Cooperative control method and device based on chassis domain controller, vehicle and medium
By employing a collaborative control method based on chassis domain controllers, the challenges of data sharing and functional coordination in traditional automotive electronic and electrical architectures have been resolved. This has enabled safety redundancy and global optimization of the chassis system, thereby enhancing the overall safety and reliability of the vehicle.
Patent Information
- Application Number
- CN202511785032.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-28
- Publication Date
- 2026-03-03
AI Technical Summary
Traditional automotive electronic and electrical architectures face challenges in achieving data sharing, dynamic scheduling of computing power, and functional collaboration when dealing with cross-domain integrated functions such as advanced driver assistance systems and smart cockpits. This results in limitations in vehicle-level performance optimization and service-oriented expansion, as well as low system redundancy, high cost, and high complexity.
A collaborative control method based on chassis domain controllers is adopted. By collecting parameters of each chassis subsystem, fault diagnosis is performed, a compensation control strategy is generated, and the resources of non-faulty subsystems are used to replace the functions of faulty subsystems. Vehicle stability is monitored in real time to achieve cross-system safety redundancy and global optimization control.
It improves the overall safety and reliability of the chassis system, reduces hardware costs and development complexity, enhances fault tolerance and adaptability, and achieves millisecond-level fault-tolerant control response.
Smart Images

Figure CN121590574A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of automotive engineering technology, specifically to a collaborative control method, device, vehicle, and medium based on a chassis domain controller. Background Technology
[0002] With the rapid development of automotive intelligence, connectivity, and electrification, the complexity of vehicle functions is increasing exponentially. To address the diverse functional requirements (such as engine management, body control, infotainment, and driver assistance), traditional electronic and electrical architectures generally adopt a distributed topology: dividing the vehicle's functions into dozens to hundreds of independent electronic control units (ECUs) based on physical location or functional domain. Each ECU implements a single or partial function through dedicated sensors, actuators, and embedded software, and relies on bus protocols such as CAN, LIN, and FlexRay for point-to-point or broadcast communication. This architecture demonstrated significant advantages at a specific historical stage: the functional boundaries of each ECU were clear, the hardware and software were deeply coupled, allowing for parallel development and rapid delivery by different suppliers; the failure of a single ECU only affected a partial function, resulting in high vehicle fault tolerance and robustness; and in the early stages, with low functional iteration frequency and limited computing power requirements, distributed deployment achieved a good balance between cost and development efficiency.
[0003] However, as advanced driver assistance systems (ADAS), smart cockpits, over-the-air (OTA) updates for vehicles, and energy management optimization become core competitive advantages, the inherent limitations of the aforementioned model are becoming increasingly apparent: each ECU is isolated from the others at the hardware and software levels, its functional logic operates in a closed loop on independent nodes, and data is passively exchanged on the bus only through preset signals, lacking a unified operating system, middleware, and global communication mechanism for coordination. This "island-like" deployment makes it difficult to achieve cross-ECU sensor data sharing, dynamic scheduling of computing power, and collaborative decision-making, posing a fundamental bottleneck to vehicle-level performance optimization, service-oriented expansion, and continuous evolution. Summary of the Invention
[0004] This invention provides a collaborative control method, device, vehicle, and medium based on a chassis domain controller, which can effectively improve the overall safety and reliability of the chassis system.
[0005] This invention provides a cooperative control method based on a chassis domain controller, the method comprising: The system collects the operating parameters of each subsystem of the vehicle chassis and performs fault diagnosis on the operating parameters according to the preset fault threshold. When a fault is detected in any of the aforementioned subsystems, the fault information of the faulty subsystem will be correlated with the vehicle stability requirements. Generate corresponding compensation and control strategies based on the correlation analysis results; Based on the aforementioned compensation control strategy, the subsystems for which no faults were found are controlled so that by sharing the hardware resources of the subsystems for which no faults were found, the subsystems for which no faults were found can cooperate to replace the faulty subsystems and perform the corresponding functions. The vehicle's stability index is monitored, and the execution intensity and strategy parameters of the compensation control strategy are adjusted according to the detected stability index until the faulty subsystem returns to normal or the vehicle enters a safe area.
[0006] Optionally, the cooperative control method based on the chassis domain controller further includes: When a fault signal is detected, the redundant signal source of the fault signal is compared with the main signal source to perform cross-validation on the fault signal. If the data deviation between the redundant signal source and the main signal source exceeds a preset threshold, the main signal source is determined to be faulty, and the fault signal fails the verification. The sensor channels corresponding to the fault signals that fail verification are isolated, and the fault signals that fail verification are shielded to prevent them from affecting the calculation process for generating the compensation control strategy.
[0007] Optionally, the cooperative control method based on the chassis domain controller further includes: The fault status information of the vehicle chassis is sent to other domains in the vehicle other than the vehicle chassis via the vehicle communication bus. The other domains include the power domain and the autonomous driving domain. Obtain the safety status feedback information from the other domains, and parse the constraint parameters related to the vehicle chassis in the safety status feedback information; Based on the constraint parameters, the execution boundary parameters of the compensation control strategy are adjusted.
[0008] Optionally, the fault information includes a fault type, wherein the fault type is a first fault type that causes the vehicle to experience a first type of dynamic imbalance, or a second fault type that causes the vehicle to experience a second type of asymmetric dynamic imbalance. The step of generating corresponding compensation control strategies based on the correlation analysis results includes: When the diagnosed fault belongs to the first fault type, a first type of compensation control strategy is generated, wherein the first type of compensation control strategy is used to control one or more functional first subsystems, and generates a compensating physical quantity to counteract the first type of dynamic imbalance by outputting or adjusting the first control quantity that the first subsystem can provide. When the diagnosed fault belongs to the second fault type, a second type of compensation control strategy is generated. The second type of compensation control strategy is used to control one or more functional second subsystems. By outputting or adjusting the second control quantity that the second subsystem can provide, a stabilizing effect is generated to restore the second type of dynamic imbalance to normal.
