Controller switching method and device, electronic equipment and readable storage medium

By acquiring and integrating the health status assessment parameters of the main controller and the backup controller, the fault level is determined and a graded response strategy is executed, which solves the problem of untimely and inaccurate controller switching, and realizes timely controller switching and improved system stability.

CN121785089APending Publication Date: 2026-04-03CHONGQING TONGWO AUTOMOBILE TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-06
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

Existing technologies cannot switch controllers in a timely and accurate manner, and are prone to erroneous or delayed switching, especially in complex fault scenarios.

Method used

By acquiring health status assessment parameters of the main controller and the backup controller, and performing fusion processing based on multiple operating status parameters, the fault level is determined, and a graded response strategy is executed. This includes maintaining control and increasing the monitoring frequency of the backup controller when the fault level is Level 1, entering a takeover preparation state when the fault level is Level 2, and switching control when the fault level is Level 3.

Benefits of technology

It enables timely and precise switching of the controller, improves the continuous operation stability of the vehicle control system and the safety and smoothness of the control switching process, avoids unnecessary switching caused by minor abnormalities, and ensures rapid response in the event of serious faults.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121785089A_ABST
    Figure CN121785089A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of equipment control, and provides a controller switching method and device, electronic equipment and a readable storage medium. The method comprises the steps that health state evaluation parameters of a main controller and a standby controller are obtained, and the health state evaluation parameters are obtained based on fusion processing of various operation state parameters of the main controller and the standby controller; determining a fault level according to the health state evaluation parameters; according to the fault level, a grading response strategy is executed, and the grading response strategy comprises at least one of the following items: under the condition that the fault level is a first-level fault level, the main controller maintains the control right, and the standby controller is indicated to improve the state monitoring frequency; under the condition that the fault level is the second-level fault level, the main controller maintains the control right and indicates the standby controller to enter a ready-to-take-over state; and under the condition that the fault level is the three-level fault level, the vehicle control right is switched from the main controller to the standby controller.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of equipment control technology, and in particular to a controller switching method, apparatus, electronic device, and readable storage medium. Background Technology

[0002] As the automotive industry accelerates towards highly automated driving and full electrification, the requirements for functional safety and operational continuity of vehicle control systems are increasing. Against this backdrop, a highly reliable dual-redundant vehicle controller architecture is gradually becoming the mainstream technology in the industry.

[0003] The dual-redundant vehicle controller architecture deploys a primary controller and a backup controller, with both operating in parallel. This aims to achieve seamless takeover in the event of a single controller failure, thus meeting the fault tolerance and robustness required for high-level autonomous driving systems. Currently, when a failure is detected in the primary controller, the system switches control to the backup controller. However, in complex fault scenarios, issues such as incorrect or delayed switching can easily occur.

[0004] Therefore, it is currently impossible to switch the controller in a timely and accurate manner. Summary of the Invention

[0005] In view of this, embodiments of this application provide a controller switching method, apparatus, electronic device, and readable storage medium to solve the problem that the prior art cannot switch the controller in a timely and accurate manner.

[0006] A first aspect of this application provides a controller switching method, comprising: Obtain health status assessment parameters for the main controller and the backup controller. These health status assessment parameters are obtained by fusing multiple operating status parameters of the main controller and the backup controller. The fault level is determined based on the health status assessment parameters; Based on the fault level, a graded response strategy is implemented, which includes at least one of the following: In the event of a level 1 fault, the main controller maintains control and instructs the backup controller to increase the frequency of status monitoring. In the event of a level 2 fault, the main controller maintains control and instructs the standby controller to enter a takeover readiness state. In the event of a level 3 fault, the vehicle control will be switched from the main controller to the backup controller.

[0007] A second aspect of this application provides a controller switching device, comprising: The acquisition module is used to acquire the health status assessment parameters of the main controller and the standby controller. The health status assessment parameters are obtained by fusing multiple operating status parameters of the main controller and the standby controller. The determination module is used to determine the fault level based on health status assessment parameters; The execution module is used to execute a graded response strategy based on the fault level. The graded response strategy includes at least one of the following: In the event of a level 1 fault, the main controller maintains control and instructs the backup controller to increase the frequency of status monitoring. In the event of a level 2 fault, the main controller maintains control and instructs the standby controller to enter a takeover readiness state. In the event of a level 3 fault, the vehicle control will be switched from the main controller to the backup controller.

[0008] A third aspect of this application provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the above-described method.

[0009] A fourth aspect of this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the above-described method.

