Multi-source redundant time synchronization method and system of intelligent driving system and application

By constructing a three-level redundant time source and an end-to-end direct connection synchronization mechanism, the time synchronization problem of intelligent driving systems in complex scenarios is solved, achieving high-precision, non-jumping time synchronization and improving system performance and safety.

CN121966779APending Publication Date: 2026-05-01ANHUI JIANGHUAI AUTOMOBILE GRP CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ANHUI JIANGHUAI AUTOMOBILE GRP CORP LTD
Filing Date
2026-03-18
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Existing intelligent driving systems lack sufficient time synchronization accuracy in complex scenarios and are susceptible to GNSS signal interference or interruption, leading to sensor timestamp jumps and system timing misalignments, which affect decision response speed and safety.

Method used

A three-level redundant time source is constructed, and the validity of the time source is detected according to the priority order. The T-BOX is used as the master clock, and an end-to-end direct connection synchronization mechanism is adopted to bypass the area controller to achieve high-precision time synchronization. The time continuity is maintained by writing to non-volatile memory when the power is off.

Benefits of technology

To ensure that the intelligent driving system has high-precision and seamless time synchronization in all scenarios, improve system performance and safety, and avoid time interruption caused by the failure of a single time source.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121966779A_ABST
    Figure CN121966779A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of intelligent driving, and provides an intelligent driving system multi-source redundant time synchronization method and system and application, and the method comprises the steps: constructing three levels of redundant time sources which are arranged in a descending order according to priorities; after the intelligent driving system is powered on, the effectiveness of time sources is detected according to the priority sequence, double-source matching operation is executed, the effective time source with the highest priority is selected as a time service main source, and the time service main source is locked and not switched in the power-on period; an area controller is bypassed through an end-to-end direct connection synchronization mechanism, and a high-precision time synchronization full link is directly established with an intelligent driving area controller; and after power-off, the synchronization time of the intelligent driving domain controller is written into the nonvolatile memory, so that the continuity of the system time is maintained based on the third-level source when both the first-level source and the second-level source fail. According to the invention, the time synchronization effect of full-scene time continuity, high precision and no jump / conflict at the source end can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

A method, system, and application for multi-source redundant time synchronization in an intelligent driving system. Technical Field

[0001] This application relates to the field of intelligent driving technology, and in particular to a method, system and application for multi-source redundant time synchronization of an intelligent driving system. Background Technology

[0002] Intelligent driving systems rely on the precise fusion of data from multiple sensors, such as LiDAR, cameras, and millimeter-wave radar, to achieve environmental perception and decision-making. The accuracy of time synchronization directly determines the fusion effect. When sensor time deviation exceeds a certain error, it may lead to safety risks such as obstacle recognition misalignment and path planning deviation. Currently, traditional technical solutions still have the following core shortcomings when dealing with complex real-world scenarios:

[0003] 1. Single-source dependency risk: Traditional solutions often rely on a single Global Navigation Satellite System (GNSS) or Network Time Protocol (NTP) as a time reference. However, in common scenarios such as tunnels, underground parking garages, and urban canyons, GNSS signals are easily lost or severely interfered with; and when the network is interrupted, the NTP synchronization function will completely fail. This single-point vulnerability causes the time reference to collapse in critical scenarios, thereby causing the time synchronization chain of the entire intelligent driving system to break.

[0004] 2. Poor consistency during multi-source switching: Time jumps are prone to occur when switching between multiple clock source schemes, which directly causes the sensor timestamps to be reversed, increasing the difficulty of algorithm processing.

[0005] 3. Insufficient internal timing coordination: The MCU and SOC within the intelligent driving domain controller need to work together. If there is a large time difference between the two, it will lead to a timing mismatch between perception results and control commands, affecting the decision response speed. In addition, if the area controller fails to maintain high-precision time synchronization with the MDC, it may also cause a timing mismatch between intelligent driving commands and the underlying vehicle body execution, resulting in delayed or uncoordinated vehicle behavior.

[0006] Currently, various time synchronization methods exist, but none can effectively solve the aforementioned problems. For example, one method uses a P-Box as the clock source, utilizing a 1-second synchronization pulse signal (PPS) from GNSS output and a GPRMC standard time synchronization message output via serial port. Upon receiving the PPS second pulse signal, the MDC resets the millisecond and smaller times in its internal system time (based on a crystal oscillator) to zero and begins calculating millisecond times. Upon receiving GPRMC data, it extracts the hour, minute, second, year, month, and day UTC times from the message, extracts the time (tx) used to parse the received second pulse into the GPRMC UTC time, adds it to the UTC whole second time, and synchronizes it to the system time. The same process is repeated every second, ensuring accurate calibration. However, this method completely fails in extreme scenarios. When GNSS signals are blocked (approximately 20% of daily road conditions involve urban canyons and tunnels), the time synchronization accuracy may fluctuate, affecting the accuracy of multi-source fusion. Furthermore, this method relies on a single GNSS source, making it vulnerable to spoofing attacks (such as fake satellite signals), and it lacks time source validity verification. Abnormal GNSS time will directly cause full-link synchronization chaos, and it has no anti-interference capability.