[0009] Optionally, the method of diagnosing faults in the operating parameters based on preset fault thresholds includes: Based on multi-source sensor data and vehicle dynamics model, the dynamic state parameters of the vehicle are estimated; Perform trend analysis on the time series of the dynamic state parameters and calculate the deviation coefficient between the rate of change of the dynamic state parameters and the historical benchmark value; When the deviation coefficient is detected to exceed the preset warning threshold, it is determined that the vehicle performance has a degradation trend or potential fault, and a safety strategy adjustment instruction is generated as the input parameter of the compensation control strategy.
[0010] Optionally, determining that the vehicle's performance is showing a deterioration trend or potential fault when the deviation coefficient exceeds a preset warning threshold includes: Based on a pre-defined vehicle dynamics model and an extended Kalman filter, the key state parameters of the target subsystem are estimated using signals from the first type of sensors. The estimated values of the key state parameters are compared with the measured values of the second type of sensor, and a residual sequence is generated based on the comparison results. Statistical analysis is performed on the residual sequence. When the statistical value obtained from the statistical analysis exceeds the preset statistical value and a self-test signal indicating an abnormal sensor state is detected, it is determined that the target subsystem or the sensor of the target subsystem has failed.
[0011] Optionally, the step of controlling the subsystems without detected faults based on the compensation control strategy, so as to enable the subsystems without detected faults to cooperate and perform corresponding functions in place of the faulty subsystems by sharing the hardware resources of the subsystems without detected faults, includes: After identifying the faulty subsystem, the prediction model set in the preset model prediction controller is reconstructed according to the fault type of the faulty subsystem. In this process, the control input corresponding to the faulty subsystem is used as the external disturbance input, and the controllable input vector and related input matrix of the model prediction controller are updated. Based on the reconstructed prediction model, the optimization problem of the model prediction controller is determined. The objective function of the optimization problem is configured to minimize the deviation between the vehicle stability index and the reference value, as well as the magnitude of the change in the constraint control input. In each control cycle, the optimization problem is solved to obtain the optimal control quantity, and the subsystems without detected faults are controlled to perform actions through the optimal control quantity to collaboratively generate compensating stabilizing torques to maintain vehicle stability.
[0012] The present invention also provides a collaborative control device based on a chassis domain controller, the device comprising: The diagnostic module is used to collect the operating parameters of each subsystem of the vehicle chassis and perform fault diagnosis on the operating parameters according to the preset fault threshold. The analysis module is used to correlate the fault information of any of the subsystems with the vehicle stability requirements when a fault is detected. The decision-making module is used to generate corresponding compensation and control strategies based on the correlation analysis results; The control module is used to control the subsystems for which no faults were found based on the compensation control strategy, so as to enable the subsystems for which no faults were found to perform corresponding functions by cooperating in place of the faulty subsystems by sharing the hardware resources of the subsystems for which no faults were found. An adjustment module is used to monitor the vehicle's stability index and adjust the execution intensity and strategy parameters of the compensation control strategy according to the detected stability index until the faulty subsystem returns to normal or the vehicle enters a safe area.
[0013] The present invention also provides a vehicle, the vehicle including a memory and a processor, the memory storing a computer program, the processor executing the computer program to implement the cooperative control method based on the chassis domain controller as described in any of the preceding claims.
[0014] The present invention also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the cooperative control method based on a chassis domain controller as described in any of the preceding claims.
[0015] The present invention has at least the following beneficial effects: This technical solution enhances the safety and reliability of the chassis system through multi-stage collaboration. First, it comprehensively collects operating parameters from all chassis subsystems and diagnoses faults in real time, ensuring timely detection. Second, it correlates faulty subsystem information with vehicle stability requirements, accurately pinpointing the impact of faults on vehicle stability and providing a basis for subsequent control. Third, it generates a compensation control strategy based on correlation analysis, utilizing the hardware resources of non-faulty subsystems to replace the functions of the faulty subsystem, ensuring the vehicle maintains basic driving functions even in fault conditions and preventing overall functional failure due to a single subsystem failure. Finally, it monitors the vehicle stability index in real time and dynamically adjusts the execution strength and parameters of the compensation control strategy, keeping the vehicle in a safe and controllable state throughout the fault period until the fault is resolved or the vehicle is safely brought to a stop. This closed-loop collaborative control approach, from fault diagnosis and correlation analysis to dynamic compensation control, effectively enhances the chassis system's fault tolerance and adaptability, significantly improving overall safety and reliability. Attached Figure Description
[0016] The accompanying drawings are provided to further understand the technical solutions of the present invention and constitute a part of the specification. They are used together with the embodiments of the present invention to explain the technical solutions of the present invention, and do not constitute a limitation on the technical solutions of the present invention.
[0017] Figure 1 This is a flowchart illustrating the steps of a collaborative control method based on a chassis domain controller. Figure 2 This is a flowchart illustrating the steps involved in verifying fault signals in a collaborative control method based on a chassis domain controller. Figure 3 This is a flowchart illustrating the steps involved in implementing feedback mediation in a collaborative control method based on a chassis domain controller. Figure 4 This is a flowchart of the fault diagnosis steps in a collaborative control method based on a chassis domain controller; Figure 5 This is a flowchart of step S104 in a collaborative control method based on a chassis domain controller; Figure 6 This is a schematic diagram of a collaborative control device based on a chassis domain controller; Figure 7 This is a flowchart illustrating the operational process of a collaborative control device based on a chassis domain controller. Detailed Implementation
[0018] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.
