Data storage and recovery system and method for vehicle-mounted centralized architecture

By implementing centralized backup and off-site redundancy through the SDSR-Edge and SDSR-Central modules in the central processing unit, the problem of low storage reliability of edge nodes in automotive E/E architecture is solved, enabling reliable recovery of critical data and optimized management of vehicle storage resources, reducing hardware costs and improving the flexibility and security of data management.

CN121597487APending Publication Date: 2026-03-03AUTOCORE INTELLIGENT TECH (NANJING) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510955903.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-11
Publication Date
2026-03-03

AI Technical Summary

Technical Problem

As automotive E/E architecture evolves from distributed to centralized systems, edge node storage suffers from low reliability and recovery difficulties. It lacks vehicle-level collaborative storage management, has limited data traceability capabilities, and suffers from insufficient data management flexibility and scalability. This makes it difficult to recover critical data after it is lost, affecting product availability and functional safety.

Method used

By employing SDSR-Edge and SDSR-Central modules, centralized backup and off-site redundancy are achieved in the central processing unit. Data at the edge nodes is monitored and backed up and restored in the central unit. Combined with CRC check and ECC status detection, unified data management and redundant storage are realized, supporting off-site backup and multi-version history management.

Benefits of technology

It effectively solves the problems of storage lifespan and reliability of edge nodes, ensures reliable recovery of critical data, reduces overall hardware costs, provides comprehensive data management and remote diagnostic capabilities, and meets security and compliance requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121597487A_ABST
    Figure CN121597487A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of automotive electronics and embedded systems, in particular to a data storage and recovery system for a vehicle-mounted centralized architecture, which comprises at least one edge microcontroller unit subsystem and a central processing unit subsystem which are deployed in a whole vehicle environment, SDSR-Edge is configured in the edge microcontroller unit subsystem, and the central processing unit subsystem is configured in the whole vehicle environment. An SDSR-Central is configured in the central processing unit subsystem, and the edge microcontroller unit subsystem communicates with the central processing unit subsystem through a communication link. Through centralized backup and remote redundancy in the central unit, the problems of storage life and reliability of the edge node are effectively solved, and even if a storage medium of the edge node is damaged, key data can be reliably recovered.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of automotive electronics and embedded systems technology, specifically to a system and method for data storage and recovery in a vehicle-mounted centralized architecture. Background Technology

[0002] Automotive electronic and electrical (E / E) architecture typically consists of three large SoC chips: intelligent driving chip, intelligent cockpit chip, and central domain controller chip. The first two are responsible for autonomous driving-related tasks and in-vehicle information and entertainment systems, respectively, while the central domain controller chip plays an overall role, responsible for cross-domain collaboration, global data integration and distribution, and function implementation.

[0003] A centralized architecture is an architectural pattern in which all computing, storage, data processing, and control logic of a system is concentrated on one or a few data protection nodes. These central nodes (servers or hosts) are the core of the system and are responsible for handling all user requests and business logic, while the client is only responsible for requesting and displaying data. In-vehicle centralized architecture is an advanced form of automotive electronic and electrical architecture (E / E architecture).

