Vehicle-mounted controller resetting method and device, vehicle and storage medium
By optimizing the startup process of the vehicle controller and skipping unnecessary self-test procedures based on the self-test results in the memory components, the problem of excessive MCU startup time was solved, achieving fast and safe startup.
Patent Information
- Application Number
- CN202511035392.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-25
- Publication Date
- 2025-11-07
AI Technical Summary
Abnormal self-test during MCU startup can lead to increased reset or startup time, affecting vehicle safety and reliability.
By obtaining the reset command from the vehicle controller, reading the reusable self-test results from the memory components, and determining whether to skip the reusable self-test program based on the results, the startup process is optimized to reduce startup time.
It reduces the startup time of the onboard controller, improves startup efficiency, and ensures that critical tests are performed at least once per driving cycle to meet safety requirements.
Smart Images

Figure CN120909840A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of vehicles, in particular to a vehicle-mounted controller reset method and device, a vehicle and a storage medium. BACKGROUND
[0002] With the improvement of vehicle safety standards, vehicle manufacturers need to follow standards such as ISO / SAE 21434, ISO 26262, etc. The electronic system in the vehicle needs to ensure safety and reliability through specific hardware and software design, among which, MCU safe startup is a core link, which needs to ensure that the startup software is not tampered with, the MCU logic operation is normal, the firmware function can be safely run, and the fault monitoring system can timely discover and report faults.
[0003] In the MCU (Microcontroller Unit) safe startup process, the MCU on the hardware may need to support encryption operations and sensitive key storage with a dedicated HSM (Hardware Security Module), and the software needs to perform self-test on internal RAM (Random Access Memory), flash memory, peripherals, etc. to ensure the safe startup of the MCU, but if the test result is abnormal in the self-test, it may cause the MCU to reset or delay startup, which in turn may cause the MCU startup time to increase exponentially. SUMMARY
[0004] One of the purposes of the present application is to provide a vehicle-mounted controller reset method to solve the problem of reset due to self-test exception in the MCU startup process in the related art, which increases the startup time; the second purpose is to provide a vehicle-mounted controller reset device; the third purpose is to provide a vehicle; and the fourth purpose is to provide a computer-readable storage medium.
[0005] To achieve the above purposes, the technical solutions adopted by the present application are as follows:
[0006] A vehicle-mounted controller reset method comprises the following steps: obtaining a reset instruction of a vehicle-mounted controller, starting a startup process of the vehicle-mounted controller based on the reset instruction, the startup process comprising a plurality of startup stages, at least one self-test program being set in each startup stage; reading a memory component of the vehicle, the memory component being used to store self-test results allowed to be reused after the vehicle is powered on; if the self-test results allowed to be reused are read, determining self-test programs allowed to be skipped according to the self-test results allowed to be reused, and skipping the self-test programs allowed to be reused in the plurality of startup stages of the startup process.
[0007] According to the technical means, when the reset instruction of the vehicle-mounted controller is acquired, the memory component of the vehicle is read, and when the self-checking result of the multiplexing is allowed is read, the self-checking procedure of the multiplexing allowed to be skipped is determined according to the self-checking result of the multiplexing allowed to be multiplexed, so that the self-checking procedure of the multiplexing allowed to be multiplexed is skipped in the multiple start-up stages of the start-up process of the vehicle controller, thereby reducing the start-up time of the vehicle-mounted controller and improving the start-up efficiency.
[0008] Further, before reading the memory component of the vehicle, the power-on instruction of the vehicle-mounted controller is acquired, the start-up process of the vehicle-mounted controller is started based on the power-on instruction, and the multiple self-checking procedures set in each start-up stage are sequentially executed; and after the start-up process is completed, the self-checking result of the multiplexing allowed to be multiplexed is stored to the memory component.
[0009] According to the technical means, when the power-on instruction of the vehicle-mounted controller is acquired, the multiple self-checking procedures set in each start-up stage are sequentially executed, and after the start-up process is completed, the self-checking result of the multiplexing allowed to be multiplexed is stored to the memory component, so as to ensure that all necessary self-checking tests are completed when the vehicle is powered off and powered on, to meet the safety requirement that the key test is performed at least once in each driving cycle, and to lay a foundation for subsequent reset multiplexing by storing the result, so as to realize the fast start-up of the subsequent vehicle-mounted controller.
[0010] Further, the multiple start-up stages include a firmware loading stage, a boot program software stage and an application software initialization stage, wherein the firmware loading stage and the boot program software stage execute the self-checking procedure of the multiplexing allowed to be multiplexed, and the application software initialization stage executes the self-checking procedure of the multiplexing not allowed to be multiplexed.