[0010] The beneficial effects of this application embodiment compared with the prior art are as follows: By acquiring the health status assessment parameters of the main controller and the backup controller, which are obtained by fusing multiple operating status parameters of the main controller and the backup controller, a comprehensive quantitative perception of the controller's health status is achieved, providing a reliable data foundation for the entire decision-making process; based on the health status assessment parameters, the fault level is determined, enabling precise identification and classification of fault severity, and allowing for the most appropriate response measures to be taken for different levels of risk; based on the fault level, a graded response strategy is executed, which includes at least one of the following: in the case of a level 1 fault, the main controller maintains control and instructs the backup controller to increase the status monitoring frequency; in the case of a level 2 fault, the main controller maintains control and instructs the backup controller to enter a takeover preparation state; in the case of a level 3 fault, the vehicle control is switched from the main controller to the backup controller. This avoids unnecessary master / slave switching due to a single minor anomaly, while also ensuring that serious faults can be quickly identified and decisively dealt with, achieving timely and accurate switching of the controller, and improving the continuous operation stability of the vehicle control system and the safety and smoothness of the control handover process. Attached Figure Description

[0011] To more clearly illustrate the technical solutions in the embodiments of this application, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0012] Figure 1 This is a flowchart illustrating a controller switching method provided in an embodiment of this application; Figure 2 This is a flowchart illustrating a data packet synchronization method for a controller provided in an embodiment of this application; Figure 3 This is a schematic diagram of the structure of a switching device for a controller provided in an embodiment of this application; Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0013] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted so as not to obscure the description of this application with unnecessary detail.

[0014] A controller switching method and apparatus according to an embodiment of this application will now be described in detail with reference to the accompanying drawings.

[0015] Figure 1 This is a flowchart illustrating a controller switching method provided in an embodiment of this application. Figure 1 The switching method for the controller can be executed by the controller's switching device. For example... Figure 1 As shown, the switching method of this controller includes: Step S101: Obtain the health status assessment parameters of the main controller and the backup controller, wherein the health status assessment parameters are obtained by fusing multiple operating status parameters of the main controller and the backup controller; In a dual-redundant vehicle controller architecture, the primary and backup controllers, as core control units, maintain reliability by continuously monitoring their own operational status. Operational status parameters include key indicators such as processor load rate, power supply voltage, communication bus error rate, and the number of sensor signal out-of-sync occurrences. Health status assessment parameters are comprehensive quantitative indicators obtained through weighted fusion calculations of these various operational status parameters, comprehensively reflecting the actual working status of the controller.

[0016] By periodically collecting various operating status parameters of the main controller and the backup controller, and using a weighted fusion algorithm to comprehensively process these parameters, the impact weight of different parameters on safety is considered. For example, abnormal power supply voltage may be given a higher weight, and finally a unified health status assessment parameter is generated.

[0017] Step S102: Determine the fault level based on the health status assessment parameters; Fault levels are hierarchical criteria based on the numerical range of health status assessment parameters or the degree of abnormality of specific operating status parameters. Specifically, they are divided into Level 1, Level 2, and Level 3 fault levels, each corresponding to different response strategies.

[0018] When health status assessment parameters fall within a specific value range or certain key operating status parameters remain abnormal, the corresponding fault level is triggered. For example, if a health status assessment parameter is within a preset second value range, or if the power supply voltage remains below the safety threshold for a set duration, it will be classified as a level two fault.

[0019] Step S103: Execute a graded response strategy based on the fault level. The graded response strategy includes at least one of the following: In the event of a level 1 fault, the main controller maintains control and instructs the backup controller to increase the frequency of status monitoring. In the event of a level 2 fault, the main controller maintains control and instructs the standby controller to enter a takeover readiness state. In the event of a level 3 fault, the vehicle control will be switched from the main controller to the backup controller.

[0020] When a Level 1 fault is detected, the primary controller maintains control while sending instructions to the backup controller, requesting it to increase the status monitoring frequency, such as shortening the monitoring cycle from 100 milliseconds to 10 milliseconds. When a Level 2 fault occurs, the primary controller retains control functions, but the backup controller enters a takeover preparation state, including preloading control parameters and initialization. If a Level 3 fault is detected, such as a complete interruption of the communication link between the primary and backup controllers, the control handover process is immediately initiated, transferring vehicle control from the primary controller to the backup controller.

[0021] By continuously monitoring the controller's operational status, early identification and classification of potential faults were achieved. Targeted response measures were implemented based on different fault levels, avoiding unnecessary switching due to momentary anomalies and ensuring rapid response in the event of severe faults. Through refined fault management and progressive response strategies, operational stability and reliability were significantly improved, while maximizing the safety and continuity of the control handover process.

[0022] In the embodiments of this application, by acquiring health status assessment parameters of the main controller and the backup controller, which are obtained by fusing multiple operating status parameters of the main controller and the backup controller, a comprehensive quantitative perception of the controller's health status is achieved, providing a reliable data foundation for the entire decision-making process. Based on the health status assessment parameters, the fault level is determined, enabling precise identification and classification of fault severity, and allowing for the most appropriate response measures to be taken for different levels of risk. According to the fault level, a graded response strategy is executed, which includes at least one of the following: in the case of a Level 1 fault, the main controller maintains control and instructs the backup controller to increase the status monitoring frequency; in the case of a Level 2 fault, the main controller maintains control and instructs the backup controller to enter a takeover readiness state; in the case of a Level 3 fault, the vehicle control is switched from the main controller to the backup controller. This avoids unnecessary main / backup switching triggered by a single minor anomaly, while also ensuring rapid identification and decisive handling in the event of a serious fault, achieving timely and accurate controller switching, and improving the continuous operational stability of the vehicle control and the safety and smoothness of the control switching process.

