hardware and software components of the computing system.

[0047] In some embodiments, a string representation comprising two or more concatenated identifiers is used to represent a particular combination of selected identifiers as a basis for comparison. Such a string representation. For example, the various included concatenated identifiers can be separated within the string by some separation symbol, such as a dot, a comma, or a semicolon. The concatenated identifiers can be feature identifiers or requirement identifiers, or there can even be a mixture of the two. The same applies to the following embodiments when the term "identifier" is used without explicitly indicating which type of identifier it is. Therefore, using a string representation, a single string, which is typically just a one-dimensional data structure, can be used to represent a combination of identifiers in an efficient manner.

[0048] In some embodiments, cryptographic techniques are used to protect at least a subset of the one or more identifiers from unauthorized access. In particular, as described above, such protection can be applied to strings that represent a combination of multiple identifiers by concatenation. Protecting identifiers according to these embodiments helps directly improve the integrity and security of the computing system and its operation, and indirectly improves the integrity and security of the operation of relevant functions of the vehicle. For example, if the computing system is configured to control safety-related functions of the vehicle, such as steering, braking, front or backlighting, key sensors, etc., protecting the identifiers can help prevent unauthorized interference with the evaluation process and, therefore, can increase the safety of the vehicle.

[0049] In some embodiments, obfuscation techniques are used to protect at least a subset of one or more identifiers from unauthorized access by applying a time-varying association between at least one specific identifier, on the one hand, and the corresponding information temporarily encoded thereby, on the other hand. Thus, rather than using (only) fixed, i.e., time-constant, associations, time-varying associations are introduced to further improve the achievable security level of the evaluation method, and thus even the achievable security level of the evaluated computing system itself. Obfuscation can particularly be combined with the aforementioned encryption techniques to achieve an even higher combined security level.

[0050] In some embodiments, at least a subset of the attributes, i.e., characteristic attributes and / or requirement attributes, are organized in a hierarchical order, which is reflected in the corresponding hierarchical code used to encode the set of relevant identifiers. For example, a hierarchical code for a specific hardware requirement for processing power can be defined by a code that reflects the required processor type (such as a general-purpose CPU, graphics processor, cryptographic engine, or neural engine) at a higher level of the hierarchy (e.g., the "category" level) and the minimum processing power to be provided by such a processor at a lower level (e.g., the "subclass" level). Using this hierarchical approach can provide very fast searching and access to key information stored by the hierarchical code, and thus can help enhance the performance level of the evaluation method. In particular, this can support the goal of more efficient selection of relevant attributes by first selecting only relevant categories and then only considering subcategories of the relevant category, while ignoring attributes in other categories.

[0051] In some embodiments, the method further comprises: pre-selecting a relevant subset of the characteristic attributes of the processing platform based on the set of requirement attributes, and performing the comparison strictly based on the pre-selected characteristic attributes with respect to the characteristic attributes considered. These embodiments may also help to improve the efficiency of the method, since the amount of characteristic attributes that need to be considered during the evaluation process may be reduced. Specifically, for a given set of hardware capabilities of a computing system, such as its processing platform, such computer programs may be selected based on the said subset of the characteristic attributes of the processing platform, the hardware requirements of which may be met by the computing system. This may be particularly useful in scenarios where, for a given functionality, multiple computer programs or program modules are available to provide such functionality, but their hardware requirements differ, for example due to different performance characteristics.

[0052] In some embodiments, the collection of one or more computer programs (as a whole) or at least one of them can be reconfigured by adding, removing, enabling, disabling, or modifying one or more computer programs or computer program modules, respectively. The method then further comprises: (i) determining an actual or planned reconfiguration of the collection of one or more computer programs or at least one of the computer programs themselves, and (ii) executing, in particular repeating, the method to determine, in particular also output information indicating, based on the results of the relevant comparison, whether the respective individual or combined hardware requirements of the collection of one or more computer programs or at least one of the computer programs themselves can be satisfied by the technical properties of the computing system when or if a corresponding reconfiguration occurs, including a corresponding update of the relevant one or more requirement attributes. Therefore, the collection of computer programs need not be time-invariant but can evolve over time through reconfiguration. Therefore, according to these embodiments, the method can be adapted to reflect such reconfigurations and provide relevant updated evaluation results taking into account the reconfigurations. This can increase the overall flexibility of the computer system, and in particular the overall flexibility of the method of evaluating a computer system according to the present invention.

[0053] In some embodiments, the computing system can be reconfigured by, for example, adding, removing, enabling, disabling, or modifying one or more of its hardware entities, respectively, in a plug-and-play manner. The method further includes: (i) determining an actual or planned reconfiguration of the computing system; and (ii) executing, in particular repeating, the method to determine, in particular also output information indicating, based on the results of the relevant comparison, whether, when or if a corresponding reconfiguration occurs, the corresponding individual or combined hardware requirements of one or more computer programs can be satisfied by the technical characteristics of the computing system, including corresponding updates to the relevant one or more characteristic attributes. Therefore, the set of hardware entities, such as hardware modules, need not be time-invariant but can evolve over time through reconfiguration. Therefore, according to these embodiments, the method can be adapted to reflect such reconfigurations and provide relevant updated evaluation results taking into account the reconfigurations. Thus, the overall flexibility of the computer system, and in particular the overall flexibility of the method for evaluating a computer system according to the present invention, can be increased. Specifically, the reconfigurability of the hardware entities can be supplemented by the reconfigurability of the computer programs discussed above to achieve maximum flexibility for the computing system and its evaluation by the present method.

[0054] In some embodiments, the method further comprises, in response to determining that, based on the results of the relevant comparison, the respective individual or combined hardware requirements of the one or more computer programs cannot be satisfied by the technical characteristics of the computing system, performing one or more of the following actions:

[0055] - Activate warning signal;

[0056] - disabling one or more functions of the computing system or its overall operation;

[0057] - interrupting or otherwise disabling execution of at least one of the computer programs on the computing system;

[0058] - outputting further information indicating characteristic attributes or other relevant hardware requirements that cannot be met based on the results of the relevant comparison;

[0059] - outputting further information indicating the extent to which characteristic attributes or other relevant hardware requirements cannot be met according to the results of the relevant comparison;

[0060] - blocking the updating of one or more computer programs or one or more computer program modules contained therein;

[0061] - transmitting the comparison results to a remotely accessible computing environment or data storage;

[0062] - requesting or proposing to replace one or more hardware entities of the computing system or to add one or more other or additional hardware entities to the computing system so that the computing system can meet the corresponding individual or combined hardware requirements;

[0063] - for a defined time interval, estimating the probability that within said time interval it will become necessary to replace or add one or more hardware entities of the computing system to meet the expected individual or combined hardware requirements, based on a trend analysis of previously occurring computer program update and / or upgrade cycles.

[0064] In this way, a negative result of the evaluation (ie, a result indicating that the technical characteristics of the computing system are insufficient) may be used to automatically trigger, for example, any one or more of the above-mentioned warning signals or other countermeasures.

[0065] In some embodiments, the comparison includes taking into account predefined margin requirements for the computing system as additional hardware requirements for determining whether the corresponding hardware requirements of the computer program or the combined hardware requirements of two or more computer programs can be met by the technical properties of the computing system, respectively. Thus, the evaluation method is "sharpened" because, in some cases, a negative evaluation result may be determined even if all hardware requirements except the margin requirements can actually be met. This ensures that a positive evaluation result is only achieved when there is sufficient margin. However, the margin requirements can also be defined so that a maximum margin is defined (for example, in addition to the minimum margin). Thus, taking into account potential future software reconfigurations, such as changes such as extensions or modifications on the computer program side, the evaluation can take into account the need for reserves and the need to keep the margin low enough to avoid unnecessary over-sizing or over-allocation of resources on the hardware side.

[0066] In some embodiments, the method is performed using at least one of: (i) an operating system (i.e., OS software, such as Linux) running on the computing system itself; or (ii) a processing device or environment of the computing system other than the computing system. For example, such an additional processing device or environment may be a specific computer, such as a specific server in a backend or processing platform, local or distributed, such as in a cloud computing environment, that is only temporarily allocated to perform the method or portions thereof. This allows for a high degree of flexibility without burdening the computer system itself with the execution of the method. However, in the first case (i), the advantage is the high degree of self-reliance of the computer system.

[0067] In some embodiments, at least one of the computer programs involved in comparing the respective individual hardware requirements of one or more of the computer programs, or the combined hardware requirements of a subset of the computer programs, with the technical properties of the computing unit is a corresponding updated or upgraded version of the computer program, supplementing or replacing a previous version already included in the computing system. Thus, computer program-level changes to the computing system can be evaluated before the updated or upgraded version is operational, and even before it is installed. This approach can provide numerous advantages. In particular, it can allow, for example, a sales team to define optimized commercial program update packages associated with hardware upgrades based on realistic metrics (provided by the evaluation) based on both hardware- and software-related aspects of the computing system. For example, this can serve as a basis for appropriately segmenting customer feature packages for creating quotes and defining computing systems, based on predictable and / or calculable costs associated with software updates / upgrades that require hardware upgrades / changes to meet their associated hardware requirements. Specifically, a partitioning of the customer's functional mix per vehicle segment can thus be performed (e.g., based on public vehicle segments such as those of ACRISS (Consortium for Car Rental Industry System Standards), the European Commission (as defined in Regulation (EEC) No. 4064 / 89), or the German Federal Motor Transport Authority (KBA), or based on proprietary, e.g., manufacturer-specific, vehicle segments). Consequently, an optimal solution in terms of cost or the optimal combination of functions supported at a given cost point can be readily defined based solely on evaluation, i.e., without requiring the prior construction of a prototype or even a real computing system. Further advantages may include: allowing, for example, an application software development team to reevaluate and / or change the software side of a computing system while maintaining or achieving a match with the available hardware side of the computing system; allowing, for example, system architects to design scalable hardware based on realistic software-based sizing metrics; enabling automatic blocking of software updates to prevent, for example, functional deviations from the specifications of the computing system or even the vehicle; and allowing evaluation of the fit between the software side and the hardware side of the computing system even in the absence of either or both of the software side and the hardware side of the computing system, particularly since the generated identifiers discussed above can be used independently.

[0068] In some embodiments, when the evaluation result indicates that the individual hardware requirements of the updated or upgraded version or the combined hardware requirements of the subset of computer programs comprising the updated or upgraded version, respectively, cannot be satisfied by the computing system,

[0069] One or more operating parameters of the updated or upgraded version are modified to reduce its hardware requirements, and the evaluation is repeated based on this reduced hardware requirement. Thus, the method then takes the evaluation results into account to proactively modify the one or more operating parameters, such as to gradually approach or even immediately achieve a match between the hardware and software sides of the updated / upgraded computing system. Repeated evaluations can be particularly useful for verifying that a match has ultimately been achieved, if at all. Furthermore, the adaptation is specifically targeted at the operating parameters of the updated or upgraded version of the software (computer program). That is, the match is achieved by optimizing the configuration of the updated or upgraded version rather than simply preventing such an update or upgrade. This provides the opportunity to achieve a match (even automatically) even in cases where the updated or upgraded version may not be suitable for all possible configurations (at least in selected cases).

[0070] In some embodiments, the vehicle's functionality includes, at least in part, one or more of the following: engine control, entertainment and / or infotainment, lighting, locking, air conditioning, braking, driver assistance, navigation, (particularly highly) automated or autonomous driving, vehicle internal or external communications, and configuration of the vehicle's interior. The evaluation is performed to assess the correct functionality of the computing system relative to its ability to correctly execute at least one or a combination of two or more of the functionality. Thus, the set of functionality can span a relatively wide range of different vehicle functions, all supported by the same computing system.

