Communication chip

By introducing a safety verification mechanism for the communication module and the anomaly response module into the communication chip of the intelligent driving system, the problem of insufficient functional safety defect diagnosis in the existing technology is solved, the high reliability and stability of the communication chip are achieved, and the safety of the system is improved.

CN120934879APending Publication Date: 2025-11-11CHENGDU TIANFU INVO TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511232343.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-29
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Existing intelligent driving system communication chips lack effective defect diagnosis design at the functional safety level, resulting in insufficient communication security and affecting the overall reliability of the vehicle.

Method used

Design a communication chip that includes a communication module and an anomaly response module. By performing security verification on received data frames, it detects abnormal data and executes security response operations or triggers the anomaly response module when an anomaly is detected. This adjusts the chip's operating state and includes multi-layered security mechanisms such as power management, temperature management, storage monitoring, and system detection.

Benefits of technology

It improves the reliability and stability of communication chips, meets the high communication security requirements of intelligent driving systems, reduces the risk of failure, and ensures the safety and reliability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120934879A_ABST
    Figure CN120934879A_ABST
Patent Text Reader

Abstract

The invention provides a communication chip, and relates to the field of intelligent driving. The communication chip comprises a communication module and an abnormal response module, and the communication module is configured to receive a current data frame and perform security verification on the current data frame; if the abnormal data which does not pass the security verification exists in the current data frame, executing a security response operation, and controlling the running state of the communication chip; or, triggering an abnormal response module, so that the abnormal response module controls the operation state of the communication chip; wherein the safety response operation represents measures taken for protecting the functional safety of the communication chip, and the running state of the communication chip represents the communication capability of the communication chip at a specific moment. According to the invention, the abnormal condition in the current data frame can be found in time, the function security of the communication chip is improved, and the stability and reliability of the communication chip are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of intelligent driving technology, specifically to a communication chip. Background Technology

[0002] With the rapid development of intelligent driving technology, users are paying more and more attention to vehicle safety, especially placing higher demands on the communication security of intelligent driving systems.

[0003] Understandably, communication security, as a crucial component of intelligent driving system security, directly impacts the overall reliability of the vehicle. However, many current intelligent driving systems prioritize the implementation of communication functions and the improvement of communication performance in their communication chips, rarely considering defect diagnosis and design at the functional safety level. Summary of the Invention

[0004] In view of this, embodiments of this application provide a communication chip.

[0005] In a first aspect, one embodiment of this application provides a communication chip, including a communication module and an exception response module. The communication module is configured to: receive a current data frame and perform a security check on the current data frame; if there is abnormal data in the current data frame that fails the security check, then perform a security response operation and control the operating state of the communication chip; or, trigger the exception response module so that the exception response module controls the operating state of the communication chip; wherein, the security response operation represents the measures taken to protect the functional safety of the communication chip, and the operating state of the communication chip represents the communication capability of the communication chip at a specific moment.

[0006] In conjunction with the first aspect, in some implementations of the first aspect, the communication module is further configured to: generate self-processing status indication information, and / or classify abnormal data to determine the classification information of the abnormal data; send the self-processing status indication information and / or the classification information of the abnormal data to the abnormal response module so that the abnormal response module can record it; discard the current data frame and capture multiple time-related data frames after the current data frame; perform security verification on the multiple time-related data frames; and control the operating status of the communication chip based on the verification results.

[0007] In conjunction with the first aspect, in some implementations of the first aspect, the communication module is further configured to: if the verification result shows that at least a target proportion of the data frames among multiple time-series associated data frames contain abnormal data that has failed the security verification, then generate an abnormal alarm command and autonomously control the communication chip to enter a communication interruption state or a communication abnormal state; wherein, in the communication interruption state, the communication chip only sends the abnormal alarm command and the classification information of the abnormal data to other modules through the abnormal response module; in the communication abnormal state, the communication module adds abnormal tags to the abnormal data existing in the multiple time-series associated data frames so that other modules can identify the abnormal data existing in the multiple time-series associated data frames, and maintain communication function and send the abnormal alarm command to other modules through the abnormal response module.

[0008] In conjunction with the first aspect, in some implementations of the first aspect, the communication module is further configured to: maintain the current operating state of the communication chip if the verification result shows that multiple time-related data frames have passed the security verification; and, when the verification result shows that multiple time-related data frames have passed the security verification, the communication module is further configured to: record the current data frame so that when multiple time-related data frames are sent to other modules, the other modules are prompted that the current data frame has been discarded; and / or, clear the recorded current data frame when the communication module is powered on again.

[0009] In conjunction with the first aspect, in some implementations of the first aspect, the communication module is further configured to: generate an abnormal alarm command and send the abnormal alarm command to the abnormal response module; the abnormal response module is configured to: receive the abnormal alarm command and control the communication chip to enter a communication interruption state or a communication abnormal state.

[0010] In conjunction with the first aspect, in some implementations of the first aspect, the communication chip also includes a power management module, which is configured to: detect the voltage of the input power supply of the communication chip; if the voltage of the input power supply is abnormal, cut off the input power supply of the communication chip and prevent the communication chip from sending relevant instructions to other modules.