[0023] In some embodiments, step S101 may specifically include the following steps: Collect operating status parameters of the main controller and the backup controller. The operating status parameters include at least one of the following: processor load rate, power supply voltage, communication bus error rate, and number of sensor signal out-of-step times. Multiple operational status parameters are weighted and fused to obtain health status assessment parameters.

[0024] Operating status parameters refer to technical indicators that reflect the controller's operating status, including but not limited to key parameters such as processor load rate, power supply voltage, communication bus error rate, and sensor signal out-of-step count. Health status assessment parameters are comprehensive evaluation values ​​obtained by weighted and fused calculation of multiple operating status parameters, which can comprehensively characterize the overall health status of the controller.

[0025] The system periodically collects various operating status parameters from the main controller and the backup controller. These parameters reflect the controller's operating status from different dimensions. For example, the processor load rate reflects the utilization of computing resources, the power supply voltage reflects the stability of the power supply, the communication bus error rate shows the reliability of data transmission, and the number of sensor signal out-of-step events characterizes the completeness of external signal acquisition.

[0026] The collected operational status parameters are weighted and fused, taking into account the varying importance of different parameters to safety, and corresponding weighting coefficients are set accordingly. For example, processor load rate and power supply voltage may be assigned higher weights because these parameters directly affect the controller's basic operational capabilities. The weighted fusion algorithm multiplies each parameter by its corresponding weighting coefficient and then sums the results to generate a unified health status assessment parameter.

[0027] Specifically, the collected raw operational status parameters with different dimensions and units are uniformly converted into dimensionless health scores ranging from 0 to 1 using a preset mapping function. This mapping function is designed independently based on the characteristics of each parameter; when the parameter is in an ideal state, the health score is 1; when the parameter reaches an unacceptable risk threshold, the health score is 0.

[0028] For processor load rate: This parameter is a percentage and can be directly mapped. For example, you can set the score to 1.0 when the load rate is below 70%; the score to 0 when the load rate is above 95%; and the score linearly decreases from 1.0 to 0 between 70% and 95%.

[0029] For power supply voltage: mapping needs to be performed according to the normal operating voltage range of the controller. For example, if the rated voltage is 12V, the score is 1.0 when the set voltage is in the range of 11.5V to 12.5V; the score is 0 when the voltage is below 10V or above 14V; outside this range and between the normal range, the score decreases linearly.

[0030] For the communication bus error rate: the score can be set to 1.0 when the error rate is below a certain extremely low value; and to 0 when the error rate exceeds a certain set safety limit; the intermediate state is mapped using a linear or exponential decay function.

[0031] For the number of times the sensor signal loses step: within a unit of time, such as 1 second, if the number of times the step is lost is 0, the score is 1.0; if the number of times the step is lost exceeds the set tolerance value, such as 10 times, the score is 0; between 0 and the tolerance value, the score decreases linearly.

[0032] After converting all operating status parameters into a unified health score, a weighted summation algorithm is used to calculate a single health status assessment parameter. The calculation formula can be expressed as: Health Status Assessment Parameter = (Weight 1 × Score 1) + (Weight 2 × Score 2) + ... + (Weight n × Score n). Each weight coefficient is pre-set according to the importance of the corresponding parameter to the controller's functional safety, and the sum of all weight coefficients is 1. For example, power supply voltage and processor load rate may be assigned higher weights (e.g., 0.3), while other parameters are assigned relatively lower weights. This allows for the integration of multi-dimensional, heterogeneous operating status information into a single quantitative indicator that accurately reflects the overall health level of the controller.

[0033] For example, when the processor load rate is detected to be consistently above 88.5% and the communication bus error rate is significantly increased, the health status assessment parameters obtained by weighted calculation will deviate significantly from the normal range, indicating that the controller may be in an abnormal working state.

[0034] By comprehensively considering multiple operating status parameters, the actual working status of the controller can be assessed more comprehensively and accurately, avoiding misjudgments that may be caused by fluctuations in a single parameter. The weighting coefficients amplify abnormal changes in important parameters in a timely manner, improving sensitivity to critical faults. Simultaneously, this quantitative assessment method provides a reliable data foundation for subsequent fault level determination, ensuring the scientific rigor and accuracy of the entire switching decision-making process.

[0035] In some embodiments, step S102 may specifically include the following steps: If the health status assessment parameter is within the first value range, or if any operating status parameter exceeds the first parameter threshold, the fault level is determined to be a level one fault level. If the health status assessment parameter is within the second value range, or if the key operating status parameter continuously exceeds the second parameter threshold for a first preset duration, the fault level is determined to be a level two fault level; the key operating status parameters include at least one of the following: processor load rate, power supply voltage, and sensor signal status related to vehicle driving safety. If the health status assessment parameter is in the third value range, or if the communication link between the main controller and the backup controller is interrupted for a second preset duration, the fault level is determined to be a level three fault level. Among them, the health status represented by the first numerical range, the second numerical range and the third numerical range decreases in sequence, and the threshold of the first parameter corresponding to the same operating status parameter is less than the threshold of the second parameter.

