A vehicle component control method, a vehicle, a storage medium, and a program product

By integrating multiple identical sensing processing components within the domain controller and utilizing a redundancy management module to achieve component-level redundancy backup, the high cost and complexity of redundancy design for sensing capabilities in existing technologies are resolved, thereby improving the system's economy and security.

CN121019608BActive Publication Date: 2026-02-10ZHEJIANG GEELY HLDG GRP CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202511511183.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-22
Publication Date
2026-02-10
Estimated Expiration
2045-10-22

AI Technical Summary

Technical Problem

The existing L3 and L4 autonomous driving systems suffer from high cost and complexity in their perception redundancy design, as well as serious communication delay and reliability issues, which affect the safety and mass production prospects of the systems.

Method used

Multiple sets of components that perform the same sensing and processing functions are integrated within the same domain controller. Component-level redundancy backup is achieved through a redundancy management module, avoiding cross-controller communication, and state synchronization and decision coordination are carried out using an internal bus.

Benefits of technology

It reduces material and integration costs, avoids communication delays and reliability issues, improves the system's economics and mass production feasibility, and ensures functional safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121019608B_ABST
    Figure CN121019608B_ABST
Patent Text Reader

Abstract

The present specification provides a vehicle component control method, a vehicle, a storage medium and a program product, which are applied to a vehicle configured with a domain controller connected with an environment sensor, the domain controller comprising at least one set of perception processing components, the perception processing components in the same set being used to realize the same perception processing function; the method comprises: in the case that a first perception processing component performing a target perception processing function fails, determining a second perception processing component from the remaining components in the set to which the first perception processing component belongs; and controlling the second perception processing component to take over the first perception processing component to perform the target perception processing function.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the field of vehicle technology, and in particular to a vehicle component control method, a vehicle, a storage medium, and a program product. Background Technology

[0002] In assisted driving scenarios, Level 3 conditional automated driving systems and Level 4 highly automated driving systems place extremely high demands on the reliability of vehicle perception capabilities. Since the vehicle's perception system is directly related to its environmental recognition and decision-making safety, the failure of any single component involved in the perception processing can lead to serious accidents. Therefore, perception redundancy design has become a necessary means to ensure functional safety, making the industry urgently need a safety architecture that can both efficiently process perception data and maintain the overall system function even when some perception processing components fail, in order to meet the basic requirements of automotive functional safety standards for operability in the event of failure and fault tolerance.

[0003] In related technologies, a dual-computing-unit structure with A and B boards is typically used, achieving perceptual redundancy through physical isolation. This architecture requires two independent hardware systems, including motherboards, chips, power supplies, and heat dissipation, which not only leads to a significant increase in material costs but also makes wiring, assembly, and system integration extremely complex, significantly driving up the overall cost. Furthermore, since the two systems reside in different physical controllers, data synchronization and state coordination between them must rely on high-bandwidth in-vehicle networks for communication. This process introduces significant transmission latency and communication reliability issues, greatly increasing the complexity of achieving system state synchronization and decision consistency, thus limiting the application prospects of this solution in large-scale mass production due to both cost and reliability concerns. Summary of the Invention

[0004] In view of this, this specification provides a vehicle component control system, method, vehicle, storage medium, and program product to address the deficiencies in the related art.

[0005] Specifically, this specification is implemented through the following technical solution:

[0006] According to a first aspect of this specification, a vehicle component control method is provided, applied to a vehicle, the vehicle being configured with a domain controller connected to environmental sensors, the domain controller including at least one group of perception processing components, the perception processing components within the same group being used to perform the same perception processing function; the method includes:

[0007] If the first perception processing component that performs the target perception processing function fails, a second perception processing component is determined from the remaining components in the group to which the first perception processing component belongs.

[0008] The second sensing processing component is controlled to take over the target sensing processing function from the first sensing processing component.

[0009] According to a second aspect of this specification, a vehicle is provided, comprising: a processor, a memory for storing processor-executable instructions, a domain controller, and environmental sensors; wherein the processor implements the steps of the method described in the first aspect by executing the executable instructions.

[0010] According to a third aspect of this specification, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps of the method described in the second aspect.

[0011] According to a fourth aspect of this specification, a computer program product includes a computer program / instructions that, when executed by a processor, implement the steps of the method described in the second aspect.

[0012] This specification describes a component-level redundant architecture built by integrating multiple sets of components that perform the same sensing and processing functions within the same domain controller, effectively overcoming the inherent shortcomings of existing dual-controller solutions. Since it does not rely on two independent hardware systems, it significantly reduces material and integration costs. Furthermore, because all redundant sensing and processing components reside within the same domain controller, their state synchronization and decision coordination are achieved through an internal bus, completely avoiding the latency and reliability issues caused by cross-controller communication. In other words, this specification significantly improves the system's economy and mass production feasibility while ensuring functional safety. Attached Figure Description

[0013] To more clearly illustrate the technical solutions in this specification, the accompanying drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are merely some embodiments of this specification, and those skilled in the art can obtain other drawings based on these drawings without any creative effort.

[0014] Figure 1 This is a schematic diagram of the architecture of a vehicle component control system shown in an exemplary embodiment of this specification;

[0015] Figure 2 This is a schematic flowchart illustrating a vehicle component control method according to an exemplary embodiment of this specification;

[0016] Figure 3 This is a schematic diagram illustrating a global data flow corresponding to a domain controller and an environmental sensor, as shown in an exemplary embodiment of this specification.

[0017] Figure 4This is a schematic diagram illustrating the data transmission relationship of an environmental data stream according to an exemplary embodiment of this specification;

[0018] Figure 5 This is a schematic diagram illustrating a data transmission relationship between a SoC and an MCU, as shown in an exemplary embodiment of this specification.

[0019] Figure 6 This is a schematic diagram of the structure of a device shown in an exemplary embodiment of this specification;

[0020] Figure 7 This is a schematic diagram of the structure of a vehicle component control device shown in an exemplary embodiment of this specification. Detailed Implementation

[0021] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this specification. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this specification.

[0022] The terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to be limiting of this specification. The singular forms “a,” “the,” and “the” as used in this specification and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any and all possible combinations of one or more of the associated listed items.

[0023] It should be understood that although the terms first, second, third, etc., may be used in this specification to describe various information, this information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this specification, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to determination."

[0024] The embodiments of the traffic accident guidance method of this specification will be described in detail below with reference to the accompanying drawings.

