Method and device for controlling display of vehicle

By detecting faults in the vehicle display controller and utilizing a partitioning mechanism and a backup rendering module, the problem of frequent screen blackouts was solved, improving the availability of the display and vehicle safety.

CN121996481APending Publication Date: 2026-05-08BOSCH AUTOMOTIVE PRODUCTS (SUZHOU) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BOSCH AUTOMOTIVE PRODUCTS (SUZHOU) CO LTD
Filing Date
2024-11-08
Publication Date
2026-05-08

AI Technical Summary

Technical Problem

The frequent blackouts of vehicle displays can distract drivers and pose a potential safety hazard; current technology struggles to effectively prevent this problem.

Method used

By detecting internal faults in the display controller, a partitioning mechanism and memory management unit are used to allocate dedicated resources. A backup rendering module and a monitor are used to perform corresponding operations based on the fault type, thus avoiding frequent blackouts of the display.

Benefits of technology

It improves display usability, reduces blackout periods, enhances the driving experience, and improves vehicle safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121996481A_ABST
    Figure CN121996481A_ABST
Patent Text Reader

Abstract

The invention relates to a method performed by a display controller of a vehicle. The method includes: detecting a fault associated with a display occurring inside the display controller; and triggering an operation corresponding to the type of the fault for maintaining a display connected to the display controller in a display state based on the detected type of the fault. The invention also relates to an apparatus for controlling a display of a vehicle, the apparatus comprising one or more monitors configured to: detect a fault associated with the display occurring inside the apparatus; and triggering an operation for maintaining a display connected to the device in a display state corresponding to the type of the fault based on the detected type of the fault.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] In general, the present invention relates to vehicles, and more specifically, to an apparatus, method, and computer-readable medium for controlling a display of a vehicle. Background Technology

[0002] Transportation tools broadly include vehicles, airplanes, ships, etc. In daily life, vehicles are the primary mode of transportation used for travel. Vehicle safety is a crucial indicator of vehicle performance. Automotive safety refers to the performance of a vehicle in avoiding accidents and ensuring the safety of pedestrians and passengers while in motion. The human-machine interface (HMI) between the vehicle and the driver is an important aspect of ensuring vehicle safety.

[0003] With the development of autonomous driving, higher demands are being placed on vehicle safety. For example, displaying safety-related HMI content (e.g., warnings or status indicator lights) on the vehicle's dashboard display can alert the driver to potential safety issues at any given moment. However, different components of the vehicle may have varying safety requirements; therefore, there is a need for further improvements to the control methods and devices used for vehicle displays. Summary of the Invention

[0004] Vehicle safety-related display mechanisms can be affected by malfunctions in the control unit that outputs HMI content. In some cases, when the control unit outputting HMI content malfunctions, the vehicle's display system enters a safety state; for example, the instrument panel display or other displays will go black to alert the driver of a vehicle malfunction. However, frequent blackouts can alter the driving environment, distract the driver, and potentially lead to other safety issues. This invention aims to provide an improved technical solution that detects display-related malfunctions and triggers corresponding operations based on the type of malfunction detected, thereby preventing frequent blackouts of displays (e.g., instrument panel displays). This improves the user's driving experience, avoids display unavailability caused by blackouts, improves display availability, and further enhances vehicle safety.

[0005] Some aspects of the present invention provide a method performed by a display controller of a vehicle, the method comprising: detecting a display-related fault occurring within the display controller; and, based on the type of the detected fault, triggering an operation corresponding to the type of fault for maintaining a display connected to the display controller in a display state.

[0006] Some aspects of the present invention provide an apparatus for controlling a display of a vehicle, the apparatus including one or more monitors, one or more of which are configured to: detect a display-related fault occurring within the apparatus; and, based on the type of the detected fault, trigger an operation corresponding to the type of fault for maintaining the display connected to the apparatus in a display state.

[0007] Some aspects of the present invention provide a computer-readable medium storing computer-executable instructions that, when executed, cause one or more processors to perform the following operations: detect a display-related fault occurring within a display controller; and, based on the type of the detected fault, trigger operations corresponding to the type of fault to maintain a display connected to the display controller in a display state.

[0008] Some aspects of the present invention provide a method performed by a display controller of a vehicle, the method comprising: applying a partition mechanism to at least one of a rendering module or a verification module located within a control unit of the display controller, wherein the partition mechanism includes at least one of: allocating dedicated central processing unit (CPU) bandwidth to at least one of the rendering module and the verification module; and applying a memory management unit (MMU) to allocate storage resources to at least one of the rendering module and the verification module, wherein the storage resources are configured to store security-related information.

[0009] Some aspects of the present invention provide an apparatus for controlling a display of a vehicle, the apparatus including a control unit configured to: apply a partitioning mechanism to at least one of a rendering module or a verification module located within the control unit of the apparatus, wherein the partitioning mechanism includes at least one of: allocating dedicated CPU bandwidth to at least one of the rendering module and the verification module; and applying a memory management unit to allocate storage resources to at least one of the rendering module and the verification module, wherein the storage resources are configured to store security-related information.