[0036] Fault level determination is based on two parallel paths: first, examining the numerical range of comprehensive health status assessment parameters; and second, monitoring whether specific operational status parameters exceed set thresholds. The first, second, and third numerical ranges correspond to different health status levels, with the health status represented by these three ranges decreasing sequentially. This means that the first range represents the best health status, and the third range represents the worst health status. Similarly, the parameter thresholds are set according to this principle, with the first parameter threshold being lower than the second parameter threshold, forming a progressively strict judgment standard.

[0037] Each operating status parameter has its own independent first parameter threshold and second parameter threshold, which are pre-calibrated based on the physical characteristics of each operating status parameter and its impact on system safety.

[0038] For example, regarding processor load rate: the first parameter threshold can be set to 85%. When the load rate exceeds 85%, it indicates that computing resources are strained, and its trend needs to be monitored. The second parameter threshold can be set to 95%. When the load rate consistently exceeds 95% for a first preset duration, it indicates that the controller is on the verge of overload, and its reliability has severely decreased.

[0039] Regarding the power supply voltage: the first parameter threshold can be set to 16V. When the voltage exceeds 16V, it indicates an overvoltage risk in the power supply system, requiring increased monitoring. The second parameter threshold can be set to 17V. When the voltage consistently exceeds 17V for a first preset duration, it indicates a serious overvoltage threat, which may damage the controller hardware.

[0040] Regarding the communication bus error rate: the first threshold parameter can be set to 10 error frames per second. Exceeding this threshold indicates that communication quality is beginning to deteriorate. The second threshold parameter can be set to 100 error frames per second. Continuously exceeding this threshold indicates that the communication link may be about to be interrupted.

[0041] For sensor signal status related to vehicle drive safety, such as the motor rotor position sensor: the first parameter threshold can be set to a signal discontinuity duration of 1 millisecond. This indicates slight signal instability. The second parameter threshold can be set to a complete signal loss lasting 10 milliseconds. This indicates that the sensor signal has failed, which will directly lead to inaccurate drive motor control.

[0042] By independently setting progressive thresholds for each key parameter, refined fault level assessment can be achieved. This design ensures that parameters of different natures and units can be accurately evaluated, collectively forming a robust, multi-dimensional fault diagnosis system.

[0043] Specifically, the system simultaneously monitors the numerical positions of health status assessment parameters and the actual values ​​of various operational status parameters. When a health status assessment parameter falls within a first value range, or when any operational status parameter exceeds the first parameter threshold, it is classified as a Level 1 fault. For example, if the processor load briefly exceeds the first parameter threshold but quickly returns to normal, or if a health status assessment parameter fluctuates slightly within the normal range, it will be classified as a Level 1 fault.

[0044] For determining a Level 2 fault, in addition to examining whether the health status assessment parameters are within the second numerical range, special attention is paid to the duration of abnormalities in key operating status parameters. Key operating status parameters include core parameters such as processor load rate, power supply voltage, and the status of sensor signals directly related to vehicle driving safety. When these key parameters consistently exceed the second parameter threshold for a first preset duration, a Level 2 fault will be determined even if the health status assessment parameters have not yet entered the worst-case range. For example, if the power supply voltage remains below the safe operating threshold for 200 milliseconds, or if sensor signals related to driving safety exhibit continuous abnormalities, a Level 2 fault determination will be triggered.

[0045] Level 3 fault status is the highest level of fault condition, and its judgment criteria are the most stringent. When the health status assessment parameters fall into the third value range, or when the communication link between the primary and backup controllers is interrupted for a second preset duration, it will be immediately determined to be a Level 3 fault. For example, when the communication link between the primary and backup controllers is completely interrupted for more than fifty milliseconds, or when the health status assessment parameters indicate that the controller is in a severely abnormal state, the highest level of fault response will be initiated.

[0046] By setting multiple judgment dimensions and progressive threshold standards, comprehensive monitoring of the controller's status is achieved. It considers not only instantaneous parameter anomalies but also the duration of these anomalies, enabling timely detection of minor performance degradation and accurate identification of severe functional failures. This refined fault classification system provides a reliable basis for subsequent targeted response measures, effectively avoiding both overreaction and underreaction.

[0047] In some embodiments, the following steps may be included before step S103: Step 201: In each control cycle, the main controller generates a control state image data packet containing the current control commands and state variables, and sends the control state image data packet to the backup controller. Step 202: Receive and parse the control state image data packet through the backup controller to obtain the parsing result, and maintain the virtual control state synchronized with the main controller based on the parsing result.