[0025] Figure 1 This is a schematic diagram illustrating the architecture of a vehicle component control system according to an embodiment disclosed in this specification. Figure 1 As shown, the system may include a domain controller 12 and an environmental sensor 14 in the vehicle 10.

[0026] Vehicle 10 is an intelligent vehicle equipped with driver assistance functions, which can be configured to support Level 3 or Level 4 driver assistance systems. Vehicle 10 integrates a domain controller 12 and environmental sensors 14 that work in conjunction with it to perceive the vehicle's surrounding environment and provide reliable data support for driver assistance decision-making and control. Furthermore, the form factor of vehicle 10 can include pure electric, hybrid, or gasoline-powered models; this specification does not limit this.

[0027] Domain controller 12, as a centralized computing unit, integrates at least one set of sensing processing components. These sensing processing components, for example... Figure 1 The first and second perception processing components can be considered as a group of perception processing components. Each perception processing component in the same group can be configured to have the same hardware computing resources and software algorithms, and can perform the same target perception processing function in a primary / backup or parallel working mode. For example, it can implement at least a part of the function in tasks such as image recognition and LiDAR point cloud processing. This builds redundancy and backup capabilities at the component level, ensuring that its function can be seamlessly taken over by other components in the same group when any processing component fails. Generally, the first perception processing component that performs the target perception processing function by default can be called the primary component, and the second perception processing component that takes over the target perception processing function in the event of component failure can be called the backup component. During the operation of the above system, the domain controller 12 integrates... Figure 1 The redundancy management module, not shown in the diagram, is used to perform real-time monitoring, failure detection, and component switching control of the operating status of the sensing processing components within the domain controller 12. Specifically, this redundancy management module can be an independent hardware monitoring circuit or a high-reliability software module running on an isolated core. It meets the corresponding functional safety level (Automotive Safety Integrity Level, ASIL) requirements. It can continuously receive heartbeat signals, self-test reports, and output results from each sensing processing component, and determine whether a component has failed based on preset health diagnostic strategies such as timeout detection and algorithm redundancy verification. When the redundancy management module detects that the first sensing processing component performing the target sensing processing function has failed, it can determine the second sensing processing component from the remaining components in the same group. Subsequently, the redundancy management module can send a switching command to the second sensing processing component to control the second sensing processing component to take over the target sensing processing function from the first sensing processing component.

[0028] Furthermore, the application scope of the aforementioned domain controller 12 is not limited to domains with specific functional safety levels. It can be applied to autonomous driving domain, powertrain domain, or chassis domain controllers 12 with extremely high safety integrity requirements, achieving the functional safety objectives corresponding to high ASIL through component-level redundancy. It can also be deployed in infotainment domain controllers, which only require ASIL to reach the Quality Management (QM) level, providing them with an economical and efficient reliability improvement strategy.

[0029] The environmental sensor 14 comprises n sensor units, which may include, but are not limited to, cameras, LiDAR (Light Detection and Ranging), Radar (Radio Detection and Ranging), and Ultrasonic Sensors (USS), where n is a positive integer. These sensors are physically distributed at different locations within the vehicle and are all communicatively connected to the domain controller 12 to continuously collect raw data of the vehicle's surrounding environment and transmit it to the perception processing components within the domain controller 12 for calculation and analysis. The environmental sensor 14 can be arranged independently or integrated within the domain controller 12.

[0030] Figure 2 This is a flowchart illustrating an exemplary embodiment of the present invention regarding a vehicle component control method. The method is applied to a vehicle equipped with a domain controller connected to environmental sensors. The domain controller includes at least one set of perception processing components, with each component within the same set performing the same perception processing function. Specifically, the method may include the following steps:

[0031] Step S202: If the first perception processing component that performs the target perception processing function fails, determine the second perception processing component from the remaining components in the group to which the first perception processing component belongs.

[0032] As previously stated, this specification allows for real-time monitoring of the operational status of sensing processing components within the domain controller via the domain controller's redundancy management module. When a failure is detected in the first sensing processing component currently executing a specific sensing processing function, a redundancy takeover process for that component is formally initiated. Failures include, but are not limited to, hardware malfunctions, software freezes, or persistently abnormal output results. Subsequently, the system can determine a successor—the second sensing processing component—from the remaining healthy sensing processing components within the same functional group as the first component.

[0033] The domain controller integrates at least one set of sensing processing components, each set containing components of different types. These component types are categorized based on the hardware architecture of their core computing units and their functional roles. For example, they may include: sensing computing components for analyzing and processing environmental data streams from environmental sensors; data allocation components for transmitting, distributing, and routing the aforementioned environmental data streams; and security monitoring components. However, multiple sensing processing components within the same set performing the same sensing processing function can be configured with identical component types. This "heterogeneous between groups, homogeneous within groups" design strategy aims to achieve specialized division of labor among different functional modules while ensuring highly consistent and seamlessly replaceable redundant backup units for any specific function. This optimizes overall system resource allocation and efficiency while ensuring functional safety.

[0034] For the perception computing components mentioned above, their core function is to analyze and process raw data collected by environmental sensors, such as images, point clouds, and radio frequency signals, and extract meaningful environmental features and target information, such as lane lines, vehicles, and pedestrians. This type of component typically requires a system-on-a-chip (SoC) and one or more paired microcontroller units (MCUs). The reason for this is that in actual circuit design architectures, a high-performance SoC—a chip containing multiple computing units such as a multi-core central processing unit (CPU), graphics processing unit (GPU), and neural processing unit (NPU)—usually needs to run complex perception algorithms, such as deep learning models, to efficiently process and fuse massive amounts of data. However, it often struggles to meet the highest functional safety requirements, such as ASIL D. Therefore, a matching MCU with the corresponding functional safety level is required to work together. The core function of this MCU is to monitor the operating status of the SoC in real time, detect and manage faults. In addition, this MCU can usually also be responsible for running highly reliable judgment logic and executing arbitration functions, such as performing consistency verification and conflict resolution on data or decision results from environmental sensors, SoC and other sensing and processing components, and finally making safe output decisions.

[0035] It's important to note that an MCU, typically designed to ensure real-time performance and reliability, cannot independently handle complex perception algorithm calculations, such as running large neural network models to process image or point cloud data, without a paired SoC. In other words, the core function of an MCU focuses on monitoring, arbitration, and safety control, rather than processing raw perception data. In summary, this combination of SoC and MCU is a common and mature hardware foundation for achieving high functional safety levels, i.e., ASIL B and above, in assisted driving perception functions.