[0007] For example, a dual-source redundancy approach using GNSS + NTP might be employed, but without a dual-source time matching mechanism. The T-BOX simultaneously connects to the GNSS module to parse satellite time and an NTP server, randomly selecting one source to synchronize to the MDC upon power-up, or switching to NTP when the GNSS signal is weak. However, this method lacks a dual-source matching mechanism. If the time acquired by NTP and GNSS is inconsistent, the conflicting time will be synchronized to the intelligent driving domain controller, causing sensor timestamp jumps, data fusion failures or degradation, and a source-end time conflict problem. Furthermore, the dynamic switching between GNSS and NTP immediately replaces the RTC time, causing the lidar point cloud time to precede the camera image time, preventing the algorithm from aligning the data and even triggering a degradation of intelligent driving functions, resulting in severe switching jumps.

[0008] Therefore, in order to meet the stringent requirements of high-level intelligent driving systems in terms of full-scenario, high real-time, and high reliability, it is urgent to build a full-link time synchronization system that can take into account high precision, strong robustness, and close adaptation to the actual hardware architecture under different operating conditions. Summary of the Invention

[0009] In view of the shortcomings of the prior art, the present invention provides a multi-source redundant time synchronization method, system and application for intelligent driving system, which can achieve time synchronization effect of continuous time in all scenarios, high precision and no jump / conflict at the source end.

[0010] To achieve the above and related objectives, the present invention adopts the following technical solution:

[0011] The first aspect of this invention provides a method for multi-source redundancy time synchronization in an intelligent driving system, comprising the following steps:

[0012] Step S100: Construct a three-level redundant time source arranged in descending order of priority, wherein the first-level source is a national-level NTP time source, the second-level source is a global navigation satellite system time source, and the third-level source is a power-down time backup source based on non-volatile memory.

[0013] Step S200: After the intelligent driving system is powered on, the validity of the time source is detected according to the priority order, and a dual-source matching operation is performed. When both the primary source and the secondary source are valid and the time difference between them is within the preset tolerance range, the valid time source with the highest priority is selected as the main time source, and the main time source is locked and not switched during the power-on cycle.

[0014] Step S300: Based on the time master source, the T-BOX is used as the master clock. The high-precision time synchronization full link is established directly with the intelligent driving domain controller through the end-to-end direct connection synchronization mechanism, bypassing the area controller.

[0015] In step S400, after the intelligent driving system is powered down, the synchronization time of the intelligent driving domain controller is written into a non-volatile memory so as to maintain the continuity of system time based on the tertiary source when both the primary and secondary sources fail.

[0016] Furthermore, in step S200, detecting the validity of the time source according to priority order includes:

[0017] The validity of a Level 1 source is detected and determined, including: in scenarios with cellular network connectivity, establishing a secure encrypted channel to communicate with the National Time Service Center, and comprehensively determining the validity of the Level 1 source based on the response to the time synchronization request and whether its deviation from the local clock meets preset standards.

[0018] Furthermore, in step S200, detecting the validity of the time source according to priority order includes:

[0019] The effectiveness detection and determination of secondary sources includes: in scenarios without network connectivity, evaluating key indicators of global navigation satellite signals to determine whether they meet the criteria for being an effective time synchronization source, and comprehensively judging the effectiveness of secondary sources. Key indicators include the number of visible global navigation satellites, satellite type composition, positioning accuracy, and time calculation accuracy.

[0020] Furthermore, in step S200, detecting the validity of the time source according to priority order includes:

[0021] The effectiveness detection and determination of the Level 3 source includes: in the scenario where both the Level 1 and Level 2 sources fail, after the intelligent driving domain controller is powered on, it reads the power-down time stored in the non-volatile memory, verifies the data integrity by CRC16 check code, compares it with the current time of the local RTC, and determines whether to enable the Level 3 source to maintain time continuity based on the relationship between the stored power-down time and the current time of the local RTC.

[0022] Furthermore, in step S300, establishing a high-precision time synchronization end-to-end includes:

[0023] Using T-BOX as the gPTP master clock node, the intelligent driving domain controller, acting as a slave node, calculates and compensates for link delay by periodically sending Sync frames, thereby achieving high-precision time synchronization between the master and slave nodes and maintaining time stability in the event of synchronization anomalies.