[0048] The control state image data packet is a complete set of data containing all key control commands and state variables of the primary controller within the current control cycle. The virtual control state, on the other hand, refers to the state image maintained internally by the backup controller based on the received data packets, which is completely consistent with the primary controller. Therefore, a continuous state synchronization mechanism is established to ensure state consistency between the primary and backup controllers.

[0049] Specifically, at the beginning of each control cycle, the main controller collects current control commands and state variables. This information includes, but is not limited to, drive motor torque commands, battery management power allocation parameters, and operating status data of each component. The main controller encapsulates this data into a control state image data packet according to a predetermined format and sends it to the backup controller via a dedicated communication link. For example, within a 10-millisecond control cycle, the main controller completes the assembly and transmission of the data packet within the first two milliseconds, ensuring that the backup controller has sufficient time to process it.

[0050] Upon receiving the control status image data packet, the backup controller immediately initiates the parsing process. This process includes data format verification, validation and confirmation, and information extraction. The backup controller updates its internal virtual control state with the parsed control commands and status variables, maintaining strict synchronization with the primary controller's actual control state.

[0051] By continuously synchronizing the states of the primary and backup controllers in real time, when a switchover of control is required, the backup controller can seamlessly take over based on its latest maintained virtual control state, avoiding control command jumps or operational fluctuations caused by inconsistent states. Simultaneously, this mechanism also enables the backup controller to continuously verify the correctness of its own processing logic, providing additional security.

[0052] The aforementioned control status image data package includes at least one of the following: drive motor torque command, battery management power allocation information, and currently active fault code list.

[0053] In a dual-redundant controller, the control state mirror data packet serves as the core carrier for state synchronization between the primary and backup controllers, and its content design directly affects the smoothness and safety of the switching process. The control state mirror data packet contains key operating parameters necessary to ensure that the backup controller can seamlessly take over control. The drive motor torque command reflects the vehicle's current power output demand, the battery management power allocation information reflects the energy flow status of the entire vehicle, and the currently active fault code list records the detected anomalies.

[0054] The drive motor torque command determines the vehicle's acceleration, deceleration, and cruising status. When the main controller is operating normally, this command is simultaneously sent to the drive actuators and the backup controller. For example, when the driver presses the accelerator pedal deeply, the main controller calculates the required drive torque output of 250 Nm, and this value is immediately included in the control status mirror data packet and sent to the backup controller. This way, in the event of a control switch, the backup controller can maintain the same torque output, avoiding power interruptions or sudden changes.

[0055] Battery management power allocation information reflects the real-time status of the vehicle's energy management. This information includes the current allowed discharge power, charging power limits, and the operating status of each high-voltage component. For example, when the vehicle is under rapid acceleration, the main controller may limit the discharge power to 80 kW to ensure battery safety, and the power allocation strategy will be synchronized to the backup controller in real time via data packets. This way, even during the switchover, the backup controller can continue to execute the same power management strategy, ensuring the safe operation of the high voltage.

[0056] The currently active fault code list provides a complete view of the health status, recording all triggered but not cleared fault information. For example, when an abnormal voltage sampling of a battery cell is detected, the main controller generates a corresponding fault code and includes it in a data packet, sending it to the backup controller. This allows the backup controller to fully understand the potential problems when taking over and to take appropriate fault-tolerant control strategies.

[0057] The control status mirror data package ensures the integrity and consistency of the status between the primary and backup controllers. By synchronizing the most critical control commands and statuses, the backup controller can quickly assume the responsibility of vehicle control whenever it needs to take over, minimizing the impact of the switching process on the stability of vehicle operation and providing a solid guarantee for high-reliability operation.

[0058] Specifically, the step of instructing the standby controller to enter the takeover readiness state mentioned above may include the following steps: The backup controller is instructed to activate a data synchronization acceleration mechanism, which includes increasing the frequency of requesting status data from the master controller and verifying the integrity of the received status data.

[0059] During the operation of dual-redundant controllers, when it is determined that a takeover readiness state needs to be entered, a sophisticated data synchronization acceleration mechanism will be activated. The core objective of this mechanism is to minimize the state differences between the primary and backup controllers before a potential switchover occurs, thus making full preparations for a possible transfer of control. The data synchronization acceleration mechanism specifically includes two key technical actions: increasing the frequency of state data requests and enhancing data integrity verification.

[0060] Once the takeover readiness state is triggered, the standby controller immediately adjusts its data interaction strategy with the primary controller. Specifically, it increases the frequency of requesting status data from the primary controller. Under normal monitoring conditions, the standby controller might request a status update every 50 milliseconds; however, after entering the takeover readiness state, this frequency may increase to every 10 milliseconds or even higher. For example, when the primary controller's processor load rate consistently exceeds 85% for a set duration, it is classified as a level two fault. In this case, the standby controller will automatically adjust its data request cycle from the usual 50 milliseconds to 10 milliseconds to ensure more timely status information.