[0019] It should be noted that, based on existing technical solutions, the newly added method further enhances the chassis system's fault response capability and stability control accuracy by optimizing the predictive model of the model predictive controller. After identifying the faulty subsystem, the fault input is treated as an external disturbance, and the predictive model is reconstructed, updating the controllable input vector and input matrix. Based on the reconstructed model, the optimization problem aims to minimize the deviation of the vehicle stability index and the magnitude of changes in the constraint control input. The optimal control quantity is solved in each control cycle, controlling the non-faulty subsystems to collaboratively generate compensatory stabilizing torque. This dynamic reconstruction and optimization control method enables the chassis system to maintain vehicle stability more accurately under fault conditions, enhancing the system's fault tolerance and adaptability, and significantly improving the vehicle's safety and reliability in complex fault scenarios.
[0020] Researchers in this application discovered numerous safety issues with traditional automotive electronic control systems. First, safety strategies are isolated and system redundancy is low. When sensors or actuators fail, degradation or failure handling is only performed within the local ECU. For example, if the rear-wheel steering system fails, it simply locks in the neutral position without considering adjusting load distribution through the suspension system to compensate for stability losses, thus missing opportunities to improve safety levels. Second, cross-system fault diagnosis and handling are delayed and complex. For instance, if a rear-wheel steering system failure causes the suspension system to exceed its load limits, the distributed architecture requires complex information exchange and decision-making across ECUs, making it difficult to achieve timely and reliable global safety responses. Furthermore, to meet high ASIL level requirements, each ECU needs to be equipped with redundant hardware resources, significantly increasing system cost, weight, and complexity. Simultaneously, the complex interactions between multiple high ASIL level ECUs may introduce new potential failure modes, increasing the difficulty of system safety analysis and certification.
[0021] To address the aforementioned technical challenges, this technical solution provides a collaborative control method, device, vehicle, and medium based on a chassis domain controller. Through centralized control of the chassis domain controller, system-level functional safety redundancy is achieved, breaking the system boundary limitations of traditional architectures. In the event of a single fault, healthy execution systems (such as active suspension) can be instructed to compensate for the faulty system (such as rear-wheel steering), creating cross-system safety redundancy and significantly improving the overall vehicle's functional safety level and robustness. Simultaneously, the centralized functional safety manager possesses global vehicle status information and subsystem health status information, enabling instantaneous globally optimal safety decisions. This avoids the latency caused by cross-network communication and negotiation in distributed architectures, achieving millisecond-level fault-tolerant control response. Furthermore, through the centralization and sharing of hardware resources, only one safety mechanism meeting the highest ASIL level requirements is needed to cover multiple systems, avoiding redundant construction and significantly reducing hardware and development costs. More importantly, integrating multiple high ASIL-level systems into a single physical unit reduces the complexity of inter-system interactions, lowers the risk of common-cause failures due to interactions, and simplifies safety analysis (such as FMEA and FTA), safety certification, and testing verification processes. The following are various embodiments of this technical solution.
[0022] Please refer to Figure 1 , Figure 1 This is a flowchart illustrating the steps of a collaborative control method based on a chassis domain controller.
[0023] This embodiment provides a collaborative control method based on a chassis domain controller, including: S101. Collect the operating parameters of each subsystem of the vehicle chassis and perform fault diagnosis on the operating parameters according to the preset fault threshold.
[0024] S102. When a fault is detected in any subsystem, the fault information of the faulty subsystem is correlated with the vehicle stability requirements.
[0025] S103. Generate corresponding compensation control strategies based on the correlation analysis results.
[0026] S104. Based on the compensation control strategy, control is applied to the subsystems for which no faults have been detected, so that by sharing the hardware resources of the subsystems for which no faults have been detected, the subsystems for which no faults have been detected can cooperate to replace the faulty subsystems and perform the corresponding functions.
[0027] S105. Monitor the vehicle's stability index and adjust the execution strength and strategy parameters of the compensation control strategy according to the detected stability index until the faulty subsystem returns to normal or the vehicle enters a safe area.
[0028] In step S104 of one embodiment, the RWS actuator is instructed to enter a high-damping mode to limit its rapid movement and avoid generating uncontrollable disturbance torque. Simultaneously, the FSM immediately calls the compensation strategy corresponding to "RWS performance limitation" from the fault-tolerant control strategy library. This strategy controls the active suspension system to actively apply a difference in force proportional to the yaw rate to the left and right suspensions when the vehicle yaws, thus forming a stable compensation torque.
[0029] Understandably, the safety and reliability of the chassis system are improved through multi-stage collaboration. First, comprehensive data collection of operating parameters from all chassis subsystems and real-time fault diagnosis ensure timely detection. Second, correlation analysis between faulty subsystem information and vehicle stability requirements accurately pinpoints the impact of faults on vehicle stability, providing a basis for subsequent control. Third, compensation control strategies are generated based on correlation analysis, utilizing the hardware resources of non-faulty subsystems to replace the functions of the faulty subsystem, ensuring the vehicle maintains basic driving functions even in fault conditions and preventing overall functional failure due to a single subsystem failure. Finally, the vehicle stability index is monitored in real-time, and the execution intensity and parameters of the compensation control strategy are dynamically adjusted, ensuring the vehicle remains in a safe and controllable state during a fault until the fault is resolved or the vehicle is safely brought to a stop. This closed-loop collaborative control approach, from fault diagnosis and correlation analysis to dynamic compensation control, effectively enhances the chassis system's fault tolerance and adaptability in the face of faults, significantly improving overall safety and reliability.