[0011] According to the technical means, the firmware loading stage and the boot program software stage of the embodiment of the application execute the self-checking procedure of the multiplexing allowed to be multiplexed, and the application software initialization stage executes the self-checking procedure of the multiplexing not allowed to be multiplexed, so as to reduce the time length caused by the reset and re-self-checking due to the self-checking failure of the self-checking procedure of the multiplexing allowed to be multiplexed.
[0012] Further, the self-checking procedure of the multiplexing allowed to be multiplexed includes a logic self-checking procedure, a power management integrated circuit self-checking procedure and a hardware security module self-checking procedure, and the self-checking procedure of the multiplexing not allowed to be multiplexed includes a memory self-checking procedure, a power management monitoring self-checking procedure, a register monitoring self-checking procedure, a death temperature monitoring self-checking procedure, a safety management unit alarm mechanism self-checking procedure, a special function register self-checking procedure and a firmware inspection self-checking procedure, wherein the firmware loading stage executes the logic self-checking procedure, and the boot program software stage executes the power management integrated circuit self-checking procedure and the hardware security module self-checking procedure.
[0013] Further, the boot program software stage verifies the self-checking result of the self-checking procedure of the multiplexing allowed to be multiplexed, executes the next stage if the verification passes, and re-triggers the self-checking procedure of the multiplexing allowed to be multiplexed if the verification fails.
[0014] According to the above technical means, the self-checking result of the self-checking program allowed to be reused is allowed to be verified by the boot program software stage verification, if the verification is passed, the next stage is executed, if the verification is not passed, the self-checking program allowed to be reused is triggered again, and when the self-checking result of the self-checking program allowed to be reused is passed at last time, the result of the self-checking passed at last time can be reused, so that the safe starting time of the vehicle-mounted controller is reduced.
[0015] Further, the self-checking program allowed to be skipped is determined according to the self-checking result allowed to be reused, including: obtaining a correspondence table of the self-checking result allowed to be reused and the self-checking program allowed to be skipped; and taking the self-checking result allowed to be reused as an index, querying the correspondence table to obtain the self-checking program allowed to be skipped.
[0016] According to the above technical means, the self-checking program allowed to be skipped is obtained by taking the self-checking result allowed to be reused as an index and querying the correspondence table, so that the self-checking program allowed to be skipped is quickly determined through a standardized query mechanism, the time consumption of logical judgment during starting is reduced, and the starting time is further optimized.
[0017] Further, the memory component resets the stored data after the vehicle is powered off.
[0018] According to the above technical means, the memory component resets the stored data after the vehicle is powered off, that is, the self-checking result, so as to ensure that there is no old self-checking result in the memory component when the vehicle is powered on again after being powered off, and all self-checking programs must be executed again, so as to ensure the safety target of testing at least once in a driving cycle.
[0019] A vehicle-mounted controller reset device, comprising: an acquisition module, configured to acquire a reset instruction of a vehicle-mounted controller, and start a starting process of the vehicle-mounted controller based on the reset instruction, the starting process comprising a plurality of starting stages, and at least one self-checking program being arranged in each starting stage; a reading module, configured to read a memory component of a vehicle, the memory component being used to store a self-checking result allowed to be reused after the vehicle is powered on; and a determination module, configured to determine a self-checking program allowed to be skipped according to the self-checking result allowed to be reused if the self-checking result allowed to be reused is read, and skip the self-checking program allowed to be reused in the plurality of starting stages of the starting process.
[0020] Further, the device further comprises: a starting module, configured to acquire a power-on instruction of the vehicle-mounted controller before reading the memory component of the vehicle, start the starting process of the vehicle-mounted controller based on the power-on instruction, and execute the plurality of self-checking programs arranged in each starting stage in sequence; and after the starting process is completed, store the self-checking result allowed to be reused to the memory component.
[0021] Further, the plurality of start-up stages include a firmware loading stage, a bootloader software stage, and an application software initialization stage, wherein the firmware loading stage and the bootloader software stage perform self-check procedures that allow multiplexing, and the application software initialization stage performs self-check procedures that do not allow multiplexing.
[0022] Further, the self-check procedures that allow multiplexing include a logic self-check procedure, a power management integrated circuit self-check procedure, and a hardware security module self-check procedure, and the self-check procedures that do not allow multiplexing include a memory self-check procedure, a power management monitoring self-check procedure, a register monitoring self-check procedure, a death temperature monitoring self-check procedure, a security management unit alarm mechanism self-check procedure, a special function register self-check procedure, and a firmware inspection self-check procedure, wherein the firmware loading stage performs the logic self-check procedure, and the bootloader software stage performs the power management integrated circuit self-check procedure and the hardware security module self-check procedure.
[0023] Further, the bootloader software stage verifies the self-check results of the self-check procedures that allow multiplexing, and if the verification is passed, the next stage is executed, and if the verification is not passed, the self-check procedures that allow multiplexing are re-triggered.