[0061] Meanwhile, the backup controller initiates a more stringent data integrity verification process. Data integrity verification may include performing multiple checks on the received status data, such as cyclic redundancy checks, sequence number continuity checks, and data range reasonableness checks. For example, after receiving the control status image data packet from the primary controller, the backup controller will not only verify the checksum of the data packet but also check the continuity of the data packet sequence number and whether the drive motor torque command within the data packet is within a reasonable range. If a jump in the data packet sequence number is detected, or the torque command value exceeds the maximum allowable range, the backup controller will immediately request a retransmission of the data to ensure the integrity and reliability of the received data.

[0062] By increasing the data update frequency, the backup controller can obtain a state closer to real-time, significantly reducing potential state lag. Enhanced data integrity verification effectively prevents the propagation of erroneous or abnormal data, ensuring the accuracy of the virtual control state maintained internally by the backup controller. These two measures work together to ensure that the backup controller is already in an optimal ready state when a control switch is actually required, thereby guaranteeing a smooth switchover process and operational continuity, providing a higher level of safety for vehicle control.

[0063] In some embodiments, after the above-described step of switching vehicle control from the main controller to the backup controller, the following steps may also be included: The new master controller broadcasts the identity change information to each sub-controller. Receive feedback information from each sub-controller and perform consistency verification based on the feedback information; If the consistency check fails, the new master controller initiates a negotiation recovery process to the sub-controller that reported the error. If the negotiation recovery process fails, the new master controller will logically isolate the sub-controller that is reporting the abnormality from the current control network and stop sending control commands to the sub-controller that is reporting the abnormality. A sub-controller that provides abnormal feedback includes at least one of the following: a sub-controller that fails to respond to identity change information within a preset time, a sub-controller whose operating status does not match the control command, or a sub-controller that refuses control of the new master controller.

[0064] After the dual redundant controllers complete the control handover, a complete post-switchover collaborative management process will be initiated to ensure that the entire control can operate in a coordinated manner. The post-switchover collaborative management process includes steps such as identity change broadcasting, feedback collection, consistency verification, negotiation recovery, and necessary logical isolation to ensure that all sub-controllers can correctly identify and obey the command of the new master controller.

[0065] Once control has successfully switched from the original master controller to the backup controller, the new master controller immediately broadcasts the identity change information to all sub-controllers connected to the vehicle network. This information includes the new master controller identifier, the switching timestamp, and necessary status updates. For example, in the first control cycle after the switch is complete, the new master controller will send this crucial information to all sub-controllers, such as the engine controller, battery management controller, and brake controller, via the CAN bus or Ethernet.

[0066] Upon receiving identity change information, each sub-controller needs to return an acknowledgment response; this feedback forms the basis for consistency verification. The new master controller analyzes the response content, response time, and reported status data of each sub-controller. For example, a normal sub-controller will return a correct response frame containing its current status within 10 milliseconds, while an abnormal sub-controller may exhibit timeout failure, return an error status code, or report an actual status that contradicts the control commands.

[0067] When a consistency check fails, it indicates that one or more sub-controllers have failed to properly adapt to the change in control. In this case, the new master controller will initiate a negotiation recovery process for these sub-controllers that have reported abnormal responses. This process may include steps such as retransmitting identity change frames, performing handshake protocol verification, or sending a soft reset command. For example, for a motor controller that does not respond within a preset time, the new master controller may repeatedly send the identity change command for three consecutive communication cycles and wait for its response.

[0068] If the negotiation recovery process ultimately fails, meaning that a sub-controller continues to be unable to return to normal operation, the new master controller will take final protective measures, namely, logically isolating the sub-controller from the current control network. This operation includes marking the sub-controller as unavailable in the internal routing table, ceasing to send any control commands to it, and recording relevant fault information for subsequent diagnostic analysis. For example, if a sensor data processing unit continuously refuses to accept control from the new master controller, it will be isolated, and the corresponding redundant backup sensor will be activated or it will continue to operate with default safety values.

[0069] By proactively notifying users of identity changes and rigorously verifying consistency, the majority of sub-controllers were able to smoothly transition to the new control environment. For the few abnormal sub-controllers, a gradual handling strategy was adopted, giving them the opportunity to return to normal while also taking isolation measures when necessary to prevent them from affecting the overall normal operation. This achieved graceful degradation of control under abnormal conditions and continuous safe operation, effectively ensuring the stability and safety of the entire vehicle during the change of control.

[0070] All of the above-mentioned optional technical solutions can be combined in any way to form the optional embodiments of this application, and will not be described in detail here.

[0071] The following are embodiments of the apparatus described in this application, which can be used to execute the embodiments of the method described in this application. For details not disclosed in the apparatus embodiments of this application, please refer to the embodiments of the method described in this application.

[0072] Figure 3 This is a schematic diagram of a switching device for a controller provided in an embodiment of this application. Figure 3 As shown, the switching device of the controller includes: The acquisition module 301 is used to acquire the health status assessment parameters of the main controller and the standby controller, wherein the health status assessment parameters are obtained by fusing multiple operating status parameters of the main controller and the standby controller. The determination module 302 is used to determine the fault level based on the health status assessment parameters; Execution module 303 is configured to execute a graded response strategy based on the fault level, wherein the graded response strategy includes at least one of the following: In the event of a level 1 fault, the main controller maintains control and instructs the backup controller to increase the frequency of status monitoring. In the event of a level 2 fault, the main controller maintains control and instructs the standby controller to enter a takeover readiness state. In the event of a level 3 fault, the vehicle control will be switched from the main controller to the backup controller.