[0071] In some embodiments, the method further includes an initialization process, the initialization process including one or more of the following:

[0072] - automatically detecting one or more of the hardware entities and determining or receiving, for each of these hardware entities, its respective associated set of one or more individual characteristic attributes;

[0073] - receiving information specifying one or more of the hardware entities, and determining or receiving, for each of the hardware entities, a corresponding set of one or more associated individual characteristic attributes;

[0074] - automatically detecting one or more of the computer programs and determining or receiving, for each of these computer programs individually or for a set comprising two or more of these computer programs, a set of associated one or more requirement attributes, said requirement attributes individually or jointly representing one or more specific hardware requirements, respectively, required by the computer program or set of computer programs for its correct execution on a computing platform;

[0075] - receiving information specifying one or more of the computer programs, and determining or receiving, for each of the computer programs individually or for a set comprising two or more of the computer programs, a set of associated one or more requirement attributes, the requirement attributes individually or jointly representing one or more specific hardware requirements, respectively, required by the computer program or set of computer programs for its correct execution on a computing platform.

[0076] Thus, the method can be extended to include an initialization process to provide information that can then be used in the subsequent actual evaluation process. In particular, this extension of the method can help achieve an even higher degree of automation for the overall evaluation of the computing system, because the information used as input for the evaluation is at least partially automatically available without the need for human interaction. This can particularly allow for overall higher performance, even up to real-time performance.

[0077] A second aspect of the present solution relates to an evaluation system for evaluating the correct functionality of a computing system. The computing system is configured as an onboard computing system for a vehicle to centrally control various vehicle functions and includes a computing platform having a plurality of hardware entities and a plurality of different computer programs configured to be executed individually or concurrently on the computing platform. The evaluation system includes a data processing device including a processor configured to perform the method of any of the preceding claims to evaluate the correct functionality of the computing system.

[0078] A third aspect of the present solution relates to a computing system configured as a centralized on-board computing system for a vehicle, such as a car, for centrally controlling different functions of the vehicle, wherein the computing system comprises the evaluation system of the second aspect for evaluating the correct functioning of the computing system itself.

[0079] In some embodiments of the computing system, the computing system includes a central computing unit (CCU) configured as an onboard computing unit for a vehicle to centrally control different functions of the vehicle. The CCU includes:

[0080] (i) a distributed computing system DCS comprising a plurality of co-located autonomous computing entities CE, each computing entity having its own separate memory, wherein the CEs are configured to communicate with each other by message passing via one or more communication networks in order to coordinate among themselves the distribution of computing tasks to be performed by the DCS as a whole;

[0081] (ii) a communications switch comprising a plurality of mutually independent switch fabrics, each switch fabric configured to variably connect a subset of or each of the CEs of the DCS to one or more of a plurality of interfaces for exchanging information thereon with communication nodes external to the computing system of the vehicle; and

[0082] (iii) a power supply system comprising a plurality of power supply subsystems for simultaneous operation, each of the plurality of power supply subsystems being capable of individually and independently of one another powering the DCS and at least two of the switch fabrics.

[0083] In particular, the CCU may comprise the evaluation system of the second aspect for evaluating the correct functioning of the computing system, in particular the CCU itself.

[0084] A fourth aspect of the present solution relates to a vehicle comprising the computing system of the third aspect as a centralized on-board computing system.

[0085] A fifth aspect of the present solution relates to a computer program or a non-transitory computer-readable storage medium, in each case comprising instructions which, when executed on a computer or multiple computer platforms, cause the computer or multiple computer platforms, respectively, to perform the method of the first aspect.

[0086] The computer program or the non-transitory computer-readable storage medium can each be implemented in the form of a data carrier on which one or more programs for executing the method are stored. For example, such a data carrier can include a hard drive or a semiconductor memory device, such as a flash memory module or embedded flash memory of a microcontroller and / or microprocessor. In another embodiment, the computer program is provided as a file on a data processing unit, such as a server, and can be downloaded via a data connection, such as the Internet or a dedicated data connection, such as a proprietary or local area network.

[0087] Thus, the evaluation system of the second aspect may have a program memory storing the computer program. Alternatively, the evaluation system may also be arranged to access an externally available computer program via a communication link, for example on one or more servers or other data processing units, in particular to exchange data used in the execution of the computer program or representing output of the computer program.

[0088] All explanations given in relation to the method of the first aspect also fully apply to each of the other aspects of the present solution.

[0089] Other advantages, features, and applications of the present invention are provided in the following detailed description and accompanying drawings, in which:

[0090] Figure 1 shows a first block diagram illustrating functional building blocks of an exemplary CCU and related high-level communication structures for communicating within the CCU with nodes external to the CCU, according to an embodiment of the present solution;

[0091] Figure 2 Shown in more detail Figure 1Some functional building blocks of the CCU;

[0092] Figure 3 A first view of a second block diagram according to an embodiment of the present solution is shown. Figure 1 More details on the functional building blocks of the CCU, with a focus on redundant setup of power supply and power coordination, control coordination, and computation coordination within the CCU;

[0093] Figure 4 Shown Figure 3 A second view of the second block diagram of FIG. 1 , however now focusing on anomaly detection in the power supply domain;

[0094] Figure 5 It is shown that each master CE and / or each associated switch fabric has multiple instantiations of redundancy schemes;

[0095] Figure 6 A classic strict layered communication scheme from the prior art according to PCI Express communication technology is shown;

[0096] Figure 7 An exemplary adapted communication scheme using PCI Express technology as a basis according to an embodiment of the present solution is shown;

[0097] Figure 8 The embodiment according to the present solution is shown by Figure 7 Various exemplary communication links enabled by the adapted communication scheme;

[0098] Figure 9 A third block diagram 500 is shown according to an embodiment of the present solution, which illustrates an exemplary CCU, e.g. Figure 1 More details on the CCU, especially its communication switches;

[0099] Figure 10 An exemplary CCU according to an embodiment of the present solution is shown, for example Figure 1 An exemplary housing scheme of a CCU;

[0100] Figure 11 Schematically illustrates a computing platform having a CCU of a vehicle or a CCU for a vehicle;

[0101] Figure 12 Schematically shows the Figure 1 A computing platform and a vehicle (particularly a car) for placing the CCU at various suitable locations within the vehicle;

[0102] Figure 13 schematically illustrates a simple scenario in which conflicting hardware requirements of different computer programs may occur in a computing platform;

[0103] Figure 14 Schematically illustrates the assignment of individual characteristic attributes to hardware entities of a given computing system, and various computer programs for assigning requirement attributes to the computing system;

[0104] Figure 15 The scheme of the abstract hardware entity is schematically shown;

[0105] Figure 16 shows a table 1200 defining various exemplary individual characteristic attributes 1005 grouped in different characteristic attribute categories;

[0106] Figure 17 A first embodiment of the method is schematically shown; and

[0107] Figure 18 A second embodiment of the method is schematically shown.

[0108] In the drawings, in many cases, the same reference numerals are used for identical or mutually corresponding elements of the computing platforms described herein. For clarity, the following detailed description is structured into sections introduced in each case by headings. However, these headings should not be construed as limiting the content corresponding to the heading or the corresponding section of any drawing described therein.

[0109] Central Computing Unit (CCU)

[0110] Figure 1 and Figure 2 A (first) block diagram is shown illustrating selected functional building blocks of an exemplary computing platform 700 having a central computing unit (CCU) 105 and associated high-level communication structures for communicating within the CCU 105 with CCU-external communication nodes.

[0111] CCU105 includes: (i) a computer module cluster 110, which has a main computing module 115, one or more general computing modules 120 and one or more special-purpose modules 125; (ii) a service module 135; and (iii) a connection device 130, such as a backplane (which can be a passive backplane in particular), for interconnecting the modules with each other and with the service module 135.

[0112] The interconnections provided by the connection device 130 may in particular include a power connection for exchanging power, such as electrical power P, a data connection (e.g., Ethernet, PCI, or PCIe) for exchanging data D, a control connection (e.g., I2C) for exchanging control information C, an alarm connection for exchanging alarm information A, and a power management connection for exchanging power management information I.

[0113] exist Figure 1In the example of FIG, the CCU external communication nodes include a first endpoint cluster 140 optically connected to the CCU 105, for example, via an optical fiber communication link O, a second endpoint cluster 145 connected to the CCU 105 via a wireless communication link W (e.g., a Bluetooth, WLAN, ZigBee, or cellular mobile connection link). A third endpoint cluster 150 may be connected by a cable connection and may specifically be or include a zoning hub for interconnecting the CCU 105 to further endpoints 330. A fourth endpoint cluster 155 may be connected to the CCU 105 via a separate intermediate wireless transceiver 160.

[0114] In addition, two or more endpoint clusters 515 can be directly linked to each other via a communication link that does not involve the CCU 105, as exemplarily shown using the wireless communication link W between the third endpoint cluster 150 and the fourth endpoint cluster 155. Each endpoint 330 is a node within a communication network formed by a communication link that directly or indirectly connects the endpoint 330 to the CCU 105 or to each other. In particular, an endpoint 330 can be or include one or more of an actuator 715, a sensor 720, and an intermediate network node, such as a hub, for connecting multiple other endpoints 330.

[0115] As used herein, the term "endpoint cluster" 515 refers to a group of endpoints 330 that are directly or indirectly connected to the same network node via corresponding communication links so that they can all exchange information with the common node. Typically, the common node will have some kind of hub functionality, i.e., acting as an intermediate node in the communication links between the other nodes connected to it.

[0116] CCU105 also includes ( Figure 1 A and 1B are not shown) communication switches and power supply systems. Figures 2 to 5 These building blocks of the CCU 105 are discussed further.

[0117] Now refer to Figure 2 , which shows in more detail Figure 2 The main computing module 115, general computing module 120 and special purpose module 125 of the computing module cluster 110 are shown. Turning first to the main computing module 115, the main computing module 115 has at least a first computing entity (CE) 115a, a separate second computing entity 115b and optionally one or more additional CEs 115c arranged within the same module and thus co-located. All of these CEs are autonomous and independent of each other in the sense that they all have comparable, ideally identical, computing power and their own separate memory, so that each of these CEs can be used as a replacement for the corresponding other CEs.

[0118] In further discussion, for simplicity and not limitation, consider an exemplary case where there is no additional CE 115c in the main computing module 115 in addition to the first CE 115a and the second CE 115b. Each of the first CE 115a and the second CE 115b can be embodied in a corresponding separate hardware unit, such as a semiconductor chip, for example, a system on a chip (SOC).

[0119] The first CE 115 a and the second CE 115 b are configured to operate redundantly, for example, through corresponding software (computer programs), so that if at least one of the first CE 115 a and the second CE 115 b is operating normally, they synchronously execute the same computing task to achieve normal operation of the CCU 105. Therefore, there is redundancy between the first CE 115 a and the second CE 115 b not only in terms of redundant hardware, but also in terms of the computing tasks they synchronously execute, so that if one of the first CE 115 a and the second CE 115 b fails (with or without early warning), the corresponding other of these CEs can immediately enter and thus maintain the computing function of the main computing module 115 based on the synchronous execution of the same computing task already being performed by the main computing module 115 itself.

[0120] Now, before continuing with the explanation of the remaining building blocks of the main computing module 115, reference will be made to the general computing module 120. It includes at least one autonomous CE 120a and optionally one or more additional CEs 120b. Each of the autonomous CE 120a and the additional CE 120b is designed as a general computing entity, that is, a computing entity designed to perform all kinds of different computing tasks, rather than being limited to performing only one or more specific kinds of computing tasks, such as graphics or audio processing or running artificial neural networks or some other artificial intelligence algorithms. Each of the autonomous CE 120a and the additional CE 120b has its own memory and is independent of the other CEs, capable of autonomously performing the computing tasks that have been assigned to it.

[0121] In addition, each general computing module 120 includes a respective individual fault management system (FMS) 120 c that is configured to detect faults, such as hardware and / or software-based errors or defects, occurring within or at least involving the general computing module 120. The FMS 120 c is further configured to communicate any such detected faults to the master computing module 115 via the connection device 130 via an alarm message A.