[0004] Currently, as automotive E / E architecture evolves from distributed to centralized systems, functions and computing resources are concentrated in a central computing unit (such as HPC / MPU). Existing technologies typically operate in a distributed architecture, where each ECU independently manages its local data. This presents the following main problems and drawbacks: 1. Low reliability and difficult recovery of edge node storage: To reduce costs, edge MCUs often use Flash to simulate EEPROM, which has a relatively short storage lifespan and low reliability. Traditional integrity checks (such as CRC) and local redundant backups (possibly within the same Flash page) are insufficient to cope with physical damage or Flash exhaustion, making it difficult to recover lost critical data (such as security configurations, activation information, mileage, key information, etc.) or causing functional abnormalities or even unavailability due to the use of default values, seriously affecting product availability and functional safety. 2. Lack of vehicle-level collaborative storage management, resulting in high costs: Each ECU has independent storage, lacking a unified storage resource scheduling and load balancing mechanism. This may lead to some ECUs experiencing storage space shortages while others have idle space, making it impossible to optimize vehicle-wide storage resources. To ensure data reliability, it may be necessary to deploy high-cost storage solutions on multiple edge nodes, increasing overall hardware costs. 3. Limited data traceability: The limited storage space of a single ECU results in insufficient recording depth of logs, fault data, etc., making effective fault diagnosis and event tracing difficult. Although there are solutions in the industry for storage transfer within a single SOC using proprietary protocols, there is a lack of standardized and collaborative solutions for the entire vehicle. 4. Insufficient flexibility and scalability in data management: The existing decentralized management method is difficult to support flexible data classification and strategy configuration (such as determining backup frequency and redundant locations based on data importance), and it is also not conducive to realizing advanced functions such as data packaging and uploading to the cloud and multi-site disaster recovery; Therefore, there is an urgent need for a system and method that can effectively and collaboratively manage the storage of critical vehicle data, ensure data integrity and availability, optimize storage costs, and meet security and compliance requirements under a centralized architecture.

[0005] To address this, a system and method for data storage and recovery in a vehicle-mounted centralized architecture are proposed. Summary of the Invention

[0006] The purpose of this invention is to provide a system and method for data storage and recovery for in-vehicle centralized architecture, in order to solve the problem that in the evolution of existing automotive E / E architecture towards centralized architecture, edge MCUs use Flash to simulate EEPROM, resulting in low storage life and insufficient reliability. Traditional CRC check and local redundant backup are difficult to cope with physical damage or Flash exhaustion, which leads to the inability to recover critical data after loss or causes functional abnormalities, seriously reducing product availability and functional safety.

[0007] To achieve the above objectives, the present invention provides the following technical solution: A data storage and recovery system for a vehicle-mounted centralized architecture includes at least one edge microcontroller unit subsystem and one central processing unit subsystem. The edge microcontroller unit subsystem is equipped with an SDSR-Edge, and the central processing unit subsystem is equipped with an SDSR-Central. The edge microcontroller unit subsystem and the central processing unit subsystem are connected via a communication link. The SDSR-Edge monitors and detects faults in local data, backs up local data to SDSR-Central, reports detected fault information to SDSR-Central, and restores data according to instructions from SDSR-Central. The SDSR-Central is used to receive and back up data sent by the SDSR-Edge, and when it receives a fault request sent by the SDSR-Edge, it sends operation instructions and backed-up fault data to the SDSR-Edge.

[0008] Compared with the prior art, the beneficial effects of the present invention are as follows: 1. By performing centralized backup in the central unit and (optional) off-site redundancy, the storage lifespan and reliability issues of edge nodes are effectively solved. Even if the storage media of the edge nodes is damaged, critical data can be reliably recovered, ensuring the availability of vehicle functions and user data. At the same time, it ensures that safety-related critical configurations and data can be recovered in the event of a failure, reducing the risk of functional abnormalities or security risks caused by data loss or damage.

[0009] 2. Through vehicle-wide storage balancing management, the storage hardware requirements of edge nodes, such as capacity and lifespan, can be reduced, and long-term storage and high reliability requirements can be transferred to the central unit, optimizing the allocation of vehicle storage resources and reducing overall hardware costs. It supports the centralized storage of logs, fault codes and other data from each ECU in the central unit, overcoming the storage space limitations of edge nodes, providing data with a longer time span and more comprehensive data, which is convenient for correlation analysis and remote diagnosis. Through quota management, status monitoring and alarm mechanisms, the management of vehicle storage resources becomes more transparent and controllable. Attached Figure Description

[0010] Figure 1 This is a schematic diagram of the data storage framework in an embodiment of the present invention. Detailed Implementation

[0011] The technical solutions of the embodiments of the present invention will be described below with reference to the accompanying drawings. The embodiments described below are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0012] Example 1 like Figure 1 As shown, this embodiment provides a data storage and recovery system for a vehicle-mounted centralized architecture. It is primarily deployed in a vehicle environment containing at least one edge microcontroller unit (MCU) subsystem and one central processing unit (MPU / HPC) subsystem, connected via a reliable communication link. The system mainly includes a storage block management and recovery module (SDSR-Edge) deployed within the edge microcontroller unit subsystem, and a data storage management service module (SDSR-Central) deployed within the central processing unit subsystem.