[0010] Some aspects of the present invention provide a computer-readable medium storing computer-executable instructions that, when executed, cause one or more processors to perform the following operations: applying a partitioning mechanism to at least one of a rendering module or a verification module located within a control unit in a display controller, wherein the partitioning mechanism includes at least one of: allocating dedicated CPU bandwidth to at least one of the rendering module and the verification module; and applying a memory management unit to allocate storage resources to at least one of the rendering module and the verification module, wherein the storage resources are configured to store security-related information.

[0011] Some aspects of the present invention provide a computer program product including computer-executable instructions that, when executed, cause one or more processors to perform the following operations: detect a display-related fault occurring within a display controller; and, based on the type of the detected fault, trigger operations corresponding to the type of fault for maintaining a display connected to the display controller in a display state.

[0012] Some aspects of the present invention provide a computer program product including computer-executable instructions that, when executed, cause one or more processors to perform the following operations: applying a partitioning mechanism to at least one of a rendering module or a verification module located within a control unit in a display controller, wherein the partitioning mechanism includes at least one of: allocating dedicated central processing unit bandwidth to at least one of the rendering module and the verification module; and applying a memory management unit to allocate storage resources to at least one of the rendering module and the verification module, wherein the storage resources are configured to store security-related information.

[0013] As generally described herein with reference to the accompanying drawings, and as illustrated by means of the drawings, aspects generally include methods, apparatus, systems, computer-readable media, and processing systems.

[0014] To achieve the foregoing and related objectives, one or more aspects include the features fully described below and those specifically pointed out in the claims. The following description and drawings set forth certain illustrative features of one or more aspects in detail. However, these features are merely indicative of some of the various ways in which the principles of the aspects may be employed, and this specification is intended to include all such aspects and their equivalents. Attached Figure Description

[0015] A more detailed description, briefly summarized above, can be provided by referring to some of the aspects shown in the accompanying drawings, so that the foregoing features of the invention can be understood in detail. However, it should be noted that since other equally effective aspects are permissible under this specification, the drawings illustrate only certain typical aspects of the invention and are therefore not intended to limit its scope.

[0016] Figure 1 According to certain aspects of the invention, an example of a display controller 101 is conceptually shown, comprising a first control unit 102 and a second control unit 106 for optimizing the availability of displays for vehicles.

[0017] Figure 2 An example of a second control unit 206 for optimizing the availability of displays in a vehicle is conceptually shown according to certain aspects of the invention.

[0018] Figure 3 An example of a second control unit 306 for optimizing the availability of displays in a vehicle is conceptually shown according to certain aspects of the invention.

[0019] Figures 4 to 7 According to certain aspects of the invention, a flow chart of a method performed by a display controller for optimizing the availability of displays for vehicles is shown.

[0020] To facilitate understanding, identical reference numerals have been used where possible to designate identical elements that are common to the accompanying drawings. It is anticipated that, in the absence of specific description, elements disclosed in one aspect may be beneficially used in other aspects. Detailed Implementation

[0021] Various aspects of the present invention relate to methods and apparatus for display controllers for vehicles.

[0022] As used herein, the terms “component,” “system,” “unit,” “module,” etc., include computer-related entities such as, but not limited to, hardware, firmware, combinations of hardware and software, software, or software in execution configured to perform a particular operation or function. For example, a component can be, but is not limited to, a process running on a processor, a processor, an object, an executable program, a thread of execution, a program, and / or a computer. By way of illustration, both an application running on a communication device and the communication device itself can be referred to as a component. One or more components may reside within a process and / or a thread of execution, and components may reside on a single processor or core and / or be distributed across two or more processors or cores. Furthermore, these components can be executed from various non-transitory computer-readable media having various instructions and / or data structures stored thereon. Components can communicate via local and / or remote processes, function or procedure calls, electronic signals, data packets, memory read / write, and other known computer, processor, and / or process-related communication methods.

[0023] It is important to note that the term "connected" or "coupled" to one or more elements can mean either a direct connection or coupling with another element, or that there may be other elements between them. If an element is described as being "directly connected" or "directly coupled" to another element, then there are no other elements between them. Other terms used to describe relationships between elements should be interpreted in a similar manner.

[0024] The ordinal numbers such as "first" and "second" described in this invention are merely distinguishing designations for certain elements, and are not intended to limit the order of certain elements or to limit the importance or preference of certain elements. Furthermore, as described herein, terms such as "configured as" or "operable as" can be used interchangeably, and when used, indicate that the entity performing the operation has the capability or ability to perform certain operations, being "configured as" or "operable as".

[0025] The specific embodiments of the present invention will now be described with reference to the accompanying drawings.