[0122] Turning now to the specialized modules 125, in contrast to the general-purpose computing modules 120, specialized modules 125 are specifically designed to perform one or more selected tasks, such as computational or communication tasks, and are generally less suited for, or even incapable of, performing the general-purpose computing tasks of the main computing modules 115 and general-purpose computing modules 120. For example, one or more specialized modules 125 may be or include a graphics processing unit (GPU), a module specifically designed to run one or more artificial intelligence algorithms, a neural processing unit (NPU), an in-memory computing unit (IMCU), or a local hub module. Thus, specialized modules 125 may specifically include one or more such specialized CEs 125a and / or one or more communication interfaces 125b for establishing communication links, such as to endpoints 330 or endpoint clusters 515. Each specialized CE 125a has its own memory and, independent of other CEs, is capable of autonomously performing the computing tasks assigned to it.

[0123] In addition, each of the dedicated modules 125 also includes a respective dedicated separate fault management system (SFMS) 125 c that is configured to detect faults, such as hardware and / or software-based errors or defects, that occur within or at least relate to the respective dedicated module 125. Each SFMS 125 c is further configured to communicate any such detected faults to the main computing module 115 via the connection device 130 via an alarm message A.

[0124] Although the computing module cluster 110 may thus include one or more general computing modules 120 and / or one or more specialized modules 125 and / or even other modules, it may be implemented in a simple form without such additional modules, such that only the master module 115 remains as a computing module. In particular, the computing module cluster 110 or any one or more of its computing modules may be implemented based on a set of interconnected chiplets as its components.

[0125] Returning now to the master computing module 115, this module, among other roles, also assumes the role of allocating tasks (including, in particular, computing tasks) to the various modules of the computing module cluster 110. This allocation process thus provides resource coordination functionality 115d for the computing module cluster 110. Thus, the first CE 115a and the second CE 115b can be designated as "master CEs," while the other CEs within the general-purpose CE 120 and the specialized CE 125 are on the receiving end of this task allocation process and, therefore, can be designated as "slave CEs" because they must perform the tasks assigned to them by the master CE.

[0126] The allocation of tasks defined by the master CE is communicated to the slave CEs by means of messages transferred via the connection device 130, thereby transferring eg corresponding control information C and / or data D.

[0127] In particular, the resource coordination function 115d may include a process in which the main computing module 115 receives periodic reports on the main software operations (including parallel and sequential operations) of all CCU 105 processes (running on the set of CEs), and the current priority master CE allocates tasks between and toward the various CEs based on such reports (while other master CEs run the same processes synchronously, although their associated task allocations will be discarded). Alternatively or additionally, the allocation may depend on the amount of available energy currently available to power the CCU 105.

[0128] Although such allocation may even include allocating computing tasks to the master CE itself, such allocation will treat both master CEs similarly, such that both will then execute such self-allocated tasks synchronously, thereby maintaining fully redundant operation of both master CEs.

[0129] In summary, the following reference Figure 6 As explained in more detail in the exemplary embodiment of the CCU 105 in FIG, a collection of CEs of various modules arranged at the same location thus forms a distributed computing system (DCS), wherein computing tasks to be executed by the DCS as a whole can be variably allocated to different CEs within the computing module cluster 110, and wherein such allocation is conveyed by passing messages between the CEs involved.

[0130] The main computing module 115 also includes a central fault management system (CFMS) 115f, which is configured to receive anomalies associated with faults that have been detected within the DCS via alarm information A provided by one or more of the FMSs 120c of other modules, or even from the main computing module 115's own independent FMS (iFMS) 115g. The CFMS 115f is configured to classify and categorize such alarm information A and initiate countermeasures, such as reallocating computing tasks from the defective CE or module to another module, or, in the event of insufficient remaining computing capacity, prioritizing tasks, such as supporting more important tasks at the expense of less important tasks.

[0131] The main computing module 115 also includes a safety management system (SMS) 115e that is configured to determine and, if necessary, initiate necessary safety measures (i.e., safety state upgrades including real-time scheduling) to enable the CCU 105 and / or the vehicle 800 (see Figure 11 Thus, the safety management system 115e may rely specifically on input from the alarm information A available from the CFMS 115f, which in turn consolidates the alarm information A received from the individual FMSs 120c and iFMS 115g of the various modules of the CCU 105.

[0132] For example, if the alert message A (or some other information available to the SMS 115e) indicates a loss of power in the power supply of the CCU 105, the SMS 115e may decide to use all remaining power to steer the vehicle 800 to the side of the road while simultaneously shutting down power to all non-essential systems of the vehicle 800. Such non-essential systems may, for example, relate to air conditioning or entertainment, and to modules of the CCU 105 that are not required for the basic tasks of enabling the vehicle 800 to be safely steered to the side of the road. Such basic tasks may, for example, include turning on warning lights and tasks related to the braking system of the vehicle 800.

[0133] The central fault management system 115f and the resource coordination function (RCOS) 115d are preferably implemented redundantly in multiple instantiations so that a failure of one instantiation can be compensated by another instantiation. In particular, each of the first CE 115a and the second CE 115b can have an associated different instantiation so that each of the first CE 115a and the second CE 115b is autonomous and has its own autonomous CFMS 115f and its own autonomous RCOS 115d.

[0134] RCOS 115 d, SMS 115 e, CFMS 115 f, FMS 120 c, and iFMS 115 g may specifically be implemented individually or jointly, in whole or in part, as one or more computer programs designed to be run synchronously (in separate instances) on each of the master CEs (i.e., on each of the first CE 115 a and the second CE 115 b, respectively). Hybrid implementations are also possible, in which dedicated hardware is provided in addition to one or more processors for running software to enable selective offloading of certain tasks, for example, to a high-performance dedicated system-on-chip (SoC).

[0135] Figure 2 A second block diagram 200 is shown according to an embodiment of the present solution, which shows Figure 1 The functional building blocks of the CCU 105 are described in more detail, with a focus on its redundant setup.

[0136] As mentioned above, Figure 1 and Figure 2 As discussed, the computing module cluster 110 includes two or more master CEs, in this example a first CE 115a and a second CE 115b, within its master computing module 115. Therefore, redundancy is available at the master CE level.

[0137] In addition, CCU 105 includes a communication switch, which in turn includes a plurality of independent switching structures. Figure 3In the example, there are two independently and autonomously operating (primary) switch fabrics, namely a first switch fabric 225a for emergency situations, a second switch fabric 225b, and a third switch fabric 225c. All switch fabrics 225a, 225b, and 225c are provided within the service module 135. Each of the first switch fabric 225a, the second switch fabric 225b, and the third switch fabric 225c includes hardware for variably connecting a plurality of different nodes of a network, such as nodes of a computer network, to variably exchange data D therebetween. In this example, the network includes modules of the computing module cluster 110 and their respective endpoints 330 or endpoint cluster 515 as nodes, such as, for example, Figure 1 、 Figure 7 、 Figure 8 and Figure 9 Any one or more of the following.

[0138] Each (master) switch fabric, namely, first switch fabric 225a and second switch fabric 225b, is signal-connected 730 to an associated one of the master CEs in master computing module 115, enabling it to selectively switch information flows between the corresponding master CE, namely, first CE 115a or second CE 115b, and other nodes of the network, such as nodes 120, 125, and 140 to 160. Specifically, the switch fabric can be designed as a switch (PCIe switch 325) compliant with the PCI Express (PCIe) industry standard. The same applies to third switch fabric 225c, although it may have limited connectivity. For example, it may be connected only to a proper subset of endpoint set 330 and / or only to a proper subset of the set of slave CEs 120a, 120b, 125a, or even to none of these CEs.

[0139] For security purposes, the network connection between the switch fabric and other nodes of the network may be protected by one or more first security functions 230a, b at the CE side and / or one or more second security functions 235a, b at the endpoint 330 side, such as authentication, packet inspection, encryption, digital signature and / or obfuscation, and may involve offloading to a designated security device. In particular, the first security functions 230a, b and / or the second security functions 235a, b may be implemented as building blocks of the corresponding associated switch fabric, such as Figure 3 and Figure 4 As shown, where authentication and packet inspection are provided in first security functions 230a, b as protection functions at the endpoint 330 side of the fabric, while one or more of second security functions 235a, b may be provided in each security block at the respective CE side of the first switch fabric 225a, the second switch fabric 225b, and the third switch fabric 225c.

[0140] It can be said that the master computing module 115 with its master CEs 115a and 115b and the switch fabrics 225a, 225b, and 225c with their associated security functions / blocks together define a computing task coordination domain 205 of the CCU 105, within which computing tasks can be variably distributed among the modules of the computing module cluster 110. The CCU 105 can be specifically configured to fully enumerate all nodes of the network during a boot process and / or a reset process, such that upon completion of these processes, all nodes have a defined identity within the network, e.g., an assigned identification code by which they can be unambiguously identified within the network. The enumeration process can be specifically performed under the direction of the communication switch and / or the master computing module 115.

[0141] In order to avoid any confusion, at each given point in time, only one master CE is defined (e.g., by a related flag) as the current priority master CE, which means that other entities of the CCU 105 will only "listen" to its commands (such as the allocation of computing tasks) while ignoring any commands from any other master CE. Figure 3 , the first CE 115 a is currently defined as the current priority master CE, while the second CE 115 b is not.

[0142] This is Figure 3 Indicated by hatching, the current priority master CE (i.e., the first CE 115a) and all other building blocks of the second block diagram 200 that are specifically associated with the current priority master CE are shown with "downward" hatching and reference number attribute "a" (such as in "225a"), while the other master CE (i.e., the second CE 115b) and all other building blocks of the computing task coordination domain 205 that are specifically associated with the other master CE are shown with "upward" hatching and reference number attribute "b" (such as in "225b").

[0143] If a failure is detected in the current priority master CE or its associated switch fabric, another / another master CE that has been determined to be functioning properly (e.g., through built-in self-test) is designated as the new priority master CE, causing the new priority master CE to take over the role previously held by the failed current master CE. The same applies to the associated switch fabric. For example, if the current priority master CE (in this example, the first CE 115a) and / or its associated first switch fabric 225a are found to have failed, e.g., due to a hardware defect, the previously redundant master CE (i.e., the second CE 115b and its associated second switch fabric 225b) is determined to now have priority and takes over the role previously held by the first CE 115a and its associated first switch fabric 225a.

[0144] Furthermore, in an emergency situation, such as when another switch fabric, namely the second switch fabric 225b (now serving as the new priority switch fabric), is also found to have failed, it can be determined that the third switch fabric 225c now receives priority and takes over the role of the previous priority switch fabric 225a or 225b. As described above, if the third switch fabric 225c has limited connectivity, then when the third switch fabric 225c takes over, all unconnected endpoints 330 and CEs will be automatically disconnected from the switching function of the service module 135. In this way, the CCU 105 can focus on urgent tasks even without having to involve the resource coordination function 115d.

[0145] Turning now to the power supply system for the CCU 105, there are two (or more) redundant, mutually independent power supplies, in this example, a first primary power supply 240a and a second primary power supply 240b, each of which is individually capable of providing sufficient power, e.g., electrical power P, to the CCU 105 to support all of its functions, at least under normal operating conditions. In normal operation, all of these power supplies are configured to operate simultaneously to collectively provide a redundant and therefore highly reliable power supply to the CCU 105. The power supplies 240a and 240b can be components of the CCU 105 itself, or can be external thereto, e.g., as batteries external to the CCU 105, such as a vehicle 800 battery. Figure 3 shown.

[0146] Furthermore, the CCU 105 may include an additional power supply, such as an emergency power supply 240c, for example, in its service module 135. The emergency power supply 240c may be specifically designed to be merely a temporary power supply having a more limited capacity than each of the first main power supply 240a and the second main power supply 240b, but having sufficient capacity to power at least the third switch fabric 225c when the third switch fabric 225c is in operation.

[0147] To further support the redundancy scheme 201 on which the CCU 105 is based, there are separate independent power networks for each main power source (respectively at Figure 3 and Figure 4 The primary power supply and its corresponding power network are configured to simultaneously power all switch fabrics, such that full redundancy is achieved and operation of the CCU 105 can be maintained even in the event of a switch fabric or primary power supply failure.