[0030] Please refer to Figure 2 , Figure 2 This is a flowchart illustrating the steps involved in verifying fault signals in a collaborative control method based on a chassis domain controller.
[0031] In some embodiments, a cooperative control method based on a chassis domain controller further includes: S201. When a fault signal is detected, the redundant signal source of the fault signal is compared with the main signal source to perform cross-validation of the fault signal.
[0032] S202. If the data deviation between the redundant signal source and the main signal source exceeds the preset threshold, the main signal source is determined to be faulty, and the fault signal fails the verification.
[0033] S203. Isolate the sensor channel corresponding to the fault signal that failed verification and shield the fault signal that failed verification to prevent the fault signal that failed verification from affecting the calculation process of generating the compensation control strategy.
[0034] Understandably, this embodiment accurately determines the authenticity of fault signals by cross-validating redundant signal sources with the main signal source. If the data deviation exceeds a threshold, the main signal source is deemed faulty, and related sensor channels are isolated or shielded to prevent erroneous signals from interfering with the generation of the compensation control strategy. This verification mechanism effectively filters out false fault signals, ensuring the accuracy of fault diagnosis while guaranteeing the reliability of the compensation control strategy. This further enhances the chassis system's fault tolerance and stability under complex operating conditions, significantly optimizing overall performance.
[0035] In one embodiment, the unreliability of the rear wheel steering angle sensor signal is diagnosed through signal plausibility checks (such as comparing with model estimates or checking whether the signal rate of change exceeds limits) or hardware redundancy checks.
[0036] Cross-validation is performed using redundant signal sources (such as angles estimated from motor resolver signals) to confirm the fault. Subsequently, the faulty sensor channel is isolated, and the control algorithm is prohibited from using its signal.
[0037] The system determined that relying solely on redundant signal sources to control the RWS actuator posed a safety risk exceeding the threshold. Therefore, it initiated a system-level degradation mode.
[0038] The dashboard sends a warning message to the driver: "Chassis system performance is limited, please drive with caution."
[0039] Ultimately, even when the RWS system failed to function properly, the vehicle maintained stability and controllability far exceeding that of traditional architectures through compensation from the active suspension.
[0040] Please refer to Figure 3 , Figure 3 This is a flowchart illustrating the steps involved in implementing feedback mediation in a collaborative control method based on a chassis domain controller.
[0041] In some embodiments, a cooperative control method based on a chassis domain controller further includes: S301. The fault status information of the vehicle chassis is sent to other domains in the vehicle other than the vehicle chassis via the vehicle communication bus. Other domains include the power domain and the autonomous driving domain.
[0042] S302. Obtain safety status feedback information from other domains and parse the constraint parameters related to the vehicle chassis in the safety status feedback information.
[0043] S303. Adjust the execution boundary parameters of the compensation control strategy based on the constraint parameters.
[0044] Understandably, this embodiment achieves cross-domain information sharing by sending fault status information to other domains such as the powertrain domain and autonomous driving domain. After obtaining safety status feedback information from other domains and parsing constraint parameters, the execution boundary parameters of the compensation control strategy can be adjusted accordingly. This improvement enables the chassis domain controller to dynamically adjust the control strategy based on the status of other key domains of the vehicle, ensuring that chassis control is consistent with other vehicle functions and avoiding safety hazards caused by cross-domain functional conflicts. Overall, this technical approach improves the adaptability and safety of the chassis system in the vehicle environment and enhances the overall reliability of the vehicle under complex fault scenarios.
[0045] In some embodiments, the fault information includes a fault type, which is a first fault type that causes a first type of dynamic imbalance in the vehicle, or a second fault type that causes a second type of asymmetric dynamic imbalance in the vehicle.
[0046] Step S103 includes: When the diagnosed fault belongs to the first fault type, a first type of compensation control strategy is generated. The first type of compensation control strategy is used to control one or more functional first subsystems. By outputting or adjusting the first control quantity that the first subsystem can provide, a compensation physical quantity is generated to counteract the first type of dynamic imbalance.
[0047] For example, if a fault is diagnosed in the RWS actuator, the FSM will not only isolate it, but will also immediately invoke the fault-tolerant control strategy, instructing the active suspension system to actively and quickly adjust the suspension force of the left and right wheels to generate a compensating yaw moment (ΔM_z) to help stabilize the vehicle and counteract the yaw disturbance caused by the loss of rear wheel steering function.
[0048] When the diagnosed fault belongs to the second type of fault, a second type of compensation control strategy is generated. The second type of compensation control strategy is used to control one or more functional second subsystems. By outputting or adjusting the second control quantity that the second subsystem can provide, a stabilizing effect is generated to restore normal operation after the second type of dynamic imbalance.
[0049] For example, if a suspension actuator fails, the FSM can instruct the RWS system to apply a small compensating steering angle to balance the resulting unbalanced torque and maintain the vehicle's straight-line stability.
[0050] Please refer to Figure 4 , Figure 4 This is a flowchart of the fault diagnosis steps in a collaborative control method based on a chassis domain controller.
[0051] In some embodiments, the method of diagnosing faults in operating parameters based on preset fault thresholds includes: S401. Based on multi-source sensor data and vehicle dynamics model, estimate the dynamic state parameters of the vehicle.