[0011] In conjunction with the first aspect, in some implementations of the first aspect, the communication chip further includes a temperature management module; the temperature management module is configured to: collect the operating temperature of the communication chip; if the operating temperature exceeds the set maximum operating temperature value and exceeds the target duration of the state, then send the operating temperature abnormality information to the abnormality response module; the abnormality response module is configured to: control the communication chip to enter a standby state based on the operating temperature abnormality information, wherein, in the standby state, the communication chip maintains its communication function and sends the operating temperature abnormality information to other modules through the abnormality response module.

[0012] In conjunction with the first aspect, in some implementations of the first aspect, the communication chip further includes a storage monitoring module and / or a clock detection module; the storage monitoring module is configured to: perform integrity verification on the stored data within the communication chip; if the stored data is abnormal, add fault information to the abnormal stored data and send the fault information to the exception response module; and / or, the clock detection module is configured to: detect the clock frequency within the communication chip; if the clock frequency is abnormal, send the exception information of the abnormal clock frequency to the exception response module; the exception response module is configured to: control the communication chip to enter a communication exception state based on the fault information and / or exception information.

[0013] In conjunction with the first aspect, in some implementations of the first aspect, the communication chip also includes a system detection module and a power management module. The system detection module is configured to: perform power-on detection on each module in the communication chip; if a module fails, the communication chip is paused from starting and a power-off request is sent to the power management module to prevent the communication chip from sending relevant data to other modules.

[0014] In conjunction with the first aspect, in some implementations of the first aspect, the communication port pins of the communication module are multi-functional pins, which include at least one of CAN communication pins, Ethernet communication pins, LIN communication pins, and SPI communication pins.

[0015] Secondly, one embodiment of this application provides a communication method applied to the communication module of a communication chip in an intelligent driving system. The communication chip further includes an exception response module. The method includes: receiving a current data frame and performing a security check on the current data frame; if there is abnormal data in the current data frame that fails the security check, then performing a security response operation and controlling the operating state of the communication chip; or, triggering the exception response module so that the exception response module controls the operating state of the communication chip; wherein, the security response operation represents measures taken to protect the functional safety of the communication chip, and the operating state of the communication chip represents the communication capability of the communication chip at a specific time.

[0016] Thirdly, one embodiment of this application provides a computer-readable storage medium storing a computer program for performing the communication method described in the second aspect.

[0017] Fourthly, one embodiment of this application provides an electronic device, the electronic device comprising: a processor; a memory for storing processor-executable instructions; the processor being configured to perform the communication method described in the second aspect.

[0018] Fifthly, one embodiment of this application provides a computer program product including instructions that, when executed on an electronic device, cause the electronic device to implement the communication method described in the second aspect.

[0019] In this embodiment, the communication module can perform security verification on the received current data frame. This security verification mechanism can promptly detect anomalies in the current data frame, effectively preventing abnormal data from entering subsequent processing flows and improving the reliability and stability of the communication chip. Furthermore, when abnormal data is detected, the communication module either executes a security response operation or triggers an anomaly response module. These two methods complement each other, allowing the communication chip to adopt the most appropriate processing method according to specific needs. In addition, this solution enhances the functional safety of the communication chip, ensuring its stability and reliability, and meeting users' high requirements for communication security in intelligent driving systems. Moreover, this application addresses different anomalies by adjusting the operating state of the communication chip. This flexible processing mechanism effectively reduces the risk of communication chip failure, thereby improving the safety of the entire intelligent driving system. Attached Figure Description

[0020] The above and other objects, features, and advantages of this application will become more apparent from the more detailed description of the embodiments of this application in conjunction with the accompanying drawings. The drawings are provided to further illustrate the embodiments of this application and form part of the specification. They are used together with the embodiments of this application to explain this application and do not constitute a limitation thereof. In the drawings, the same reference numerals generally represent the same components or steps.

[0021] Figure 1 The diagram shown is a flowchart illustrating the execution method of a communication module according to an embodiment of this application.

[0022] Figure 2 The diagram shown is a structural schematic of a communication chip provided in an embodiment of this application.

[0023] Figure 3 The diagram shown is a structural schematic of an electronic device provided in an exemplary embodiment of this application. Detailed Implementation

[0024] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0025] In intelligent driving systems, the communication chip, as a core component, is responsible for data interaction with multiple modules of the vehicle. Optionally, the communication chip in this application can connect to the vehicle's sensor modules (such as cameras, radar, and lidar) and actuator modules (such as steering and braking systems) via its multi-function pins. Specifically, the sensor modules continuously collect data about the vehicle's surrounding environment and send the data to the communication chip in the form of current data frames. After receiving these current data frames, the communication module of the communication chip performs security verification on the data to ensure its integrity and accuracy. Further, if the current data frame is normal, the communication chip forwards the relevant data to the vehicle's central processing unit (CPU) for environmental perception, path planning, and decision-making. Then, the CPU forwards the decision results to the corresponding actuator modules through the gateway module. Upon receiving the instructions, the actuator modules execute the specific actions.

[0026] The functions and roles of the communication chip provided in this application are described in detail below with reference to specific embodiments, especially its key roles in data transmission, security verification, and anomaly handling.

[0027] The communication chip provided in this application includes a communication module and an exception response module. For example, Figure 1 The diagram shown is a flowchart illustrating the execution method of a communication module according to an embodiment of this application. Figure 1 As shown, the method includes the following steps.