[0036] In particular, in application scenarios with lower functional safety requirements, the hardware configuration of the aforementioned domain controller can be simplified accordingly. For example, when the domain controller functions as an infotainment domain controller, its required sensing functions typically only need to meet ASIL A or QM standards. In such cases, the security monitoring requirements for the computing unit are significantly reduced, and the high-performance SoC, with its powerful computing capabilities, is sufficient to independently and reliably complete the specified target sensing processing functions. Therefore, the accompanying independent MCU is no longer a necessary component. In this case, the aforementioned sensing computing component can physically consist of only a high-performance SoC, which internally achieves necessary self-monitoring and fault tolerance through software partitioning or built-in security mechanisms, thereby further optimizing cost and structural complexity while meeting functional requirements.

[0037] In addition to the aforementioned sensing computing components, the data distribution component, when not corresponding to any particular set of sensing processing components, serves as the distribution hub for data flow within the domain controller. Physically, it can be a standalone hardware unit, such as a dedicated switch, gateway, or deserializer, or it can be a logical functional module integrated into a main control chip. This data distribution component can exist as a single device, and its high reliability can be ensured through its internal high-availability design.

[0038] by Figure 3 For example, Ethernet switches A and B, and deserializers A, B, C, and D in a domain controller can all be regarded as a type of data distribution component. Even though the deserializer can perform additional format conversion operations on the received raw video stream from the camera compared to the Ethernet switch, so as to convert it into parallel data that can be received and analyzed by the SoC, the core capability of both is to further distribute the environmental data stream from the environmental sensor. Therefore, they can both be classified as the component type of data distribution component.

[0039] Based on this data distribution component, raw environmental data streams from environmental sensors can be received. Subsequently, instead of directing the data stream solely to a single sensing computing component currently performing a task, this component can copy and distribute the same environmental data stream in parallel to all sensing computing components within the same group performing the same target sensing processing function. This design ensures that each sensing processing component within the group receives completely consistent input data simultaneously, regardless of which components are the primary components prioritized for performing the corresponding sensing processing function, or which are backup components used to take over the function when the primary component fails. In practical scenarios, the advantage of this method is that when the redundancy management module detects a failure and determines that the second sensing computing component needs to take over from the first, since the second component has already received all necessary environmental data in real time, it can directly start processing from the latest data frame. This completely avoids the delay and data loss risks caused by data switching or retransmission, thus achieving truly seamless switching and function succession, greatly improving the system's real-time performance and reliability.

[0040] The following is still based on Figure 3 For example, as shown in the figure, environmental sensors may include various sets of cameras, ultrasonic sensors, lidar, millimeter-wave radar, Advanced Driver Assistance Systems (ADAS) map modules, map facility information modules, and Global Navigation Satellite System (GNSS) modules, Inertial Measurement Units (IMUs), and Real-Time Kinematic (RTK) modules integrated within the domain controller. The map facility information received by the aforementioned map facility information module can originate from various sources, including but not limited to: data uploaded to the vehicle-to-everything (V2X) platform by other vehicles along the vehicle's subsequent travel path, real-time environmental information detected by road vehicles, backend interactive data transmitted from high-precision cameras or other sensors deployed along the road, and traffic accident information reported by users. Furthermore, its 5G information reception methods include, but are not limited to, 5G networks and Bluetooth connectivity technologies; this specification does not limit these methods.

[0041] Each of the above environmental sensors can send its own environmental data stream to the corresponding sensing and computing component through its matching data distribution component. Of course, those skilled in the art will understand that even Figure 3The diagram only shows the matching relationship between the environmental sensors and data distribution components, namely the "camera-deserializer" and the "LiDAR-Ethernet switch," during data stream transmission. This does not mean that other environmental sensors can be directly connected to the sensing computing component. In fact, other environmental sensors can usually send environmental data streams, such as Ethernet communication, to the corresponding sensing computing component based on their respective Physical Layer Interface (PHY) chips. However, for the sake of readability, this manual selects the more representative deserializer Ethernet switch from the data distribution component for introduction.

[0042] Based on this, targeting Figure 3 The deserializer A in the diagram receives the raw environmental data stream from the first group of cameras, converts it into parallel data, and then sends it to both the first SoC and the second SoC. Both, as sensing computing components, can perform the same sensing processing function. If the first SoC, currently performing image recognition, fails, the second SoC in the same group can promptly take over the image recognition function based on the previously received real-time video data. Similarly, the other deserializers B, C, and D operate in the same manner and will not be described further in this specification.

[0043] When the aforementioned data allocation component is used as a component type corresponding to a group of sensing and processing components, it means that the domain controller will contain two or more data allocation components. Therefore, when the first data allocation component, which is the first sensing and processing component, fails, the target environmental range of the environmental data stream corresponding to the first data allocation component can be obtained. This range typically refers to the physical sensing area handled by the component, such as the left frontal field of view, the direct frontal long-range field of view, or the logical identifier of the associated specific sensor group. Subsequently, the redundancy management module does not arbitrarily select one of the remaining data allocation components to replace it. Instead, it filters based on the key condition of environmental range matching. Specifically, it selects one of the remaining healthy data allocation components whose preset environmental range matches the target environmental range of the failed component, and designates it as the second sensing and processing component to be executed, i.e., the second data allocation component. This mechanism ensures that the data stream provided by the replacement component is physically consistent with the original data stream, which is the core of achieving functional safety and effective replacement.

[0044] The following is based on Figure 3 Design Figure 4 For example, suppose Figure 3The first group of cameras includes one front narrow-angle camera, one front wide-angle camera A, and one rear-view camera A; the second group includes four surround-view cameras; the third group includes four side-view cameras; and the fourth group includes one front wide-angle camera B and one rear-view camera B. Each camera is responsible for capturing environmental images from a specific perspective of the vehicle. Taking deserializer A as an example, its pre-assigned environmental range is the video stream from the first group of cameras, which together cover the vehicle's forward main field of view. If deserializer A malfunctions, the redundancy management module will determine its failure and initiate a replacement process. The system will lock the target environmental range corresponding to deserializer A—the "vehicle's forward main field of view"—and then search for candidates with matching environmental ranges among other redundant data allocation components. (See also...) Figure 4 It can be seen that deserializer D is pre-programmed to handle the fourth set of cameras. Although its sensor combination is not exactly the same as the first set, its core physical perception area is also focused on the "vehicle forward" field of view, which highly matches the target environment range of deserializer A. Therefore, deserializer D can be selected as the second data distribution component, taking over the work of deserializer A and continuing to provide an uninterrupted forward-facing video stream to the downstream perception computing components, thereby ensuring the continuity of the vehicle's forward perception function. If there is no component with a completely identical range in the environment, the system can follow a preset strategy and select the component with the closest range and the most functional compatibility for demotion and replacement.

