Redundant communication method and system based on vehicle-mounted network, vehicle and equipment

By introducing redundant communication methods and systems into the vehicle network, and utilizing redundant controllers and network segment switching, the data transmission problem caused by communication failures in complex environments is solved, thereby improving vehicle safety and reliability.

CN121284057APending Publication Date: 2026-01-06ANHUI DEEPWAY TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511277706.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-08
Publication Date
2026-01-06

AI Technical Summary

Technical Problem

Existing vehicle networks are prone to delays or loss of critical data transmission due to communication failures or interference in complex environments, affecting vehicle functional safety and reliability.

Method used

A redundant communication method is adopted, which uses redundant controllers and network segments to achieve a redundant data transmission strategy by switching between control modules and network segments. This ensures that in the event of a failure, the communication task is completed by switching to the redundant controller, and the strategy can be flexibly adjusted according to requirements.

Benefits of technology

It improves the security and reliability of the vehicle network, ensuring normal communication even in the event of a malfunction, and enhances the functional safety and operational reliability of the vehicle.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121284057A_ABST
    Figure CN121284057A_ABST
Patent Text Reader

Abstract

The invention discloses a redundant communication method and system based on a vehicle-mounted network, a vehicle and equipment. The redundant communication method based on the vehicle-mounted network comprises the steps that when a first control module sends a control command to a receiving end, whether a fault exists in the first control module or not is judged, and the fault comprises at least one of a system fault, a message overtime fault, a message failure fault and a message verification fault of the first control module; if yes, the receiving end executes a control command sent by a second control module; and when the fault of the first control module is recovered and the receiving end executes the control command sent by the second control module, executing the control command sent by the first control module. According to the embodiment of the invention, when communication of a certain controller fails or is interfered, the controller can be switched to the redundant controller to complete a communication task, and a redundancy strategy can be flexibly adjusted according to requirements, so that the safety and reliability of a vehicle-mounted network are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of vehicle network communication technology, and in particular to a redundant communication method, system, vehicle and equipment based on vehicle network. Background Technology

[0002] As the level of automotive intelligence continues to increase, in-vehicle networks are gradually undertaking more and more critical data transmission tasks. In existing technologies, most in-vehicle network architectures adopt a single-path data transmission method. During vehicle operation, if a complex environment is encountered, especially when some communication controllers or communication network segments malfunction or experience interference, critical data transmission can easily be delayed or lost, thereby affecting the vehicle's functional safety and overall performance, and reducing the reliability and safety of vehicle operation. Summary of the Invention

[0003] Therefore, it is necessary to provide a redundant communication method, system, vehicle, and equipment based on vehicle network to address the above-mentioned technical problems. When the communication of a certain controller fails or is interfered with, the system can switch to a redundant controller to complete the communication task. Furthermore, the redundancy strategy can be flexibly adjusted according to requirements, thereby improving the security and reliability of the vehicle network.

[0004] Firstly, a redundant communication method based on a vehicle network is provided. The vehicle network includes a gateway and multiple controllers. A first controller among the multiple controllers includes an independent first control module and a second control module, the first control module and the second control module having the same function. The redundant communication method includes: When the first control module sends a control command to the receiving end, it is determined whether the first control module has a fault. The fault includes at least one of the following: system fault of the first control module, message timeout fault, message invalidation fault, and message verification fault. If so, the receiving end executes the control command sent by the second control module; Once the fault in the first control module is resolved and the receiving end has executed the control command sent by the second control module, the control command sent by the first control module is executed.

[0005] Furthermore, it also includes: If both the first control module and the second control module have the aforementioned fault, the receiving end will not execute the control commands sent by the first control module and the second control module, and will control the vehicle to enter a safe mode.

[0006] Furthermore, among the plurality of controllers, the second controller and the third controller are two independent controllers, and the third controller is a redundant controller of the second controller. The redundant communication method further includes: Determine whether the second controller has a fault, wherein the fault includes at least one of the following: system fault of the second controller, node loss fault, message failure fault, and message verification fault; If so, then execute the control command sent by the third controller; Once the fault of the second controller is recovered and the control command sent by the third controller has been executed, the control command sent by the second controller is executed.