[0024] Furthermore, in step S300, establishing a high-precision time synchronization end-to-end also includes:

[0025] The intelligent driving domain controller periodically sends synchronization frames containing high-precision timestamps to the SOC, driving the SOC to make micro-step adjustments to its local clock, thereby achieving microsecond-level time synchronization between the two and ensuring application layer timing consistency.

[0026] Furthermore, step 300, establishing a high-precision time synchronization end-to-end also includes:

[0027] The intelligent driving domain controller adaptively selects a synchronization strategy based on the downstream devices' support for the precise time protocol: for downstream devices that support the precise time protocol, the protocol is used for hardware-level timestamp alignment; for downstream devices that do not support the precise time protocol, a method based on the average of the hardware trigger signal and the timestamp returned by the device is used to complete time synchronization with the downstream devices.

[0028] A second aspect of the present invention provides a multi-source redundant time synchronization system for an intelligent driving system, comprising:

[0029] The module is used to build a three-level redundant time source arranged in descending order of priority. The first-level source is a national-level NTP time source, the second-level source is a global navigation satellite system time source, and the third-level source is a power-down time backup source based on non-volatile memory.

[0030] The matching and locking module is used to detect the validity of time sources according to priority order after the intelligent driving system is powered on, and to perform dual-source matching operation. When both the primary source and the secondary source are valid and their time deviation is within the preset tolerance range, the valid time source with the highest priority is selected as the main time source, and the main time source is locked and not switched during the power-on cycle.

[0031] The end-to-end direct connection synchronization module is used to bypass the area controller and directly establish a high-precision time synchronization full link with the intelligent driving domain controller based on the time master source, with T-BOX as the master clock, through the end-to-end direct connection synchronization mechanism.

[0032] The protection module is used to write the synchronization time of the intelligent driving domain controller into non-volatile memory after the intelligent driving system is powered off, so as to maintain the continuity of system time based on the tertiary source when both the primary and secondary sources fail.

[0033] A third aspect of the present invention provides a computer-readable storage medium storing computer-readable instructions thereon, which, when executed by a computer's processor, cause the computer to perform the aforementioned multi-source redundant time synchronization method for intelligent driving systems.

[0034] A fourth aspect of the present invention provides a computer device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the above-described intelligent driving system multi-source redundancy time synchronization method.

[0035] The beneficial technical effects of this invention are as follows:

[0036] This invention constructs a three-level redundant time source, which can ensure that the intelligent driving system has a usable time reference in all scenarios, fundamentally solving the problem of system time interruption or failure caused by a single time source due to signal loss, failure or interference.

[0037] This invention uses dual-source matching operation and single-cycle locking to select the highest priority valid time source as the main time source only when both the primary and secondary sources are valid and their time deviation is within a preset tolerance range. The main time source is locked and not switched during the power-on cycle, thereby eliminating time jumps and conflicts and ensuring the monotonicity and consistency of the timestamp.

[0038] This invention uses an end-to-end direct connection synchronization mechanism to bypass the area controller and directly establish a high-precision time synchronization full link with the intelligent driving domain controller. This eliminates the need for area controller forwarding, achieves microsecond-level end-to-end synchronization accuracy, and improves the upper limit of system performance.

[0039] This invention uses a three-stage source to increase the power-off time as a fallback, so as to maintain time continuity when both the primary and secondary sources fail.

[0040] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description

[0041] The accompanying drawings, incorporated in and forming part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application. It is obvious that the drawings described below are merely some embodiments of this application, and those skilled in the art can obtain other drawings based on these drawings without inventive effort. In the drawings:

[0042] Figure 1 is a flowchart of the multi-source redundancy time synchronization method of the intelligent driving system of this application;

[0043] Figure 2 is a diagram of the overall logical architecture of the method in this application;

[0044] Figure 3 is a flowchart of the effectiveness detection of the three-level redundancy time source in this application;

[0045] Figure 4 is a diagram of the time synchronization process inside and outside the intelligent driving domain control in this application;

[0046] Figure 5 is a framework diagram of the multi-source redundant time synchronization system of the intelligent driving system of this application;

[0047] Figure 6 shows a schematic diagram of the structure of a computer system suitable for an embodiment of the present application. Detailed Implementation

[0048] Unless otherwise defined, all technical and / or scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. It should be understood that certain features of the invention (described in the context of separate embodiments for clarity) may also be provided in a single embodiment. Conversely, multiple features of the invention (described in the context of a single embodiment for brevity) may also be provided separately or in any suitable combination or, where appropriate, in any other described embodiment of the invention. Certain features described in the context of various embodiments will not be considered essential features of those embodiments unless the embodiment is inoperable without those elements. The invention is further illustrated below by specific examples; however, it should be noted that the specific process conditions and results described in the embodiments of the invention are merely illustrative and should not be construed as limiting the scope of protection of the invention. All equivalent changes or modifications made in accordance with the spirit and essence of the invention should be covered within the scope of protection of the invention.