[0045] It's worth noting that the connection relationships between each data allocation component and the environmental sensors in the aforementioned domain controller are not randomly assigned, but rather configured according to the principle of minimum complementarity of environmental range. This principle means that when assigning connected environmental sensors to a single data allocation component, the spatial continuity requirements of advanced perception algorithms such as Bird's Eye View (BEV) should be considered. Sensors with adjacent perception fields that can be spatially pieced together to form a complete and continuous perception area should be prioritized, for example, covering the entire side of the vehicle or one direction, rather than being randomly or simply grouped by sensor type. The advantage of this design strategy lies in the algorithmic level. When a data allocation component, such as the first data allocation component mentioned above, fails, the sensor group connected to it as its redundant replacement component, the second data allocation component, covers a complementary area that is spatially and algorithmically self-consistent, such as completely covering all cameras on the left side of the vehicle. This allows its perception data to independently and effectively support perception algorithms such as BEV, thereby seamlessly reconstructing the environmental model of that area. This means that the system can maintain basic safety functions without relying on the data of the failed component, achieving true functional safety degradation. Specifically, the implementation of the connection topology can be achieved in several ways:

[0046] The first method, the traditional point-to-point topology, involves each camera equipped with a serializer, connected to a dedicated deserializer in the domain controller via a separate coaxial cable. This method offers the lowest latency and highest reliability, but it requires a large number of interfaces on the domain controller and involves complex wiring.

[0047] The second approach, known as aggregation topology, connects multiple cameras with adjacent fields of view in series via a serializer chain, ultimately transmitting the data through a single cable to a deserializer interface on the domain controller. The deserializer decomposes the aggregated data streams and then transmits them to the corresponding SoC via a high-speed interface. This approach significantly reduces the number of wiring harnesses and controller interface requirements, demonstrating the principle of minimum complementarity in physical connections.

[0048] Thus, combined Figure 4 The flow of environmental data streams shown in the figure summarizes the types of environmental data streams in this specification. As illustrated, environmental data streams, based on their source, format, and transmission protocol, include at least one of the following types: video data streams, Ethernet data streams, and vehicular network data streams. These different types of data streams collectively constitute the basic input of the vehicle perception system, thereby enhancing the flexibility and scalability of the architecture. The data streams generated by various environmental sensors can be categorized as follows:

[0049] I. Video Data Stream: This type of data stream is primarily generated by optical imaging sensors and is characterized by high bandwidth and strong timing requirements. Its sources include:

[0050] Each group of cameras: They convert the raw image data they acquire into serial signals through a serializer, and transmit them to the deserializer in the domain controller via a medium such as a coaxial cable. The deserializer then restores the data to a parallel video signal, such as the Mobile Industry Processor Interface Camera Serial Interface 2 (MIPI CSI-2), forming a video data stream for SoC processing.

[0051] II. Ethernet Data Streams: These data streams are typically based on the Transmission Control Protocol / Internet Protocol (TCP / IP) or User Datagram Protocol / Internet Protocol (UDP / IP) protocol stacks, and are suitable for transmitting high-speed, large-volume unstructured or semi-structured data. Their sources include:

[0052] LiDAR and millimeter-wave radar: These sensors can be directly integrated with Ethernet interfaces to package the point cloud or radio frequency signal processing results they generate into Ethernet data packets for output.

[0053] ADAS map modules and map facility information modules: These service modules, which provide high-precision positioning and lane-level information, also typically interact with the domain controller via Ethernet to transmit their data updates.

[0054] III. In-vehicle network data streams: This type of data stream specifically refers to data transmitted via traditional vehicle buses. It features low latency and high determinism, but its bandwidth is relatively limited. Its sources include:

[0055] Ultrasonic sensors typically transmit near-field obstacle information measured by them in the form of message frames via buses such as Controller Area Network (CAN) or Local Interconnect Network (LIN).

[0056] GNSS, IMU, and RTK modules integrated within the domain controller: Although these modules are inside the domain controller, their raw positioning, acceleration, angular velocity, and high-precision differential data are usually first read by the main control chip through internal buses such as the Serial Peripheral Interface (SPI) or the Inter-Integrated Circuit (I²C). At the system level, they can be regarded as an internal vehicle network data stream.

[0057] It is important to note that the above classification of environmental sensor data stream types is not absolute. The specific transmission format can be flexibly adjusted based on factors such as the actual system architecture, performance requirements, and cost control. For example, in scenarios with extremely high real-time requirements but low bandwidth demands, LiDAR or millimeter-wave radar can be designed to transmit pre-processed sensing data via high-speed in-vehicle networks such as Controller Area Network Flexible Data-Rate (CAN FD), rather than relying on Ethernet protocols. Similarly, if the system needs to integrate more high-resolution sensors or support more complex data fusion algorithms, sensors that originally transmitted data via the in-vehicle network can be replaced with Ethernet interfaces to meet the requirements for higher bandwidth and lower latency data exchange. This modular and configurable data stream design allows the system to better adapt to the diverse needs of different vehicle models, functional configurations, and application scenarios.

[0058] Based on this, the data distribution component within the aforementioned domain controller can also be designed to simultaneously receive, identify, and route these multiple types of environmental data streams, and distribute them to the corresponding internal sensing and processing components for calculation and analysis according to their type and preset strategies.