[0007] Furthermore, the vehicle network also includes a main communication network segment and a redundant communication network segment, wherein the main communication network segment and the redundant communication network segment send the same message, the data on the main communication network segment has a higher priority than the data on the redundant communication network segment, and the fourth controller among the plurality of controllers can send the same data on the main communication network segment and the redundant communication network segment. The redundant communication method further includes: Determine whether there is a fault in the main communication network segment, wherein the fault includes at least one of the following: main communication network segment message timeout fault, main communication network segment message failure fault, and main communication network segment message verification fault. If so, the receiving end executes the message from the redundant communication network segment; Once the fault in the main communication network segment is recovered and the messages from the redundant communication network segment have been executed, the messages from the main communication network segment are executed.

[0008] Furthermore, it also includes: When both the main communication network segment and the redundant communication network segment have the aforementioned fault, the receiving end does not execute messages from the main communication network segment and the redundant communication network segment, and controls the vehicle to enter a safe mode.

[0009] Furthermore, the fifth controller among the plurality of controllers includes a main control module and a redundant control module. The main control module is connected to both the main communication network segment and the redundant communication network segment, and the redundant control module is connected to both the main communication network segment and the redundant communication network segment. The redundant communication method further includes: Determine whether there is a fault in the control command sent by the main control module on the main communication network segment. The fault includes at least one of the following: message timeout fault, message invalidation fault, and message verification fault in the control command sent by the main control module on the main communication network segment. If so, the receiving end executes the control commands sent by the main control module through the redundant communication network segment; After the fault of the control commands sent by the main control module on the main communication network segment is recovered and the control commands sent by the main control module through the redundant communication network segment are executed, the control commands sent by the main control module on the main communication network segment will continue to be executed.

[0010] Furthermore, it also includes: Determine whether the main control module has a fault, wherein the fault includes at least one of the following: system fault of the main control module, message timeout fault of control commands sent by the main control module on the main communication network segment and redundant communication network segment, message invalidation fault of control commands sent by the main control module on the main communication network segment and redundant communication network segment, and message verification fault of control commands sent by the main control module on the main communication network segment and redundant communication network segment. If so, execute the control commands sent from the redundant control module through the main communication network segment; After the fault is recovered and the control commands sent from the redundant control module through the main communication network segment are executed, the control commands sent from the main control module through the main communication network segment or the redundant communication network segment continue to be executed.

[0011] Secondly, a redundant communication system based on a vehicle network is provided. The vehicle network includes a gateway and multiple controllers. A first controller among the multiple controllers includes an independent first control module and a second control module. The first control module and the second control module have the same function. The redundant communication system includes: The judgment module is used to determine whether the first control module has a fault when the first control module sends a control command to the receiving end. The fault includes at least one of the following: system fault of the first control module, message timeout fault, message invalidation fault, and message verification fault. The execution module is used to execute the control commands sent by the second control module when the first control module malfunctions, and to execute the control commands sent by the first control module after the first control module recovers from its malfunction and the receiving end has executed the control commands sent by the second control module.

[0012] Thirdly, a vehicle is provided, comprising: a redundant communication system based on an in-vehicle network as described in the second aspect above.

[0013] Fourthly, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements the steps of the redundant communication method based on a vehicle network described in the first aspect and any possible implementation of the first aspect.

[0014] In the embodiments of this application, when the first control module sends a control command to the receiving end, it is first determined whether the first control module has a fault. The fault includes at least one of the following: system fault, message timeout fault, message invalidation fault, and message verification fault. If so, the receiving end executes the control command sent by the second control module. After the fault in the first control module is resolved and the receiving end has executed the control command sent by the second control module, the control command sent by the first control module is executed. Therefore, when a controller communication fails or is interfered with, the communication task can be switched to a redundant controller, and the redundancy strategy can be flexibly adjusted according to requirements, thereby improving the security and reliability of the vehicle network. Attached Figure Description