[0024] Further, the determining module is further configured to: obtain a correspondence table of the self-check results that allow multiplexing and the self-check procedures that allow skipping; and query the correspondence table by using the self-check results that allow multiplexing as an index to obtain the self-check procedures that allow skipping.
[0025] Further, the memory component resets the stored data after the vehicle is powered off.
[0026] A vehicle includes a memory, a processor, and a computer program stored on the memory and executable on the processor, and the processor executes the program to implement the vehicle controller reset method of the above embodiments.
[0027] A computer readable storage medium having stored thereon a computer program or instructions executable by a processor for implementing the vehicle controller reset method of the above embodiments.
[0028] Advantages of the present application:
[0029] (1) When the reset instruction of the vehicle controller is obtained, the memory component of the vehicle can be read, and when the self-check results that allow multiplexing are read, the corresponding self-check procedures that allow skipping are determined according to the self-check results that allow multiplexing, so that the self-check procedures that allow multiplexing are skipped in the plurality of start-up stages of the start-up process of the vehicle controller, thereby reducing the start-up time of the vehicle controller and improving the start-up efficiency.
[0030] (2) When the power-on command of the vehicle controller is obtained, multiple self-test programs set in each startup stage can be executed sequentially. After the startup process is completed, the reusable self-test results are stored in the memory component to ensure that all necessary self-tests are completed when the vehicle is powered off and powered on again, meeting the safety requirement of performing key tests at least once per driving cycle. The stored results lay the foundation for subsequent reset reuse, so as to enable the rapid startup of the vehicle controller.
[0031] (3) The firmware loading stage and the bootloader software stage execute the self-test program that can be reused, while the application software initialization stage executes the self-test program that cannot be reused, so as to reduce the time caused by the reset and retest due to the failure of the self-test program that can be reused.
[0032] (4) The boot program software stage verifies the self-test results of the self-test program that can be reused. If the verification passes, the next stage is executed. If the verification fails, the self-test program that can be reused is retried. If the self-test program that can be reused passed the self-test result during the last reset, it can reuse the result that passed the self-test during the last reset to reduce the safe startup time of the vehicle controller.
[0033] (5) Using the reusable self-check results as an index, query the corresponding relationship table to obtain the self-check procedures that can be skipped. The skipped self-check procedures are quickly determined through a standardized query mechanism, reducing the time consumed by logical judgment at startup and further optimizing startup time.
[0034] (6) The memory component resets the stored data, i.e. the self-test results, after the vehicle is powered off, to ensure that when the vehicle is powered on again, there are no old self-test results in the memory component. All self-test procedures must be re-executed to ensure that the safety goal of at least one test is achieved during the driving cycle. Attached Figure Description
[0035] Figure 1 This is a flowchart of the vehicle controller reset method proposed according to an embodiment of the present invention;
[0036] Figure 2 This is a flowchart illustrating the startup process of the vehicle controller according to a specific embodiment of the present invention;
[0037] Figure 3 This is a schematic diagram illustrating the division of the vehicle controller startup phase according to a specific embodiment of the present invention;
[0038] Figure 4 This is a flowchart illustrating the optimized startup process of the vehicle controller according to a specific embodiment of the present invention;
[0039] Figure 5 This is a schematic diagram of an on-board controller reset device according to an embodiment of the present invention;
[0040] Figure 6 A structural schematic diagram of a vehicle according to an embodiment of the present application. DETAILED DESCRIPTION
[0041] Other advantages and effects of the present application can be easily understood by those skilled in the art from the above description of the embodiments of the present application. The present application can also be implemented or applied in other different specific embodiments, and various modifications or changes can be made to the details of the present application based on different views and applications without departing from the spirit of the present application. It should be understood that the preferred embodiments are only for illustrating the present application, but not for limiting the protection scope of the present application.
[0042] It should be noted that the diagrams provided in the following embodiments only schematically illustrate the basic concept of the present application, and only the components related to the present application are shown in the diagrams, but not the number, shape and size of the components when actually implemented. The shapes, number and proportions of the components when actually implemented can be arbitrarily changed, and the layout pattern of the components can also be more complex.
[0043] Specifically, Figure 1 A flowchart of a vehicle controller reset method according to an embodiment of the present application.
[0044] As Figure 1 shown, the vehicle controller reset method includes the following steps:
[0045] In step S101, a reset instruction of a vehicle controller is acquired, and a startup process of the vehicle controller is started based on the reset instruction. The startup process includes multiple startup stages, and at least one self-checking program is set in each startup stage.
[0046] The vehicle controller is an MCU; the reset instruction is an instruction for triggering the MCU to restart, including hot reset (also referred to as hot startup, restart caused by an exception, and the vehicle is not powered off) and cold reset (also referred to as cold startup, startup after power on after power off); the startup process is the whole process from power on to normal operation of the MCU, and the multiple startup stages include a firmware loading stage, a BOOT software stage and an application software initialization stage; and the self-checking program is a program for checking in the startup stage of the MCU to ensure the safe startup of the MCU.