[0026] Figure 1 According to certain aspects of the present invention, an example of a display controller 101 for optimizing the availability of displays in a vehicle is conceptually illustrated. The display controller 101 may include a controller for controlling the displays of the vehicle. For example, the display controller 101 may include, but is not limited to, a vehicle's driver information and entertainment head unit (also referred to as a digital cockpit head unit, DHU), or other types of electronic control units (ECUs) or embedded control units (ECUs). In some examples, the display controller 101 may include a first control unit 102 and a second control unit 106, and a controlled display 115 may be connected to the display controller. In some examples, the display 115 may be connected to the display controller 101. In some examples, the display 115 may be connected to the second control unit 106 in the display controller 101. In some examples, the display 115 may include an instrument panel display or other types of displays. Instrument panel displays are typically located near the steering wheel and provide the driver with information necessary for driving, such as vehicle speed, gear position, etc. The instrument panel display may include various types of screens, such as liquid crystal displays (LCDs), plasma displays, touchscreens, etc., and may include one or more additional analog display components, or be divided into areas providing different information. For example, the tachometer and speedometer may be located on one side of the instrument panel display, while gauges such as fuel gauges, engine temperature gauges, battery level gauges, and oil pressure gauges may be located on the other side. Other components may also exist between the second control unit 106 and the display 115, for example, to simplify the drawings, Figure 1 The components such as the serializer and deserializer between the second control unit 106 and the display 115 are not shown.

[0027] The first control unit 102 may include, but is not limited to, a microcontroller unit (MCU), a central processing unit (CPU), or other types of processors, and the second control unit 106 may include, but is not limited to, a system-on-a-chip (SoC), a CPU, or other types of processors. The first control unit 102 or the second control unit 106 may be configured with processor-executable instructions or computer-executable instructions to perform control operations on the vehicle's displays, including operations in various embodiments. The second control unit 106 and the first control unit 102 transmit data to be displayed on the display 115 via a serial peripheral interface (SPI) bus (e.g., SPI bus 1 116 or SPI bus 2 117). For example, the data to be displayed may come from the software component (SWC) 103 in the first control unit 102, including but not limited to information to be displayed on the instrument panel, such as various parameters or information of the vehicle sensed by sensors.

[0028] The first rendering module 108 in the second control unit 106 can receive data to be displayed from the first control unit 102 via the SPI bus 1116, render the data to be displayed on the display 115, and then send the rendered data to the interface module 113. In some examples, the first rendering module 108 may be referred to as the main rendering module. In some examples, the first rendering module 108 may include one or more rendering modules, including but not limited to a cluster application and / or an HMI application. In some examples, the interface module 113 may include but is not limited to Open WFD. The interface module 113 can send the rendered data to the data processing unit (DPU) 114. Although Figure 1 The diagram shows that DPU 114 is located within the second control unit 106, but in some instances, DPU 114 may be located outside the second control unit 106 and connected to the interface module 113. DPU 114 can process the rendered data and send it to the display 115 for display, verify the displayed data to generate a verification result, and send the verification result to the first control unit 102 for confirmation.

[0029] The first control unit 102 can detect whether a fault has occurred within the second control unit 106 in a black-box manner. For example, the first control unit 102 may detect a fault within the second control unit 106, but cannot determine the type of fault. When a fault is detected within the second control unit 106, the first control unit 102 can instruct the vehicle's display system to enter a safe state; for example, the display 115 connected to the second control unit 106 may go into a black screen state to alert the driver to a vehicle malfunction. However, frequent black-screen states of the display 115 can frequently alter the driving environment, distract the driver, and potentially lead to other safety issues.

[0030] In some examples, when the first control unit 102 detects a fault within the second control unit 106, it can trigger a hardware warning light implemented by another electronic control unit or embedded control unit to warn the driver. However, such fault warning methods rely on vehicle-level configuration and require additional hardware costs. Therefore, in some cases, certain vehicle-level designs may not support or recommend such fault warning methods due to cost considerations. Furthermore, the trend of removing hardware warning lights is becoming increasingly apparent in intelligent vehicle systems.

[0031] As described above, the first control unit 102 monitors the output of the second control unit 106 in a black-box manner. Therefore, any fault in the second control unit 106 will trigger the display system to enter a safe state, causing the display 115 to frequently enter a black screen state. For example, even if the fault is resolved quickly, the display 115 will still enter a black screen state during the brief fault period. In this case, it is desirable to further improve the control method and control device for the vehicle's display to avoid the display 115 frequently entering a black screen state when certain types of faults occur, thereby improving the user's driving experience, avoiding display unavailability caused by the black screen state, improving display availability, and further enhancing vehicle safety.

[0032] Continue to refer to Figure 1In some examples, the display controller 101 may include a first control unit 102 and a second control unit 106. The first control unit 102 may detect display-related faults occurring within the second control unit 106. The first control unit 102 may include a first monitor 104. In some examples, the first monitor 104 may include a Safe HMI Monitor or other types of monitors. In some examples, the first monitor 104 may detect display-related faults occurring within the second controller. For example, the first monitor 104 may detect transient hardware faults occurring within the second controller 106 or rendering faults occurring within the first rendering module 108, which is used to render data to be displayed on the display 115, such as various parameters or information of the vehicle sensed by sensors. In some examples, transient hardware faults may include transient faults in the hardware on which related software or modules are installed, or transient faults in the connections between hardware components, such as minor hardware damage or minor poor wiring connections. In some examples, rendering faults may include, for example, damage to the rendering module.