[0015] Other features, objects, and advantages of this application will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings: Figure 1 A flowchart illustrating the redundant communication method based on an in-vehicle network provided in this application embodiment; Figure 2 A schematic diagram of the overall structure of the redundant communication method based on vehicle network provided in the embodiments of this application; Figure 3 A structural block diagram of a redundant communication system based on an in-vehicle network provided in an embodiment of this application; Figure 4 This is a structural block diagram of a computer device provided in an embodiment of this application. Detailed Implementation

[0016] The present application will now be described in further detail with reference to the embodiments and accompanying drawings. It should be understood that the specific embodiments described herein are for illustrative purposes only and are not intended to limit the application. Furthermore, it should be noted that, for ease of description, only the parts relevant to the application are shown in the accompanying drawings.

[0017] It should be noted that, unless otherwise specified, the embodiments and features of the embodiments in this application can be combined with each other. This application will now be described in detail with reference to the accompanying drawings and embodiments.

[0018] The following describes in detail, with reference to the accompanying drawings, a redundant communication method, system, vehicle, and device based on an in-vehicle network according to embodiments of this application.

[0019] Figure 1 This is a flowchart of a redundant communication method based on a vehicle network according to an embodiment of this application. Figure 1As shown, the in-vehicle network includes a gateway and multiple controllers. The first controller among the multiple controllers includes an independent first control module and a second control module. The first control module and the second control module have the same function. According to an embodiment of this application, the redundant communication method based on the in-vehicle network includes the following steps: S101: When the first control module sends a control command to the receiving end, it is determined whether the first control module has a fault, wherein the fault includes at least one of the following: system fault of the first control module, message timeout fault, message invalidation fault, and message verification fault.

[0020] Specifically, if a fault signal from the first control module is received, it is determined that the first control module has a system fault; if no message is received within a preset timeout threshold, it is determined that the first control module has a message timeout fault, and the value previously sent by the first control module is used in the algorithm calculation within the timeout threshold; if the message liveness counter does not match three times consecutively, it is determined that the first control module has a message failure fault; if a cyclic redundancy check error is received in any message frame, it is determined that the first control module has a message check fault.

[0021] S102: If so, the receiving end executes the control command sent by the second control module.

[0022] In a specific example, such as Figure 2 As shown, assuming that the EHPSM module and the EHPSS module are the first control module and the second control module respectively, when the above-mentioned fault is determined to exist in the EHPSM module, the receiving end immediately executes the control command sent by the EHPSS module.

[0023] S103: After the fault of the first control module is recovered and the receiving end has executed the control command sent by the second control module, the control command sent by the first control module is executed.

[0024] The fault recovery of the first control module can be determined when the following conditions are met simultaneously: receiving any frame of the fault-free signal of the first control module; being able to receive all messages of the first control module normally; the survival counter verification of the first control module message is calculated without error for three consecutive times; and the cyclic redundancy check of the first control module message is calculated without error for three consecutive times.

[0025] It also includes: if both the first control module and the second control module have the aforementioned fault, the receiving end will not execute the control commands sent by the first control module and the second control module, and will control the vehicle to enter a safe mode.

[0026] In one embodiment of this application, the second controller and the third controller among the plurality of controllers are two independent controllers, and the third controller is a redundant controller of the second controller. The redundant communication method further includes: determining whether the second controller has a fault, wherein the fault includes at least one of the following: system fault, node loss fault, message failure fault, and message verification fault of the second controller; if so, executing the control command sent by the third controller; after the fault of the second controller is recovered and the control command sent by the third controller is executed, executing the control command sent by the second controller.

[0027] Specifically, if a fault signal from the second controller is received, it is determined that the second controller has a system fault; if the second controller fails to send any messages, it is determined that the second controller has a node loss fault; if the message liveness counter does not match three times in a row, it is determined that the second controller has a message failure fault; if a cyclic redundancy check error is received in any message frame, it is determined that the second controller has a message verification fault.

[0028] The fault recovery of the second controller can be determined when the following conditions are met simultaneously: receiving any frame of the fault-free signal of the second controller; receiving any frame of the message of the second controller; the survival counter verification of the second controller message is calculated without error for three consecutive times; the cyclic redundancy check of the second controller message is calculated without error for three consecutive times.