[0059] At the same time, it will be understood by those skilled in the art that, corresponding Figure 4 In this embodiment, even if there are no technical feasibility issues, redundancy is not implemented for the ultrasonic sensor, GNSS, and RTK; that is, their outputs are not connected to the second SoC or the second MCU respectively. This is due to a comprehensive consideration of system functional safety level, failure impact, and cost-effectiveness. Specifically:

[0060] For the GNSS / RTK module, the cooperation between the aforementioned GNSS / RTK module and the ADAS map provides the vehicle with absolute positioning and lane-level heading reference. When the domain controller is working normally, the first SoC performs data fusion and computation to obtain high-precision vehicle position information, which has a certain degree of time persistence and predictability. When the first SoC suddenly fails, although the system can no longer obtain the latest absolute positioning update, the vehicle's precise positioning, heading, and information on the road features pre-loaded from the ADAS map, such as road curvature, tunnels, intersections, and construction zones, are already known to the system just before the failure. Therefore, the redundancy management module, upon activating the second perception computing component (i.e., the second SoC taking over), can immediately trigger a deceleration strategy based on the memorized forward road features. This strategy can ensure basic vehicle safety for a short period without relying on real-time GNSS / RTK signal input. For example, in high-speed scenarios, the system can control the vehicle to smoothly decelerate to 80 km / h or lower based on information such as road curvature recorded in the next 10-15 seconds of travel before failure, so as to safely pass through curves or tunnels; in urban or intersection scenarios, the system can control the vehicle to decelerate to 40 km / h or lower and increase alertness to surrounding dynamic obstacles in order to deal with situations where the visual perception range may be reduced.

[0061] The lack of redundancy in ultrasonic sensors is primarily due to their functional characteristics and system-level sensor redundancy. Firstly, ultrasonic sensors are mainly used for very close-range obstacle detection, such as in low-speed parking scenarios. Their short effective range and susceptibility to environmental interference mean they are not typically the sole reliance of the main perception link in high-speed autonomous driving. Secondly, a vehicle's perception system is a multi-sensor fusion system. Within the typical operating area of ​​ultrasonic sensors, their functionality often overlaps with that of surround-view cameras, short-range millimeter-wave radar, and even lateral lidar. When several ultrasonic sensors fail, the system can use algorithms to fuse data from other types of sensors with existing redundant designs, compensating for the functional loss of ultrasonic sensors to some extent and meeting the safety requirements after system degradation. Thirdly, establishing independent hardware redundancy channels for numerous, low-cost ultrasonic sensors results in increased wiring complexity and cost, which is extremely inefficient compared to their safety contribution to the overall perception system.

[0062] In summary, the system architecture selection in the illustrations of this specification does not provide dedicated signal redundancy for ultrasonic, GNSS, and RTK. This is a comprehensive judgment based on the functional importance, the effectiveness of failure mitigation measures, and cost-effectiveness of the corresponding embodiments, which is in line with the As Low As Reasonably Practicable (ALARP) principle in functional safety standards.

[0063] When determining the second sensing processing component, an optimization selection strategy based on processing performance can be further introduced. When the first sensing processing component is the first MCU, and a successor needs to be determined from the remaining MCUs in its group, the redundancy management module can first obtain the real-time processing performance indicators of each of the remaining components that can be considered as a candidate second MCU. These performance indicators can comprehensively consider its current computing load rate, available memory resources, main frequency status, historical task processing latency, and communication latency with other components, such as the SoC. Subsequently, the redundancy management module does not select randomly or simply according to a preset order, but compares and evaluates the obtained performance indicators according to a preset algorithm, and finally determines the second MCU with the highest processing performance as the second sensing processing component to be executed. The purpose of this design is to ensure that after a failure switch, the system can quickly recover to the optimal performance state, avoid the successor component itself becoming a new bottleneck due to insufficient performance, and thus maximize the system efficiency and real-time performance after the sensing function is restored.

[0064] It should be noted that the effectiveness of the above strategy relies on a specific hardware interconnect architecture. In this architecture, each MCU is connected to a SoC within the same perceptual computing component and to at least one SoC in another perceptual computing component. This cross-connectivity enables any MCU to potentially monitor and serve multiple SoCs at the technical level, thus providing a physical basis and practical significance for the redundancy management module to select the optimal MCU from among multiple available MCUs.

[0065] The following is based on Figure 3 Design Figure 5 Taking the first SoC and the first MCU as examples, we will introduce the first perceptual computing component, and the second SoC and the second MCU as examples. First, it should be noted that for... Figure 3 , Figure 4 or Figure 5 The first and second sensing computing components differ structurally. The first SoC and first MCU in the first sensing computing component are independent chips, requiring external buses such as Ethernet switch A for data transmission. In contrast, the second SoC and second MCU in the second sensing computing component are integrated into a single physical package using a multi-chip module (MCM) or system-in-package (SoC). Therefore, in addition to external buses like Ethernet switch B, high-speed data transmission can be achieved through internal interconnections between chips, resulting in lower latency and higher reliability. Of course, those skilled in the art can configure the first and second sensing computing components according to actual needs, and this specification does not impose such limitations. Furthermore, it is assumed that the processing performance of the first SoC is greater than that of the second SoC, and the processing performance of the second MCU is greater than that of the first MCU. By default, the system uses the more powerful first SoC and its associated first MCU as the primary sensing computing unit; the slightly less powerful second SoC and the more powerful second MCU serve as backup units. Based on this configuration, the failover process is as follows:

[0066] In the event of a failure of the first SoC, the redundancy management module can control the second SoC to take over the main sensing processing functions, and... Figure 5 The first MCU in the system is associated with the second SoC via Ethernet switch A and Ethernet switch B. Since the absolute computing power of the second SoC is lower than that of the first SoC, the system may automatically enter a performance degradation mode after the switch is completed, such as suspending some non-essential enhanced perception functions to ensure the stable operation of core driver assistance functions until the entire system is restored after maintenance.

[0067] In the event of a failure of the primary MCU, the redundancy management module will initiate a performance selection strategy. This strategy involves real-time evaluation of the performance status of the backup secondary MCU and selecting it as the replacement second sensing processing component. Figure 5 The first SoC is associated with the second MCU via Ethernet switch B. Since the second MCU has higher performance than the first MCU and is in a standby low-load state, it can not only fully assume the original MCU's responsibilities for security monitoring and arbitration, but may even bring additional reliability improvements.

[0068] It is important to emphasize that this embodiment focuses on illustrating the replacement method of the backup component after the failure of the primary component, and its discussion is based on the typical and reasonable assumption that "the backup component itself is in a healthy state." In more complex practical applications, such as scenarios where the backup component fails after the primary component fails, the system also needs to consider multi-level redundancy and fault diagnosis, and needs to re-integrate the remaining components in the same group of sensing and processing components. Since this is beyond the core scope of this example, it will not be elaborated here.

[0069] The aforementioned domain controller can also connect to multiple target environment sensors with the same sensing capabilities but different sensing performance. These target environment sensors are functionally of the same type, for example... Figure 4 The front wide-angle cameras in the video are A, B, etc., but their specific models or specifications differ, resulting in different perception performance parameters such as resolution, frame rate, dynamic range, and ranging accuracy.