[0049] Please refer to Figure 1, which is a flowchart of the multi-source redundancy time synchronization method for the intelligent driving system of this application, and is described in detail below:

[0050] Step S100: Construct a three-level redundant time source arranged in descending order of priority. The first-level source is a national-level NTP time source, the second-level source is a global navigation satellite system time source, and the third-level source is a power-down time backup source based on non-volatile memory.

[0051] Specifically, the hardware carrier of the primary source in this application is: a vehicle-grade 4G / 5G module (such as Qualcomm MDM9206) built into the T-BOX, supporting cellular network communication; and an integrated security chip (such as Huada HC32L136) storing national cryptographic SM2 / SM4 keys to ensure encrypted communication. The hardware carrier of the secondary source is: a Beidou-3 / GPS dual-mode chip (vehicle-grade, supporting multipath interference resistance) integrated into the T-BOX, and an external active ceramic antenna (gain ≥28dB) to ensure signal reception stability in urban canyon scenarios. The hardware carrier of the tertiary source is: a vehicle-grade EEPROM built into the intelligent driving domain controller MDC, specifically storing power-off timestamps; and the RTC module of the MDC main chip.

[0052] Step S200: After the intelligent driving system is powered on, the validity of the time source is detected according to the priority order, and a dual-source matching operation is performed. When both the primary source and the secondary source are valid and the time difference between them is within the preset tolerance range, the valid time source with the highest priority is selected as the main time source, and the main time source is locked and not switched during the power-on cycle.

[0053] Specifically, referring to Figure 3, this application detects the effectiveness of time sources according to priority order, including:

[0054] 1. The validity detection and determination of the primary source includes: in scenarios with cellular network connectivity, establishing a secure encrypted channel to communicate with the National Time Service Center, and comprehensively determining the validity of the primary source based on the response result of the time synchronization request and whether its deviation from the local clock meets preset standards. For example, the detailed process of primary source validity detection and determination is as follows:

[0055] 1.1) After the vehicle is powered on, the T-BOX first initiates a connection with the Beidou Time Service Center NTP server through the 4G / 5G network, establishes an encrypted channel using the TLS1.3 protocol, verifies the server's identity using the SM2 algorithm to prevent man-in-the-middle attacks, and encrypts the time data using the SM4 algorithm to prevent tampering.

[0056] 1.2) Initial synchronization: Send an NTPv4 request frame (containing local RTC coarse time), the server returns a response frame containing "standard UTC time + transmission delay compensation value", T-BOX parses and calibrates the local hardware clock, where a deviation ≤ 50ms is considered valid.

[0057] 1.3) Periodic calibration: A calibration request is sent every 30 seconds. The synchronization results of five consecutive times are processed by sliding window filtering to eliminate single outliers. Then, the average deviation (≤10ms) is calculated and the local clock is finely adjusted to avoid frequent jumps.

[0058] 1.4) Validity Determination: If three consecutive synchronization failures occur (e.g., network interruption, server unresponsiveness), the primary source is marked as invalid, and the current time remains unchanged (without switching to other sources, only waiting for the next power-on retest). If the network is connected, security authentication is successful, and the single synchronization deviation is ≤50ms, the primary source is marked as valid.

[0059] 2. The effectiveness of secondary sources is detected and determined, including: in scenarios without network connectivity, evaluating key indicators of Global Navigation Satellite (GNSS) signals to determine whether they meet the criteria for a valid timing source, thus comprehensively assessing the effectiveness of the secondary source. Key indicators include the number of visible GNSS satellites, satellite type composition, positioning accuracy, and time resolution accuracy. For example, the detailed process for detecting and determining the effectiveness of secondary sources is as follows:

[0060] 2.1) When there is no network upon power-on, such as when the 4G / 5G signal strength is <-100dBm, the T-BOX will automatically start the GNSS module. The cold start time is ≤30s and the warm start time is ≤5s.

[0061] 2.2) Signal validity determination: if the number of visible satellites within 10 consecutive seconds is ≥4 (≥2 for BeiDou and ≥2 for GPS), and the positioning accuracy is ≤10m and the time calculation accuracy is ≤1μs (in static cases, atmospheric delay is compensated by ephemeris data), it is considered valid.