[0148] Current limiters 245a, b may be provided within the power network to ensure that any current flowing in the power lines of the CCU 105 (particularly in its service modules 135) remains below respective defined current thresholds in order to avoid any current-based damage or failure that may occur if the current levels rise above such respective thresholds. The power network and optionally also the main power supply (if part of the CCU 105) define the power supply domain 220 of the CCU 105, which provides a high degree of reliability due to its redundant setup.

[0149] Various hardware components of the CCU 105 may have different voltage requirements for their power supply. Therefore, the power supply system of the CCU 105 may also include various redundantly provided voltage generation units, each of which is configured to provide the same group of different supply voltage levels as needed and distributed to the switch fabrics 225a, 225b, and 225c via the backplane. For example, a first voltage level may be 3.3V for powering a first group of devices, such as the Ethernet to PCIe bridge of the CCU 105, while a second voltage level may be 1.8V for powering a second group of devices, such as the microcontroller and NOR flash devices of the CCU 105, a third voltage level may be 0.8V for powering a third group of devices, such as the DRAM memory devices of the CCU 105, and so on. In particular, this allows the control coordination domain 210 of the CCU 105 to control the voltage levels of the entire service module 135 as well as the voltage levels generated within the computer module cluster 110 itself.

[0150] Furthermore, the CCU 105, i.e., its service module 135, includes two or more mutually redundant controllers 260a, 260b, such as microcontrollers, for controlling selected functions of the service module 135. In particular, the controllers 260a, 260b can be configured to use the power management information I to control power supply to the communication switches having the switch fabrics 225a and 225b.

[0151] Specifically, the number of first voltage generation units 250a, b and second voltage generation units 255a, b can be one or more, and they can all generate the same set of voltages. Each first voltage generation unit 250a, b provides a complete set of voltage levels to an associated one of the first switch fabric 225a and the second switch fabric 225b, while each second voltage generation unit 255a, b provides the same complete set of voltage levels to an associated one of the controllers 260ab. Each controller 260a, 260b compares the set of voltages delivered by its associated first voltage generation unit 250a, 250b to its associated switch fabric with the set received from the second voltage generation unit 255ab. Typically, these voltage sets should match. However, if the controllers 260a, b determine that the voltage level sets do not match, a problem is detected, and the controllers 260a, b can initiate a reaction, such as shutting down one or more components.

[0152] All of the first and second voltage generating units 255a, b individually generate output voltage groups based on a load sharing or voting process related to the power simultaneously supplied from the first and second main power supplies 240a, 240b. For example, when both main power supplies are found to be stable, power sharing can be applied, while in the event that the power supply of one of the main power supplies is unstable, voting can be applied.

[0153] The service module 135 includes monitoring functionality, which is also redundantly implemented in at least two independent instantiations, e.g., a first hardware component and a second hardware component. Monitoring may specifically include one or more of current monitoring, voltage monitoring, and clock monitoring. Such monitoring may specifically relate to the power output of the first voltage generation unit 250a, b and the second voltage generation unit 255ab. The monitoring results are provided to the controllers 260a, 260b, where they are analyzed and control information (signals) C defining a response to the analysis results and / or, in the event of a detected fault, an alarm information (signal) A may be issued and transmitted to other relevant components of the CCU 105, such as the CFMS 115f in the main computing module 115 and / or other safety functions of the CCU 105 (if any). The CFMS 115f can then react accordingly, such as by reassigning current or upcoming computing tasks to a CE not affected by the detected fault.

[0154] Thus, the controller 260a, b, the first voltage generating unit 250a, b and the second voltage generating unit 255a, b as well as the monitoring unit 265a, b can be designated as the control coordination domain 210 of the service module 135. In practice, the components of the priority path (i.e. associated with the current priority master CE) on the one hand and the components of the redundant path (i.e. associated with the current other master CE) on the other hand are now grouped separately, and for each master CE a corresponding associated structural power coordination domain 215 comprising the components of the associated group can be defined. Figure 3 In FIG, only one of these structural power coordination domains 215 is drawn (dashed box).

[0155] like Figure 4 As shown (the power supply paths are not shown here to reduce the complexity of the drawing), the current limiters 245a, b can be particularly equipped with a diagnostic output function to generate and output diagnostic data based on the characteristics of the operation of the respective current limiters 245a, b and / or the power they receive or provide. If the diagnostic data indicates a malfunction or failure of one or more components of the CCU 105 that may affect the correct functioning of the current priority master CE and / or its associated switch fabric, the diagnostic data can then be provided to the controllers 260a, 260b for further analysis and for initiating an adequate reaction, such as changing the priority from one master CE and its associated switch fabric to another master CE and its associated switch fabric.

[0156] like Figure 5 As shown, as described above, further enhancements can be made by adding further levels of redundancy beyond the basic redundancy provided by the redundancy scheme 201 defining two or more pairs 170a, 170b. Figure 3 and Figure 4 , each pair 170a, 170b has an associated primary CE and an associated switch fabric. The additional redundancy level is based on creating redundancy within such pairs 170a, b by providing the primary CE and / or switch fabric of the pairs 170a, b redundantly (i.e., in multiple instantiations) and further providing, in accordance with such pairs 170a, b, configuration switches 270a, b for switching between different configurations of the pair 170b.

[0157] Thus, if a redundantly provided primary CE and / or redundantly provided switch fabric within a given pair 170a, 170b fails, the pair 170a, 170b as a whole remains operational due to the remaining one or more other primary CEs and / or switch fabrics. The priority scheme discussed above for basic redundancy between pairs 170a, 170b can be similarly applied to further levels of redundancy within a given pair 170ab. Thus, if a pair 170a, 170b has multiple redundant instantiations of a primary CE, such as a first instantiation 115a-1 of a first primary CE, a second instantiation 115a-2 of a first primary CE, a first instantiation 115b-1 of a second primary CE, and a second instantiation 115b-2 of a second primary CE, these instantiations can be operated to simultaneously execute the same computing task when one of the first CE 115a and the second CE 115b is defined as the priority primary CE for the pair 170a, b. The same applies to the switch fabrics of each pair 170a, b when the pair 170a, b has multiple instantiations of each switch fabric (e.g., a first instantiation 225a-1 of a first switch fabric, a second instantiation 225a-2 of a first switch fabric, a first instantiation 225b-1 of a second switch fabric, and a second instantiation 225b-2 of a second switch fabric).

[0158] As an example, Figure 5 Two separate pairs of such pairs 170a, b are shown. Unless such a pair 170a, b consists of a single master CE (e.g., a single first instantiation of a first master CE 115a-1) and a single switch fabric (e.g., a first instantiation of a first switch fabric 225a-1) ("I-shaped"), it includes its own configuration switch 270a, b and two (or more) associated master CEs, such as two or more instantiations of a first CE 115a or a second CE 115b, or two (or more) associated switch fabrics, such as two or more instantiations of a switch fabric. The configuration switches 270a, b are operable to variably switch between at least two different possible configurations of the respective pair 170a, b.

[0159] Exemplary shapes for each pair 170a, 170b are: (i) multiple instances of a master CE, e.g., an instance of the first CE 115a and a single instantiation of a switch fabric 225a-1 (or 225b-1) ("Y-shape"); (ii) a single master CE 115a-1 (or 115b-1) and multiple switch fabrics 225a-1 and 225a-2 (or 225b-1 and 225b-2) ("inverted Y-shape"); and multiple instantiations of a master CE 115a-1 and 115a-2 (or 115b-1 and 115b-2) and multiple instantiations of a switch fabric 225a-1 and 225a-2 (or 225b-1 and 225b-2) ("X-shape"). Pairs 170a, 170b may have the same or different shapes generally or at a given point in time. For example, the first pair 170a may have a Y-shape, and the second pair 170b may simultaneously have an X-shape. If the pair 170a,b has a shape other than an I-shape, its associated configuration switch 270a,b may be configured, in particular based on the operational state of its components, such as error-free operation or a fault / failure. For example, if the first pair 170a has an X-shape or an inverted Y-shape, and a fault of the second instantiation 225a-2 of the first switch fabric is detected, the first configuration switch 270a may be (re)configured such that it now connects the (error-free) second instantiation 225a-2 of the first switch fabric to the current priority master CE of the pair 170a,b, e.g., to the first instantiation 115a-1 of the first master CE.

[0160] Now refer to Figure 6 , which shows an exemplary conventional classical strict layered communication scheme 300 according to the standardized PCI Express (PCIe) communication technology for communication between different nodes of a PCIe network, specifically including two different computing entities, such as a first central processing unit 305 (CPU) and a second CPU 310.

[0161] The first CPU 305 includes, for example, a first management function 305 a for scheduling computing tasks, a first processing function 305 b for executing the scheduled computing tasks, and a PCIe first PCIe root complex 305 c having three first PCIe root ports 315 ( 315 - 1 , 315 - 2 , and 315 - 3 ).

[0162] Similarly, the CPU 310 includes, for example, a second management function 310 a for scheduling computing tasks, a second processing function 310 b for executing the scheduled computing tasks, and a second PCIe root complex 310 c having three second PCIe root ports 320 ( 320 - 1 , 320 - 2 , and 320 - 3 ).

[0163] All communication flows between such a CPU (e.g., the first CPU 305) and any endpoint 330 in the PCIe network associated with the CPU must pass through the first PCIe root complex 305c using one or more of its first PCIe root ports 315 (315-1, 315-2, and 315-3). In addition to the PCIe endpoints 430, there may be intermediate hubs in the PCIe network, such as one or more PCIe switches 325.

[0164] Thus, each of the first CPU 305 and the second CPU 310 has its own communication hierarchy including its own address space and / or clock domain for communication between any two nodes of its PCIe network, such that due to this hierarchy, every communication between two nodes of the same network must pass through the root complex of the associated CPU.

[0165] Communication between nodes at different communication hierarchies is enabled via an inter-CPU communication link 335 running between the first CPU 305 and the second CPU 310. Thus, if a first endpoint 330 located in the communication hierarchy of the first CPU 305 needs to communicate with a second endpoint 330 located in the communication hierarchy of the second CPU 310, the communication path must be

[0166] - Communication levels from the first endpoint 330 upstream through the first CPU 305

[0167] - via a first root complex having an associated first PCIe root port 315,

[0168] - by the first management function 305a of the first CPU 305,

[0169] - then further to the second CPU 310 via the inter-CPU communication link 335, and

[0170] - there in the downstream direction through its second management function 310a,

[0171] - through its second root complex 310c and its associated second root port 320,

[0172] - and finally reaches the second endpoint 330.

[0173] Therefore, because the endpoints 330 of the different communication tiers are isolated from the CPU of each respective other communication tier, such communication is not very efficient and may suffer from high latency, among other things.

[0174] and Figure 6 Compared to conventional methods, embodiments of the present solution can implement an adapted PCIe communication scheme 400, such as Figure 7 and Figure 8Also in this exemplary adapted PCIe communication scheme 400, there are two PCIe hierarchies, each with its own address space and corresponding first PCIe single root complex 405c and second single root complex. In the adapted PCIe communication scheme 400, Figure 6 The first CPU 305 consists of a main CE (e.g., Figure 1 B's first CE 115a) is replaced, and the second CPU 310 is replaced by a slave CE (e.g., Figure 3 Replaced from CE120a).

[0175] The first CE 115a (master CE) includes management functionality 405a, processing functionality 405b, and a first single PCIe root complex 405c with three PCIe root ports 405d (405d-1, 405d-2, and 405d-3). Similarly, the slave CE 120a includes additional management functionality 410a, additional processing functionality 410b, a second PCIe single root complex 410c with three additional PCIe root ports 410d (410d-1, 410d-2, and 410d-3), and a resource coordination system block 415d including a resource coordination function (RCOS) 115d. All nodes of the adapted PCIe communication scheme 400 share a common clock, meaning they are in the same clock domain.