[0033] When a fault associated with the display is detected to be either a transient hardware failure or a rendering failure of the first rendering module 108, the first monitor 104 may trigger an operation corresponding to the aforementioned type of fault to maintain the display 115 in a display state. In some examples, the operation to maintain the display 115 in a display state may include rendering warning data via the second rendering module 112 within the second control unit 106.

[0034] In some examples, the second rendering module 112 may be referred to as a backup rendering module, including but not limited to a Safety Backup HMI App. In some examples, warning data may be sent from the first control unit to the second control unit (e.g., via the SPI bus). The backup rendering module 112 may render the warning data, and the rendered warning data may then be sent to the DPU 114 via the interface module 113, and after processing by the DPU 114, sent to the display 115 for display. In some examples, the warning data may be displayed on the display 115 in the form of images, videos, or text to notify the driver of a malfunction in the display system, for example, to remind the driver that the first rendering module has been damaged. By using the second rendering module to render the warning data, the availability of the display 115 can be optimized by avoiding frequent black screen states when a transient hardware failure occurs within the second control unit 106 or a rendering failure of the first rendering module is detected, without increasing hardware costs.

[0035] Although Figure 1 Only display 115 is depicted, but display controller 101 can also be connected to other displays (not shown) besides display 115 via additional serializers and deserializers, and send warning data to these other displays for display. For example, a second control unit can be connected to other displays (not shown) besides display 115 via additional serializers and deserializers, and send warning data to these other displays for display. In this way, vehicle safety can be improved more effectively.

[0036] In some examples, the first control unit 102 may send warning data to be rendered to the second control unit via SPI bus 2 117. In some examples, the first rendering path associated with the first rendering module 108 and the second rendering path associated with the second rendering module 112 are at least partially decoupled. For example, the first rendering path associated with the first rendering module 108 may include: raw data being sent from SWC 103 to the first rendering module 108 via Integrated Network Communication Transmission Protocol 107 (INC TP); while the second rendering path associated with the second rendering module 112 may include: warning data being sent from the first monitor 104 to the INC scheduler 105, then from the INC scheduler 105 to the INC scheduler 110 via INC TP 107, and then from the INC scheduler 110 to the second rendering module 112. In some examples, the first and second rendering paths may be decoupled only at the application layer. By decoupling the first rendering path from the second rendering path at least partially, warning data can be rendered independently, thereby effectively preventing rendering failures in the first rendering module from interfering with the second rendering module.

[0037] As previously described, DPU 114 can process the rendered data and send it to display 115 for display, verify the displayed data to generate a verification result, and the verification result is finally sent to the first control unit 102 for confirmation. In some examples, the first control unit may include a first monitor 104 and an INC scheduler 105, and the second control unit 106 may include a verification module 109 and an INC transmission protocol 107. In some examples, DPU 114 can generate a verification result (e.g., a Multiple Input Signature Register (MISR) Cyclic Redundancy Check (CRC)) and send it to interface module 113. Interface module 113 can send the verification result to verification module 109, which logically sends the verification result to the first monitor 104 via INC schedulers 110 and 105 and INC transmission protocol (INC TP) 107 for confirmation of the verification result. In some examples, the verification module 109 may include one or more verification modules, including but not limited to at least one of the INC scheduler 110 and the Signature Unit Controller (SUC) 111.

[0038] In some cases, a transient hardware failure may occur within the second controller 106, causing the first monitor 104 to be unable to confirm the verification result in a normal manner. For example, the MISR CRC can be transmitted to the first monitor 104 through relevant modules or software in the second control unit 106 (e.g., interface module 113, verification module 109, etc.). However, a transient hardware failure within the second controller 106 may cause the MISR CRC to be unable to be confirmed by the first monitor 104 for a certain period of time.

[0039] In some examples, a transient hardware failure within the second controller 106 may prevent the first monitor 104 from acknowledging the MISR CRC within the Failure Detection Time Interval (FDTI). If the duration of the failure to acknowledge the MISR CRC exceeds the FDTI, the first monitor 104 may still trigger the display 115 to enter a black screen state to alert the driver of a vehicle malfunction. In some cases, the transient hardware failure may be temporary and recover after a short period. However, even if the transient hardware failure recovers quickly, the display 115 may still enter a black screen state because the duration of the failure to acknowledge the MISR CRC exceeds the FDTI. Therefore, it may be desirable to avoid triggering the display 115 to enter a black screen state based on only a single instance of unacknowledged verification results.

[0040] In some examples, the first monitor 104 can detect display-related faults occurring within the second controller. For example, the first monitor 104 can detect transient hardware faults occurring within the second controller 106. In some examples, transient hardware faults may include transient faults in the hardware on which related software or modules are installed, or transient faults in the connections between hardware components, such as minor hardware damage or minor poor contact in a circuit.