[0062] 2.3) Time resolution and synchronization: The GNSS chip outputs UTC time, which is read by the T-BOX through the UART interface to calibrate the local clock.

[0063] 2.4) If the number of satellites is less than 4 and the time lasts for 1 minute, only the current time is recorded, and the synchronized local clock remains unchanged.

[0064] 3. The validity detection and determination of the Level 3 source includes: In scenarios where both Level 1 and Level 2 sources fail, after the intelligent driving domain controller powers on, it reads the power-down time stored in the non-volatile memory. After verifying the data integrity using a CRC16 checksum, it compares the data with the current time of the local RTC. Based on the relationship between the stored power-down time and the current time of the local RTC, it determines whether to enable the Level 3 source to maintain time continuity. For example, the detailed process for Level 3 source validity detection and determination is as follows:

[0065] 3.1) Power-off time storage: When the vehicle is powered off normally, the MDC triggers an interrupt, reads the current synchronized time, adds a checksum, and writes it to the specified address of the EEPROM.

[0066] 3.2) Power-on reading and verification: When both the primary and secondary sources fail, the MDC reads the time stored in the EEPROM after power-on, first verifies the CRC16 checksum to confirm that the data has not been tampered with, and then compares it with the current time of the local RTC.

[0067] 3.3) Time initialization: If the storage time is greater than the RTC time, the RTC is calibrated using the storage time; if the storage time is less than the RTC time, the RTC time is retained to avoid time reversal, and the third-level source exception log is marked.

[0068] 3.4) Backup cycle: When relying on a level 3 source, MDC records the RTC drift amount once per hour. The drift amount is the difference between the drift amount and the power-off time.

[0069] Specifically, when both the primary and secondary sources are deemed valid, a dual-source matching operation is triggered. The T-BOX simultaneously acquires the UTC times of both primary and secondary sources and calculates their time deviation. The preset tolerance range is adjusted according to system accuracy requirements, such as ≤10ms. If the deviation is ≤10ms, the dual-source matching is successful; if the deviation is >10ms, the dual-source matching fails. In this case, a log is recorded, the primary source is not switched, and the currently locked time source is maintained or degraded mode is entered.

[0070] Specifically, if the two sources match successfully, the time source with higher priority is selected as the main time source between the primary source and the secondary source. If the primary source is valid and the two sources match successfully, the primary source is the primary source; if the primary source fails but the secondary source is valid, the secondary source is the secondary source.

[0071] Specifically, this application avoids time source switching jumps from the root by using dual-source matching operations and single-cycle locking of a unique time source, thus solving the problem of timestamp reversal caused by dynamic switching in the prior art.

[0072] In step S300, based on the time master source, the T-BOX is used as the master clock. Through an end-to-end direct connection synchronization mechanism, the area controller is bypassed, and a high-precision time synchronization full link is directly established with the intelligent driving domain controller.

[0073] Specifically, this application constructs an end-to-end direct synchronous link from T-BOX to MDC, utilizing a high-precision time synchronization protocol (gPTP / IEEE 802.1AS) and hardware-level timestamps (Ethernet physical layer embedded timestamps) to compress the time deviation of the entire link to the microsecond level.

[0074] Specifically, referring to Figure 2, the T-BOX of this application serves as the time source access core, connecting to a national-level NTP server via a 4G / 5G module and receiving satellite signals via a GNSS chip; the MDC serves as the synchronization control core, with a built-in automotive-grade EEPROM storing the power-down time, and directly synchronizing with the T-BOX, sensors, and area controller via the gPTP protocol.

[0075] Specifically, referring to Figure 2, the high-precision time synchronization end-to-end link established in this application includes:

[0076] (1) T-BOX→MDC: Using T-BOX as the gPTP master clock node, Sync frames are periodically sent to enable the intelligent driving domain controller as a slave node to calculate and compensate for the link delay, thereby achieving high-precision time synchronization between the master and slave nodes and maintaining time stability in case of synchronization failure. For example, the detailed process is as follows:

[0077] The T-BOX acts as the in-vehicle time master node (Grandmaster), and the MDC acts as the slave node (Slave). They are connected via in-vehicle Ethernet and support the IEEE 802.1AS (gPTP) protocol.

[0078] The master node T-BOX sends a Sync frame every 1ms;

[0079] When receiving Sync frames from node MDC, the local reception time is recorded and the link delay is calculated.

[0080] MDC fine-tunes the local RTC to avoid jumps based on master node time and link latency compensation.

[0081] If no Sync frames are received for 10 consecutive times, MDC will maintain the current time, mark "T-BOX Synchronization Interruption" in the log, and will not switch sources.