[0029] In a specific example, such as Figure 2 As shown, the EBS module is the second controller; the EPB module is the third controller.

[0030] In one embodiment of this application, the vehicle network further includes a main communication network segment and a redundant communication network segment, wherein the main communication network segment and the redundant communication network segment send the same message, and the data on the main communication network segment has a higher priority than the data on the redundant communication network segment. A fourth controller among the plurality of controllers can send the same data on the main communication network segment and the redundant communication network segment. The redundant communication method further includes: determining whether there is a fault in the main communication network segment, wherein the fault includes at least one of a main communication network segment message timeout fault, a main communication network segment message failure fault, and a main communication network segment message verification fault; if so, the receiving end executes the message from the redundant communication network segment; after the fault in the main communication network segment is recovered and the message from the redundant communication network segment is executed, the message from the main communication network segment is executed.

[0031] Specifically, if no message is received within the preset timeout threshold, it is determined that there is a message timeout fault in the main communication network segment, and the value of the last message sent by the main communication network segment is used in the algorithm calculation within the timeout threshold; if the message liveness counter does not match three times in a row, it is determined that there is a message failure fault in the main communication network segment; if a cyclic redundancy check error is received in any frame of message, it is determined that there is a message check fault in the main communication network segment.

[0032] The fault recovery of the main communication network segment can be determined when the following conditions are met simultaneously: all messages of the main communication network segment are received normally; the liveness counter of any frame of the main communication network segment is checked three times consecutively without error; and the cyclic redundancy check of the messages of the main communication network segment is checked three times consecutively without error.

[0033] It also includes: when both the main communication network segment and the redundant communication network segment have the aforementioned fault, the receiving end does not execute messages from the main communication network segment and the redundant communication network segment, and controls the vehicle to enter a safe mode.

[0034] In a specific example, such as Figure 2 As shown, the IPDU module is the fourth controller, and the IPDU module is connected to the main communication network segment and the redundant communication network segment respectively.

[0035] In one embodiment of this application, the fifth controller among the plurality of controllers includes a main control module and a redundant control module. The main control module is connected to both the main communication network segment and the redundant communication network segment, and the redundant control module is also connected to both the main communication network segment and the redundant communication network segment. The redundant communication method further includes: determining whether a control command sent by the main control module on the main communication network segment has a fault, wherein the fault includes at least one of a message timeout fault, a message invalidation fault, and a message verification fault in the control command sent by the main control module on the main communication network segment; if so, the receiving end executes the control command sent by the main control module through the redundant communication network segment; after the fault of the control command sent by the main control module on the main communication network segment is recovered and the control command sent by the main control module through the redundant communication network segment is executed, the execution of the control command sent by the main control module on the main communication network segment continues.

[0036] Specifically, if no message is received within the preset timeout threshold, a message timeout fault is determined, and the value of the last sent message is used in the algorithm calculation within the timeout threshold; if the message liveness counter does not match three times in a row, a message failure fault is determined; if a cyclic redundancy check error is received in any frame of message, a message check fault is determined.

[0037] The fault recovery of the control commands sent by the main control module on the main communication network segment can be determined when the following conditions are met simultaneously: all messages sent by the main control module on the main communication network segment are received normally; the liveness counter verification of any frame of message sent by the main control module on the main communication network segment is calculated without error for three consecutive times; and the cyclic redundancy check of the messages sent by the main control module on the main communication network segment is calculated without error for three consecutive times.

[0038] In a specific example, such as Figure 2 As shown, the ADCU module is the fourth controller; the MCUA module is the main control module; and the MCUB module is the redundant control module. The MCUA module and the MCUB module are respectively connected to the main communication network segment and the redundant communication network segment.

[0039] In one embodiment of this application, the method further includes: determining whether the main control module has a fault, wherein the fault includes at least one of the following: a system fault of the main control module, a message timeout fault of the control command sent by the main control module on the main communication network segment and the redundant communication network segment, a message invalidation fault of the control command sent by the main control module on the main communication network segment and the redundant communication network segment, and a message verification fault of the control command sent by the main control module on the main communication network segment and the redundant communication network segment; if so, executing the control command sent by the redundant control module through the main communication network segment; after the fault is recovered and the control command sent by the redundant control module through the main communication network segment is executed, continuing to execute the control command sent by the main control module through the main communication network segment or the redundant communication network segment.