[0176] In each communication layer, there is a layer-related PCIe switch 415a, b, which has one or more first non-transparent PCIe bridges (NTBs) 420a, b for connecting with the associated CE and one or more second non-transparent PCIe bridges (NTBs) 425a, b for connecting directly or indirectly with one or more PCIe endpoints 430 or the corresponding other communication layer (i.e., its root complex). Figure 6 The inter-CPU communication link 335 has now become obsolete and can be omitted.

[0177] Now specific reference Figure 8 , three exemplary communication paths enabled by the adapted PCIe communication scheme 400 are shown.

[0178] A first communication path 435 enables communication between a first selected PCIe endpoint 430-1 in the hierarchy of the first CE 115a acting as a master CE and the autonomous CE 120a acting as a slave CE, in particular its further processing function 410b. The first communication path 435 runs from the first selected PCIe endpoint 430-1 to the corresponding first PCIe switch 415a in the same hierarchy, and from there through the second NTB 425a to another CE, namely another PCIe root port 410d (specifically, root port 410d-2) of the second PCIe single root complex 410c of the slave CE 120a, and from there ultimately to the further processing function 410b.

[0179] The second communication path 440 enables communication between the second selected PCIe endpoint 430-2 in the hierarchy of the slave CE 120a and the further processing function 410b of the slave CE 120a. Thus, the second communication path 440 remains within the same hierarchy from the second selected PCIe endpoint 430-2 to the corresponding second PCIe switch 415b to the further PCIe root port 410d (specifically: root port 410d-1) and from there through the further PCIe root port 410d (specifically: root port 410d-2) to its further processing function 410b (i.e., the processing function of the slave CE 120a), similar to Figure 6 The normal situation.

[0180] A third communication path 445 enables communication between a second selected PCIe endpoint 430-2 in the hierarchy of the slave CE 120 a and another selected PCIe endpoint 430 in the hierarchy of the master CE 115 a. The third communication path 445 extends from the second selected PCIe endpoint 430-2 to a corresponding second PCIe switch 415 b in the same hierarchy, to another PCIe root port 410 d (specifically, root port 410 d-1) of the second PCIe single root complex 410 c of the slave CE 120 a, and from there to another PCIe root port 410 d (specifically, root port 410 d-2), from where it passes through the NTB 425 a of the corresponding first PCIe switch 415 a, and from there ultimately proceeds to the processing function 405 b.

[0181] All of these communication paths, in particular the first and third paths interconnecting the different hierarchical levels, can be managed by the management function 405a of the master CE 115a. Thus, the adapted communication scheme 400 uses the NTB to enable "direct" point-to-point communication between distributed locations within the same clock domain, including at different hierarchical levels, while the communication paths are centrally managed, in particular configured.

[0182] Figure 9A third block diagram 500 is shown according to an embodiment of the present solution, which shows more details of an exemplary CCU 105, in particular more details of its communication switches with the service module 135. The CCU 105 has a computing module cluster 110, which includes a main computing module 115, three general computing modules 120 and a single dedicated module 125, each of which is a combination of the above and the attached Figure 1 and Figure 2 The corresponding type of description.

[0183] Each module of the computing module cluster 110 is connected to two hierarchically related PCIe switches 415a, b. Each of these hierarchically related PCIe switches 415a, b is equipped with a plurality of first NTBs 420a, b on the CE side and a plurality of second NTBs 425a, b on the PCIe endpoint 430 side. Thus, the setup so far is similar to Figure 7 / Figure 8 settings, although optionally with a different number of NTBs.

[0184] Furthermore, the CCU 105 of the third block diagram 500 includes a corresponding conversion bridge 505 for one or more, in particular all, endpoint-side second NTBs 425a, b, for performing conversion between different communication technologies used in the relevant communication paths running through the corresponding NTBs. For example, such a conversion bridge 505 can be configured to perform conversion from Ethernet communication technology to PCIe technology. Specifically, in Figure 9 In the example of FIG, the translation bridge 505 is configured to perform translation from Ethernet communication technology on the endpoint side to PCIe technology on the CE side of the NTB.

[0185] Thus, PCIe technology is used for communication between the modules of the computing module cluster 110, and for communication with the corresponding first PCIe switch 415a and the corresponding second PCIe switch 415b, and towards the translation bridge 505, while Ethernet technology is used for communication between the translation bridge 505 and the PCIe endpoints 430. The latter can be arranged in particular spatially or by some other common properties such as shared functionality, address space, or clock within the endpoint cluster 515 of the PCIe endpoints 430. Between the bridge 505 and the endpoint cluster 515, an Ethernet switch 510 can be arranged to variably connect selected individual PCIe endpoints 430 to selected translation bridges 505. The set of hierarchically related PCIe switches 415a, 415b and translation bridges 505 can be implemented in particular within a single SoC or by means of a chiplet solution, wherein the hierarchically related PCIe switches 415a, 415b and translation bridges 505 are distributed across multiple chiplets, each chiplet carrying one or more of these components.

[0186] Thus, each module of the compute module cluster 110 is connected to each of two switch fabrics, each of which includes a corresponding hierarchical PCIe switch 415a, b, various NTBs 420a / 425a or 420b / 425b, and a plurality of translation bridges 505. In this way, the desired redundancy is achieved, wherein each PCIe endpoint 430 can be reached from any module of the compute module cluster 110 via each communication fabric (and vice versa).

[0187] Figure 10 An exemplary computing system (eg, Figure 1 105). The housing 600 includes a rack-shaped housing structure 605 having a plurality of compartments, each of which is used to accommodate a module of the CCU 105, such as a computing module of the computing module cluster 110 or a service module 135, preferably in a replaceable manner. In this example, a total of six compartments (slots) are arranged in the structure and housing 600 (co-located, specifically in an adjacent manner): the main computing module 115, two general-purpose computing modules 120, two specialized modules 125, and the service module 135.

[0188] While the first end of the housing structure 605 includes corresponding openings for each compartment for inserting or removing modules, the opposite end of the housing structure 605 includes a connection device 130, which is configured to provide a connection for exchanging one or more of power P, data D, control information C, alarm information A or power management information I between different modules.

[0189] The connection device 130 may in particular have a substantially planar shape and may therefore be designated as a "backplane." Between the connection device 130 and the opposite back side of the module, each module has one or more connectors 610 to provide the aforementioned connections. In particular, the connectors 610 may be designed as detachable connectors 610, such that the modules can be (i) inserted and connected simply by pushing them into their respective compartments until the associated one or more connectors 610 are connected, and (ii) removed and disconnected simply by pulling them from the compartments and thereby detaching the connection.

[0190] Computing Platform

[0191] Now refer to Figure 11 , vehicle 800 (e.g. Figure 3 、 Figure 4) comprises a central computing unit (CCU) 105 having a modular design, wherein a plurality of different modules 105a to 105f are combined with a common housing 600, for example of the rack type, to jointly define a computing device. The modules 105a to 105f may in particular correspond to the modules 115, 120 (2x), 125a, 125b and 135 described above (see Figure 10 ). The housing 600 and optionally other parts of the CCU 105 form the fixed part thereof. In contrast, at least one of the modules 105a to 105f, preferably several of them, are releasably connected to the housing 600 in a replaceable manner, such that they can be easily removed based on releasable mechanical, electrical and / or optical connectors 610, so as to allow hardware-based reconfiguration, maintenance or enhancement of the CCU 105 by adding, removing or replacing one or more of the modules relative to the fixed part. In particular, one of the modules, for example module 105b, may be an energy supply module for supplying energy to at least one, preferably all other modules 105a and 105c to 105f. The energy supply module 105b may in particular belong to the fixed part of the CCU 105, but it is also conceivable that the energy supply module 105b is releasably connected to the housing 600 in a replaceable manner, such that the energy supply module 105b can be easily removed, replaced, etc.

[0192] As used herein, the term "computing platform" 700 may specifically refer to the environment in which a piece of software executes. This can be hardware or an operating system 1345 (OS), or even a web browser and associated application programming interfaces, or other underlying software, if the program code is executed with it. Computing platform 700 can have different levels of abstraction, including computer architecture, OS, or runtime libraries. Thus, computing platform 700 is the stage on which computer programs can run. It may specifically include or be based on multiple computers or processors.

[0193] The CCU 105 is designed to serve as the central computing entity of the computing platform 700 and is configured to provide on-demand computing to a plurality of different other functional units of the vehicle 800 based on the flexible, software-defined resource and process management and / or control functions of the CCU 105. Specifically, the CCU 105 can be designed to communicate with such other functional units via one or more preferably standardized high-speed communication links 725 (such as one or more high-speed bus systems) or several individual communication links (such as Ethernet links), for example, for data rates of 10 Mbit / s or higher. These high-speed communication links 725 can be used in particular to transmit one or more of data D, control information C, alarm information A, and power management information I, as described above, for example, with respect to Figure 1 、 Figure 2 、 Figure 3 and / or Figure 4 discussed.

[0194] Furthermore, the CCU 105 may include a multi-core operating system 1345 including a main core and a plurality of other cores, wherein the main core is configured to simultaneously control the plurality of other cores while at least two of the cores are concurrently running.

[0195] Another of the modules, such as module 105a (which may specifically correspond to the main computing module 115, as described above), may include a general-purpose computing device, such as one or more general-purpose microprocessors. In particular, module 105a may serve as the main computing resource (e.g., a main controller unit) of the CCU 105 and be configured to distribute computing requirements among multiple computing resources of the CCU 105 (including computing resources of other CCU modules in the CCU 105 module).

[0196] Module 105c (which may be particularly consistent with dedicated computing module 125, as described above) may, for example, include a dedicated computing device, such as a graphics processing unit (GPU) and / or a dedicated processor for running artificial intelligence-based algorithms (e.g., algorithms implementing one or more artificial neural networks). In addition, modules 105d, 105e, and 105f may include other general-purpose or dedicated computing resources / devices and / or memory.

[0197] For example, module 105d may include a security controller for protecting data and / or programs within the CCU 105 and restricting access thereto (module 105d may in particular include one or more of the first security functions 230a, b and / or the second security functions 235a, b as described above), and module 105e may include one or more interface controllers or communication devices for connecting the CCU 105 to one or more communication links with other devices external to the CCU 105, such as actuators 715, sensors 720 or a cluster hub 710 (hub) for aggregating / routing or splitting signals from / to several actuators 715 and / or sensors 720 so as to form a cluster centered around the hub (e.g., one or more of the endpoint clusters 515, 140, 145, 150 and 160 described above), each including several actuators 715 and / or sensors.

[0198] When such a cluster / hub solution is used, it can be implemented, in particular, based on a tree topology, wherein various actuators 715 and / or sensors 720 are connected to one or more cluster hubs 710 of the CCU 105, or multiple cascaded cluster hubs 710, such as module 105e of the CCU, via associated signal connections 730. Cluster hubs 710, which may be denoted, for example, as "Zone Electric Controllers" 260a,b (ZeC), can specifically aggregate signals from different sources (such as actuators 715 and / or sensors 720) and, therefore, can also be configured to act as a gateway between different communication protocols (such as CAN, LIN, and Ethernet). Consequently, significant wiring savings can be achieved, and central computing capabilities can be used to process signals from / to actuators 715 and / or sensors 720, particularly for the purpose of controlling one or more functions of the vehicle 800 based on those signals. However, it is also possible to have a hubless or hybrid topology, where some or all of the actuators 715 and / or sensors 720 are directly connected to the CCU 105 without any intermediate cluster hub 710 .

[0199] The computing platform 700 may be designed as a multi-computing layer platform and thus include a plurality of computing layers, for example, (i) a first computing layer 740 for processing basic mobility functions of a vehicle 800 (e.g., a car), such as acceleration, deceleration, and steering, (ii) a second computing layer for processing all kinds of other (e.g., digital) functions of the vehicle 800, such as driver assistance, infotainment, or (other) comfort-related functions, such as climate control, etc., as described herein, and (iii) a third computing layer 750 for processing functions of the vehicle 800 related to highly automated or even autonomous driving, for example, processing signals from relevant sensors 720 for detecting objects or road markings in the environment of the vehicle 800, etc. The second computing layer may be specifically configured according to the attached Figure 11 to design (but excluding the first computing layer 740 and the third computing layer 750, respectively, and the related interfaces with the second computing layer (described below)).