[0070] In one embodiment, each target environment sensor can establish a fixed correspondence with different sensing computing components within the domain controller. This correspondence is preset during the system design phase, indicating that the corresponding target environment sensor and the designated sensing computing component will work together as a bound functional unit to perform the same sensing processing function, such as "image detection and recognition of forward targets." The establishment of this correspondence follows a specific optimization principle: the sensing performance of any target environment sensor is negatively correlated with the processing performance of its bound sensing computing component. This means that a high-performance target environment sensor, such as an 8-megapixel high-definition camera, will be intentionally paired with a sensing computing component with relatively low processing performance, such as a SoC with limited computing power. Conversely, a lower-performance or standard target environment sensor, such as a 1.2-megapixel ordinary camera, will be paired with a sensing computing component with higher processing performance, such as a high-end, high-computing-power SoC.

[0071] The above design strategy achieves global optimization of system resources and maximizes cost-effectiveness. Specifically, it avoids the potential for excessive computing power or wasted resources that might result from binding two high-performance units together, while also preventing processing bottlenecks caused by pairing high-performance sensors with low-performance computing units. It ensures that the performance of each component is fully utilized without significant weaknesses. Furthermore, by pairing high-cost, high-performance sensors with relatively low-cost, medium-performance chips, and low-cost sensors with high-cost, high-performance chips that handle more complex algorithms, it achieves an optimized balance in system bill of materials (BOM) cost while meeting overall functional performance requirements.

[0072] Step S204: Control the second perception processing component to take over the target perception processing function from the first perception processing component.

[0073] After identifying the second sensing processing component, the redundancy management module of the aforementioned domain controller can send control commands and necessary context state information to it, instructing it to take over the execution of the target sensing processing function. Specifically, this takeover process can be implemented in different ways depending on the system design:

[0074] The first method is to switch the environmental data stream originally input from the environmental sensor to the first sensing and processing component and transmit it to the second sensing and processing component, and load and run the same algorithm model and parameters as the failed component.

[0075] The second method: Within the domain controller, the aforementioned environmental data stream can be pre-transmitted to each component within the group. The identified second sensing and processing component can be in a standby state before taking over, and can choose not to receive or receive the data stream but without consuming computing power to process it, until it receives a control command from the aforementioned domain controller before it is formally activated and processed.

[0076] In summary, thanks to the consistency of hardware resources and software configuration of the same group of components, the second perception processing component can quickly take on the responsibility of data processing, realize rapid switching without the user's awareness, thereby ensuring the continuity and reliability of the vehicle's assisted driving functions and meeting functional safety requirements.

[0077] The following is combined with Figure 3 The failure scenarios and maximum operating conditions of each component after a single point of failure are discussed, such as... Figure 3As shown, assume the first group of cameras includes one front narrow-angle camera, one front wide-angle camera A, and one rear-view camera A; the second group of cameras includes four surround-view cameras; the third group of cameras includes four side-view cameras; the fourth group of cameras includes one front wide-angle camera B and one rear-view camera B, totaling 13 cameras, abbreviated as 13V; the first group of ultrasonic sensors includes 12 ultrasonic sensors at different vehicle orientations, abbreviated as 12USS; the first group of LiDAR includes two LiDARs for blind spot detection; the second group of LiDAR includes one LiDAR, totaling three LiDARs, abbreviated as 3L; the first group of millimeter-wave radar includes one front millimeter-wave radar; the second group of LiDAR includes four corner millimeter-wave radars, totaling five, abbreviated as 5Radar; the ADAS map module and the road infrastructure information module each contain one module. At this point, assume the maximum operating capacity of the primary domain controller, composed of the first SoC as the main component, is 13V3L+5Radar+12USS, and the maximum operating capacity of the secondary domain controller, composed of the first SoC as the backup component, is 11V1L+5Radar; where:

[0078] In one embodiment, if the first SoC, which is the primary component, fails, it cannot configure deserializers A and B, resulting in the loss of video data streams from the corresponding cameras, as well as the loss of real-time GNSS and RTK signals. Meanwhile, the 12USS and IMU A can be transmitted via Switch A to Switch B and then to the second SoC, which serves as a backup component in the first sensing processing unit. Although the LiDAR used for blind spot detection can be transmitted to the second SoC via Switch A and B, the maximum operation of the secondary domain controller is 5R6V1L, specifically including four side-view cameras, one front wide-angle camera B, one rear-view camera B, one LiDAR, five LiDARs, a 12USS, IMU A, and IMU B. Under normal circumstances, the vehicle can be required to decelerate less than 0.5g, continuously pass through the current location and seek opportunities to pull over, and in case of an emergency, brake to a stop on the current path or steer around obstacles.

[0079] In one embodiment, if the second SOC, serving as a backup component, fails, it cannot configure deserializers C and D, resulting in the loss of video data streams from the corresponding cameras and the loss of data from IMU A. Therefore, the maximum operation of the secondary domain controller is 5R7V3L, specifically including 4 surround-view cameras, 1 front narrow-angle camera, 1 front wide-angle camera A, 1 rear-view camera A, plus 3 LiDARs, 5 Radars, 12 USS, and IMU A. Under normal circumstances, the vehicle can be required to decelerate less than 0.5g, continuously pass through the current position and seek opportunities to pull over to the side of the road, and in case of emergency, brake to a stop on the current path or steer around obstacles.

[0080] In one embodiment, if Switch A, the primary component, fails, data streams from the two LiDARs and IMU A used for blind spot detection cannot be obtained, and the main SOC and MCU cannot communicate; at this time, the maximum operation of the main domain controller is 13V1L+5Radar. The vehicle can then slowly decelerate or choose to pull over.

[0081] In one embodiment, if Switch B, which serves as a backup component, fails, the data stream of 1Lidar cannot be obtained, and the primary SOC and secondary SOC cannot communicate; at this time, the maximum operation of the primary domain controller is 13V2L + 5Radar + 12USS; at this time, the vehicle can slowly decelerate or choose to pull over.

[0082] In one embodiment, if the first MCU, which is the primary component, fails, data streams from IMU A and 12USS cannot be obtained; at this time, the maximum operation of the primary domain controller is 13V1L+5Radar. The vehicle can slowly decelerate or choose to pull over.

[0083] In one embodiment, if the second MCU, which serves as a backup component, fails, the data stream from the IMU cannot be obtained; at this time, the maximum operation of the main domain controller is 13V3L+5Radar+12USS; the vehicle can slowly decelerate or choose to pull over.