[0040] Specifically, if a fault signal from the main control module is received, the main control module is determined to have a system fault; if no message is received within a preset timeout threshold, the main control module is determined to have a message timeout fault, and the previously sent value is used in the algorithm calculation within the timeout threshold; if the liveness counters of control command messages sent by the main control module on the main communication network segment and the redundant communication network segment do not match three times consecutively, the main control module is determined to have a message failure fault; if a cyclic redundancy check error is received in any message frame, the main control module is determined to have a message verification fault.

[0041] The fault recovery of the main control module can be determined when the following conditions are met simultaneously: receiving any frame of fault-free signal from the main control module; receiving all messages sent by the main control module normally; the liveness counter verification of messages sent by the main control module on the main communication network segment and the redundant communication network segment is correct for three consecutive calculations; and the cyclic redundancy check of messages sent by the main control module on the main communication network segment and the redundant communication network segment is correct for three consecutive calculations.

[0042] According to the redundant communication method based on a vehicle network according to an embodiment of this application, when the first control module sends a control command to the receiving end, it is first determined whether the first control module has a fault. The fault includes at least one of the following: system fault, message timeout fault, message invalidation fault, and message verification fault of the first control module. If so, the receiving end executes the control command sent by the second control module. After the fault in the first control module is resolved and the receiving end has executed the control command sent by the second control module, the control command sent by the first control module is executed. Therefore, when a controller communication fails or is interfered with, the communication task can be switched to a redundant controller, and the redundancy strategy can be flexibly adjusted according to requirements, thereby improving the security and reliability of the vehicle network.

[0043] Figure 3 This is a structural block diagram of a redundant communication system based on a vehicle network according to an embodiment of this application. Figure 3 As shown, a redundant communication system based on a vehicle network according to an embodiment of this application includes: a judgment module 310 and an execution module 320, wherein: The judgment module 310 is used to determine whether the first control module has a fault when the first control module sends a control command to the receiving end. The fault includes at least one of the following: system fault of the first control module, message timeout fault, message invalidation fault, and message verification fault. The execution module 320 is used to execute the control command sent by the second control module when the first control module malfunctions, and to execute the control command sent by the first control module after the first control module recovers from the malfunction and the receiving end has executed the control command sent by the second control module.

[0044] According to the redundant communication system based on a vehicle network according to an embodiment of this application, when the first control module sends a control command to the receiving end, it first determines whether the first control module has a fault. The fault includes at least one of the following: system fault, message timeout fault, message invalidation fault, and message verification fault. If so, the receiving end executes the control command sent by the second control module. After the fault in the first control module is resolved and the receiving end has executed the control command sent by the second control module, the receiving end executes the control command sent by the first control module. Therefore, when a controller's communication fails or is interfered with, the system can switch to a redundant controller to complete the communication task, and the redundancy strategy can be flexibly adjusted according to requirements, thereby improving the security and reliability of the vehicle network.

[0045] Specific limitations regarding redundant communication systems based on vehicular networks can be found in the limitations of redundant communication methods based on vehicular networks described above, and will not be repeated here. Each module of the aforementioned redundant communication system based on vehicular networks can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device in hardware form, or stored in the memory of a computer device in software form, so that the processor can call and execute the corresponding operations of each module.

[0046] Furthermore, a vehicle is provided, comprising: a redundant communication system based on an in-vehicle network according to any of the above embodiments. When the first control module sends a control command to the receiving end, the vehicle can determine whether the first control module is faulty, wherein the fault includes at least one of a system fault, message timeout fault, message invalidation fault, and message verification fault of the first control module; if so, the receiving end executes the control command sent by the second control module; when the fault of the first control module is resolved and the receiving end has executed the control command sent by the second control module, the receiving end executes the control command sent by the first control module. Thus, when a controller communication fails or is interfered with, the system can switch to a redundant controller to complete the communication task, and the redundancy strategy can be flexibly adjusted according to requirements, thereby improving the security and reliability of the in-vehicle network.