[0028] Step S110: Receive the current data frame and perform a security check on the current data frame.

[0029] The security verification here refers to performing a series of checks on the received current data frame to ensure data reliability and prevent the current data frame from being corrupted or tampered with. Optionally, security verification includes integrity verification, accuracy verification, message sequence verification, timeout verification, etc. Optionally, the current data frame includes communication content, verification information (such as checksum, hash value), timestamp, sequence number, etc.

[0030] For example, the checksum of the communication content in the current data frame is calculated and compared with the checksum carried in the current data frame. If they match, the current data frame is considered complete. Cyclic redundancy check is performed to verify that the communication content in the current data frame meets expectations; if it does, the current data frame is considered accurate. Furthermore, the sequence number of the current data frame can be checked for continuity; if it is, the message order of the current data frame is considered correct. Alternatively, the arrival of the current data frame within the specified time can be checked; if the current data frame times out, it is considered to have failed the timeout check.

[0031] Finally, if the current data frame passes all the pre-set security checks, it is considered normal and can be further processed; otherwise, it is considered abnormal and step S120 or step S130 needs to be executed.

[0032] In other embodiments, the communication module may also add protection mechanisms to the current data frame, such as encryption and signing, to ensure that the current data frame is not tampered with or damaged during transmission.

[0033] Figure 2 The diagram shown is a structural schematic of a communication chip provided in an embodiment of this application. Figure 2 As shown, the communication module can autonomously control the operating state of the communication chip (step S120), and can also indirectly control the operating state of the communication chip through the abnormal response module (step S130).

[0034] Step S120: If there is abnormal data in the current data frame that has failed the security check, then perform a security response operation and control the operating status of the communication chip.

[0035] The presence of abnormal data that failed security checks in the current data frame indicates that the frame may be corrupted during transmission. Therefore, the communication module will execute corresponding security response operations and control the operating state of the communication chip. The security response operations represent measures taken to protect the functional safety of the communication chip, while the operating state of the communication chip represents its communication capability at a specific moment.

[0036] Optionally, the security response operations performed by the communication module include discarding the current data frame to prevent it from entering subsequent processing flows; or recording abnormal information, such as recording the checksum, sequence number, and timestamp of the abnormal data in an internal log. Optionally, controlling the operating state of the communication chip includes temporarily stopping the communication chip from receiving and sending data, depending on the severity of the abnormal data, to prevent further anomalies from occurring.

[0037] Step S130: If there is abnormal data in the current data frame that has failed the security check, the abnormal response module is triggered.

[0038] Similarly, the purpose of step S130 is to facilitate the abnormal response module in controlling the operating status of the communication chip.

[0039] In this embodiment, the communication module can perform security verification on the received current data frame. This security verification mechanism can promptly detect anomalies in the current data frame, effectively preventing abnormal data from entering subsequent processing flows and improving the reliability and stability of the communication chip. Furthermore, when abnormal data is detected, the communication module either executes a security response operation or triggers an anomaly response module. These two methods complement each other, allowing the communication chip to adopt the most appropriate processing method according to specific needs. In addition, this solution enhances the functional safety of the communication chip, ensuring its stability and reliability, and meeting users' high requirements for communication security in intelligent driving systems. Moreover, this application addresses different anomalies by adjusting the operating state of the communication chip. This flexible processing mechanism effectively reduces the risk of communication chip failure, thereby improving the safety of the entire intelligent driving system.

[0040] Next, we will explain in detail how the communication module "executes security response operations and controls the operating state of the communication chip" to achieve more efficient anomaly management. Specifically, the communication module is also configured to: generate self-processing status indication information, and / or classify abnormal data and determine the classification information of the abnormal data; send the self-processing status indication information and / or the classification information of the abnormal data to the anomaly response module for recording; discard the current data frame and capture multiple time-related data frames following the current data frame; perform security verification on the multiple time-related data frames; and control the operating state of the communication chip based on the verification results.

[0041] Optionally, the self-processing status indication information indicates that the communication module will automatically control the operating state of the communication chip for subsequent analysis and diagnosis. That is, while the communication chip adjusts its operating state, the communication module generates self-processing status indication information. Classifying abnormal data includes categorizing abnormal data according to abnormal characteristics or causes. Correspondingly, classification information refers to the categorized identification information. For example, the classification information includes at least one of abnormality type, abnormality source, and abnormality severity.

[0042] For example, when the communication module receives a current data frame on the CAN (Controller Area Network) bus, it detects that the security checksum of a certain data frame is inconsistent with the calculated result, indicating that the current data frame may have been corrupted during transmission. The communication module will autonomously determine the operating state of the communication chip, generate its own processing status indication information, and record the measures it takes. Simultaneously, the communication module will also classify the abnormal data, for example, determining its classification information as "data corruption." Then, the communication module sends this information to the anomaly response module. Upon receiving this information, the anomaly response module will record it in its internal log for subsequent analysis and processing.

[0043] Optionally, time-related data frames refer to multiple data frames that are consecutive or related in time, and these data frames usually have a certain logical relationship. Further, security checks are performed on multiple time-related data frames, and then, based on the check results, the operating state of the communication chip is controlled.