[0082] (2) Within the MDC: The intelligent driving domain controller periodically sends synchronization frames containing high-precision timestamps to the SOC, driving the SOC to make micro-step adjustments to its local clock, completing microsecond-level time synchronization between the two and ensuring application layer timing consistency. For example, the detailed process is as follows:

[0083] The MCU and SOC in the MDC are connected via an SPI bus, with the SOC acting as an SPI slave and the MCU acting as a master.

[0084] The MCU generates an "internal synchronization frame" (containing the MCU's current timestamp and lock source identifier) ​​every 100μs and sends it to the SOC via SPI.

[0085] After receiving the data, the SOC parses the timestamp, compares it with the local clock, and calculates the deviation.

[0086] The SOC calibrates the local clock step by step by fine-tuning the crystal oscillator frequency, ensuring that the deviation converges to ≤1μs within 1 second, thus avoiding time reversal.

[0087] The AI ​​perception algorithm of the SOC and the control logic on the MCU both mark the data with synchronized timestamps to ensure that the perception results are consistent with the timing of the control commands.

[0088] (3) MDC → Downstream Devices: In multi-protocol compatible synchronization scenarios, the intelligent driving domain controller adaptively selects a synchronization strategy based on the downstream device's support for the precise time protocol: for downstream devices that support the precise time protocol, the protocol is used for hardware-level timestamp alignment; for downstream devices that do not support the precise time protocol, the average value of the hardware trigger signal and the device's returned timestamp is used to complete time synchronization with the downstream device.

[0089] Referring to Figure 4, this application uses the gPTP protocol for time synchronization within the MDC. Sensors outside the domain controller that support gPTP are also synchronized using the gPTP protocol. The IMU uses the CAN protocol for time synchronization. The MCU triggers camera exposure via the PSS signal and records the time the image arrives at the MCU. For example, the detailed process is as follows:

[0090] Scenario 1: The device MDC supporting gPTP acts as the master node within the domain, and downstream devices act as slave nodes, directly connected via vehicle Ethernet.

[0091] A Sync frame is sent every 250μs, containing a timestamp after MDC synchronization;

[0092] After receiving the data, the device records the reception time using a hardware timestamp (triggered by the PHY layer), compensates for link delay, and then calibrates the local clock with a deviation of ≤10μs.

[0093] Scenario 2: For devices that do not support gPTP (such as cameras), a hybrid method of hardware triggering and timestamp marking is used. The MDC sends a synchronization pulse (triggered on rising edge) every 10ms through the GPIO interface and records the timestamp Tg sent by the GPIO; the MCD records the timestamp Tp returned by the camera, and (Tg+Tp) / 2 is used as the camera exposure time.

[0094] In step S400, after the intelligent driving system is powered down, the synchronization time of the intelligent driving domain controller is written into a non-volatile memory so as to maintain the continuity of system time based on the tertiary source when both the primary and secondary sources fail.

[0095] Please refer to Figure 5, which is a framework diagram of the multi-source redundant time synchronization system 500 for intelligent driving system of this application, including:

[0096] Module 510 is used to construct a three-level redundant time source arranged in descending order of priority. The first-level source is a national-level NTP time source, the second-level source is a global navigation satellite system time source, and the third-level source is a power-down time backup source based on non-volatile memory.

[0097] The matching and locking module 520 is used to detect the validity of the time source according to the priority order after the intelligent driving system is powered on, and to perform dual-source matching operation. When both the primary source and the secondary source are valid and the time difference between them is within the preset tolerance range, the valid time source with the highest priority is selected as the main time source, and the main time source is locked and not switched during the power-on cycle.

[0098] The end-to-end direct connection synchronization module 530 is used to bypass the area controller and directly establish a high-precision time synchronization full link with the intelligent driving domain controller based on the time master source, with T-BOX as the master clock, through the end-to-end direct connection synchronization mechanism.

[0099] The protection module 540 is used to write the synchronization time of the intelligent driving domain controller into a non-volatile memory after the intelligent driving system is powered down, so as to maintain the continuity of system time based on the tertiary source when both the primary and secondary sources fail.

[0100] Specifically, each time the vehicle is powered on, the matching and locking module 520 automatically operates, first detecting the validity of the primary source; if the primary source is invalid, it detects the validity of the secondary source; if both the primary and secondary sources are determined to be invalid, it initiates the detection of the validity of the tertiary source. When both the primary and secondary sources are detected to be valid, a dual-source matching operation is performed. If the matching is successful, the highest priority source among the valid sources is selected as the primary timing source; if the matching fails, the secondary source is selected as the primary timing source. Once the primary timing source is selected, a single-cycle locking is performed.