[0047] Furthermore, other components and functions of the vehicle according to the embodiments of this application are known to those skilled in the art and will not be described in detail here.

[0048] The following is for reference. Figure 4 , Figure 4 A schematic diagram of a computer device structure suitable for implementing embodiments of this application is shown.

[0049] like Figure 4 As shown, the computer system 1000 includes a central processing unit (CPU) 1001, which can perform various appropriate actions and processes based on programs stored in read-only memory (ROM) 1002 or programs loaded from storage section 1008 into random access memory (RAM) 1003. The RAM 1003 also stores various programs and data required for the system's operating instructions. The CPU 1001, ROM 1002, and RAM 1003 are interconnected via a bus 1004. An input / output (I / O) interface 1005 is also connected to the bus 1004.

[0050] The following components are connected to I / O interface 1005: an input section 1006 including a keyboard, mouse, etc.; an output section 1007 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and speakers, etc.; a storage section 1008 including a hard disk, etc.; and a communication section 1009 including a network interface card such as a LAN card, modem, etc. The communication section 1009 performs communication processing via a network such as the Internet. A drive 1010 is also connected to I / O interface 1005 as needed. A removable medium 1011, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on drive 1010 as needed so that computer programs read from it can be installed into storage section 1008 as needed.

[0051] Specifically, according to embodiments of this application, the flowchart above refers to... Figure 1 The described process can be implemented as a computer-readable storage medium. For example, embodiments of this application include a computer-readable storage medium comprising a computer program containing program code for performing the method shown in the flowchart, such as performing: when a first control module sends a control command to a receiving end, determining whether the first control module has a fault, wherein the fault includes at least one of a system fault, a message timeout fault, a message invalidation fault, and a message verification fault of the first control module; if so, the receiving end executes the control command sent by the second control module; after the fault of the first control module is recovered and the receiving end has executed the control command sent by the second control module, the receiving end executes the control command sent by the first control module.

[0052] Specifically, according to embodiments of this application, the flowchart above refers to... Figure 1 The described process can be implemented as a computer software program. For example, embodiments of this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the method shown in the flowchart, for example, performing: when a first control module sends a control command to a receiving end, determining whether the first control module has a fault, wherein the fault includes at least one of a system fault, a message timeout fault, a message invalidation fault, and a message verification fault of the first control module; if so, the receiving end executes the control command sent by the second control module; after the fault of the first control module is recovered and the receiving end has executed the control command sent by the second control module, the receiving end executes the control command sent by the first control module.

[0053] In such an embodiment, the computer program includes program code for performing the methods shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via communication section 1009, and / or installed from removable media 1011. When the computer program is executed by the central processing unit (CPU) 1001, it performs the functions defined in the system of this application.

[0054] It should be noted that the computer-readable medium shown in this application can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this application, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this application, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media can also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.

[0055] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operational instructions of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two connected blocks may actually be executed substantially in parallel, or they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified functions or operational instructions, or using a combination of dedicated hardware and computer instructions.

[0056] The units or modules described in the embodiments of this application can be implemented in software or hardware. The described units or modules can also be located in a processor. The names of these units or modules do not, in certain circumstances, constitute a limitation on the unit or module itself.

[0057] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0058] The above embodiments merely illustrate several implementation methods of this application, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this patent application should be determined by the appended claims.

Claims

1. A method for redundant communication based on an in-vehicle network, characterized by, The vehicle-mounted network comprises a gateway and a plurality of controllers, a first controller in the plurality of controllers comprises independent first and second control modules, the first and second control modules have the same function, and the redundant communication method comprises: When the first control module sends a control command to a receiving end, it is judged whether the first control module has a fault, wherein the fault comprises at least one of a system fault, a message timeout fault, a message invalidation fault and a message check fault of the first control module; If yes, the receiving end executes a control command sent by the second control module; After the fault of the first control module is recovered and the receiving end executes the control command sent by the second control module, a control command sent by the first control module is executed.