[0044] In this embodiment, the communication module can autonomously control the operating state of the communication chip, improving the chip's response speed and processing efficiency, and ensuring its functional safety and reliability. Secondly, the communication module classifies abnormal data, allowing the chip to more accurately identify the nature and source of the abnormal data, thus enabling more targeted remedial measures. Furthermore, the communication module sends its self-processing status indication information and / or abnormal data classification information to the abnormal response module for recording, enhancing the transparency and traceability of abnormal data and providing a basis for subsequent functional expansion and upgrades. Upon detecting abnormal data, the communication module discards the current data frame and captures subsequent time-related data frames for further inspection. This mechanism quickly isolates abnormal data, preventing it from entering subsequent processing flows and ensuring the functional safety of the communication chip. By performing security verification on multiple time-related data frames, the chip can confirm the degree of abnormality of these data frames, thereby providing accurate decision-making basis for subsequent chip state control.

[0045] Below, embodiments of this application provide two implementation methods for "controlling the operating state of the communication chip based on the verification result". The specific implementations are described below.

[0046] In one implementation, if the verification result shows that at least a target proportion of the data frames among multiple time-related data frames contain abnormal data that has failed the security verification, an abnormal alarm command is generated, and the communication chip is autonomously controlled to enter a communication interruption state or a communication abnormal state.

[0047] Optionally, the number of data frames that failed the security check is counted, and their proportion in the batch of data frames is calculated. Then, this proportion is compared with a preset target proportion. If the proportion reaches or exceeds the target proportion, an abnormal alarm command is generated, and the communication chip is controlled to enter either a communication interruption state or a communication abnormal state. It is understood that the target proportion can be configured according to different functional safety levels or application scenarios, thereby achieving flexible adjustment and adaptive management of the target proportion.

[0048] For example, the number of abnormal frames is determined among multiple time-series associated data frames, where an abnormal frame represents a data frame containing abnormal data that has failed security checks; the total number of time-series associated data frames is determined; the ratio of the number of abnormal frames among the multiple time-series associated data frames to the total number of time-series associated data frames is determined; and the product of this ratio and the weighting coefficients under different ASIL (Automotive Safety Integrity Level) functional safety levels is determined as the target ratio.

[0049] Specifically, it can be expressed by the formula: P = N abnormal / N total ×S asil Among them, N abnormal N represents the number of abnormal frames. total S represents the total number of time-series associated data frames. asil This represents the weighting coefficient for different ASIL levels of functional safety.

[0050] Optionally, if the ASIL level is QM, then S asil The value is 1; if the ASIL level is A, then S asil The value is 1.01; if the ASIL level is B, then S asil It is 1.05; if the ASIL level is C, then S asil The value is 1.10; if the ASIL level is D, then S asil The value is 1.15. Among them, QM, A, B, C, and D represent different vehicle safety integrity levels.

[0051] Specifically, in the event of a communication interruption, the communication chip sends the abnormal alarm command and classification information of the abnormal data to other modules (such as the central processing unit and the gateway module) only through the abnormal response module. This ensures that other modules can be aware of the abnormal situation in a timely manner and prevents the abnormal data from further affecting the normal operation of the intelligent driving system.

[0052] In the event of a communication anomaly, the communication module adds anomaly tags to abnormal data in multiple time-series associated data frames, enabling other modules to identify the abnormal data in these frames. It also maintains communication functionality and sends anomaly alarm commands to other modules through the anomaly response module. This allows the communication chip to perform anomaly handling while simultaneously receiving and sending normal data.

[0053] In this embodiment, the communication chip is only deemed to have encountered a persistent or severe fault when the proportion of abnormal data frames reaches or exceeds a preset target proportion. This triggers an abnormal alarm command and autonomously switches the operating state of the communication chip. This determination mechanism significantly reduces the probability of falsely triggering protection measures due to momentary interference or occasional errors, improving control accuracy and system reliability. Furthermore, in the communication interruption state, only the abnormal response module sends abnormal alarm commands and classification information, ensuring that the intelligent driving system can promptly detect specific abnormal situations. In the communication abnormality state, the communication module adds abnormal tags to the abnormal data and maintains the communication function of the communication chip, while simultaneously sending an abnormal alarm command through the abnormal response module. This mechanism not only ensures communication continuity but also provides other modules with the ability to identify abnormal data, enabling the intelligent driving system to handle abnormalities while continuing communication.

[0054] In another implementation, if the verification result shows that multiple time-related data frames have passed the security verification, the current operating state of the communication chip is maintained.

[0055] Optionally, if the verification results indicate that all data frames have passed the security verification, the current communication link of the communication chip is considered to be normal, with no risk of persistent or substantial failure, and the existing operating state of the communication chip is maintained.

[0056] This solution demonstrates the stability of the communication chip, that is, when the communication status is confirmed to be good, unnecessary state switching or intervention operations are avoided, thereby ensuring the continuity and reliability of communication services, while reducing the additional overhead and potential risks that may be caused by state transitions.

[0057] Furthermore, if the verification result shows that multiple time-related data frames have passed the security verification, the communication module is also configured to record the current data frame so that when multiple time-related data frames are sent to other modules, the other modules are prompted that the current data frame has been discarded.

[0058] In other words, after confirming that multiple time-related data frames have passed security checks, the communication module records the current data frame's discard status in its internal storage and simultaneously sends a discard notification. This mechanism not only improves the transparency of data transmission but also helps other modules understand the data processing status, thereby enabling them to make corresponding adjustments or decisions.