[0101] Specifically, the end-to-end direct synchronization module 530 starts immediately after the matching and locking module 520 determines the timing master source and continues to run until power-off. The protection module 540 is executed before the system power is cut off during each normal vehicle power-off process.

[0102] Specifically, the intelligent driving system of this application relies solely on the internal crystal oscillator time for time synchronization to avoid the influence of external time jumps. However, the internal crystal oscillator time is aligned with the T-BOX time in real time, which facilitates troubleshooting.

[0103] It should be noted that the intelligent driving system multi-source redundancy time synchronization system provided in the above embodiments and the intelligent driving system multi-source redundancy time synchronization method provided in the above embodiments belong to the same concept. The specific methods of operation of each module and unit have been described in detail in the method embodiments and will not be repeated here. In practical applications, the intelligent driving system multi-source redundancy time synchronization system provided in the above embodiments can be assigned to different functional modules as needed, that is, the internal structure of the system can be divided into different functional modules to complete all or part of the functions described above. This is not a limitation here.

[0104] Embodiments of this application also provide a computer device, including: one or more processors; and a storage device for storing one or more programs, which, when executed by the one or more processors, cause the computer device to implement the multi-source redundancy time synchronization method for intelligent driving systems provided in the above embodiments.

[0105] Figure 6 shows a schematic diagram of the structure of a computer system suitable for an embodiment of this application. It should be noted that the computer system 600 of the electronic device shown in Figure 6 is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.

[0106] As shown in Figure 6, the computer system 600 includes a central processing unit (CPU) 601, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage section 608 into a random access memory (RAM) 603, such as executing the methods described in the above embodiments. The RAM 603 also stores various programs and data required for system operation. The CPU 601, ROM 602, and RAM 603 are interconnected via a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604. The following components are connected to the I / O interface 605: an input section 606 including a keyboard, mouse, etc.; an output section 607 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and speakers, etc.; a storage section 608 including a hard disk, etc.; and a communication section 609 including a network interface card such as a LAN (local area network) card, modem, etc. The communication section 609 performs communication processing via a network such as the Internet. A driver 610 is also connected to the I / O interface 605 as needed. Removable media 611, such as disks, optical discs, magneto-optical discs, semiconductor memories, etc., are installed on drive 610 as needed so that computer programs read from them can be installed into storage section 608 as needed.

[0107] Specifically, according to embodiments of this application, the processes described above with reference to the flowcharts can be implemented as computer tool programs. For example, embodiments of this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program including a computer program for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 609, and / or installed from removable medium 611. When the computer program is executed by central processing unit (CPU) 601, it performs various functions defined in the system of this application.

[0108] It should be noted that the computer-readable medium shown in the embodiments of this application can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory, a read-only memory, an erasable programmable read-only memory, flash memory, an optical fiber, a portable compact disk read-only memory, an optical storage device, a magnetic storage device, or any suitable combination thereof. In this application, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying a computer-readable computer program. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. Computer programs contained on computer-readable media can be transmitted using any suitable medium, including but not limited to wireless, wired, etc., or any suitable combination thereof.

[0109] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. Each block in a flowchart or block diagram may represent a module, segment, or portion of code, which contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0110] The units described in the embodiments of this application can be implemented by tools or by hardware, and the described units can also be located in a processor. The names of these units do not necessarily limit the unit itself.

[0111] Another aspect of this application provides a computer-readable storage medium storing a computer program thereon, which, when executed by a computer's processor, causes the computer to perform the multi-source redundancy time synchronization method for intelligent driving systems as described above. This computer-readable storage medium may be included in the computer device described in the above embodiments, or it may exist independently and not assembled into the computer device.

[0112] Another aspect of this application provides a computer program product or computer program including computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the multi-source redundancy time synchronization method for intelligent driving systems provided in the various embodiments described above.

[0113] The above embodiments are merely illustrative of the principles and effects of the present invention and are not intended to limit the invention. Any person skilled in the art can modify or alter the above embodiments without departing from the spirit and scope of the present invention. Therefore, all equivalent modifications or alterations made by those skilled in the art without departing from the spirit and technical concept disclosed in the present invention should still be covered by the claims of the present invention.