[0052] S402. Perform trend analysis on the time series of dynamic state parameters and calculate the deviation coefficient between the rate of change of dynamic state parameters and historical benchmark values.
[0053] S403. When the deviation coefficient is detected to exceed the preset warning threshold, it is determined that the vehicle performance has a degradation trend or potential fault, and a safety strategy adjustment command is generated as the input parameter of the compensation control strategy.
[0054] In one specific embodiment, it is assumed that during the vehicle's operation, the dynamic status of the vehicle chassis needs to be monitored and analyzed in real time through a fault diagnosis system in order to detect potential faults in advance and take corresponding measures.
[0055] The vehicle is equipped with a variety of sensors, including accelerometers, gyroscopes, wheel speed sensors, and steering angle sensors. These sensors are distributed at different locations on the vehicle chassis to collect data in real time, such as longitudinal acceleration, lateral acceleration, yaw rate, wheel speed, and steering angle. Meanwhile, a vehicle dynamics model is built based on the vehicle's physical parameters (such as mass, center of gravity position, and tire characteristics) to describe the vehicle's dynamic behavior under different operating conditions.
[0056] By inputting multi-source sensor data into the vehicle dynamics model, the system estimates the vehicle's dynamic state parameters, such as lateral acceleration, longitudinal acceleration, and yaw rate. These parameters reflect the vehicle's actual dynamic performance under the current driving conditions.
[0057] The system performs time series analysis on the estimated dynamic state parameters. Taking the lateral acceleration of a vehicle as an example, the system records its trend over a period of time. Assuming the vehicle is driving normally, the baseline value of the lateral acceleration is 0.2g (where g is the acceleration due to gravity). By analyzing the time series data of the lateral acceleration, the system calculates its rate of change, i.e., the amount of change in lateral acceleration per unit time.
[0058] Furthermore, the system calculates the deviation coefficient between the current dynamic state parameters and the historical reference values. Assuming the current rate of change of lateral acceleration is 0.05 g / s², while the historical reference rate of change is 0.02 g / s², the deviation coefficient is 2.5 (i.e., 0.05 / 0.02). This deviation coefficient reflects the degree of deviation between the current vehicle dynamic state and the normal state.
[0059] The system has a preset warning threshold, for example, the warning threshold for the lateral acceleration deviation coefficient is 2.0. When the system detects that the deviation coefficient exceeds the warning threshold (2.5), it determines that the vehicle's lateral stability may be deteriorating or there may be a potential malfunction.
[0060] At this point, the system generates safety strategy adjustment instructions. For example, these instructions might include adjusting the vehicle's Electronic Stability Program (ESP) control parameters to increase intervention intensity on the vehicle's yaw rate, or adjusting the vehicle's braking force distribution strategy to enhance lateral stability. These adjustment instructions, as input parameters for the compensation control strategy, are further transmitted to the vehicle's chassis control system to optimize the vehicle's dynamic performance.
[0061] Understandably, this embodiment estimates dynamic state parameters using multi-source sensor data and a vehicle dynamics model, performs trend analysis on their time series, and calculates the deviation coefficient. When the deviation coefficient exceeds a warning threshold, it preemptively determines vehicle performance degradation or potential faults, generating a safety strategy adjustment command as input parameters for the compensation control strategy. This dynamic trend-based fault diagnosis method can identify potential problems in advance, transforming fault handling from passive response to early warning and proactive intervention. This further enhances the reliability and safety of the chassis system, effectively reduces safety risks caused by sudden faults, and improves the overall stability of vehicle operation.
[0062] In some embodiments, step S403 includes: Based on a pre-defined vehicle dynamics model and an extended Kalman filter, the key state parameters of the target subsystem are estimated using signals from the first type of sensor.
[0063] The estimated values of key state parameters are compared with the measured values of the second type of sensor, and a residual sequence is generated based on the comparison results.
[0064] Statistical analysis is performed on the residual sequence. When the statistical value obtained from the statistical analysis exceeds the preset statistical value and a self-test signal indicating an abnormal sensor state is detected, it is determined that the target subsystem or the sensor of the target subsystem has failed.
[0065] Specifically, the unified state observer continuously runs a high-fidelity vehicle dynamics model (such as an extended model of a two-DOF bicycle). The model's output includes yaw rate, lateral acceleration, etc. Simultaneously, an extended Kalman filter (EKF) is activated. This EKF takes steering wheel angle, wheel speed, etc., as inputs, and the rear wheel steering angle as the state or parameter to be estimated, outputting the estimated value δ_r_hat of the rear wheel steering angle in real time.
[0066] The residual r between the measured value δ_r_meas of the rear wheel steering angle sensor and the estimated value δ_r_hat of the EKF is continuously calculated: r(k) = |δ_r_meas(k) - δ_r_hat(k)|.
[0067] The residual sequence r(k) is fed into a change detection algorithm such as Cumulative Sum (CUSUM) or Sequential Probability Ratio Test (SPRT). These algorithms are highly sensitive to small, persistent deviations and can effectively distinguish noise from real faults.
[0068] When the output of the detection algorithm exceeds the preset safety threshold, and the internal hardware self-test signals of the sensor (such as power supply voltage and signal range) are also abnormal, it is determined that the rear wheel steering angle sensor has a permanent fault, and the fault-tolerant control process is immediately triggered.