[0041] When a transient hardware failure is detected as the fault associated with the display, the first monitor 104 can trigger operations corresponding to the aforementioned type of fault to maintain the display 115 in a display state. In some examples, when a transient hardware failure is detected as the fault associated with the display, the first monitor 104 can maintain the display 115 in a display state through multiple debounce operations. For example, the first monitor 104 can confirm the verification result (e.g., MISR CRC) by requesting multiple CRC fault confirmations before triggering the display 115 to enter a black screen state. Therefore, in the event that a transient hardware failure causes the first monitor 104 to fail to confirm the verification result within the FDTI, the first monitor 104 can request multiple confirmations of the verification result through multiple debounce operations, thereby avoiding triggering the display 115 to enter a black screen state with only a single unconfirmed verification result.

[0042] Figure 2 According to certain aspects of the invention, an example of a second control unit 206 for optimizing the availability of displays in a vehicle is conceptually illustrated. In some examples, the second control unit 206 may have... Figure 1 The second control unit 106 in the middle has similar, identical or different functions.

[0043] In some examples, the second control unit 206 may be located within the display controller. For simplicity of the accompanying drawings, Figure 2 The display controller is not shown, but it may have the same characteristics as... Figure 1 The display controller 101 shown has similar, identical, or different functions. The second control unit 206 may include a second monitor 218. In some examples, the second monitor 218 may include a safety mechanism monitor. The second monitor 218 can monitor modules within the second control unit 206. For example, at least one module within the second control unit 206 (e.g., rendering module 208, verification module 209, interface module 213, etc.) may first register with the second monitor 218, and then the second monitor 218 can monitor the registered module.

[0044] The second monitor 218 can detect display-related faults occurring within the display controller. In some examples, the second monitor 218 can detect display-related faults occurring within the second control unit 206. In some examples, a fault in a module within the second control unit 206 may include delays or loss of that module. For example, at least one module within the second control unit 206 may be registered to the second monitor and may be performing a security-related task. The second monitor 218 can receive a heartbeat signal associated with that task to ensure that the task is being performed as intended. If a heartbeat signal associated with that task is not received, the second monitor 218 can detect delays or loss of the module performing the task.

[0045] Continue to refer to Figure 2 Upon detecting a fault of the aforementioned type (e.g., module delay or loss), the second monitor 218 can trigger an operation corresponding to that type of fault to maintain the display (not shown for simplicity) in a display state. In some examples, when the second monitor 218 detects a module delay or loss occurring within the second control unit 206, the second monitor 218 can reset the module within a Failure Detection Time Interval (FDTI) to restore normal operation of the module within the FDTI. In this example, if the module resumes normal operation within the FDTI due to being reset, the display will not frequently enter a black screen state due to the module's brief delay or loss, thereby optimizing the display's availability.

[0046] In some examples, the modules registered to the second monitor 218 may include rendering modules or verification modules, etc. In some examples, the rendering module 208 may include, but is not limited to, at least one of a cluster app and an HMI app. In some examples, the verification module may include, but is not limited to, at least one of an INC scheduler 110 and a SUC 111.

[0047] In some examples, after the verification module 209 registers with the second monitor 218, the second monitor 218 can detect delays or loss of verification module 209. For example, delays or loss of verification module 209 during MISR CRC transmission may lead to delays or loss of MISR CRC. If the delay or loss of MISR CRC causes the acknowledgment of MISR CRC to exceed the FDTI, the display may enter a black screen state. In this case, the second monitor 218 can reset the verification module 209 within the FDTI to restore the normal operation of the verification module 209 within the FDTI, thereby preventing the display from frequently entering a black screen state due to brief delays or loss of verification module 209.

[0048] In some examples, after the rendering module 208 registers with the second monitor 218, the second monitor 218 can detect delays or loss of the rendering module 208. For example, during a rendering task, delays or loss of the rendering module 208 may cause delays or stuttering of information on the display. If the delay or loss of the rendering module 208 causes the acknowledgment of the MISR CRC to exceed the FDTI, the display may enter a black screen state. In this case, the second monitor 218 can reset the rendering module 208 within the FDTI to restore normal operation of the rendering module 208 within the FDTI, thereby preventing the display from frequently entering a black screen state due to brief delays or loss of the rendering module 208.

[0049] In some examples, Figure 2 The rendering module 208 depicted may also include multiple rendering modules. In this example, the output of multiple rendering modules may correspond to one or more layers on the display. For example, the first layer may display information necessary for driving, such as vehicle speed and gear position, while the second layer may display safety-related HMI content, such as warning or status indicator lights. Although an example of two layers is given here, more layers may exist on the display, such as a background layer.