2. The in-vehicle network-based redundant communication method according to claim 1, characterized by, Further comprising: If the first and second control modules both have the fault, the receiving end does not execute the control commands sent by the first and second control modules, and controls the vehicle to enter a safety mode.

3. The in-vehicle network-based redundant communication method according to claim 1, characterized by, A second controller and a third controller in the plurality of controllers are two independent controllers, and the third controller is a redundant controller of the second controller, and the redundant communication method further comprises: It is judged whether the second controller has a fault, wherein the fault comprises at least one of a system fault, a node loss fault, a message invalidation fault and a message check fault of the second controller; If yes, a control command sent by the third controller is executed; After the fault of the second controller is recovered and the control command sent by the third controller is executed, a control command sent by the second controller is executed.

4. The method of claim 1-3, wherein, The vehicle-mounted network further comprises a main communication network segment and a redundant communication network segment, wherein the main and redundant communication network segments send the same message, the priority of data on the main communication network segment is higher than that on the redundant communication network segment, a fourth controller in the plurality of controllers can send the same data on the main and redundant communication network segments, and the redundant communication method further comprises: It is judged whether the main communication network segment has a fault, wherein the fault comprises at least one of a main communication network segment message timeout fault, a main communication network segment message invalidation fault and a main communication network segment message check fault; If yes, the receiving end executes a message from the redundant communication network segment; After the fault of the main communication network segment is recovered and the message from the redundant communication network segment is executed, a message from the main communication network segment is executed.

5. The in-vehicle network-based redundant communication method according to claim 4, characterized by, Further comprising: When the main and redundant communication network segments both have the fault, the receiving end does not execute the messages from the main and redundant communication network segments, and controls the vehicle to enter a safety mode.

6. The in-vehicle network-based redundant communication method according to claim 4, characterized by, A fifth controller in the plurality of controllers comprises a main control module and a redundant control module, the main control module is connected with the main and redundant communication network segments respectively, the redundant control module is connected with the main and redundant communication network segments respectively, and the redundant communication method further comprises: determining whether a control command sent by the master control module on the master communication network segment has a fault, the fault including at least one of a message timeout fault, a message invalidation fault, and a message check fault of the control command sent by the master control module on the master communication network segment; if yes, the receiving end executes a control command sent by the master control module through the redundant communication network segment; after the fault of the control command sent by the master control module on the master communication network segment is recovered and the control command sent by the master control module through the redundant communication network segment is executed, the receiving end continues to execute the control command sent by the master control module on the master communication network segment.

7. The in-vehicle network-based redundant communication method according to claim 6, characterized by, Further comprising: determining whether the master control module has a fault, wherein the fault includes at least one of a system fault of the master control module, a message timeout fault of a control command sent by the master control module on the master communication network segment and the redundant communication network segment, a message invalidation fault of the control command sent by the master control module on the master communication network segment and the redundant communication network segment, and a message check fault of the control command sent by the master control module on the master communication network segment and the redundant communication network segment; if yes, executing a control command sent by the redundant control module through the master communication network segment; after the fault is recovered and the control command sent by the redundant control module through the master communication network segment is executed, continuing to execute a control command sent by the master control module through the master communication network segment or the redundant communication network segment.

8. A redundant communication system based on an in-vehicle network, characterized by The vehicle-mounted network includes a gateway and a plurality of controllers, a first controller of the plurality of controllers includes independent first and second control modules, the first and second control modules have the same function, and the redundant communication system includes: a determining module configured to determine whether the first control module has a fault when the first control module sends a control command to a receiving end, wherein the fault includes at least one of a system fault of the first control module, a message timeout fault, a message invalidation fault, and a message check fault; an executing module configured to execute a control command sent by the second control module when the first control module has the fault, and execute a control command sent by the first control module after the fault of the first control module is recovered and the receiving end executes the control command sent by the second control module.

9. A vehicle characterized by comprising: Further comprising: The redundant communication system based on a vehicle-mounted network according to claim 8.

10. A computer device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor executes a program to implement the redundant communication method based on a vehicle-mounted network according to any one of claims 1-7. The processor executes a program to implement the redundant communication method based on a vehicle-mounted network according to any one of claims 1-7.