[0047] It can be understood that the embodiment of the present application can acquire the reset instruction of the vehicle controller MCU, and start the startup process of the vehicle controller based on the reset instruction.
[0048] In step S102, a memory component of the vehicle is read, the memory component being configured to store results of self-tests that are allowed to be reused after power-up of the vehicle.
[0049] The memory component can be a NVM (Non-Volatile Memory) component that stores the results of self-tests that are allowed to be reused after power-up of the vehicle, which can be understood as the results of the tests at the last reset being allowed to be reused.
[0050] In the embodiment of the application, the memory component resets the stored data after power-down of the vehicle.
[0051] It can be understood that the memory component of the embodiment of the application resets the stored data, i.e. the results of the self-tests, after power-down of the vehicle, so as to ensure that no old test results are stored in the memory component when the MCU is cold started (power-up after power-down of the vehicle), and all self-tests must be performed again, thereby ensuring the safety goal of testing at least once in a driving cycle.
[0052] In the embodiment of the application, before reading the memory component of the vehicle, the method further comprises: obtaining a power-up instruction of the vehicle controller, starting a start-up process of the vehicle controller based on the power-up instruction, and sequentially performing a plurality of self-test programs set in each start-up stage; and after the start-up process is completed, storing the results of the self-tests that are allowed to be reused in the memory component.
[0053] The power-up instruction is the first power-up instruction after power-down of the vehicle, and is a cold start of the vehicle.
[0054] It can be understood that the embodiment of the application can sequentially perform a plurality of self-test programs set in each start-up stage when the power-up instruction of the vehicle controller is obtained, and store the results of the self-tests that are allowed to be reused in the memory component after the start-up process is completed, so as to ensure that all necessary safety tests are completed when the vehicle is cold started, to meet the safety requirement of performing a key test at least once in each driving cycle, and to lay a foundation for reuse of hot reset by storing the results, so as to facilitate subsequent fast start of the vehicle controller.
[0055] In the embodiment of the application, the plurality of start-up stages include a firmware loading stage, a bootloader software stage and an application software initialization stage, wherein the firmware loading stage and the bootloader software stage perform the self-test programs that are allowed to be reused, and the application software initialization stage performs the self-test programs that are not allowed to be reused; the self-test programs that are allowed to be reused include a logic self-test program, a power management integrated circuit self-test program and a hardware security module self-test program, and the self-test programs that are not allowed to be reused include a memory self-test program, a power management monitoring self-test program, a register monitoring self-test program, a death temperature monitoring self-test program, a safety management unit alarm mechanism self-test program, a special function register self-test program and a firmware check self-test program.
[0056] The startup stage can be divided with reference to a chip manual, the firmware loading stage is to define the startup mode, address and default configuration through a firmware configuration word, cannot customize software, mainly executes the basic hardware initialization related test, the BOOT software stage is the earliest stage of the customizable software, executes the power management integrated circuit self-check, hardware security module self-check and the like reusable program, the application software initialization stage is the late stage of the startup, executes the memory self-check, register monitoring and the like program which must be executed every time startup.
[0057] Through the division of the above stages, the test task boundary of each stage is clear, irrelevant test cross execution is avoided, the logicality of the startup process is optimized, meanwhile, the core safety test (not reusable) is ensured to be completed in the startup stage, and the safety target of the vehicle-mounted controller during startup is not affected.
[0058] It should be noted that whether each self-check program causes the vehicle-mounted controller to reset or whether the self-check result allows reuse is determined based on its characteristics.
[0059] In the embodiment of the application, the firmware loading stage executes a logic self-check program, and the boot program software stage executes a power management integrated circuit self-check program and a hardware security module self-check program.
[0060] Since the firmware loading stage is the earliest stage of the startup process, is responsible for basic hardware initialization, and the logic self-check is a self-detection on the storage and logic circuit in the internal integrated circuit, belongs to the most basic hardware function verification, therefore needs to be completed in the earliest stage of the startup process, provides hardware basis guarantee for the test and running of the subsequent boot program software stage and application software initialization stage, and the startup stage can define that the software is the earliest in the boot program software stage, and the power management integrated circuit self-check program and the hardware security module self-check program will cause the MCU to reset, therefore, they are placed in the BOOT software stage, so that when the reset occurs, only a small amount of process in the early stage needs to be re-executed, and the late-stage large amount of self-check programs are avoided from being repeatedly executed, thereby reducing time loss.
[0061] In the embodiment of the application, the boot program software stage checks the self-check result of the self-check program allowed to be reused, if the checking passes, the next stage is executed, and if the checking does not pass, the self-check program allowed to be reused is retriggered.