[0050] For example, the multiple rendering modules of rendering module 208 may include a first rendering module and one or more additional rendering modules, wherein the output of the first rendering module may correspond to a first layer of the display, and the output of one or more additional rendering modules may correspond to one or more additional layers of the display. In this example, after the first rendering module and one or more additional rendering modules are registered with the second monitor 218, the second monitor 218 can detect delays or loss of the first rendering module. For example, during a rendering task, delays or loss of the first rendering module may cause delays or stuttering of information on the first layer of the display. If the delay or loss of the first rendering module causes the acknowledgment of the MISR CRC to exceed the FDTI, the display may enter a black screen state, making it impossible to display information that was originally displayed on one or more additional layers. The second monitor 218 can reset the first rendering module within the FDTI to restore normal operation of the first rendering module within the FDTI. During FDTI, although the first rendering module is reset and unable to output information to the display, the output of one or more other rendering modules can be displayed normally on one or more other layers of the display, thus preventing the display from going black due to the brief delay or loss of the first rendering module. In other words, in a specific example, when the first rendering module is reset, although the information on the first layer (e.g., vehicle speed, gear, etc.) may not be displayed normally until the first rendering module returns to normal during FDTI, the display can still display information on one or more other layers (e.g., warning or status indicator lights, background information), so the display does not go black during FDTI.

[0051] Figure 3 Another example of a second control unit 306 for optimizing the availability of displays in a vehicle is conceptually illustrated according to certain aspects of the invention. In some examples, the second control unit 306 may have... Figure 1 The second control unit 106 or the second control unit 206 in the middle has similar, identical or different functions.

[0052] In some examples, the second control unit 306 may be located within the display controller. For simplicity of the accompanying drawings, Figure 3 The display controller is not shown, but it may have the same characteristics as... Figure 1 The display controller 101 shown may have similar, identical, or different functions. The second control unit 306 may include a rendering module 308, a verification module 309, etc. In some examples, the rendering module 308 may include, for example, Figure 1The first rendering module (e.g., a cluster app and / or an HMI app), the second rendering module (e.g., a safety backup HMI app) or other rendering modules, and the verification module 309 may include at least one of the INC scheduler 310 and the SUC 311.

[0053] In some cases, the second control unit 306 can also perform tasks other than display tasks. For example, the second control unit 306 may also contain other modules such as a game module, an audio module, or a video module. The operation of these other modules besides display-related modules (e.g., rendering module 308 and / or verification module 309) may increase CPU load or consume memory resources, thereby causing the second control unit 306 to send signals to the display (not shown, e.g., ...). Figure 1 When the display (115) outputs display information, stuttering or lag occurs on the display. This stuttering or lag may also trigger the display system to enter a safe state, causing the display to go black. For example, if the game module increases CPU load or consumes memory resources when running on the second control unit 306, it may cause insufficient processing or storage resources for rendering or verification tasks on the second control unit 306, thus affecting the normal operation of the rendering or verification tasks.

[0054] In some examples, the second control unit 306 may apply a partitioning mechanism to at least one of the rendering module 308 or the verification module 309 located within the second control unit 306. In some examples, the partitioning mechanism may be applied to both the rendering module 308 and the verification module 309. In some examples, the partitioning mechanism includes allocating dedicated CPU bandwidth to at least one of the rendering module 308 or the verification module 309. In some examples, dedicated CPU bandwidth may be allocated to both the rendering module 308 and the verification module 309. In some examples, the partitioning mechanism includes applying a memory management unit (MMU) to allocate storage resources to at least one of the rendering module 308 and the verification module 309, wherein the storage resources are configured to store security-related information. In some examples, the memory management unit may allocate storage resources to both the rendering module 308 and the verification module 309, wherein the storage resources are configured to store security-related information. In some examples, the second control unit 306 may apply the partitioning mechanism through configuration of the operating system, which may include, but is not limited to, […]. Or other types of operating systems. By adopting the above partitioning mechanism, the display task-related modules in the second control unit 306 can be prevented from entering a black screen state due to insufficient resources.

[0055] Figure 4 According to certain aspects of the invention, an example of a method performed by a display controller for optimizing the availability of displays for vehicles is shown.

[0056] Figure 4 The method may include, at 401, detecting a display-related fault occurring within the display controller.

[0057] Figure 4 The method may further include, at 402, triggering an operation corresponding to the type of the detected fault to maintain the display connected to the display controller in a display state. For example, the method at 402 could be as follows: Figure 1 The first monitor 104 or Figure 2 The second monitor 218 in the display controller is used to perform this action, wherein the display controller may include, for example, Figure 1 and Figure 2 The display controller and display described herein may include, for example, Figure 1 and Figure 2 The display described in [the document]. The following will refer to [the document / document] in conjunction with [other documents / documents]. Figure 5 and Figure 6 To describe Figure 4 The specific operations in boxes 401 and 402.

[0058] Figure 5 According to certain aspects of the invention, an example of a method performed by a display controller for optimizing the availability of displays in transportation vehicles is shown. For example, Figure 5 The method described in the text can be in Figure 4 This is based on the method described in [the document / article].