[0059] In addition, when the communication module is powered on again, the recorded current data frames are cleared, ensuring that the communication chip can start running from an initial state after restarting, avoiding interference from old data to the new communication process, while also reducing storage space usage and improving the efficiency of the communication chip.

[0060] In this embodiment, when multiple time-correlated data frames pass the security check, the communication module records the current data frame. This allows other modules to promptly recognize that previous data frames containing abnormal data have been discarded when receiving subsequent data frames, thus avoiding misunderstandings or incorrect processing due to incomplete data and improving the stability of the communication chip. Furthermore, the communication module automatically clears the previously recorded current data frames upon power-up, ensuring that the communication chip can start a new communication session from a clean state. This avoids potential interference from old data in the new communication process and reduces the risk of performance degradation due to residual historical data.

[0061] Next, we will explain in detail how the communication module triggers the exception response module so that the exception response module can control the operating state of the communication chip. Specifically, the communication module is also configured to: generate an exception alarm command and send the exception alarm command to the exception response module; the exception response module is configured to: receive the exception alarm command and control the communication chip to enter a communication interruption state or a communication exception state.

[0062] An abnormal alarm command is a command generated by the communication module to notify the abnormal response module that there is abnormal data in the current data frame during the communication process.

[0063] Optionally, when the communication module detects abnormal data, it only sends an abnormal alarm command to the abnormal response module, which then determines how to control the operating state of the communication chip. Therefore, in this embodiment, in the communication interruption state, the communication chip only sends the abnormal alarm command to other modules through the abnormal response module. Furthermore, in the communication abnormality state, the communication chip maintains its communication function and sends the abnormal alarm command to other modules through the abnormal response module.

[0064] In this embodiment, an anomaly response module is introduced to control the operating state of the communication chip. When the communication module detects abnormal data and sends an anomaly alarm command, the anomaly response module can quickly take over and control the operating state of the communication chip, which reduces the burden on the communication module. Furthermore, the anomaly response module can flexibly decide to adjust the communication chip to a communication interruption state or a communication abnormal state according to the nature and severity of the abnormal data, thereby preventing abnormal data from further affecting the normal operation of the communication chip.

[0065] In some embodiments, while ensuring the communication module effectively protects the functional safety of the communication chip, the overall design of the communication chip also considers other potential security threats. To this end, the communication chip also includes a power management module, a temperature management module, a storage monitoring module, a clock detection module, and a system detection module. Through this multi-layered security design, the communication chip can provide more reliable protection, ensuring its functional safety and stable operation in various complex environments. The specific functions of each module are described in detail below, as well as how some of these modules cooperate with the anomaly response module to adjust the operating state of the communication chip.

[0066] In some embodiments, the power management module is configured to: detect the voltage of the input power supply of the communication chip; if the voltage of the input power supply is abnormal, cut off the input power supply of the communication chip and prevent the communication chip from sending relevant instructions to other modules.

[0067] For example, the power management module monitors the input power supply voltage in real time through a built-in voltage detection circuit. Optionally, the voltage detection circuit sets a normal voltage range, and triggers an abnormal signal when the input voltage is outside this range. For example, voltage abnormalities include undervoltage (too low voltage) or overvoltage (too high voltage).

[0068] Then, the power management module executes protective measures. Specifically, it prevents damage to the communication chip from abnormal voltage by cutting off the input power. Optionally, the power cutting operation can be implemented through hardware circuitry, such as using a relay or MOSFET (Metal-Oxide-Semiconductor Field-Effect Transistor) to disconnect the power circuit. Simultaneously, the power management module also prevents the communication chip from sending commands to other modules to avoid uncontrollable behavior under abnormal power conditions.

[0069] Assuming the normal operating voltage range of the communication chip is 3.3V±0.3V, if the input voltage suddenly rises to 4.0V, the voltage detection circuit will identify this overvoltage condition and trigger the protection mechanism, that is, cut off the input power supply of the communication chip and prevent the communication chip from sending relevant instructions to other modules until the voltage returns to normal.

[0070] In this embodiment, the design of the power management module further enhances the functional safety and operational stability of the communication chip in complex environments. Specifically, the power management module monitors the input voltage in real time to ensure that the communication chip always operates within the normal voltage range. Upon detecting abnormal conditions such as undervoltage or overvoltage, the power management module quickly cuts off the input power to prevent hardware damage and prevents the communication chip from sending commands to other modules, thus mitigating risks. This rapid response mechanism not only protects the communication chip itself but also enhances the overall reliability of the intelligent driving system. Furthermore, those skilled in the art can adjust the normal voltage range and optimize the response strategy according to specific application scenarios to ensure the reliability of the communication chip in complex environments.

[0071] In some embodiments, the temperature management module is configured to: collect the operating temperature of the communication chip; if the operating temperature exceeds the set maximum operating temperature value and exceeds the target duration of the state, then send the operating temperature anomaly information to the anomaly response module. Correspondingly, the anomaly response module is configured to: control the communication chip to enter a standby state based on the operating temperature anomaly information, wherein, in the standby state, the communication chip maintains its communication function and sends the operating temperature anomaly information to other modules through the anomaly response module.