[0062] It can be understood that the boot program software stage of the embodiment of the application checks the self-check result of the self-check program allowed to be reused, if the checking passes, the next stage is executed, and if the checking does not pass, the self-check program allowed to be reused is retriggered, when the self-check result of the self-check program allowed to be reused passes in the last reset, the result of the self-check passing in the last reset can be reused, so as to reduce the safety startup time length of the vehicle-mounted controller, and if the self-check does not pass in the last reset, the self-check program allowed to be reused is retriggered.
[0063] In step S103, if the multiplexing-allowed self-checking result is read, the self-checking procedure allowed to be skipped is determined according to the multiplexing-allowed self-checking result, and the multiplexing-allowed self-checking procedure is skipped in multiple start-up stages of the start-up process.
[0064] It can be understood that, after the multiplexing-allowed self-checking result is read, the self-checking procedure allowed to be skipped is determined according to the multiplexing-allowed self-checking result, so as to skip the multiplexing-allowed self-checking procedure in multiple start-up stages of the start-up process, and the start-up time of the vehicle-mounted controller is shortened under the premise of ensuring safety by multiplexing the passed self-checking procedure.
[0065] In the embodiment of the present application, the self-checking procedure allowed to be skipped is determined according to the multiplexing-allowed self-checking result, including: obtaining a correspondence table of the multiplexing-allowed self-checking result and the self-checking procedure allowed to be skipped; and querying the correspondence table with the multiplexing-allowed self-checking result as an index to obtain the self-checking procedure allowed to be skipped.
[0066] The correspondence table is pre-set and used to calibrate the multiplexing-allowed self-checking result and the self-checking procedure allowed to be skipped.
[0067] It can be understood that, in the embodiment of the present application, the self-checking procedure allowed to be skipped is obtained by querying the correspondence table with the multiplexing-allowed self-checking result as an index, so that the self-checking procedure allowed to be skipped is quickly determined through a standardized query mechanism, the time consumption of logical judgment during start-up is reduced, and the start-up time is further optimized.
[0068] The vehicle-mounted controller reset method of the embodiment of the present application will be described below with a specific embodiment taken as an example, in which Infineon TC39x is matched with TLF35585 PMIC hardware, and the overall process is as shown in Figure 2 .
[0069] Step S11: The safety confirmation components (i.e., self-checking procedures) are sorted and analyzed from three dimensions of whether to reset, whether to test cold start, test the multiplexing test result of hot start, and the necessity of test during the start-up process.
[0070] The safety confirmation components are introduced as follows:
[0071] The MCU logic self-checking is a self-detection of the storage and logic circuit in the integrated circuit of the MCU, and at least one logic self-checking needs to be performed every driving cycle. After the logic self-checking is completed, the MCU will restart.
[0072] PMIC (power management integrated circuit) self-test is to detect whether the power management module has normal power management capability, make correct diagnosis and shut down in time for power supply abnormality. The PMIC self-test test process will cause the MCU to reset.
[0073] HSM (Hardware Security Module) has independent processor core, and can run in parallel with the MCU. If the HSM test result is not passed, the software in the current Flash may be illegally tampered with, and the system should restart the MCU.
[0074] PMSMON BIST (Power Management System Monitor Built-In Self Test) (i.e. MONBIST in Table 1) ensures that the power management module monitoring mechanism is effective, and needs to be executed once in the startup phase, and the SMU alarm will be triggered in the test process.
[0075] REGMON (Register Monitor Test) (i.e. REGBIST in Table 1) aims to verify whether the register security monitoring mechanism is effective, and the SMU alarm may be triggered in the test process.
[0076] MBIST (Memory Built-In Self Test) implements comprehensive testing of the memory, and verifies the MCU corresponding memory test process to initialize the test memory, which must be completed in the MCU startup phase.
[0077] DTS (Die Temperature Monitor) (i.e. DTCBIST in Table 1) includes two tests that the difference between the two temperature sensors is not more than 9℃ and the current temperature obtained by the temperature sensor is not more than the limit temperature value. The test system will continuously monitor during system operation, and can not be executed in the startup phase.
[0078] Firmware check aims to check whether the initial state of the MCU firmware is in the known initialization state, and the test must be executed in the startup phase.
[0079] SMU (Safety Management Unit) alarm mechanism test is used to confirm the possible errors in the SMU core, and to ensure that the SMU core is reliable before startup, which should be completed in the startup phase.
[0080] Special function register: special function register is used to confirm that the special function register is initially in the default security state, and the test needs to be performed in the startup phase.
[0081] The analysis result is shown in Table 1, which is an analysis table of the security confirmation component.
[0082] Table 1
[0083]
[0084] Referring to the chip manual, the startup phase is divided into three phases of firmware loading, BOOT software, and application software startup initialization, as shown in Figure 3 . Among them, the firmware loading phase defines the startup mode, address and part of the default initial configuration through the firmware configuration word, and cannot customize software. The startup phase can customize software earliest in the BOOT software phase.