[0069] Understandably, this embodiment uses an extended Kalman filter combined with a vehicle dynamics model to estimate key state parameters of the target subsystem using signals from the first type of sensors, and compares these parameters with measurements from the second type of sensors to generate a residual sequence. Further statistical analysis is performed on the residual sequence; when the statistical value exceeds a preset threshold and an abnormal sensor self-test signal is detected, a fault is determined in the target subsystem or its sensors. This dual verification mechanism based on filtering and statistical analysis can more accurately identify faults, avoid misjudgments, and improve the reliability of fault diagnosis. Simultaneously, combining self-test signals further confirms the sensor status, ensuring the accuracy of the diagnostic results, thereby enhancing the chassis system's fault tolerance and safety under complex operating conditions and improving the overall reliability of vehicle operation.
[0070] Please refer to Figure 5 , Figure 5 This is a flowchart of step S104 in a collaborative control method based on a chassis domain controller.
[0071] In some embodiments, step S104 includes: S501. After identifying the faulty subsystem, the prediction model of the preset model predictive controller is reconstructed according to the fault type of the faulty subsystem. The control input corresponding to the faulty subsystem is used as the external disturbance input, and the controllable input vector and related input matrix of the model predictive controller are updated.
[0072] S502. Based on the reconstructed prediction model, determine the optimization problem of the model predictive controller. The objective function of the optimization problem is configured to minimize the deviation between the vehicle stability index and the reference value, as well as the magnitude of the change in the constraint control input.
[0073] S503. In each control cycle, the optimization problem is solved to obtain the optimal control quantity, and the subsystems without detected faults are controlled to perform actions through the optimal control quantity, so as to collaboratively generate compensating stabilizing torque to maintain vehicle stability.
[0074] Specifically, upon confirmation of a fault, a system-level fault-tolerant control strategy is immediately initiated. The core of this strategy is the online reconfiguration of a model-based predictive controller (MPC).
[0075] Under normal conditions, the prediction model used by MPC is: x(k+1) = A * x(k) + B * u(k). Here, the state variables x include yaw rate γ, body slip angle β, etc.; the control input u includes the front wheel steering angle δ_f, the rear wheel steering angle δ_r, and the operating forces of the four suspensions F_fl, F_fr, F_rl, F_rr.
[0076] Sensor failure renders δ_r unmeasurable and uncontrollable. The prediction model of MPC is dynamically reconstructed: x(k+1) = A * x(k) + B1 * u1(k) + B2 * d(k), where u1 = [δ_f, F_fl, F_fr, F_rl, F_rr]^T is the new controllable input vector, and d = δ_r is redefined as an unmeasurable disturbance input. B1 and B2 are the reassigned input matrices.
[0077] Objective Function: The new MPC controller solves the following optimization problem: Minimize: Σ [ ||Γ(k+i) - Γ_ref(k+i)||^2_Q ] + Σ [ ||ΔU(k+i-1)||^2_R ] (i ranges from 1 to the prediction time domain Np and the control time domain Nc); Constraints: x(k+1) = A*x(k) + B1*u1(k) + B2*d(k); u1_min ≤ u1 ≤ u1_max; Δu1_min ≤ Δu1 ≤ Δu1_max; Where Γ = [γ, β]^T is the output vector, Γ_ref is the desired steady state (usually 0), the first term penalizes the vehicle's dynamic stability deviation from the reference value, and the second term penalizes drastic changes in the control quantity. Q and R are weight matrices.
[0078] To compensate for the impact of the disturbance d(k) (i.e. the failure δ_r), a disturbance observer is enabled to estimate the real-time value of d(k) online and feed it forward into the MPC prediction model, which greatly improves the accuracy of the compensation control.
[0079] The reconstructed MPC solves the above optimization problem online in each control cycle based on the latest vehicle state and disturbance observations. The solution is the optimal front wheel steering angle increment and the optimal action force increment of the four suspensions. By generating precise force differences through the active suspension, a compensating yaw moment is generated to actively counteract the instability caused by rear wheel steering system anomalies.
[0080] Understandably, this embodiment achieves advanced fault-tolerant control through online reconfiguration of the predictive control model (MPC) and a disturbance observer. It moves beyond simply isolating the faulty system; instead, it leverages the control redundancy of the healthy system and uses a series of advanced algorithms to calculate an optimal compensation scheme in real time. This allows the vehicle to maintain high levels of dynamic performance and stability even after a core sensor fails, minimizing the impact of a single point of failure on safety. This represents a leap from passive safety to active fault tolerance.
[0081] Please refer to Figure 6 , Figure 6 This is a schematic diagram of a collaborative control device based on a chassis domain controller.
[0082] This embodiment also provides a collaborative control device based on a chassis domain controller, including: The diagnostic module 601 is used to collect the operating parameters of each subsystem of the vehicle chassis and perform fault diagnosis on the operating parameters according to the preset fault threshold.
[0083] The analysis module 602 is used to perform correlation analysis between the fault information of any subsystem and the vehicle stability requirements when a fault is detected in any subsystem.
[0084] The decision module 603 is used to generate corresponding compensation control strategies based on the correlation analysis results.
[0085] The control module 604 is used to control the subsystems for which no faults have been found based on a compensation control strategy, so that the subsystems for which no faults have been found can cooperate to replace the faulty subsystems to perform the corresponding functions by sharing the hardware resources of the subsystems for which no faults have been found.
[0086] The adjustment module 605 is used to monitor the vehicle's stability index and adjust the execution intensity and strategy parameters of the compensation control strategy according to the detected stability index until the faulty subsystem returns to normal or the vehicle enters a safe area.
[0087] In some embodiments, a chassis domain controller-based cooperative control device is a centralized chassis domain controller (CDC): its hardware platform employs an ASIL D-compliant multi-core microprocessor and includes necessary built-in safety features. The CDC runs the following key software modules: Unified Function Safety Manager (FSM). Global state observation and fault prediction module, system-level fault-tolerant control strategy library, and secure communication interface.