[0084] In one embodiment, if deserializer A fails, the data streams from the front narrow-angle camera, front wide-angle camera A, and rear-view camera A cannot be acquired; at this time, the maximum operation of the main domain controller is 10V3L + 5Radar + 4 surround-view cameras + 4 side-view cameras + front wide-angle camera B + rear-view camera B + 3Lidar + 5Radar. The vehicle can slowly decelerate or choose to pull over.

[0085] In one embodiment, if the deserializer B fails, the data streams from the four surround-view cameras cannot be acquired; at this time, the maximum operation of the main domain controller is 9V3L+5Radar+12USS; at this time, the vehicle can slowly decelerate or choose to pull over.

[0086] In one embodiment, if the deserializer C fails, the data streams from the four side-view cameras cannot be acquired; at this time, the maximum operation of the main domain controller is 9V3L+5Radar+12USS; at this time, the vehicle can slow down and travel straight without moving to the side of the road.

[0087] In one embodiment, if the deserializer D fails, the data streams from the front wide-angle camera B and the rear-view camera B cannot be acquired; at this time, the maximum operation of the main domain controller is 11V3L+5Radar+12USS; the vehicle can slowly decelerate or choose to pull over.

[0088] In one embodiment, if the RTK module fails, the vehicle's positioning will be inaccurate, and the ADAS map may deviate significantly. At this time, the maximum operation of the main domain controller is 11V3L+5Radar+12USS. The vehicle can slowly decelerate or choose to pull over.

[0089] In one embodiment, if the ADAS map module fails, the vehicle will not have a real-time map and will need to rely on its own perception to build a map and operate. At this time, the maximum operation of the main domain controller is 11V3L+5Radar+12USS. The vehicle can slowly decelerate or choose to pull over.

[0090] In one embodiment, if any of the environmental sensors (not shown in the figure), such as the sunlight sensor, rain sensor, fog sensor, and road surface sensor, fails, redundancy can be achieved by relying on other preset methods. For example, the sunlight sensor can be used to identify light levels and automatically control the use of low beam and high beam headlights; the wiper activation control and sensing can be used to identify rainfall; a visual model based on the acquired images can be trained to identify foggy scenes; and road surface conditions such as ice, snow, and mud can be identified based on the road 5G detection information collected by the road infrastructure information module. In this case, the vehicle can slowly decelerate or choose to pull over.

[0091] Figure 6 This is a schematic structural diagram of an electronic device according to an exemplary embodiment. Please refer to... Figure 6 At the hardware level, the electronic device includes a processor, internal bus, network interface, memory, and non-volatile memory, and may also include other necessary hardware. The processor reads the corresponding computer program from the non-volatile memory into memory and then executes it, forming a vehicle component control device at the logical level. Of course, in addition to software implementation, this specification does not exclude other implementation methods, such as logic devices or a combination of hardware and software, etc. That is to say, the execution subject of the following processing flow is not limited to individual logic units, but can also be hardware or logic devices.

[0092] Corresponding to the embodiments of the aforementioned vehicle component control method, this specification also provides embodiments of a vehicle component control device.

[0093] Please refer to Figure 7 , Figure 7 This is a schematic diagram illustrating the structure of a vehicle component control device in an exemplary embodiment. For example... Figure 7 As shown, the device is applied to a vehicle equipped with a domain controller connected to environmental sensors. The domain controller includes at least one set of perception processing components, with the perception processing components within the same set performing the same perception processing function. The device includes:

[0094] The component determination unit 702 is used to determine a second perception processing component from the remaining components in the group to which the first perception processing component belongs when the first perception processing component fails.

[0095] The component replacement unit 704 is used to control the second perception processing component to take over the target perception processing function from the first perception processing component.

[0096] Optionally, the component types corresponding to each group of perception processing components are different, while the component types within the same group of perception processing components are the same, and the component types include perception computing components.

[0097] Optionally, the domain controller further includes a data distribution component; the apparatus includes:

[0098] The data stream transmission unit receives environmental data streams from the environmental sensors based on the data allocation component, and sends the environmental data streams to different sensing computing components within the same group.

[0099] Optionally, the component type further includes the data allocation component; the first perception processing component is the first data allocation component; the component determination unit 702 is specifically used for:

[0100] Obtain the target environment range of the environment data stream corresponding to the first data allocation component;

[0101] The second data allocation component is selected from the remaining components, and one or more combinations thereof that match the target environmental range are selected as the second perception processing component.

[0102] Optionally, each data distribution component can be connected to a different environmental sensor based on the principle of minimum complementarity within the environmental range.

[0103] Optionally, the type of the environmental data stream includes at least one of the following:

[0104] Video data stream, Ethernet data stream, vehicular network data stream.

[0105] Optionally, the sensing computing component includes a system-on-a-chip (SoC) and a microcontroller (MCU), with each MCU connected to the SoC in the same sensing computing component and at least one SoC in another sensing computing component; the first sensing processing component is the first MCU; the component determination unit 702 is specifically used for:

[0106] Obtain the processing performance of each second MCU in the remaining components;

[0107] The second MCU with the highest processing performance is used as the second sensing processing component.

[0108] Optionally, the domain controller is connected to multiple target environment sensors with the same sensing capability but different sensing performance. Each target environment sensor is associated with a different sensing computing component. The association indicates that the corresponding target environment sensor and the sensing computing component jointly perform the same sensing processing function. The sensing performance of any target environment sensor is negatively correlated with the processing performance of the corresponding sensing computing component.

[0109] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to in the description of the method embodiments. The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of the solution in this specification according to actual needs. Those skilled in the art can understand and implement this without creative effort.

[0110] Based on the same concept as the methods described above, this specification also provides a vehicle, including: a processor, a memory for storing processor-executable instructions, a domain controller, and environmental sensors; wherein the processor executes the executable instructions to implement the steps of the method as described in any of the above embodiments.

[0111] Based on the same concept as the methods described above, this specification also provides a computer-readable storage medium having computer instructions stored thereon that, when executed by a processor, implement the steps of the methods as described in any of the above embodiments.

[0112] Based on the same concept as the methods described above, this specification also provides a computer program product, including a computer program / instructions that, when executed by a processor, implement the steps of the methods as described in any of the above embodiments.