[0013] SDSR-Edge monitors and detects faults in local data, backs up local data to SDSR-Central, reports detected fault information to SDSR-Central, and restores data according to instructions from SDSR-Central. The Storage Block Management and Recovery Module (SDSR-Edge) is deployed on nodes requiring data protection, including edge ECUs and the central computing unit itself. Depending on the configuration, it monitors the CRC check status of locally specified non-volatile memory (NVM) blocks or the ECC status of custom Flash / RAM address segments. The CRC check status of NVM blocks is applicable to AUTOSAR architectures, while the ECC status of RAM address segments is applicable to non-AUTOSAR scenarios or scenarios requiring finer-grained control. When an unrecoverable storage fault is detected, the fault type and location are identified. Faults include CRC errors and uncorrectable ECC errors; fault types include uncorrectable RAM ECC, unrecoverable Data Flash, and unrecoverable CodeFlash; and locations include Block ID or address range. The fault information, such as type, location, and unique ID of the data protection node, along with the current system status of the data protection node (whether recovery operations and resets are allowed), is reported to SDSR-Central via a channel, which can also be a secure channel.

[0014] SDSR-Edge uses a unique Data Protection Node Identity (UID) and security credentials to authenticate with the SDSR-Central service. Based on the configuration synchronized from SDSR-Central, including the NVM Block / address range to be backed up, backup policies, data tags, etc., it reads local data under a specified triggering mechanism, such as triggering periodic or event-triggered events. Through a security protocol, ensuring the integrity and confidentiality of the information, it transmits the backup data to SDSR-Central. SDSR-Central securely receives the recovery data and instructions from SDSR-Central, such as triggering backups, performing recovery, and querying status, and verifies the integrity and source of the data, while reporting the results of the above operations.

[0015] After receiving the recovery instruction from SDSR-Central and confirming that the data protection node status is allowed, SDSR-Edge performs recovery, securely writing the received and verified recovery data to the specified local NVM Block, file, or Flash address. (Optional) After recovery, local verification is performed, including recalculating the CRC / checksum. The final status of the recovery operation, i.e., success / failure and the reason, is reported to SDSR-Central.

[0016] SDSR-Central is used to receive and back up data sent by SDSR-Edge, and when it receives a fault request from SDSR-Edge, it sends operation instructions and backed-up fault data to SDSR-Edge. The Data Storage Management Service Module (SDSR-Central) is deployed in the Central Computing Unit (HPC / MPU) with redundant deployment to improve availability. It securely receives backup data and status information from certified SDSR-Edge data protection nodes and verifies data integrity. The received data is cached and indexed, with the indexes categorized by data protection node ID, data tag, timestamp, and version. The backup data, indexed accordingly, is persistently stored on non-volatile storage media such as NAND Flash in the central unit.

[0017] It supports configuring, managing, and executing backup policies for different data. Backup policies include frequency, trigger conditions, and granularity. It supports off-site / redundant backups, storing backup copies of critical data in physically isolated locations, such as different partitions or physical storage chips on the same HPC; preferably, on different (redundant) central computing unit nodes to achieve disaster recovery. It has a data synchronization mechanism to ensure data consistency between redundant backup copies; (optionally) it supports the management of multiple historical versions of stored data.

[0018] Receive, record, and process storage fault reports from SDSR-Edge; perform integrity checks during data reception, storage, and transmission; detect transmission or storage anomalies; coordinate data recovery processes based on fault reports, diagnostic instructions, or preset policies; query the status of the target data protection node; retrieve the correct data version from (redundant) backups; send recovery instructions and data to the target data protection node SDSR-Edge; track recovery status and record results; and issue notifications or alarms when data verification fails, recovery fails, or the service itself malfunctions.