[0088] In some embodiments, the Unified Functional Safety Manager (FSM) continuously monitors the status of internal hardware such as the CPU, memory, and bus, the rationality and validity of all external sensor signals, the consistency of feedback signals from the rear-wheel steering and active suspension actuators with expected values, and the integrity of the communication network.
[0089] The global state observation and fault prediction module estimates vehicle dynamics (such as yaw angle and sideslip angle) in real time based on fused sensor data and a high-precision vehicle model. More importantly, this module can predict potential performance degradation or impending faults by analyzing trends, providing input for proactive safety strategies.
[0090] The system-level fault-tolerant control strategy library pre-stores cross-system compensation strategies for various single-point or two-point failure modes.
[0091] The secure communication interface is responsible for reliable safety status information exchange with other domains of the vehicle (such as the power domain and the autonomous driving domain) to achieve cross-domain safety coordination.
[0092] Please refer to Figure 7 , Figure 7 This is a flowchart illustrating the operational process of a collaborative control device based on a chassis domain controller.
[0093] As shown in the figure, the Unified Function Safety Manager monitors the integrity of internal hardware resources, external sensor signals, actuator feedback signals, and communication networks. The Global Status Observation and Fault Prediction module analyzes the collected data to detect potential faults. Once a fault is detected, the system confirms the fault to ensure the accuracy of the fault signal. After confirming the fault, the system locates and isolates the faulty part to prevent the fault from spreading. The fault type is identified based on the fault characteristics, such as RWS failure, suspension actuator failure, or other fault modes.
[0094] Based on the identified fault type, the system invokes the corresponding preset strategy (Strategy A, Strategy B, or Strategy C). According to the preset strategy, the system instructs the relevant actuators to perform the compensation control strategy. For example, if the RWS fails, the active suspension system is instructed to adjust the left and right suspension forces to generate a compensating yaw moment.
[0095] The system communicates fault information and fault-tolerant measures taken through a secure communication interface to other domain controllers. It continuously monitors the vehicle's stability index and adjusts the strength and parameters of the compensation control strategy based on the monitoring results.
[0096] Once the faulty subsystem returns to normal or the vehicle enters a safe area, the system will restore the vehicle to a stable state.
[0097] This invention also provides a vehicle control device, including a memory, a processor, and a program stored in the memory and executable on the processor. When the program is executed by the processor, it implements the chassis domain controller-based cooperative control method of the above embodiments.
[0098] Taking the example of a processor and memory in a vehicle controller being connected via a bus, the memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, the memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, the memory may optionally include memory remotely located relative to the control processor, and these remote memories can be connected to the control device via a network. The non-transitory software programs and instructions required to implement the control methods of the above embodiments are stored in the memory, and when executed by the processor, the control methods of the above embodiments are performed.
[0099] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0100] This invention also provides a vehicle, including the vehicle control device described in the above embodiments.
[0101] The vehicle can be a private car, such as a sedan, SUV, MPV, or pickup truck. It can also be a commercial vehicle, such as a van, bus, small truck, or large semi-trailer. The vehicle must have an electric motor capable of outputting power or acting as a generator to store mechanical energy. When the vehicle is a new energy vehicle, it can be a hybrid or a pure electric vehicle.
[0102] Since the vehicle applies all the technical solutions of the above-mentioned control device or vehicle controller, it has at least all the beneficial effects brought about by the technical solutions of the above embodiments, which will not be repeated here.
[0103] Furthermore, one embodiment of the present invention provides a computer-readable storage medium storing computer-executable instructions for performing the aforementioned chassis domain controller-based cooperative control method.
[0104] It is worth noting that, since the computer-readable storage medium of the present invention is capable of executing the chassis domain controller-based cooperative control method of any of the above embodiments, the specific implementation and technical effects of the computer-readable storage medium of the present invention can be referred to the specific implementation and technical effects of the chassis domain controller-based cooperative control method of any of the above embodiments.
[0105] Furthermore, one embodiment of the present invention provides a computer program product, including a computer program or computer instructions, which are stored in a computer-readable storage medium. A processor of a computer device reads the computer program or computer instructions from the computer-readable storage medium and executes the computer program or computer instructions, causing the computer device to perform the aforementioned chassis domain controller-based cooperative control method.
[0106] It is worth noting that, since the computer program product of this embodiment can execute the cooperative control method based on chassis domain controller of any of the above embodiments, the specific implementation method and technical effect of the computer program product of this embodiment can refer to the specific implementation method and technical effect of the cooperative control method based on chassis domain controller of any of the above embodiments.
[0107] It will be understood by those skilled in the art that all or some of the steps and systems in the methods disclosed above can be implemented as software, firmware, hardware, and suitable combinations thereof. Some or all of the physical components can be implemented as software executed by a processor, such as a central processing unit, digital signal processor, or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which can include computer storage media (or non-transitory media) and communication media (or transient media). As is known to those skilled in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical disc storage, magnetic cartridges, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer. Furthermore, as is known to those skilled in the art, communication media typically include computer-readable instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery medium.