[0200] In a multi-computing layer embodiment of the computing platform 700, one of the modules 105a-f of the CCU 105 may further include or be configured to be linked to (i) a first interface unit 735 for connecting the second computing layer to the first computing layer 740 and (ii) a second interface unit 745 for connecting the second computing layer to the third computing layer 750 so as to exchange information therewith in a controlled manner, respectively, e.g., according to one or more defined protocols.

[0201] The module 105 f may, for example, include, among other things, a communication interface 125 b for implementing an interface functionality to the third computing layer 750. In practice, the module 105 f itself may also include one or more computing units of the third computing layer 750, so that the second computing layer and the third computing layer 750 (although defined as separate computing layers with separate functionality and structure) are then physically integrated in the same physical device, i.e., the housing 600, and even at least partially within the same module of the CCU 105.

[0202] Further details of the multi-computing tier embodiment of computing platform 700 are described in PCT / EP2023 / 055182, which is incorporated herein by reference in its entirety.

[0203] vehicle

[0204] Figure 12 An exemplary vehicle 800, in particular an automobile, is shown, comprising a Figure 11 10. An exemplary computing platform 700 is shown, which includes a CCU 105. The CCU 105 is configured to centrally control different functions (not shown) of the vehicle 800. To reduce complexity, only some elements of the computing platform 700 (particularly its second computing layer) are shown, while other elements are not explicitly shown. This includes, in particular, all actuators 715 and sensors 720, and, in the case of a multi-computing layer embodiment, all elements of the first and third computing layers 740, 750, and the first and second interface units 735, 745.

[0205] Figure 12 (a) also shows several cluster hubs 710 of the second computing layer and associated high-speed communication links 725 from the cluster hubs 710 to the CCUs 105. Each of these hubs 710 can in turn be connected to a plurality of actuators 715 and / or sensors 720, such as Figure 11 As shown in more detail in .

[0206] While in principle the CCU 105 could be located anywhere within the vehicle 800 , there are certain preferred locations, particularly in view of safety requirements and the need to make it readily accessible so that the modules 105a to 105f can be easily removed and replaced into the housing 600 of the CCU 105 .

[0207] Figure 12(b) shows another simplified view of vehicle 800, illustrating three different exemplary locations within vehicle 800: a first location 805, a second location 810, and a third location 815. These locations are particularly suitable for placing the CCU 105 within vehicle 800. First location 805 and third location 815 are located on or near the (imaginary) centerline of vehicle 800, which extends along the main extension (y dimension) of vehicle 800, midway between the two sides of vehicle 800. While first location 805 is located between the two front seats of vehicle 800, for example, in the center console, third location 815 is located below the rear single seat or bench seat of the second or third seat row. These central locations (at least in the x and y dimensions) are particularly advantageous for safety and protection from damage or destruction in the event of an accident. They are also easily accessible for maintenance, repair, or replacement, particularly when one or more modules 105a to 105f need to be removed from the CCU 105, particularly from its housing 600.

[0208] The second position 810 is also highly accessible and well protected from collisions from almost any direction. This second position 810810 may also be particularly suitable for an entertainment wireless communication link W with a communication node external to the vehicle 800, such as a communication node of traffic infrastructure or another vehicle 800 (e.g., a communication node for vehicle-to-vehicle communication), because due to its position close to the windshield, it will generally be less affected by the electromagnetic shielding of the vehicle 800 itself.

[0209] Thus, the CCU 105 may in particular be located in or near the glove box of the vehicle 800 or in the center console, i.e. somewhere in or near the center of the passenger compartment of the vehicle 800 , so that the CCU 105 is both well protected from external mechanical impacts, for example in the event of an accident with the vehicle 800 , and easily accessible.

[0210] Method for automatically assessing the correct functionality of a computing system configured as a centralized onboard computing system

[0211] Figure 13A simple scenario 900 is shown in which conflicting hardware requirements of different computer programs may occur in a computing platform 700 (such as a CCU 105). According to this scenario 900, a first computer program 905, comprising a first virtual machine, and a second computer program 910, comprising a second virtual machine, are simultaneously running on the same microprocessor having four computing cores 915. First computer program 905 requires two computing cores 915 for proper function, while second computer program 910 requires all four computing cores 915 for proper function. Consequently, the number of required computing cores 915 (i.e., the cumulative hardware requirements of the two computer programs) exceeds the number of available computing cores 915, and the two hardware requirements conflict. Consequently, it cannot be safely avoided that one computer program will sometimes have to wait for the other computer program to become idle, i.e., when the cumulative hardware requirements for the number of computing cores 915 exceed four. Consequently, the overall performance of at least one computer program is limited.

[0212] The following figures show some exemplary embodiments of the method of the first aspect of the present solution.

[0213] Figure 14 An assignment scheme is shown as an element of the method for assigning various attributes to hardware entities and computer programs of a given computing system, as described above.

[0214] Specifically, according to the allocation scheme 100, individual characteristic attributes 1005 are assigned to various hardware entities of the computing system, and requirement attributes 1010 are assigned to various computer programs of the computing system. The hardware entities may specifically include, for example, one or more modules of the computing platform 700, such as its computer module cluster 110, and may specifically be defined as abstract hardware entities 1105, as will be described below with reference to Figure 15 As further explained in more detail, each hardware entity is assigned a first attribute set 1015 comprising one or more individual characteristic attributes 1005 characterizing the respective hardware entity, and each computer program is assigned a second attribute set 1020 comprising one or more requirement attributes 1010 characterizing one or more hardware requirements of the hardware on which the respective computer program runs.

[0215] exist Figure 14In the example of , the hardware entities relate to the CCU 105 and include its main computing module 115, two instantiations of the general computing module 120, and one instantiation of the specialized module 125. A corresponding separate set of first attributes 1015 is assigned to each of these hardware entities, wherein these first attribute sets 1015 are generally different between hardware entities, at least between those hardware entities of different types. Alternatively or additionally, the hardware entities can also be defined based on a finer granularity (e.g., based on the level of individual CEs of the CCU 105 (such as the first CE 115a, the second CE 115b, etc.)).

[0216] On the software side, in this example, there are five different computer programs, namely a first computer program 905, a second computer program 910, a third computer program 920, a fourth computer program 925, and a fifth computer program 930. A corresponding individual set of second attributes 1020 is assigned to each of these computer programs, wherein these second attribute sets 1020 generally differ among the computer programs.

[0217] Figure 15 An overview of an abstract hardware entity 1100 is shown. According to the scheme, an abstract hardware entity 1105 can be defined by a set of individual hardware properties, represented as individual property attributes 1005, which can be shared by multiple different real instantiations 1110 of the abstract hardware entity 1105, for example, different real instantiations 1110 designed and / or manufactured by different providers. Thus, the set of individual hardware properties of the abstract hardware entity 1105 can be derived by combining the respective individual property attributes 1005 involved.

[0218] This is particularly important in the context of dual-source or even multi-source scenarios 900 , where, for example, similar components of vehicle 800 originate from different suppliers, and these components must be interchangeable within vehicle 800 , i.e., one component can replace or be used as a replacement for another component, as long as their relevant technical specifications (i.e., their hardware feature sets (i.e., first attribute set 1015 )) coincide or are at least compatible. Compatibility, in this context, means that all real instantiations 1110 meet the same minimum requirements regarding their individual feature attributes 1005 , even if they differ in one or more of those instantiations. For example, if the minimum hardware feature related to available memory space is defined as 1GB, then different instantiations within real instantiations 1110 are compatible in this respect if each of them has at least 1GB of available memory space, even if their memory space differs. Therefore, the corresponding feature attribute 1005 of the relevant abstract hardware entity 1105 can then be defined as "1GB." The first attribute set 1015 characterizing a given abstract hardware component includes one or more individual feature attributes 1005 that are typically different from one another.

[0219] Figure 16 A table 1200 is shown that defines various exemplary individual characteristic attributes 1005 grouped into different characteristic attribute 1005 categories. These characteristic attribute 1005 categories include, for example, a category "Device Type (DT)", a category "Interface Type (IT)," and a category "Application Type (AT)". Within each category, there may be one or more, typically multiple, different characteristic attributes 1005, such as "ASIC" or "Digital Signal Processor (DSP)" having the category "Device Type (DT)". Each individual characteristic attribute 1005 has a corresponding associated unique and computer-readable characteristic identifier, such as "DT1", "IT3", "AT6", etc., to name a few.

[0220] Thus, even by its characteristic identifier alone, each characteristic attribute 1005 can be unambiguously identified and distinguished. Individual characteristic attributes 1005 of the same category can be considered different "subcategories" of that category. Thus, categories and their corresponding subcategories are organized in a hierarchical order that is also reflected in the identifiers. For example, the identifier "DT1" is associated with the first subcategory of the category "Device Type" having the top-level identifier "DT."

[0221] Thus, a hardware entity, in particular an abstract hardware entity 1105, can be characterized by a set of its associated characteristic identifiers, which can in particular be concatenated to define a string that can be used as a unique identifier ID for the hardware entity as a whole. An example is given below:

[0222] ID=pcb.1.comp.1.DT9.EG2.LC2.BWP4.AT1.IT5.1.IP5.CAN.D.IT5.2.PCIe.IP5.B

[0223] Hardware board = pcb.1

[0224] Equipment Considered = comp.1 (Part Number 1)

[0225] Device Type = DT9 (μC-microcontroller)

[0226] Environmental capability = EG2 (AEC-Q100 Grade 1)

[0227] Component specified life = LC2 (>8000; less than 12000 hours)

[0228] μC-performance = BWP4 (>17000DMIPS)

[0229] Application Type = AT1 (Automotive Safety)

[0230] Interface type = IT5 (Specification).1 (First Interface).IP5 (Safety).CAN (CAN Bus).D (ASIL D)

[0231] Interface Type = IT5 (Specification).2 (Second Interface).IP5 (Safety).PCIe (PCIe Bus).B (ASIL B)

[0232] In general, the first set of attributes 1015 and the second set of attributes 1020 may be stored in any suitable data structure, such as a string (see above), a matrix, a table 1200 , a dataset of a database D, or the like.

[0233] Figure 17 A first embodiment 1300 of the method is shown, in which a computing system is evaluated, which includes three different computer programs, namely a first computer program 905, a second computer program 910, and a third computer program 920, which need to be run concurrently, at least sometimes, on the same shared computing platform 700 of the computing system. The computer programs may in particular be application-level programs and / or programs belonging to a lower software layer, such as an operating system 1345 or a virtual machine environment (e.g., a hypervisor).

[0234] Computing platform 700 may specifically conform to Figures 1 to 12 Any one or more of, and thus may specifically include, CCU 105. The method comprises assigning a first set of attributes 1015 to relevant hardware entities of the computing platform 700, as described above, for example, with respect to Figures 14 to 16 discussed.

[0235] Furthermore, the method includes assigning a respective second attribute set 1020 to each of the three computer programs, wherein each of the second attribute sets 1020 includes one or more requirement attributes 1010 that individually or jointly represent one or more specific hardware requirements that the respective computer program requires for its correct execution on the computing platform 700. Conversely, a group of two or more computer programs may also share a combined second attribute set 1020 that defines the hardware requirements required for the entire group of computer programs as a whole, e.g., for their simultaneous execution. The latter is particularly useful if their simultaneous operation is a regular use case.