Claims

1. A method for multi-source redundant time synchronization in an intelligent driving system, characterized in that, Includes the following steps: Step S100: Construct a three-level redundant time source arranged in descending priority order, wherein the first-level source is a national-level NTP time source, the second-level source is a global navigation satellite system time source, and the third-level source is a power-off time backup source based on non-volatile memory; Step S200: After the intelligent driving system is powered on, the validity of the time sources is detected according to the priority order, and a dual-source matching operation is performed. When both the first-level and second-level sources are valid and their time deviation is within a preset tolerance range, the valid time source with the highest priority is selected as the primary time source, and the primary time source is locked and not switched during the power-on cycle; Step S300: Based on the primary time source, the T-BOX is used as the master clock, and a high-precision time synchronization link is established directly with the intelligent driving domain controller through an end-to-end direct connection synchronization mechanism, bypassing the area controller; Step S400: After the intelligent driving system is powered off, the synchronization time of the intelligent driving domain controller is written into the non-volatile memory so that the continuity of system time is maintained based on the third-level source when both the first-level and second-level sources fail.

2. The time synchronization method according to claim 1, characterized in that, In step S200, detecting the validity of the time source according to the priority order includes: detecting and determining the validity of the primary source, including: in a scenario with cellular network connectivity, establishing a secure encrypted channel to communicate with the National Time Service Center, and comprehensively determining the validity of the primary source based on the response result of the time synchronization request and whether its deviation from the local clock meets a preset standard.

3. The time synchronization method according to claim 1, characterized in that, In step S200, detecting the validity of the time source according to the priority order includes: detecting and determining the validity of the secondary source, including: in a scenario without network connection, judging whether the key indicators of the global navigation satellite signal meet the criteria for being a valid time source by evaluating them, and comprehensively judging the validity of the secondary source. The key indicators include the number of visible global navigation satellites, satellite type composition, positioning accuracy, and time calculation accuracy.

4. The time synchronization method according to claim 1, characterized in that, In step S200, detecting the validity of the time source according to the priority order includes: detecting and determining the validity of the third-level source, including: in the scenario where both the first-level source and the second-level source fail, after the intelligent driving domain controller is powered on, it reads the power-down time stored in the non-volatile memory, verifies the data integrity by CRC16 check code, compares it with the current time of the local RTC, and determines whether to enable the third-level source to maintain time continuity based on the relationship between the stored power-down time and the current time of the local RTC.

5. The time synchronization method according to claim 1, characterized in that, In step S300, establishing a high-precision time synchronization full link includes: using the T-BOX as the gPTP master clock node, periodically sending Sync frames to enable the intelligent driving domain controller as a slave node to calculate and compensate for the link delay, thereby completing high-precision time synchronization between the master and slave nodes, and maintaining time stability in the event of synchronization anomalies.

6. The time synchronization method according to claim 5, characterized in that, In step S300, establishing a high-precision time synchronization full link further includes: periodically sending synchronization frames containing high-precision timestamps to the SOC through the intelligent driving domain controller, driving the SOC to make micro-step adjustments to its local clock, completing microsecond-level time synchronization between the two and ensuring consistent application layer timing.

7. The time synchronization method according to claim 6, characterized in that, In step S300, establishing a high-precision time synchronization full link further includes: the intelligent driving domain controller adaptively selects a synchronization strategy based on the downstream device's support for the precise time protocol: for downstream devices that support the precise time protocol, the protocol is used for hardware-level timestamp alignment; for downstream devices that do not support the precise time protocol, a calculation method based on the average value of the hardware trigger signal and the device's returned timestamp is used to complete time synchronization with the downstream device.

8. A multi-source redundant time synchronization system for an intelligent driving system, characterized in that, include: The module is used to build a three-level redundant time source arranged in descending order of priority. The first-level source is a national-level NTP time source, the second-level source is a global navigation satellite system time source, and the third-level source is a power-down time backup source based on non-volatile memory. The matching and locking module is used to detect the validity of time sources according to the priority order after the intelligent driving system is powered on, and to perform a dual-source matching operation. When both the primary source and the secondary source are valid and their time deviation is within a preset tolerance range, the valid time source with the highest priority is selected as the main time source, and the main time source is locked and not switched during the power-on cycle. The end-to-end direct connection synchronization module is used to establish a high-precision time synchronization link directly with the intelligent driving domain controller based on the main time source, using T-BOX as the master clock, bypassing the area controller through the end-to-end direct connection synchronization mechanism. The guarantee module is used to write the synchronization time of the intelligent driving domain controller into a non-volatile memory after the intelligent driving system is powered off, so as to maintain the continuity of system time based on the tertiary source when both the primary source and the secondary source fail.

9. A computer-readable storage medium, characterized in that, It stores computer-readable instructions, which, when executed by the computer's processor, cause the computer to perform the multi-source redundancy time synchronization method for the intelligent driving system as described in any one of claims 1 to 7.

10. A computer device, comprising: A memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, when the processor executes the computer program, it implements the steps of the multi-source redundancy time synchronization method for an intelligent driving system as described in any one of claims 1 to 7.