[0108] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
Claims
1. A cooperative control method based on a chassis domain controller, characterized in that, The method includes: The system collects the operating parameters of each subsystem of the vehicle chassis and performs fault diagnosis on the operating parameters according to the preset fault threshold. When a fault is detected in any of the aforementioned subsystems, the fault information of the faulty subsystem will be correlated with the vehicle stability requirements. Generate corresponding compensation and control strategies based on the correlation analysis results; Based on the aforementioned compensation control strategy, the subsystems for which no faults were found are controlled so that by sharing the hardware resources of the subsystems for which no faults were found, the subsystems for which no faults were found can cooperate to replace the faulty subsystems and perform the corresponding functions. The vehicle's stability index is monitored, and the execution intensity and strategy parameters of the compensation control strategy are adjusted according to the detected stability index until the faulty subsystem returns to normal or the vehicle enters a safe area.
2. The method according to claim 1, characterized in that, The method further includes: When a fault signal is detected, the redundant signal source of the fault signal is compared with the main signal source to perform cross-validation on the fault signal. If the data deviation between the redundant signal source and the main signal source exceeds a preset threshold, the main signal source is determined to be faulty, and the fault signal fails the verification. The sensor channels corresponding to the fault signals that fail verification are isolated, and the fault signals that fail verification are shielded to prevent them from affecting the calculation process for generating the compensation control strategy.
3. The method according to claim 1, characterized in that, The method further includes: The fault status information of the vehicle chassis is sent to other domains in the vehicle other than the vehicle chassis via the vehicle communication bus. The other domains include the power domain and the autonomous driving domain. Obtain the safety status feedback information from the other domains, and parse the constraint parameters related to the vehicle chassis in the safety status feedback information; Based on the constraint parameters, the execution boundary parameters of the compensation control strategy are adjusted.
4. The method according to claim 1, characterized in that, The fault information includes fault type, which is either a first fault type that causes the vehicle to experience a first type of dynamic imbalance, or a second fault type that causes the vehicle to experience a second type of asymmetric dynamic imbalance. The step of generating corresponding compensation control strategies based on the correlation analysis results includes: When the diagnosed fault belongs to the first fault type, a first type of compensation control strategy is generated, wherein the first type of compensation control strategy is used to control one or more functional first subsystems, and generates a compensating physical quantity to counteract the first type of dynamic imbalance by outputting or adjusting the first control quantity that the first subsystem can provide. When the diagnosed fault belongs to the second fault type, a second type of compensation control strategy is generated. The second type of compensation control strategy is used to control one or more functional second subsystems. By outputting or adjusting the second control quantity that the second subsystem can provide, a stabilizing effect is generated to restore the second type of dynamic imbalance to normal.
5. The method according to claim 1, characterized in that, The methods for diagnosing faults in the operating parameters based on preset fault thresholds include: Based on multi-source sensor data and vehicle dynamics model, the dynamic state parameters of the vehicle are estimated; Perform trend analysis on the time series of the dynamic state parameters and calculate the deviation coefficient between the rate of change of the dynamic state parameters and the historical benchmark value; When the deviation coefficient is detected to exceed the preset warning threshold, it is determined that the vehicle performance has a degradation trend or potential fault, and a safety strategy adjustment instruction is generated as the input parameter of the compensation control strategy.
6. The method according to claim 5, characterized in that, The step of determining that the vehicle's performance is deteriorating or has a potential fault when the deviation coefficient is detected to exceed a preset warning threshold includes: Based on a pre-defined vehicle dynamics model and an extended Kalman filter, the key state parameters of the target subsystem are estimated using signals from the first type of sensors. The estimated values of the key state parameters are compared with the measured values of the second type of sensor, and a residual sequence is generated based on the comparison results. Statistical analysis is performed on the residual sequence. When the statistical value obtained from the statistical analysis exceeds the preset statistical value and a self-test signal indicating an abnormal sensor state is detected, it is determined that the target subsystem or the sensor of the target subsystem has failed.
7. The method according to claim 1, characterized in that, The control of subsystems without detected faults, based on the compensation control strategy, enables these subsystems to cooperate and perform corresponding functions in place of the faulty subsystems by sharing their hardware resources. This includes: After identifying the faulty subsystem, the prediction model set in the preset model prediction controller is reconstructed according to the fault type of the faulty subsystem. In this process, the control input corresponding to the faulty subsystem is used as the external disturbance input, and the controllable input vector and related input matrix of the model prediction controller are updated. Based on the reconstructed prediction model, the optimization problem of the model prediction controller is determined. The objective function of the optimization problem is configured to minimize the deviation between the vehicle stability index and the reference value, as well as the magnitude of the change in the constraint control input. In each control cycle, the optimization problem is solved to obtain the optimal control quantity, and the subsystems without detected faults are controlled to perform actions through the optimal control quantity to collaboratively generate compensating stabilizing torques to maintain vehicle stability.
8. A cooperative control device based on a chassis domain controller, characterized in that, The device includes: The diagnostic module is used to collect the operating parameters of each subsystem of the vehicle chassis and perform fault diagnosis on the operating parameters according to the preset fault threshold. The analysis module is used to correlate the fault information of any of the subsystems with the vehicle stability requirements when a fault is detected. The decision-making module is used to generate corresponding compensation and control strategies based on the correlation analysis results; The control module is used to control the subsystems for which no faults were found based on the compensation control strategy, so as to enable the subsystems for which no faults were found to perform corresponding functions by cooperating in place of the faulty subsystems by sharing the hardware resources of the subsystems for which no faults were found. An adjustment module is used to monitor the vehicle's stability index and adjust the execution intensity and strategy parameters of the compensation control strategy according to the detected stability index until the faulty subsystem returns to normal or the vehicle enters a safe area.
9. A vehicle, characterized in that, The vehicle includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the collaborative control method based on a chassis domain controller as described in any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the collaborative control method based on the chassis domain controller as described in any one of claims 1 to 7.