[0236] One or more of the computer programs may be designed, at least in part, in a modular fashion, such that each such program includes two or more program modules. Specifically, these program modules may be designed to be reused by multiple computer programs. Each program module has one or more individual module-level requirement attributes 1010 assigned to it, which individually or in combination represent one or more specific hardware requirements required for the corresponding program module to execute correctly on computing platform 700. Thus, a second set of attributes 1020 for the corresponding module-based computer program may be derived, for example, by simple aggregation or in any other suitable manner (such as selecting the largest requirement) from the corresponding individual module-level requirement attribute sets 1350 of the program modules included in or otherwise used by the computer program (e.g., by linking modules from an inventory of software modules).

[0237] exist Figure 17 In this example, there are seven different program modules, namely, first program module 1305, second program module 1310, third program module 1315, fourth program module 1320, fifth program module 1325, sixth program module 1330, and seventh program module 1335. Some program modules, namely, third program module 1315 and sixth program module 1330, are used by more than one computer program. Each program module has a corresponding assigned module-level requirement attribute set 1350, and each computer program's corresponding second attribute set 1020 is derived from the module-level requirement attribute sets 1350 of the program modules it uses.

[0238] The method can be performed by an evaluation system 1340 for evaluating the correct functioning of a computing system. The evaluation system 1340 includes a data processing device including a processor configured to perform the method. The data processing device can be separate from the computing system, or can alternatively overlap or form part of the computing platform 700 to be evaluated itself. For example, when the computing platform 700 is provided by the CCU 105, the processor can be a processor of one of the CEs of the CCU 105. The method can be implemented by a resource management function 1360, which can be implemented in whole or in part in software. For example, the resource management function 1360 can be included in the operating system 1345 or as an application designed to run on top of the operating system 1345.

[0239] The resource management function 1360 receives or accesses a second set of properties 1020 for the computer program and a first set of properties 1015 for the selected hardware entity or the joint first set of properties 1015 for the selected group of hardware entities on which the computer program should run.

[0240] The resource management function 1360 then performs a comparison of (i) the combined hardware requirements of the computer program represented by the aggregation or other suitable combination of the second attribute set 1020 with the technical characteristics of the computing unit represented by the first attribute set 1015 to determine and output an evaluation result 1365 indicating whether the computing system can meet the corresponding hardware requirements. The comparison can particularly take into account predetermined margin requirements of the computing platform 700, so that situations can be avoided in which the hardware requirements can only be met with a very small margin, leaving little room for flexibility or varying computing capabilities.

[0241] If the evaluation result 1365 indicates that the combined hardware requirements of all three computer programs can be met, the third computer program 920 can be executed concurrently with the first computer program 905 and the second computer program 910 .

[0242] Otherwise, a warning is output and the execution of the third computer program 920 is blocked, for example, by means of the operating system 1345, at least until sufficient hardware resources for its proper operation are available again, for example, if one or both of the first computer program 905 and the second computer program 910 are terminated or require less relevant hardware resources, such as computing power, than before. Furthermore, other countermeasures are possible, such as disabling one or more functions of the computing platform 700, interrupting or otherwise disabling the execution of one or more computer programs, etc. (see above).

[0243] Figure 18A second embodiment 1400 of the present method is shown, which is based on and largely similar to the first embodiment 1300. In contrast, it addresses an alternative scenario in which an assessment is performed to determine whether an update or upgrade of one or more computer programs already present in a computing system (in a previous version) can still be properly operated without running into a lack of sufficient hardware resources. In this example, the third computer program 920 is to be updated. The update may specifically include modifications to the third computer program 920 that require certain routines in the third computer program 920 to have higher computing power than the currently installed previous version of the third computer program 920.

[0244] While in principle the first embodiment 1300 can be used to perform such an assessment, i.e. perform an upgrade and then perform the Figure 17 However, this does not allow for pre-upgrade evaluation, and if the evaluation produces an evaluation result 1365 indicating a lack of sufficient hardware resources, the upgrade must typically be undone.

[0245] Thus, in the second embodiment 1400 , an evaluation is performed before performing the actual update or upgrade based solely on a comparison of the first set of properties 1015 of the computing platform 700 or a selected combination of related hardware entities thereof with the second set of properties 1020 of computer programs (including the second set of properties 1020 of the updated / upgraded version of the third computer program 920 ).

[0246] If the evaluation result 1365 indicates that the combined hardware requirements of the updated / upgraded versions of the first computer program 905, the second computer program 910, and the third computer program 920 can be met, then the third computer program 920 can be updated / upgraded accordingly. Otherwise, the update / upgrade is rejected, or (e.g. Figure 18 ) triggers an optimization process 1370 by which the hardware requirements of the updated / upgraded version are reduced by modifying one or more operating parameters of the updated / upgraded version. For example, if the third computer program 920 is a camera application, such an optimization process 1370 may specifically include reducing one or more operating parameters defining the sampling rate of the camera application, which in turn may result in reduced hardware requirements in terms of computing power and / or memory space required to properly support the camera application.

[0247] Alternatively or cumulatively, the optimization process 1370 may include a real or virtual modification of the hardware resources, for example, by adding another hardware entity, such as a more powerful CE or a whole computing module, to cover the extended hardware requirements of the updated / upgraded version of the third computer program 920. Thus, the optimization process 1370 results in a modified second set of properties 1380 of the third computer program 920 and / or a modified first set of properties 1375 of the computing platform 700.

[0248] Based on this, a re-evaluation 1385 can be performed to generate an updated evaluation result 1365′ related to the optimized situation. Multiple iterations are possible. The finally achieved updated evaluation result 1365′ can then be treated similarly to the evaluation result 1365 according to the first embodiment 1300.

[0249] Typically, in both embodiments, the set of considered attributes in the first attribute set 1015 and / or the second attribute set 1020 can be limited to those attributes that are actually relevant to achieving a meaningful evaluation result 1365, while other attributes can be ignored for the evaluation, which other attributes are irrelevant or only minimally relevant to the evaluation.

[0250] Reference Signs List

[0251] 100 First Block Diagram

[0252] 105CCU

[0253] 110 computer module cluster

[0254] 115 main computing module

[0255] 115a First Computing Entity (CE)

[0256] 115a-1 First instantiation of the first master CE

[0257] 115a-2 Second instantiation of the first master CE

[0258] 115b Second computing entity

[0259] 115b-1 First instantiation of the second master CE

[0260] 115b-2 Second instantiation of the second master CE

[0261] 115c Additional CE

[0262] 115d Resource Coordination Function

[0263] 115e Safety Management System

[0264] 115f Central Fault Management System

[0265] 115g's own separate FMS

[0266] 120 general computing modules

[0267] 120a autonomous CE

[0268] 120b additional CE

[0269] 120c independent fault management system

[0270] 125 dedicated module

[0271] 125a Special CE

[0272] 125b communication interface

[0273] 125c special individual fault management system

[0274] 130 connected devices

[0275] 135 service module

[0276] 140 First Endpoint Cluster

[0277] 145 Second endpoint cluster

[0278] 150 Third endpoint cluster

[0279] 155 Fourth endpoint cluster

[0280] 160 intermediate wireless transceiver

[0281] 170a first pair

[0282] 170a, b are correct

[0283] 170b second pair

[0284] 200 Second Block Diagram

[0285] 201 redundancy plan

[0286] 205 Computing Task Coordination Domain

[0287] 210 Control Coordination Domain

[0288] 215 Structural Power Coordination Domain

[0289] 220 power supply domain

[0290] 225a First Switching Fabric

[0291] 225a-1 First instantiation of the first switch fabric

[0292] 225a-2 Second instantiation of the first switch fabric

[0293] 225b second switching structure

[0294] 225b-1 First instantiation of the second switch fabric

[0295] 225b-2 Second instantiation of the second switch fabric

[0296] 225c third switching structure

[0297] 230a, b First safety function

[0298] 235a, b Second safety function

[0299] 240a first main power supply

[0300] 240b second main power supply

[0301] 240c emergency power supply

[0302] 245a, b current limiter

[0303] 250a, b first voltage generating unit

[0304] 255a, b second voltage generating unit

[0305] 260a, b controller

[0306] 265a, b monitoring unit

[0307] 270a first configuration switch

[0308] 270a, b configuration switch

[0309] 300 layered communication solution

[0310] 305 First Central Processing Unit (CPU)

[0311] 305a First Management Function

[0312] 305b First processing function

[0313] 305c First PCIe Root Complex

[0314] 310 Second CPU

[0315] 310a Second Management Function

[0316] 310b Second processing function

[0317] 310c Second PCIe Root Complex

[0318] 315 first PCIe root port

[0319] 320 Second PCIe root port

[0320] 325PCIe switch

[0321] 330 endpoint

[0322] 335Inter-CPU communication link

[0323] 400-compatible PCIe communication solution

[0324] 405a management features

[0325] 405b handling function

[0326] 405c first PCIe single root complex

[0327] 405d PCIe root port

[0328] 410a Additional Management Functions

[0329] 410b additional processing functions

[0330] 410c second PCIe single root complex

[0331] 410d additional PCIe root port

[0332] The first PCIe switch corresponding to 415a

[0333] 415a, b level related PCIe switches

[0334] The second PCIe switch corresponding to 415b

[0335] 415d Resource Coordination System Block

[0336] 420a, b first non-transparent PCIe bridge (NTB)

[0337] 425a, b Second non-transparent PCIe bridge (NTB)

[0338] 430PCIe endpoints

[0339] 430-1 First selected PCIe endpoint

[0340] 430-2 Second selected PCIe endpoint

[0341] 435 First Communication Path

[0342] 440 Second Communication Path

[0343] 445 Third Communication Path

[0344] 500 Third Block Diagram

[0345] 505 conversion bridge

[0346] 510 Ethernet switch

[0347] 515 endpoint cluster

[0348] 600 shell

[0349] 605 shell structure

[0350] 610 connector

[0351] 700 computing platform

[0352] 710 Cluster Hub

[0353] 715 actuator

[0354] 720 sensor

[0355] 725 high-speed communication link

[0356] 730 signal connection

[0357] 735 First Interface Unit

[0358] 740 First Computing Layer

[0359] 745 Second Interface Unit

[0360] 750 Third Computing Layer

[0361] 800 vehicles

[0362] 805 first position

[0363] 810 second position

[0364] 815 third position

[0365] 900 scenes

[0366] 905 First Computer Program

[0367] 910 Second Computer Program

[0368] 915 computing core

[0369] 920 Third Computer Program

[0370] 925 Fourth Computer Program

[0371] 930 Fifth Computer Program

[0372] 1000 attribute allocation scheme

[0373] 1005 characteristic attributes

[0374] 1010 Requirement Attributes

[0375] 1015 First attribute set

[0376] 1020 Second attribute set

[0377] 1100 Scheme of abstract hardware entity

[0378] 1105 Abstract Hardware Entity

[0379] 1110 Real Instantiation

[0380] 1200 table

[0381] 1300 First Embodiment

[0382] 1305 First Program Module

[0383] 1310 Second Program Module

[0384] 1315 Third Program Module

[0385] 1320 Fourth Program Module

[0386] 1325 Fifth Program Module

[0387] 1330 Sixth Program Module

[0388] 1335 Seventh Program Module

[0389] 1340 Evaluation System

[0390] 1345 operating system

[0391] 1350 module-level requirement attribute collection

[0392] 1360 resource management function

[0393] 1365 evaluation results

[0394] 1365' updated evaluation results

[0395] 1370 Optimization Process

[0396] 1375 Modified first attribute set

[0397] 1380 Modified Second Attribute Set

[0398] 1400 Second Embodiment

[0399] AAlarm information

[0400] C control information

[0401] D data

[0402] Power management information

[0403] ID unique identifier

[0404] OFiber optic communication link

[0405] P (electrical) power

[0406] W wireless communication link

Claims

1. A method of automatically evaluating the correct functionality of a computing system configured as a centralized onboard computing system for a vehicle (800) to centrally control various functions of the vehicle (800), The computing system includes: a computing platform (700) having a plurality of hardware entities, and a plurality of different computer programs configured to execute individually or concurrently on the computing platform (700) to enable one or more of the functions of the vehicle (800); and The method comprises: assigning or accessing, for one or more of the hardware entities, an associated set of one or more individual characteristic attributes (1005), said characteristic attributes individually or jointly representing one or more technical characteristics of the respective hardware entity; allocating or accessing, for one or more of the computer programs individually or jointly for a subset comprising two or more of the computer programs, a set of associated one or more requirement attributes (1010), the requirement attributes individually or jointly representing one or more specific hardware requirements required for the computer program or subset of computer programs, respectively, to execute correctly on the computing platform (700); and The respective individual hardware requirements of the one or more computer programs or the combined hardware requirements of the subset of computer programs are compared with the technical characteristics of the computing platform (700) defined by the characteristic attributes (1005) to determine an evaluation result (1365) indicating whether the computing system is capable of meeting the respective hardware requirements.