[0085] Step S12: Based on the analysis of step S11, adjust the startup test execution position and sequence.
[0086] In order to reduce the influence of MCU reset on system startup time, combined with the MCU startup firmware configuration word, the MCU logic self-check is triggered through the configuration word in the firmware phase, and the test result of the MCU logic self-check is checked in the BOOT software. If the test result does not pass, the LBIST register is configured by software to trigger the test again. The MCU logic self-check can cover hardware random failure by performing a test once in a driving cycle, so the logic self-check can not be performed after the reset (i.e. hot start) during software running, and the last cold start test result can be reused.
[0087] Similarly, in order to reduce the influence of MCU reset on system startup time, the PMIC self-check test is performed in the BOOT software to reduce the influence of MCU reset caused by PMIC self-check on startup time. The power management chip only needs to perform a self-check test within its own survival period to ensure the reliability of the power management chip. MCU hot reset PMIC will not power off, and will not affect the PMIC survival state, so the MCU hot reset can reuse the last PMIC self-check test result, and the PMIC self-check test is not performed.
[0088] Similarly, in order to reduce the influence of MCU reset on system startup time, the software integrity and correctness need to be confirmed before starting the application software, and the HSM result verification must be performed in the BOOT software. The HSM result verification can cover the failure by performing a test once in a driving cycle, so the HSM verification can not be performed after the reset (i.e. hot start) during software running, and the last cold start test result can be reused.
[0089] Considering that the above test only needs to be executed once by the MCU cold start, if the cold start test result passes, the MCU hot reset does not execute the above test. The test result needs to be stored in a specific location in the NVM that is not initialized by the hot reset. Each time the startup process queries the test result stored in the specific location NVM according to the startup type, if the current MCU startup type is hot reset and the test result stored on the NVM is passed, the execution of this test is skipped. If the hot reset but the test result stored on the NVM is failed, the software triggers the test.
[0090] DTS (Die temperature sensor) redundant temperature sensor difference verification is continuously monitored during system operation, and the test can not be executed in the startup stage. The DTS test is removed from the startup test, and the periodic test is used to cover the latent failure of the excessive difference of the redundant temperature sensor.
[0091] The remaining tests must be tested at least once in the startup stage, and the comprehensive test modifies the register default value and generates the SMU alarm. The optimized safety startup process of the Infineon TC39x combined with the TLF35585 PMIC is as shown in Figure 4 .
[0092] The adjusted startup process does not reduce the test items. According to the project Infineon TC39x FMEDA (Failure Modes Effects and Diagnostic Analysis, failure mode effect and diagnostic analysis), it is calculated that the adjustment of the startup process does not affect the overall safety target of the software.
[0093] Step S13: Run the adjusted software, test the MCU startup time, and compare the startup time before optimization. It is found that the time is shortened by about 140 ms under the condition that there is no test failure leading to reset in normal startup.
[0094] In summary, the vehicle-mounted controller reset method of the embodiment of the application comprises:
[0095] 1. The tests that may cause reset are arranged at the front of the startup software to maximize the reduction of the influence of reset on the startup time.
[0096] 2. The test results are reused. Part of the MCU test only needs to be executed once during cold reset to ensure the safety and reliability of the MCU. The test result is saved in a specific location, and the hot reset does not execute the test result reuse cold reset test.
[0097] 3. The self-test test that is not necessary to be executed in the startup stage is moved from the startup stage to the software periodic operation process after the MCU startup.
[0098] The vehicle-mounted controller reset method provided by the embodiment of the present application can read the memory component of the vehicle when the reset instruction of the vehicle-mounted controller is acquired, read the self-check result of the allowed reuse, determine the self-check procedure of the allowed skip according to the self-check result of the allowed reuse, and skip the self-check procedure of the allowed reuse in the multiple start stages of the start flow of the vehicle controller, thereby reducing the start duration of the vehicle-mounted controller and improving the start efficiency.
[0099] Secondly, the parameter attached drawing describes the vehicle-mounted controller reset device provided by the embodiment of the present application.
[0100] Figure 5 The schematic diagram of the vehicle-mounted controller reset device provided by the embodiment of the present application is shown.
[0101] As shown in the drawing, Figure 5 The vehicle-mounted controller reset device 10 includes an acquisition module 100, a reading module 200 and a determination module 300.
[0102] The acquisition module 100 is configured to acquire the reset instruction of the vehicle-mounted controller, start the start flow of the vehicle-mounted controller based on the reset instruction, and the start flow includes multiple start stages, and at least one self-check procedure is arranged in each start stage; the reading module 200 is configured to read the memory component of the vehicle, and the memory component is configured to store the self-check result of the allowed reuse after the vehicle is powered on; and the determination module 300 is configured to determine the self-check procedure of the allowed skip according to the self-check result of the allowed reuse if the self-check result of the allowed reuse is read, and skip the self-check procedure of the allowed reuse in the multiple start stages of the start flow.