[0072] The operating temperature here refers to the actual temperature value generated by the communication chip during operation, while the maximum operating temperature value is a pre-set safety upper limit used to ensure that the communication chip operates within its normal operating range. Furthermore, the target time refers to the shortest duration after the operating temperature exceeds the maximum operating temperature value, used to avoid unnecessary changes in the operating state of the communication chip due to short-term temperature fluctuations.

[0073] Optionally, the temperature management module continuously collects the operating temperature of the communication chip and compares it with the maximum operating temperature value. If the operating temperature exceeds the maximum operating temperature value and this state persists for a target time, the temperature management module sends an abnormal operating temperature information to the anomaly response module. Optionally, this abnormal operating temperature information includes key information such as the specific data of the temperature anomaly and its duration.

[0074] Furthermore, upon receiving this anomaly information, the anomaly response module will control the communication chip to enter standby mode. In standby mode, although the communication chip suspends its main processing functions, it still maintains basic communication capabilities and can also send abnormal operating temperature information to other modules.

[0075] For example, the maximum operating temperature of the communication chip is set to 85°C, and the target time is 10 seconds. If the operating temperature of the communication chip rises to 90°C under high load and remains there for more than 10 seconds, the temperature management module will detect this anomaly and transmit the abnormal operating temperature information to the anomaly response module. The anomaly response module will then control the chip to enter standby mode and send the abnormal operating temperature information to other modules, indicating that the current operating temperature of the communication chip is abnormal.

[0076] In this embodiment, the temperature management module monitors the operating temperature of the communication chip in real time and avoids false alarms triggered by short-term temperature fluctuations by setting a maximum operating temperature value and a target time, ensuring that the communication chip operates within its normal working range and avoiding unnecessary interruptions. Then, when the operating temperature exceeds the maximum operating temperature value and remains above the target time, the temperature management module transmits the abnormality information to the abnormality response module. The abnormality response module then controls the chip to enter a standby state. This state protects the communication chip hardware while maintaining basic communication functions, enabling interaction with other modules regarding abnormal operating temperature information, further enhancing the overall reliability of the intelligent driving system.

[0077] In some embodiments, the storage monitoring module is configured to: perform integrity verification on the stored data within the communication chip; if the stored data is abnormal, add fault information to the abnormal stored data and send the fault information to the anomaly response module. Correspondingly, the anomaly response module is configured to: control the communication chip to enter a communication anomaly state based on the fault information.

[0078] Integrity verification refers to checking whether stored data is complete, undamaged, or untampered with using a verification algorithm (such as a hash algorithm). If anomalies are found in the stored data during the verification process, the storage monitoring module will add fault information to this abnormal data. Optionally, the fault information includes a fault indicator code.

[0079] Specifically, the storage monitoring module periodically or in real-time verifies the stored data. If any abnormalities are detected, fault information is added to the abnormal data and sent to the fault response module. Upon receiving the fault information, the fault response module controls the communication chip to enter a communication anomaly state. In this state, the communication chip does not disconnect its communication function; instead, it sends anomaly alarm commands to other modules through the fault response module.

[0080] This embodiment effectively improves the data integrity and stability of the communication chip through the collaborative work of the storage monitoring module and the anomaly response module. Specifically, the storage monitoring module monitors the stored data in real time to ensure that the stored data is not corrupted or tampered with. Once an anomaly is detected, fault information is added to the abnormal stored data to ensure that the problem is traceable and to provide a basis for subsequent fault diagnosis. Then, after receiving the fault information, the anomaly response module controls the communication chip to enter a communication anomaly state, reducing the risk of the communication chip crashing due to data anomalies and ensuring the stable operation of the communication chip under abnormal conditions.

[0081] In some embodiments, the clock detection module is configured to: detect the clock frequency within the communication chip; if the clock frequency is abnormal, send the abnormal clock frequency information to the abnormal response module. Correspondingly, the abnormal response module is configured to: control the communication chip to enter a communication abnormal state based on the abnormal information.

[0082] Clock frequency refers to the oscillation frequency of the internal clock signal of the communication chip, which is fundamental to the normal operation of the chip. Optionally, the clock frequency of the communication chip is compared with a preset normal frequency range. If the clock frequency exceeds this range, the clock detection module will detect the problem and send the corresponding abnormal information to the abnormal response module. Optionally, this abnormal information includes the specific value of the abnormal frequency, the time of the abnormality, and possible causes. Upon receiving the abnormal information, the abnormal response module will control the communication chip to enter a communication abnormal state.

[0083] In this embodiment, the clock detection module monitors the clock frequency in real time. Once an abnormal clock frequency is detected, it generates an error message and sends it to the error response module to prevent data errors caused by the clock anomaly. Upon receiving the error message, the error response module controls the communication chip to enter a communication anomaly state to prevent the abnormal clock frequency from affecting other modules. This design not only protects the communication chip itself but also enhances the stability of the entire intelligent driving system.

[0084] In some embodiments, the system detection module is configured to: perform power-on detection on each module in the communication chip; if a module fails, suspend the startup of the communication chip and send a power-off request to the power management module so as to prevent the communication chip from sending relevant data to other modules.

[0085] Power-on self-test (POST) is a comprehensive check performed on all internal modules of a communication chip before it starts up, aiming to ensure that all modules are in a normal working state before formal operation. Optionally, POST includes testing hardware connections, software initialization, and critical functions.