[0073] According to the technical solution provided in this application, by acquiring health status assessment parameters of the main controller and the backup controller, which are obtained by fusing multiple operating status parameters of the main controller and the backup controller, a comprehensive quantitative perception of the controller's health status is achieved, providing a reliable data foundation for the entire decision-making process. Based on the health status assessment parameters, the fault level is determined, enabling precise identification and classification of fault severity, and allowing for the most appropriate response measures to be taken for different levels of risk. Based on the fault level, a graded response strategy is executed, which includes at least one of the following: in the case of a Level 1 fault, the main controller maintains control and instructs the backup controller to increase the status monitoring frequency; in the case of a Level 2 fault, the main controller maintains control and instructs the backup controller to enter a takeover preparation state; in the case of a Level 3 fault, the vehicle control is switched from the main controller to the backup controller. This avoids unnecessary main / backup switching triggered by a single minor anomaly, while also ensuring rapid identification and decisive handling in the event of a serious fault, achieving timely and accurate switching of the controller, and improving the continuous operational stability of the vehicle control and the safety and smoothness of the control switching process.

[0074] In some embodiments, the acquisition module 301 is specifically used for: Collect operating status parameters of the main controller and the backup controller. The operating status parameters include at least one of the following: processor load rate, power supply voltage, communication bus error rate, and number of sensor signal out-of-step times. Multiple operational status parameters are weighted and fused to obtain health status assessment parameters.

[0075] In some embodiments, the determining module 302 is specifically used for: If the health status assessment parameter is within the first value range, or if any operating status parameter exceeds the first parameter threshold, the fault level is determined to be a level one fault level. If the health status assessment parameter is within the second value range, or if the key operating status parameter continuously exceeds the second parameter threshold for a first preset duration, the fault level is determined to be a level two fault level; the key operating status parameters include at least one of the following: processor load rate, power supply voltage, and sensor signal status related to vehicle driving safety. If the health status assessment parameter is in the third value range, or if the communication link between the main controller and the backup controller is interrupted for a second preset duration, the fault level is determined to be a level three fault level. Among them, the health status represented by the first numerical range, the second numerical range and the third numerical range decreases in sequence, and the threshold of the first parameter corresponding to the same operating status parameter is less than the threshold of the second parameter.

[0076] In some embodiments, the switching device 300 of the controller further includes: The generation module 304 is used to generate a control state image data packet containing the current control instructions and state variables through the main controller in each control cycle, and send the control state image data packet to the backup controller. The parsing module 305 is used to receive and parse the control state image data packet through the backup controller, obtain the parsing result, and maintain the virtual control state synchronized with the main controller based on the parsing result.

[0077] In some embodiments, the control status image data packet includes at least one of the following: drive motor torque command, battery management power allocation information, and a list of currently active fault codes.

[0078] In some embodiments, the execution module 303 is specifically used for: The backup controller is instructed to activate a data synchronization acceleration mechanism, which includes increasing the frequency of requesting status data from the master controller and verifying the integrity of the received status data.

[0079] In some embodiments, the switching device 300 of the controller further includes: Control module 306 is used to control the new master controller to broadcast identity change information to each sub-controller; The verification module 307 is used to receive feedback information from each sub-controller and perform consistency verification based on the feedback information. The control module 306 is used to control the new master controller to initiate a negotiation recovery process to the sub-controller that reported the abnormality if the consistency check fails. The control module 306 is used to control the new master controller to logically isolate the abnormal sub-controller from the current control network and stop sending control commands to the abnormal sub-controller if the negotiation recovery process fails. A sub-controller that provides abnormal feedback includes at least one of the following: a sub-controller that fails to respond to identity change information within a preset time, a sub-controller whose operating status does not match the control command, or a sub-controller that refuses control of the new master controller.

[0080] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0081] Figure 4 This is a schematic diagram of the electronic device 6 provided in an embodiment of this application. Figure 4As shown, the electronic device 6 of this embodiment includes a processor 601, a memory 602, and a computer program 603 stored in the memory 602 and executable on the processor 601. When the processor 601 executes the computer program 603, it implements the steps in the various method embodiments described above. Alternatively, when the processor 601 executes the computer program 603, it implements the functions of each module / unit in the various device embodiments described above.

[0082] Electronic device 6 can be a desktop computer, laptop, handheld computer, cloud server, or other electronic device. Electronic device 6 may include, but is not limited to, processor 601 and memory 602. Those skilled in the art will understand that... Figure 4 This is merely an example of electronic device 6 and does not constitute a limitation on electronic device 6. It may include more or fewer components than shown, or different components.

[0083] The processor 601 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.