[0019] By implementing centralized backup and (optional) off-site redundancy in the central unit, the storage lifespan and reliability issues of edge nodes are effectively resolved. Even if the storage media of an edge node fails, critical data can be reliably recovered, ensuring the availability of vehicle functions and user data. Simultaneously, it ensures that safety-related critical configurations and data can be recovered in the event of a failure, reducing functional abnormalities or safety risks caused by data loss or corruption. Furthermore, through balanced vehicle storage management, the storage hardware requirements of edge nodes, such as capacity and lifespan, can be reduced, transferring long-term storage and high reliability requirements to the central unit. This optimizes the allocation of vehicle storage resources and reduces overall hardware costs. It supports the centralized storage of logs, fault codes, and other data from each ECU in the central unit, overcoming the storage space limitations of edge nodes and providing data with a longer time span and more comprehensive coverage, facilitating correlation analysis and remote diagnostics. Quota management, status monitoring, and alarm mechanisms make the management of vehicle storage resources more transparent and controllable.

[0020] Optionally, SDSR-Central also includes data classification and tagging, as well as configuring management policies based on tags and automatically executing management. SDSR-Central supports data classification and tagging, with tags including critical configurations, general logs, user privacy data, VINs, security logs, etc. Authorized users can configure management policies based on tags. Management policies include: backup policies, redundancy policies, storage lifecycle, processing policies (such as deletion after uploading), security policies (such as whether to encrypt), etc. Management operations are automatically executed according to the configured policies. Through data tagging and policy-based management, backup, redundancy, lifecycle, access permissions, etc. can be flexibly configured according to business needs. The standardized framework is easy to extend to support new data application scenarios, and it also supports data protection requirements based on AUTOSAR NVM Blocks and heterogeneous edge nodes based on custom address ranges.

[0021] Optionally, SDSR-Central also includes configuring storage space quotas based on SDSR-Edge and querying storage space usage through an interface. SDSR-Central supports configuring and enforcing storage space quotas by data protection node unique ID (UID) or application ID, provides an interface to query storage space usage and remaining capacity, and supports storage space usage threshold alarms.

[0022] Optionally, SDSR-Central also includes integration with the vehicle key management system through access control, encrypted storage, protection of critical data against unauthorized deletion and modification, and protection of the logs themselves. It implements strict role / ID-based access control, restricting data read, write, recovery, deletion, and policy configuration; supports encrypted storage of sensitive data, such as personal information; employs mechanisms (such as access control, checksums / signatures) to protect critical data (including VINs, key parameters, security logs, etc.) from unauthorized deletion and modification; provides regulatory-compliant secure deletion functions (such as personal information); records secure audit logs of critical operations and protects the logs themselves; integrates with the vehicle key management system; and securely manages communication and encryption keys. Through centralized security policy management, such as access control, encryption, tamper-proofing, secure deletion, and audit logs, it helps to systematically meet the requirements of data security regulations such as GB 44495.

[0023] Optionally, SDSR-Central also includes support for lossless data compression, data packaging into file formats, and standardized service interfaces. It supports efficient lossless data compression algorithms, allows on-demand data packaging into file formats for easy uploading or exporting, and provides standardized service interfaces (APIs) for other modules or tools to use. Through standardized data management, compression, and packaging functions, it simplifies the secure and efficient transmission of data to the cloud, laying the foundation for applications such as remote diagnostics, big data analysis, OTA pre-analysis, and cloud disaster recovery backup. Data compression reduces storage space occupied in the central unit and bandwidth consumption during cloud uploads.

[0024] Optionally, SDSR-Central also includes measures to avoid common-cause failures (CCFs) between data by employing physical isolation. The system design considers the independence between the SDSR-Central service and the data it protects, especially when the source data is also located on the same HPC, by avoiding common-cause failures (CCFs) through physical isolation, such as redundant backups to different data protection nodes.