[0086] If a module malfunctions during the inspection process, the system detection module will immediately pause the chip's startup process to prevent the faulty module from affecting the operation of the entire communication chip. Simultaneously, the system detection module will send a power-down request to the power management module, instructing it to cut off the power supply to the communication chip. Upon receiving this request, the power management module will then cut off the power, ensuring that the communication chip cannot send data to other modules, thereby avoiding potential risks.

[0087] In this embodiment, the system detection module performs a comprehensive power-on check when the communication chip is powered on, ensuring that all internal modules are in a normal state before formal operation, thus avoiding data errors caused by faulty modules. Then, when a fault is detected in a module, the system detection module immediately suspends the chip's startup process and sends a power-off request to the power management module, thereby preventing the fault from spreading to the entire communication chip. This mechanism not only protects the communication chip itself but also enhances the overall safety of the intelligent driving system. Furthermore, the rigorous checks during the startup phase reduce maintenance costs and downtime caused by undetected faults during operation, significantly improving the availability and stability of the communication chip.

[0088] Finally, the communication port pins of the communication module are multi-functional pins, including at least one of CAN communication pins, Ethernet communication pins, LIN communication pins, and SPI communication pins.

[0089] Multi-functional pins refer to pins in a communication module that can be configured to perform different communication functions according to actual needs, such as CAN communication pins, Ethernet communication pins, LIN (Local Interconnect Network) communication pins, and SPI (Serial Peripheral Interface) communication pins. This design allows the communication chip to flexibly adjust the communication method in different application scenarios without hardware modification.

[0090] For example, after the communication port pins of the communication module are powered on normally, the function of each pin can be defined through software configuration. This flexibility of software configuration allows the communication chip to adapt to multiple communication protocols.

[0091] For example, during the development phase, a communication port pin can be configured as a CAN communication pin for communication with the vehicle's ECU (Electronic Control Unit); while during the testing phase, the same pin can be reconfigured as an Ethernet communication pin for high-speed data transmission with test equipment. This design not only improves the versatility of the communication chip but also reduces the complexity of hardware design, providing greater adaptability and scalability for the communication chip.

[0092] The embodiments of the communication chip provided in this application have been described in detail above. The embodiments of the communication method correspond to the embodiments of the communication chip. Therefore, the embodiments of the communication method will not be described again, but can be referred to the description in the foregoing embodiments.

[0093] Below, for reference Figure 3 This describes an electronic device according to embodiments of the present application. Figure 3 The diagram shown is a structural schematic of an electronic device provided in an exemplary embodiment of this application.

[0094] like Figure 3 As shown, the electronic device 30 includes one or more processors 301 and memory 302.

[0095] The processor 301 may be a central processing unit (CPU) or other form of processing unit with data processing capabilities and / or instruction execution capabilities, and may control other components in the electronic device 30 to perform desired functions.

[0096] The memory 302 may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage medium, and the processor 301 may execute the program instructions to implement the communication methods and / or other desired functions of the various embodiments of this application described above. The computer-readable storage medium may also store various contents such as current frame data, abnormal data, and abnormal alarm instructions.

[0097] In one example, the electronic device 30 may also include an input device 303 and an output device 304, which are interconnected via a bus system and / or other forms of connection mechanism (not shown).

[0098] The input device 303 may include, for example, a keyboard, a mouse, etc.

[0099] The output device 304 can output various information to the outside, including current frame data, abnormal data, and abnormal alarm commands. The output device 304 may include, for example, a display, a speaker, a printer, and a communication network and its connected remote output devices, etc.

[0100] Of course, for the sake of simplicity, Figure 3 Only some of the components of the electronic device 30 relevant to this application are shown in this illustration; components such as buses, input / output interfaces, etc., are omitted. In addition, the electronic device 30 may include any other suitable components depending on the specific application.

[0101] In addition to the methods and devices described above, embodiments of this application may also be computer program products, which include computer program instructions that, when executed by a processor, cause the processor to perform the steps of the communication methods according to the various embodiments of this application described above.

[0102] The computer program product can be written in any combination of one or more programming languages ​​to perform the operations of the embodiments of this application. The programming languages ​​include object-oriented programming languages ​​such as Java and C++, as well as conventional procedural programming languages ​​such as C or similar languages. The program code can be executed entirely on the user's computing device, partially on the user's computing device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.

[0103] Furthermore, embodiments of this application may also be computer-readable storage media storing computer program instructions thereon, which, when executed by a processor, cause the processor to perform the steps of the communication methods according to the various embodiments of this application described above.

[0104] The computer-readable storage medium may be any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may, for example, include, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: electrical connections having one or more wires, portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0105] The basic principles of this application have been described above with reference to specific embodiments. However, it should be noted that the advantages, benefits, and effects mentioned in this application are merely examples and not limitations, and should not be considered as essential features of each embodiment of this application. Furthermore, the specific details disclosed above are for illustrative and facilitative purposes only, and are not limitations. These details do not limit the application to the necessity of employing the aforementioned specific details for implementation.