[0084] The memory 602 can be an internal storage unit of the electronic device 6, such as a hard disk or RAM of the electronic device 6. The memory 602 can also be an external storage device of the electronic device 6, such as a plug-in hard disk, Smart Media Card (SMC), Secure Digital (SD) card, Flash Card, etc., equipped on the electronic device 6. The memory 602 can also include both internal and external storage units of the electronic device 6. The memory 602 is used to store computer programs and other programs and data required by the electronic device.

[0085] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0086] If an integrated module / unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments can also be implemented by a computer program instructing related hardware. The computer program can be stored in a readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program may include computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. A computer-readable medium may include: any entity or device capable of carrying computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in a computer-readable medium can be appropriately added to or subtracted according to the requirements of legislation and patent practice in a jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electrical carrier signals and telecommunication signals.

[0087] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.

Claims

1. A method for switching controllers, characterized in that, The method includes: Obtain health status assessment parameters for the main controller and the backup controller, wherein the health status assessment parameters are obtained by fusing multiple operating status parameters of the main controller and the backup controller; The fault level is determined based on the health status assessment parameters. Based on the fault level, a graded response strategy is implemented, wherein the graded response strategy includes at least one of the following: In the event of a level 1 fault, the main controller maintains control and instructs the backup controller to increase the status monitoring frequency. In the event of a level 2 fault, the main controller maintains control and instructs the backup controller to enter a takeover readiness state. When the fault level is level three, the vehicle control is switched from the main controller to the backup controller.

2. The method according to claim 1, characterized in that, The acquisition of health status assessment parameters for the main controller and the standby controller includes: The operating status parameters of the main controller and the backup controller are collected, and the operating status parameters include at least one of the following: processor load rate, power supply voltage, communication bus error rate, and number of sensor signal out-of-step times; The health status assessment parameters are obtained by weighted fusion of various operating status parameters.

3. The method according to claim 2, characterized in that, The step of determining the fault level based on the health status assessment parameters includes: If the health status assessment parameter is within a first value range, or if any of the operating status parameters exceeds the first parameter threshold, the fault level is determined to be a level one fault level. If the health status assessment parameter is within the second value range, or if the key operating status parameter continuously exceeds the second parameter threshold for a first preset duration, the fault level is determined to be a level two fault level; the key operating status parameter includes at least one of the following: processor load rate, power supply voltage, and sensor signal status related to vehicle driving safety. If the health status assessment parameter is within the third value range, or if the communication link between the main controller and the backup controller is interrupted for a second preset duration, the fault level is determined to be a level three fault level. The health status represented by the first numerical range, the second numerical range, and the third numerical range decreases sequentially, and the first parameter threshold corresponding to the same operating status parameter is less than the second parameter threshold.

4. The method according to claim 1, characterized in that, Before executing the graded response strategy according to the fault level, the method further includes: In each control cycle, the main controller generates a control status image data packet containing the current control command and system status variables, and sends the control status image data packet to the backup controller. The backup controller receives and parses the control state image data packet to obtain the parsing result, and maintains a virtual control state synchronized with the main controller based on the parsing result.

5. The method according to claim 4, characterized in that, The control status image data packet includes at least one of the following: drive motor torque command, battery management system power allocation information, and currently active fault code list.

6. The method according to claim 1, characterized in that, The instruction for the standby controller to enter the takeover readiness state includes: The backup controller is instructed to activate a data synchronization acceleration mechanism, wherein the data synchronization acceleration mechanism includes: increasing the frequency of requesting status data from the main controller, and verifying the integrity of the received status data.

7. The method according to claim 1, characterized in that, After switching vehicle control from the main controller to the backup controller, the method further includes: The new master controller broadcasts the identity change information to each sub-controller. Receive feedback information from each sub-controller and perform system consistency verification based on the feedback information; If the system consistency check fails, the new master controller will initiate a negotiation recovery process to the sub-controller that reported the anomaly. If the negotiation recovery process fails, the new master controller will logically isolate the sub-controller with the feedback error from the current control network and stop sending control commands to the sub-controller with the feedback error. The sub-controller with the feedback error includes at least one of the following: a sub-controller that fails to respond to identity change information within a preset time, a sub-controller whose feedback operating status does not match the control command, or a sub-controller that refuses the control right of the new master controller.

8. A switching device for a controller, characterized in that, Applied to servers, including: The acquisition module is used to acquire health status assessment parameters of the main controller and the backup controller, wherein the health status assessment parameters are obtained by fusing multiple operating status parameters of the main controller and the backup controller. The determination module is used to determine the fault level based on the health status assessment parameters; An execution module is configured to execute a graded response strategy based on the fault level, the graded response strategy including at least one of the following: In the event of a level 1 fault, the main controller maintains control and instructs the backup controller to increase the status monitoring frequency. In the event of a level 2 fault, the main controller maintains control and instructs the backup controller to enter a takeover readiness state. When the fault level is level three, the vehicle control is switched from the main controller to the backup controller.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method as described in any one of claims 1 to 7.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method as described in any one of claims 1 to 7.