[0103] In the embodiment of the present application, the device 10 of the embodiment of the present application further includes a start module.
[0104] The start module is configured to acquire the power-on instruction of the vehicle-mounted controller before reading the memory component of the vehicle, start the start flow of the vehicle-mounted controller based on the power-on instruction, and sequentially execute the multiple self-check procedures arranged in each start stage; and after the start flow is completed, the self-check result of the allowed reuse is stored to the memory component.
[0105] In the embodiment of the present application, the multiple start stages include a firmware loading stage, a boot program software stage and an application software initialization stage, wherein the firmware loading stage and the boot program software stage execute the self-check procedure of the allowed reuse, and the application software initialization stage executes the self-check procedure of the not allowed reuse.
[0106] In the embodiment of the present application, the self-check procedures allowed to be multiplexed include a logic self-check procedure, a power management integrated circuit self-check procedure and a hardware security module self-check procedure, and the self-check procedures not allowed to be multiplexed include a memory self-check procedure, a power management monitoring self-check procedure, a register monitoring self-check procedure, a death temperature monitoring self-check procedure, a security management unit alarm mechanism self-check procedure, a special function register self-check procedure and a firmware inspection self-check procedure, wherein the logic self-check procedure is executed in the firmware loading stage, and the power management integrated circuit self-check procedure and the hardware security module self-check procedure are executed in the boot program software stage.
[0107] In the embodiment of the present application, the boot program software stage verifies the self-check results of the self-check procedures allowed to be multiplexed, and if the verification is passed, the next stage is executed, and if the verification is not passed, the self-check procedures allowed to be multiplexed are retriggered.
[0108] In the embodiment of the present application, the determining module 300 is further configured to: acquire a correspondence table of the self-check results allowed to be multiplexed and the self-check procedures allowed to be skipped; and query the correspondence table by taking the self-check results allowed to be multiplexed as an index to obtain the self-check procedures allowed to be skipped.
[0109] In the embodiment of the present application, the memory component resets the stored data after the vehicle is powered off.
[0110] The vehicle controller reset device provided in the embodiment of the present application can read the memory component of the vehicle when the reset instruction of the vehicle controller is acquired, and determine the self-check procedures allowed to be skipped according to the self-check results allowed to be multiplexed when the self-check results allowed to be multiplexed are read, so as to skip the self-check procedures allowed to be multiplexed in the multiple start stages of the start process of the vehicle controller, thereby reducing the start time length of the vehicle controller and improving the start efficiency.
[0111] Figure 6 A structural schematic diagram of a vehicle is provided in the embodiment of the present application. The vehicle can include:
[0112] The memory 601, the processor 602 and the computer program stored in the memory 601 and executable on the processor 602.
[0113] The processor 602 implements the vehicle controller reset method provided in the above embodiment when executing the program.
[0114] Further, the vehicle further includes:
[0115] The communication interface 603 is configured to communicate between the memory 601 and the processor 602.
[0116] The memory 601 is configured to store the computer program executable on the processor 602.
[0117] The memory 601 can include a high-speed RAM memory and can also include a non-volatile memory, such as at least one disk memory.
[0118] If the memory 601, the processor 602 and the communication interface 603 are implemented independently, the communication interface 603, the memory 601 and the processor 602 can be connected to each other through a bus and complete communication between each other. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For convenience of representation, Figure 6 Only one thick line is used in the figure to represent the bus, but it does not mean that there is only one bus or only one type of bus.
[0119] Optionally, in a specific implementation, if the memory 601, the processor 602 and the communication interface 603 are integrated on a chip, the memory 601, the processor 602 and the communication interface 603 can complete communication between each other through an internal interface.
[0120] The processor 602 can be a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement embodiments of the present application.
[0121] The embodiments of the present application also provide a computer readable storage medium, which stores a computer program or instructions, and the computer program or instructions are executed by a processor to implement the vehicle-mounted controller reset method.
[0122] The above embodiments are only preferred embodiments of the present application, and the protection scope of the present application is not limited thereto. Any equivalent replacement or transformation of the present application based on the present application is within the protection scope of the present application.
[0123] In the description of the present specification, the description of the terms "one embodiment", "some embodiments", "an example", "a specific example", or "some examples" and the like means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In the present specification, the illustrative description of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any appropriate manner in any one or N embodiments or examples. In addition, the person skilled in the art can combine and combine the different embodiments or examples described in the present specification and the features of the different embodiments or examples, without contradiction.
[0124] In addition, the terms "first", "second" are only for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined with "first", "second" can explicitly or implicitly include at least one of the features. In the description of the present application, the meaning of "N" is at least two, for example, two, three, etc., unless otherwise specifically limited.