[0113] The embodiments of the subject matter and functional operation described in this specification can be implemented in the following ways: digital electronic circuits, tangibly embodied computer software or firmware, computer hardware including the structures disclosed in this specification and their structural equivalents, or combinations thereof. Embodiments of the subject matter described in this specification can be implemented as one or more computer programs, i.e., one or more modules of computer program instructions encoded on a tangible, non-transitory program carrier for execution by a data processing apparatus or for controlling the operation of a data processing apparatus. Alternatively or additionally, the program instructions may be encoded on artificially generated propagation signals, such as machine-generated electrical, optical, or electromagnetic signals, which are generated to encode information and transmit it to a suitable receiving device for execution by the data processing apparatus. The computer storage medium may be a machine-readable storage device, a machine-readable storage substrate, a random or serial access memory device, or combinations thereof.

[0114] The processing and logic flow described in this specification can be executed by one or more programmable computers that execute one or more computer programs to perform corresponding functions by operating on input data and generating output. The processing and logic flow can also be executed by dedicated logic circuitry—such as FPGAs (Field-Programmable Gate Arrays) or ASICs (Application-Specific Integrated Circuits), and the device can also be implemented as dedicated logic circuitry.

[0115] Suitable computers for executing computer programs include, for example, general-purpose and / or special-purpose microprocessors, or any other type of central processing unit. Typically, the central processing unit receives instructions and data from read-only memory and / or random access memory. The basic components of a computer include a central processing unit for implementing or executing instructions and one or more memory devices for storing instructions and data. Typically, a computer will also include one or more mass storage devices for storing data, such as disks, magneto-optical disks, or optical disks, or the computer will be operatively coupled to such mass storage devices to receive data from or transfer data to them, or both. However, a computer is not required to have such devices. Furthermore, a computer can be embedded in another device, such as a mobile phone, a personal digital assistant (PDA), a mobile audio or video player, a game console, a GPS receiver, or a portable storage device such as a universal serial bus (USB) flash drive, to name a few.

[0116] Computer-readable media suitable for storing computer program instructions and data include all forms of non-volatile memory, media, and memory devices, such as semiconductor memory devices (e.g., EPROM, EEPROM, and flash memory devices), magnetic disks (e.g., internal hard disks or removable disks), magneto-optical disks, and CD-ROM and DVD-ROM disks. Processors and memory may be supplemented by or incorporated into dedicated logic circuitry.

[0117] While this specification contains numerous specific implementation details, these should not be construed as limiting the scope of any invention or the scope of the claims, but rather are primarily intended to describe features of specific embodiments of a particular invention. Certain features described in the various embodiments herein may also be implemented in combination in a single embodiment. Conversely, various features described in a single embodiment may also be implemented separately in various embodiments or in any suitable sub-combination. Furthermore, while features may function in certain combinations as described above and even initially claimed in this way, one or more features from a claimed combination may be removed from that combination in some cases, and a claimed combination may refer to a sub-combination or a variation thereof.

[0118] Similarly, although the operations are depicted in a specific order in the accompanying drawings, this should not be construed as requiring these operations to be performed in the specific order shown or sequentially, or requiring all illustrated operations to be performed to achieve the desired result. In some cases, multitasking and parallel processing may be advantageous. Furthermore, the separation of various system modules and components in the above embodiments should not be construed as requiring such separation in all embodiments, and it should be understood that the described program components and systems can generally be integrated together in a single software product or packaged into multiple software products.

[0119] Therefore, specific embodiments of the subject matter have been described. Furthermore, the processes depicted in the figures are not necessarily shown in a specific order or sequence to achieve the desired result. In some implementations, multitasking and parallel processing may be advantageous.

[0120] The above description is merely a preferred embodiment of this specification and is not intended to limit this specification. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this specification should be included within the scope of protection of this specification.

Claims

1. A method for controlling vehicle components, characterized in that, Applied to vehicles, the vehicles are equipped with a domain controller connected to environmental sensors. The domain controller includes at least one group of perception processing components. Perception processing components within the same group perform the same perception processing function. The component types corresponding to each group of perception processing components are different, while components within the same group have the same type. The component type includes a perception computing component. The perception computing component includes a system-on-a-chip (SoC) and a microcontroller (MCU). Each MCU is connected to the SoC in the same perception computing component and to the SoC in at least one other perception computing component. The method includes: In the event that the first sensing processing component performing the target sensing processing function fails, a second sensing processing component is determined from the remaining components in the group to which the first sensing processing component belongs. Both the first sensing processing component and the second sensing processing component belong to SoC or MCU. The second sensing processing component is controlled to take over the target sensing processing function from the first sensing processing component.

2. The method according to claim 1, characterized in that, The domain controller also includes a data allocation component, and the method further includes: The data distribution component receives environmental data streams from the environmental sensors and sends the environmental data streams to different sensing and computing components within the same group.

3. The method according to claim 2, characterized in that, The component type also includes the data allocation component; the first sensing processing component is the first data allocation component; determining the second sensing processing component from the remaining components in the group to which the first sensing processing component belongs includes: Obtain the target environment range of the environment data stream corresponding to the first data allocation component; The second data allocation component is selected from the remaining components, and one or more combinations thereof that match the target environmental range are selected as the second perception processing component.

4. The method according to claim 3, characterized in that, Each data distribution component is connected to a different environmental sensor based on the principle of minimum complementarity within the environmental range.

5. The method according to any one of claims 2 to 4, wherein the type of the environmental data stream includes at least one of the following: Video data stream, Ethernet data stream, vehicular network data stream.

6. The method according to claim 1, characterized in that, The first sensing processing component is a first MCU; determining the second sensing processing component from the remaining components within the group containing the first sensing processing component includes: Obtain the processing performance of each second MCU in the remaining components; The second MCU with the highest processing performance is used as the second sensing processing component.

7. The method according to claim 1, characterized in that, The domain controller is connected to multiple target environment sensors with the same sensing capability but different sensing performance. Each target environment sensor is associated with a different sensing computing component. The association indicates that the corresponding target environment sensor and the sensing computing component jointly perform the same sensing processing function. The sensing performance of any target environment sensor is negatively correlated with the processing performance of the corresponding sensing computing component.

8. A vehicle, characterized in that, include: A processor, a memory for storing processor-executable instructions, a domain controller, and an environmental sensor; wherein the processor implements the steps of the method as described in any one of claims 1 to 7 by executing the executable instructions.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the steps of the method as described in any one of claims 1 to 7.

10. A computer program product, characterized in that, Includes a computer program / instructions that, when executed by a processor, implement the steps of the method as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Intelligent driving method, intelligent driving domain controller and sensor

    CN117922610A