[0106] The block diagrams of devices, apparatuses, devices, and systems involved in this application are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, devices, and systems can be connected, arranged, and configured in any manner. Words such as “comprising,” “including,” “having,” etc., are open-ended terms meaning “including but not limited to,” and are used interchangeably with them. The terms “or” and “and” as used herein refer to the terms “and / or,” and are used interchangeably with them unless the context clearly indicates otherwise. The term “such as” as used herein refers to the phrase “such as but not limited to,” and is used interchangeably with it.

[0107] It should also be noted that in the apparatus, equipment, and methods of this application, the components or steps can be disassembled and / or recombined. These disassemblies and / or recombinations should be considered as equivalent solutions of this application.

[0108] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use this application. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of this application. Therefore, this application is not intended to be limited to the aspects shown herein, but rather to be accorded the widest scope consistent with the principles and novel features disclosed herein.

[0109] The above description has been given for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of this application to the forms disclosed herein. Although numerous exemplary aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations thereof.

Claims

1. A communication chip, characterized in that, The communication chip, used in intelligent driving systems, includes a communication module and an anomaly response module. The communication module is configured as follows: Receive the current data frame and perform security verification on the current data frame; If there is abnormal data in the current data frame that fails the security check, a security response operation is performed and the operating state of the communication chip is controlled; or, the abnormal response module is triggered so that the abnormal response module controls the operating state of the communication chip. The security response operation refers to the measures taken to protect the functional safety of the communication chip, and the operating state of the communication chip refers to the communication capability of the communication chip at a specific moment.

2. The communication chip according to claim 1, characterized in that, The communication module is also configured to: Generate self-processing status indication information, and / or classify the abnormal data to determine the classification information of the abnormal data; send the self-processing status indication information and / or the classification information of the abnormal data to the abnormal response module so that the abnormal response module can record it; Discard the current data frame and capture multiple time-series related data frames following the current data frame; Security checks are performed on the multiple time-series associated data frames; Based on the verification results, the operating status of the communication chip is controlled.

3. The communication chip according to claim 2, characterized in that, The communication module is also configured to: If the verification result indicates that at least a target proportion of the multiple time-series associated data frames contain abnormal data that has failed the security verification, an abnormal alarm command is generated, and the communication chip is autonomously controlled to enter a communication interruption state or a communication abnormal state. In the communication interruption state, the communication chip sends the abnormal alarm command and the classification information of the abnormal data to other modules only through the abnormal response module; In the abnormal communication state, the communication module adds abnormal tags to the abnormal data in the multiple time-series associated data frames so that other modules can identify the abnormal data in the multiple time-series associated data frames, maintain communication function, and send the abnormal alarm command to other modules through the abnormal response module.

4. The communication chip according to claim 2, characterized in that, The communication module is also configured to: If the verification result is that all of the multiple time-related data frames pass the security verification, then the current operating state of the communication chip is maintained; Preferably, when the verification result shows that all of the multiple time-series associated data frames pass the security verification, the communication module is further configured to: The current data frame is recorded so that when the multiple time-related data frames are sent to other modules, the other modules are notified that the current data frame has been discarded. And / or, upon power-up of the communication module, clear the recorded current data frame.

5. The communication chip according to claim 1, characterized in that, The communication module is further configured to: generate an abnormal alarm command and send the abnormal alarm command to the abnormal response module; The abnormal response module is configured to receive the abnormal alarm command and control the communication chip to enter a communication interruption state or a communication abnormal state.

6. The communication chip according to any one of claims 1 to 5, characterized in that, It also includes a power management module, which is configured as follows: The voltage of the input power supply of the communication chip is detected; If the voltage of the input power supply is abnormal, the input power supply of the communication chip will be cut off, preventing the communication chip from sending relevant instructions to other modules.

7. The communication chip according to any one of claims 1 to 5, characterized in that, It also includes a temperature management module; The temperature management module is configured to: collect the operating temperature of the communication chip; if the operating temperature exceeds the set maximum operating temperature value and exceeds the target duration of the state, then send the abnormal operating temperature information to the abnormal response module. The anomaly response module is configured to: control the communication chip to enter a standby state based on the abnormal operating temperature information, wherein, in the standby state, the communication chip maintains its communication function and sends the abnormal operating temperature information to other modules through the anomaly response module.

8. The communication chip according to any one of claims 1 to 5, characterized in that, It also includes a storage monitoring module and / or a clock detection module; The storage monitoring module is configured to: perform integrity verification on the stored data in the communication chip; if the stored data is abnormal, add fault information to the abnormal stored data and send the fault information to the abnormal response module; And / or, the clock detection module is configured to: detect the clock frequency in the communication chip; if the clock frequency is abnormal, send the abnormal clock frequency information to the abnormal response module; The abnormal response module is configured to control the communication chip to enter a communication abnormal state based on the fault information and / or the abnormal information.

9. The communication chip according to any one of claims 1 to 5, characterized in that, It also includes a system detection module and a power management module, wherein the system detection module is configured as follows: Power-on testing is performed on each module in the communication chip; If a module malfunctions, the communication chip will be paused from starting, and a power-off request will be sent to the power management module to prevent the communication chip from sending relevant data to other modules.

10. The communication chip according to any one of claims 1 to 5, characterized in that, The communication port pins of the communication module are multi-functional pins, which include at least one of CAN communication pins, Ethernet communication pins, LIN communication pins, and SPI communication pins.