2. The method according to claim 1, characterized in that The computing system comprises a central computing unit (105), CCU (105), the CCU being configured as a centralized onboard computing system for the vehicle (800) to centrally control various functions of the vehicle (800), and the method being applied to automatically evaluate the correct functioning of the CCU (105), wherein the CCU (105) comprises: a distributed computing system DCS comprising a plurality of co-located autonomous computing entities CE, each computing entity having its own separate memory, wherein the CEs are configured to communicate with each other by message passing via one or more communication networks in order to coordinate among themselves the distribution of computing tasks to be performed by the DCS as a whole; a communication switch comprising a plurality of mutually independent switch fabrics, each switch fabric being configured to variably connect a subset of or each CE of the DCS to one or more of a plurality of interfaces for exchanging information thereon with communication nodes external to the computing system of the vehicle (800); and A power supply system includes a plurality of power supply subsystems for simultaneous operation, each of the plurality of power supply subsystems being capable of individually and independently of one another powering the DCS and at least two of the switch fabrics.

3. The method according to any one of the preceding claims, characterized in that at least one of the computer programs includes two or more program modules designed for reuse by a plurality of the computer programs, each program module having or being assigned one or more individual module-level requirement attributes (1010), the one or more individual module-level requirement attributes individually or jointly representing one or more specific hardware requirements required for the respective program module to execute correctly on a computing platform (700); and Assigning a related set of one or more individual requirement attributes (1010) to each of the computer programs includes deriving its respective set of individual requirement attributes (1010) at least in part by combining respective individual module-level requirement attributes (1010) assigned to its respective program modules.

4. The method according to claim 3, characterized in that The computing system comprises two or more of the computer programs, and at least a subset of the reusable program modules are included as elements in an inventory software module library such that they can be individually integrated or accessed by different ones of the computer programs via the inventory, such that evaluating the correct functionality of the computing system comprises performing the evaluation based on the two or more computer programs comprising the subset of reusable program modules respectively integrated in or accessed by one or more of the computer programs.

5. The method according to any one of the preceding claims, characterized in that Defining the technical characteristics of the computing system by means of a set of characteristic attributes (1005) of the one or more hardware entities comprises: defining one or more abstract hardware entities (1105), each of the one or more abstract hardware entities virtually representing a set of different possible real instantiations (1110) of such hardware entities by means of a set of corresponding individual characteristic attributes (1005) of each abstract hardware entity (1105).

6. The method according to any one of the preceding claims, characterized in that At least one of the characteristic attributes (1005) is individually encoded by a corresponding unique and computer-readable characteristic identifier; and When comparing the individual hardware requirements of one or more computer programs or the combined hardware requirements of a subset of computer programs respectively with the technical properties of a computing unit, at least one of the characteristic identifiers is decoded to determine the characteristic property encoded by said characteristic identifier (1005) as a basis for the comparison.

7. The method according to any one of the preceding claims, characterized in that At least one of the requirement attributes (1010) is individually encoded by a corresponding unique and computer-readable requirement identifier; and When comparing the individual hardware requirements of one or more computer programs or the combined hardware requirements of a subset of computer programs, respectively, with technical properties of a computing unit, at least one of the requirement identifiers is decoded to determine the requirement property encoded by the requirement identifier (1010) as a basis for the comparison.

8. The method according to claim 6 or 7, characterized in that A string representation comprising two or more concatenated identifiers is used to represent a particular combination of selected identifiers as a basis for the comparison.

9. The method according to any one of claims 6 to 8, characterized in that Encryption techniques are used to protect at least a subset of the one or more identifiers from unauthorized access.

10. The method according to any one of claims 6 to 9, characterized in that Obfuscation techniques are used to protect at least a subset of the one or more identifiers from unauthorized access by applying a time-varying association between, on the one hand, at least one specific identifier and, on the other hand, the corresponding information temporarily encoded thereby.

11. The method according to any one of claims 6 to 10, characterized in that At least a subset of the attributes are organized in a hierarchical order that is reflected in a corresponding hierarchical code used to encode the set of related identifiers.

12. The method according to any one of the preceding claims, characterized in that The method further comprises: preselecting a relevant subset (1005) of characteristic attributes of the processing platform based on the set of requirement attributes (1010); and In terms of the characteristic attributes ( 1005 ) considered, the comparison is performed strictly based on pre-selected characteristic attributes ( 1005 ).

13. The method according to any one of the preceding claims, characterized in that the set of one or more computer programs, or at least one of the computer programs, is reconfigurable by adding, removing, enabling or disabling, or modifying, respectively, one or more computer programs or computer program modules; and The method further comprises: determining an actual or planned reconfiguration of the set of one or more computer programs or at least one computer program itself; and The method is performed to determine information indicating whether, based on the results of the relevant comparison, respective individual or combined hardware requirements of a set of one or more computer programs or of at least one computer program itself can be satisfied by the technical properties of the computing system when or if correspondingly reconfigured, which includes a respective update of the relevant one or more requirement properties (1010).

14. The method according to any one of the preceding claims, characterized in that The computing unit is reconfigurable by adding, removing, enabling or disabling, or modifying, respectively, one or more of its hardware entities; and The method further comprises: determining an actual or planned reconfiguration of the computing unit; and The method is performed to determine information indicating whether, based on the result of the relevant comparison, the respective individual or combined hardware requirements of the one or more computer programs can be met by the technical characteristics of the computing unit when or if the corresponding reconfiguration comprises a respective update of the relevant one or more characteristic attributes (1005).

15. Method according to any one of the preceding claims, characterized in that The method further includes, in response to determining that, based on the results of the relevant comparison, the respective individual or combined hardware requirements of the one or more computer programs cannot be satisfied by the technical characteristics of the computing unit, performing one or more of the following actions: - Activate warning signal; - disabling one or more functions of the computing unit or its overall operation; - interrupting or otherwise disabling execution of at least one of the computer programs on the computing unit; - outputting further information indicating characteristic attributes (1005) or other relevant hardware requirements that cannot be met according to the results of the relevant comparison; - outputting further information indicating the extent to which the characteristic attribute (1005) or other relevant hardware requirement cannot be met according to the result of the relevant comparison; - blocking the updating of one or more computer programs or one or more computer program modules contained therein; - transmitting the comparison results to a remotely accessible computing environment or data (D) storage; - requesting or proposing to replace one or more hardware entities of the computing system or to add one or more other or additional hardware entities to the computing system so that the computing system can meet the corresponding individual or combined hardware requirements; - for a defined time interval, estimating the probability that within said time interval it will become necessary to replace or add one or more hardware entities of the computing system to meet the expected individual or combined hardware requirements, based on a trend analysis of previously occurring computer program update and / or upgrade cycles.

16. The method according to any one of the preceding claims, characterized in that The comparison includes taking into account predefined margin requirements for the computing system as further hardware requirements for determining whether the respective hardware requirements of a computer program or the combined hardware requirements of two or more computer programs can respectively be met by the technical properties of the computing system.

17. The method according to any one of the preceding claims, characterized in that The method is performed using at least one of: an operating system running on the computing system itself; a processing device of the computing system other than the computing unit.

18. Method according to any one of the preceding claims, characterized in that At least one of the computer programs involved in the comparison of the respective individual hardware requirements of one or more of the computer programs or the combined hardware requirements of a subset of the computer programs with the technical properties of the computing unit is a respective updated or upgraded version of a computer program, as a supplement or replacement for a previous version, which already belonged to the computing system.

19. The method according to claim 18, characterized in that When the evaluation result (1365) indicates that the individual hardware requirements of the updated or upgraded version or the combined hardware requirements of the subset of the computer program comprising the updated or upgraded version, respectively, cannot be satisfied by the computing system, modifying one or more operating parameters of the updated or upgraded version so as to reduce its hardware requirements, and The evaluation is repeated based on this reduced hardware requirement.

20. The method according to any one of the preceding claims, characterized in that The functions of the vehicle (800) to be centrally controlled by the computing system include, at least in part, one or more of the following: -Engine control; -Entertainment or infotainment; -illumination; -locking; -air conditioner; -brake; - Driver assistance; -navigation; -Automated or autonomous driving; -Communication inside or outside the vehicle; - the configuration of the interior of the vehicle (800); and - performing said evaluation to assess the correct functionality of the computing system with respect to its ability to correctly perform at least one or a combination of two or more of said functions.

21. The method according to any one of the preceding claims, characterized in that The method further includes an initialization process, wherein the initialization process includes one or more of the following: - automatically detecting one or more of the hardware entities and determining or receiving for each of these hardware entities its respective associated set of one or more individual characteristic attributes ( 1005 ); - receiving information specifying one or more of the hardware entities, and determining or receiving, for each of the hardware entities, a set of its corresponding associated one or more individual characteristic attributes (1005); - automatically detecting one or more of the computer programs and determining or receiving, for each of these computer programs individually or for a set comprising two or more of these computer programs, a set of associated one or more requirement attributes (1010), said requirement attributes individually or jointly representing one or more specific hardware requirements, respectively, required by the computer program or set of computer programs for its correct execution on the computing platform (700); - receiving information specifying one or more of the computer programs and determining or receiving, for each of the computer programs individually or for a set comprising two or more of the computer programs, a set of associated one or more requirement attributes (1010), the requirement attributes individually or jointly representing one or more specific hardware requirements, respectively, required by the computer program or set of computer programs for its correct execution on the computing platform (700).

22. An evaluation system for evaluating the correct functioning of a computing system, the computing system being configured as an onboard computing system for a vehicle (800) for centrally controlling different functions of the vehicle (800), and comprising a computing platform (700) having a plurality of hardware entities, and a plurality of different computer programs configured for execution on the computing platform (700) individually or concurrently; in, The evaluation system (1340) comprises a data (D) processing device comprising a processor configured to perform a method according to any one of the preceding claims for evaluating the correct functionality of a computing system.

23. A computing system configured as a centralized onboard computing system for a vehicle (800), such as a car, to centrally control different functions of the vehicle (800), wherein: The computing system comprises an evaluation system (1340) according to claim 22 for evaluating the correct functioning of the computing system itself.

24. The computing system according to claim 23, wherein: The computing system includes a central computing unit (105), CCU (105), configured as an on-board computing unit for the vehicle (800) to centrally control different functions of the vehicle (800), the CCU (105) including: a distributed computing system DCS comprising a plurality of co-located autonomous computing entities CE, each computing entity having its own separate memory, wherein the CEs are configured to communicate with each other by message passing via one or more communication networks in order to coordinate among themselves the distribution of computing tasks to be performed by the DCS as a whole; a communication switch comprising a plurality of mutually independent switch fabrics, each switch fabric being configured to variably connect a subset of or each CE of the DCS to one or more of a plurality of interfaces for exchanging information thereon with communication nodes external to the computing system of the vehicle (800); and A power supply system includes a plurality of power supply subsystems for simultaneous operation, each of the plurality of power supply subsystems being capable of individually and independently of one another powering the DCS and at least two of the switch fabrics.

25. A vehicle comprising a computing system according to claim 23 or 24 as a centralized on-board computing system.

26. A computer program or non-transitory computer-readable storage medium comprising instructions which, when executed on a computer or multiple computer platforms, cause the computer or multiple computer platforms to respectively perform the method according to any one of claims 1 to 21 to evaluate the computing system.