[0025] Example 2 This embodiment also provides a data storage and recovery method for a vehicle-mounted centralized architecture using the system described in Embodiment 1, including: SDSR-Edge monitors the CRC or ECC status of the Flash / RAM address range of the NVM Block. When an unrecoverable fault is detected, it records the type, location, and node status, and reports it to SDSR-Central. Nodes on SDSR-Edge use a unique UID and security credentials to authenticate with SDSR-Central, securely back up local data according to the synchronization configuration, receive / verify recovery instructions, and finally report the operation results. After confirming that the status allows, the nodes on SDSR-Edge safely write and verify the recovery data, and finally report the operation results to SDSR-Central. SDSR-Central securely receives and verifies backup data from certified SDSR-Edge nodes, and persists it by index. SDSR-Central supports flexible configuration of backup strategies, enabling off-site / redundant storage and synchronized copies, and allows for the selection of operations to retain historical data from multiple versions; SDSR-Central receives and verifies SDSR-Edge fault reports, coordinates redundant backup and recovery processes, tracks status and records anomaly alarms.

[0026] Embodiments of the present invention have been shown and described. It will be apparent to those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A data storage and recovery system for a vehicle-mounted centralized architecture, characterized in that, It includes at least one edge microcontroller unit subsystem and one central processing unit subsystem. The edge microcontroller unit subsystem is equipped with an SDSR-Edge, and the central processing unit subsystem is equipped with an SDSR-Central. The edge microcontroller unit subsystem and the central processing unit subsystem are connected through a communication link. The SDSR-Edge monitors and detects faults in local data, backs up local data to SDSR-Central, reports detected fault information to SDSR-Central, and restores data according to instructions from SDSR-Central. The SDSR-Central is used to receive and back up data sent by the SDSR-Edge, and when it receives a fault request sent by the SDSR-Edge, it sends operation instructions and backed-up fault data to the SDSR-Edge.

2. The data storage and recovery system for a vehicle-mounted centralized architecture according to claim 1, characterized in that, The SDSR-Central classifies and tags the data, configures management strategies based on the tags, and automatically executes management.

3. The data storage and recovery system for a vehicle-mounted centralized architecture according to claim 1, characterized in that, The SDSR-Central configures storage space quotas based on the SDSR-Edge and queries storage space usage through an interface.

4. A data storage and recovery system for a vehicle-mounted centralized architecture according to claim 1, characterized in that, The SDSR-Central integrates with the vehicle key management system through access control, encrypted storage, protection of critical data to prevent unauthorized deletion and modification, and protection of the logs themselves.

5. A data storage and recovery system for a vehicle-mounted centralized architecture according to claim 1, characterized in that, The SDSR-Central supports lossless data compression and packages data into file formats and standardized service interfaces.

6. A data storage and recovery system for a vehicle-mounted centralized architecture according to claim 1, characterized in that, The SDSR-Central avoids common-cause failures between data by employing physical isolation.

7. A method for data storage and recovery in a vehicle-mounted centralized architecture, characterized in that, SDSR-Edge monitors the CRC or ECC status of the Flash / RAM address range of the NVM Block. When an unrecoverable fault is detected, it records the type, location, and node status, and reports it to SDSR-Central. Nodes on SDSR-Edge use a unique UID and security credentials to authenticate with SDSR-Central, securely back up local data according to the synchronization configuration, receive / verify recovery instructions, and finally report the operation results. After confirming that the status allows, the nodes on SDSR-Edge safely write and verify the recovery data, and finally report the operation results to SDSR-Central. SDSR-Central securely receives and verifies backup data from certified SDSR-Edge nodes, and persists it by index. SDSR-Central supports flexible configuration of backup strategies, enabling off-site / redundant storage and synchronized copies, and allows for the selection of operations to retain historical data from multiple versions; SDSR-Central receives and verifies SDSR-Edge fault reports, coordinates redundant backup and recovery processes, tracks status and records anomaly alarms.