[0059] Figure 5 The method at point 501 may include detecting a fault via a monitor within a first control unit in the display controller. The fault may include a transient hardware fault located within a second control unit in the display controller or a rendering fault in a first rendering module within the second control unit. For example, the method at point 501 could be achieved by... Figure 1 The first monitor 104 in the system performs this action, wherein the first control unit may include, for example, Figure 1 The first control unit 102 shown may include, for example, the second control unit 102. Figure 1 The second control unit 106 shown, and the first rendering module may include, for example: Figure 1 The first rendering module 108 is shown.

[0060] Figure 5The method may further include, at 502, rendering the warning data via a second rendering module within the second control unit, wherein the first rendering path associated with the first rendering module and the second rendering path associated with the second rendering module are at least partially decoupled. For example, the method at 502 could be as follows: Figure 1 The first monitor 104 in the process is used for execution, wherein the second rendering module may include, for example, Figure 1 The second rendering module 112 is shown.

[0061] Figure 6 According to certain aspects of the invention, an example of a method performed by a display controller for optimizing the availability of displays in transportation vehicles is shown. For example, Figure 6 The method described in the text can be in Figure 4 This is based on the method described in [the document / article].

[0062] Figure 6 The method may include, at 601, detecting a fault via a monitor within the second control unit of the display controller, the fault including delay or loss of at least one module among the modules registered to the monitor located within the second control unit of the display controller. For example, the method at 601 could be by, as... Figure 2 The second monitor 218 in the system performs this action, wherein the second control unit may include, for example, Figure 2 The second control unit 206 shown, and at least one module registered to the monitor, may include, for example: Figure 2 At least one of the rendering module 208 or the verification module 209 shown.

[0063] Figure 6 The method may further include: at 602, when a delay or loss of at least one module is detected, resetting at least one module within the FDTI to restore normal operation of the module within the FDTI. For example, the method at 602 could be as follows: Figure 2 The second monitor 218 in the system performs this operation.

[0064] In some examples, the modules registered to the monitor may include a first rendering module and one or more additional rendering modules, wherein the output of the first rendering module may correspond to a first layer of the display, and the output of one or more additional rendering modules may correspond to one or more additional layers of the display. In this example, faults include delays or loss of the first rendering module.

[0065] Figure 7 According to certain aspects of the invention, an example of a method performed by a display controller for optimizing the availability of displays for vehicles is shown.

[0066] Figure 7 The method may include, at 701, applying a partitioning mechanism to at least one of a rendering module or a verification module located within a control unit in the display controller. In some examples, the partitioning mechanism may be applied to both the rendering module and the verification module. For example, the method at 701 may be by means of... Figure 3 The rendering module is executed by the control unit 306, and may include, for example, the control unit 306. Figure 2 The rendering module 208 shown is... Figure 3 The rendering module 308 shown, and the verification module may include, for example: Figure 2 The verification module 209 shown is or Figure 3 The verification module 309 is shown. In some instances, the rendering module may include, for example, Figure 1 The first rendering module 108 and the second rendering module 112 shown, as well as the verification module, may include, for example: Figure 1 The verification module 109 shown.

[0067] Figure 7 The method may further include, at 702, allocating dedicated CPU bandwidth to at least one of the rendering module and the verification module. For example, the method at 702 could be as follows: Figure 3 It is executed by the control unit 308 in the middle.

[0068] Figure 7 The method may further include, at 703, the application memory management unit (MMU) allocating storage resources to at least one of the rendering module and the verification module, wherein the storage resources are configured to store security-related information. For example, the method at 703 could be derived from... Figure 3 It is executed by the control unit 308 in the middle.

[0069] The present invention also provides a computer-readable medium storing computer-executable instructions, which, when executed, cause one or more processors to perform the above-described... Figures 4 to 7 The method.

[0070] Although Figures 1 to 3 Examples in and Figures 4 to 7 The methods described in the document are separate, but depending on the specific implementation, these examples and methods can also be combined. For example, Figure 3 The examples in can be compared with Figures 1 to 2 At least one example from the above is combined, and Figure 7 The method in can be compared with Figures 4 to 6 At least one of the methods mentioned above can be combined. For example, one could first use methods such as... Figure 3 or Figure 7 The partitioning mechanism is described in the text, and then a method such as... Figures 1 to 2 and Figures 4 to 6The examples or methods described herein. By combining the above methods, the frequent black screen states of the display can be avoided more effectively. The above combinations are provided merely as examples; depending on the specific implementation, the invention may also include combinations of other different examples or methods.

[0071] Examples of implementation methods are described in the following numbered examples.

[0072] Example 1: A method performed by a display controller of a vehicle, the method comprising: detecting a display-related fault occurring within the display controller; and, based on the type of the detected fault, triggering an operation corresponding to the type of fault for maintaining a display connected to the display controller in a display state.