[0125] Any process or method descriptions in flow charts or described herein in other ways can be understood as representing code modules, segments, or portions of code that include one or N executable instructions for implementing the specified logical functions or processes, and the scope of the preferred embodiments of the present application includes additional implementation in which the functions are carried out in different orders, in substantially simultaneous fashion, or in reverse order, depending on the functionality involved, as will be understood by those skilled in the art.
[0126] It should be understood that parts of the present application can be implemented in hardware, software, firmware or a combination thereof. In the above-described embodiments, N steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. As in another embodiment, if implemented in hardware, any one or a combination of the following technologies known in the art can be used: discrete logic circuit with logic gate circuit for implementing logical functions on data signals, application specific integrated circuit with suitable combination logic gate circuit, programmable gate array, field programmable gate array, etc.
[0127] Those skilled in the art of the present technology can understand that all or part of the steps carried out by the above-described embodiment method can be completed by a program instructing the relevant hardware, and the program can be stored in a computer readable storage medium. The program, when executed, includes one or a combination of the steps of the method embodiment.
Claims
1. A method for resetting an in-vehicle controller, the method comprising: The method comprises the following steps: obtaining a reset instruction of the vehicle-mounted controller, and starting a starting process of the vehicle-mounted controller based on the reset instruction, wherein the starting process comprises multiple starting stages, and at least one self-checking program is arranged in each starting stage; reading a memory component of the vehicle, wherein the memory component is used to store self-checking results allowed to be reused after the vehicle is powered on; if the self-checking results allowed to be reused are read, determining self-checking programs allowed to be skipped according to the self-checking results allowed to be reused, and skipping the self-checking programs allowed to be reused in the multiple starting stages of the starting process.
2. The vehicle controller reset method of claim 1, wherein, Before the memory component of the vehicle is read, the method further comprises the following steps: obtaining a power-on instruction of the vehicle-mounted controller, and starting a starting process of the vehicle-mounted controller based on the power-on instruction, and sequentially executing multiple self-checking programs arranged in each starting stage; after the starting process is completed, the self-checking results allowed to be reused are stored in the memory component.
3. The vehicle-mounted controller reset method according to claim 1 or 2, characterized by, The multiple starting stages comprise a firmware loading stage, a bootloader software stage and an application software initialization stage, wherein the firmware loading stage and the bootloader software stage execute the self-checking programs allowed to be reused, and the application software initialization stage executes the self-checking programs not allowed to be reused.
4. The vehicle controller reset method of claim 3, wherein, The self-checking programs allowed to be reused comprise a logic self-checking program, a power management integrated circuit self-checking program and a hardware security module self-checking program, and the self-checking programs not allowed to be reused comprise a memory self-checking program, a power management monitoring self-checking program, a register monitoring self-checking program, a death temperature monitoring self-checking program, a security management unit alarm mechanism self-checking program, a special function register self-checking program and a firmware check self-checking program, wherein the firmware loading stage executes the logic self-checking program, and the bootloader software stage executes the power management integrated circuit self-checking program and the hardware security module self-checking program.
5. The vehicle controller reset method of claim 3, wherein, The bootloader software stage verifies the self-checking results of the self-checking programs allowed to be reused, and if the verification is passed, the next stage is executed, and if the verification is not passed, the self-checking programs allowed to be reused are retriggered.
6. The vehicle controller reset method of claim 1, wherein, The method of determining the self-checking programs allowed to be skipped according to the self-checking results allowed to be reused comprises the following steps: obtaining a correspondence table of the self-checking results allowed to be reused and the self-checking programs allowed to be skipped; using the self-checking results allowed to be reused as an index, querying the correspondence table to obtain the self-checking programs allowed to be skipped.
7. The vehicle controller reset method of claim 1, wherein, The memory component resets the stored data after the vehicle is powered off.
8. An in-vehicle controller reset device, characterized by comprising: The method comprises the following steps: a obtaining module is configured to obtain a reset instruction of the vehicle-mounted controller, and start a starting process of the vehicle-mounted controller based on the reset instruction, wherein the starting process comprises multiple starting stages, and at least one self-checking program is arranged in each starting stage; a reading module is configured to read a memory component of the vehicle, wherein the memory component is used to store self-checking results allowed to be reused after the vehicle is powered on; a determining module is configured to, if the self-checking results allowed to be reused are read, determine self-checking programs allowed to be skipped according to the self-checking results allowed to be reused, and skip the self-checking programs allowed to be reused in the multiple starting stages of the starting process.
9. A vehicle characterized by comprising: The method comprises the following steps: A memory, a processor, and a computer program stored on the memory and executable on the processor, the processor executing the program to implement the vehicle controller reset method of any of claims 1-7.
10. A computer readable storage medium having stored thereon a computer program or instructions, characterized in that, The computer program or instructions are executed by a processor for implementing the vehicle controller reset method of any of claims 1-7.