[0073] Example 2: According to the method of Example 1, wherein detecting a display-related fault occurring within the display controller includes: detecting the fault via a monitor within a first control unit in the display controller, the fault including a transient hardware fault located within a second control unit in the display controller or a rendering fault of a first rendering module within the second control unit, and wherein the operation includes: rendering warning data via a second rendering module within the second control unit, wherein a first rendering path associated with the first rendering module and a second rendering path associated with the second rendering module are at least partially decoupled.

[0074] Example 3: According to the method in Example 1 or 2, wherein detecting a display-related fault occurring within the display controller includes: detecting the fault via a monitor within a second control unit in the display controller, the fault including delay or loss of at least one module among modules registered to the monitor located within the second control unit in the display controller, and wherein the operation includes: when a delay or loss of at least one module is detected, resetting at least one module within a fault detection time interval (FDTI) to restore normal operation of the module within the FDTI.

[0075] Example 4: The method according to any one of Examples 1 to 3, wherein at least one module includes at least one of a rendering module or a verification module within the second control unit.

[0076] Example 5: The method according to any one of Examples 1 to 4, wherein the module includes a first rendering module and one or more additional rendering modules, wherein the output of the first rendering module corresponds to a first layer of the display, and the output of one or more additional rendering modules corresponds to one or more additional layers of the display, and wherein the fault includes delay or loss of the first rendering module.

[0077] Example 6: An apparatus for controlling a display of a vehicle, comprising: one or more monitors configured to: detect a display-related fault occurring within the apparatus; and, based on the type of the detected fault, trigger an operation corresponding to the type of fault to maintain the display connected to the apparatus in a display state.

[0078] Example 7: According to the apparatus of Example 6, detecting a display-related fault occurring within the apparatus includes: detecting the fault via a monitor within a first control unit in the apparatus, the fault including a transient hardware fault located within a second control unit in the apparatus or a rendering fault of a first rendering module within the second control unit, and wherein the operation includes: rendering warning data via a second rendering module within the second control unit, wherein a first rendering path associated with the first rendering module and a second rendering path associated with the second rendering module are at least partially decoupled.

[0079] Example 8: The apparatus according to Example 6 or Example 7, wherein detecting a display-related fault occurring within the apparatus comprises: detecting the fault via a monitor within a second control unit in the apparatus, the fault including delay or loss of at least one module among modules registered to the monitor located within the second control unit in the apparatus, and wherein the operation comprises: when a delay or loss of at least one module is detected, resetting at least one module within a fault detection time interval (FDTI) to restore normal operation of the module within the FDTI.

[0080] Example 9: The apparatus according to any one of Examples 6 to 8, wherein at least one module includes a rendering module or a verification module within the second control unit.

[0081] Example 10: An apparatus according to any one of Examples 6 to 9, wherein the module includes a first rendering module and one or more additional rendering modules, wherein the output of the first rendering module corresponds to a first layer of the display, and the output of one or more additional rendering modules corresponds to one or more additional layers of the display, and wherein the fault includes delay or loss of the first rendering module.

[0082] Example 11: A method performed by a display controller of a vehicle, the method comprising: applying a partitioning mechanism to at least one of a rendering module or a verification module located within a control unit of the display controller, wherein the partitioning mechanism includes at least one of: allocating dedicated central processing unit (CPU) bandwidth to at least one of the rendering module and the verification module; and applying a memory management unit (MMU) to allocate storage resources to at least one of the rendering module and the verification module, wherein the storage resources are configured to store security-related information.

[0083] Example 12: A method performed by a display controller of a vehicle, comprising any combination of Examples 1 through 5 and Example 11.

[0084] Example 13: An apparatus for controlling a display of a vehicle, comprising: a control unit configured to: apply a partitioning mechanism to at least one of a rendering module or a verification module located within the control unit of the apparatus, wherein the partitioning mechanism includes at least one of: allocating dedicated central processing unit (CPU) bandwidth to at least one of the rendering module and the verification module; and applying a memory management unit (MMU) to allocate dedicated storage resources to at least one of the rendering module and the verification module, wherein the dedicated storage resources are configured to store security-related information.

[0085] Example 14: A device for controlling a display of a vehicle, comprising any combination of Examples 6 to 10 and Example 13.

[0086] exist Figures 1 to 7 The examples or methods provided herein are not intended to limit the scope, applicability, or examples set forth in the claims. Changes may be made in the function and arrangement of the elements discussed without departing from the scope of the invention. Various processes or components may be omitted, substituted, or added as appropriate in the examples. For example, the described methods may be performed in a different order than described, and steps may be added, omitted, or combined. Furthermore, features described in some examples may be combined into other examples. For example, an apparatus or method may be implemented using any number of aspects set forth herein. Additionally, the scope of the invention is intended to cover apparatus or methods practiced using structures, functions, or structures and functions other than those set forth herein or different from those set forth herein. It should be understood that any aspect of what is disclosed herein may be embodied by one or more elements of the claims. The word “exemplary” as used herein means “serving as an example, instance, or illustration.” Any aspect described herein as “exemplary” is not necessarily to be construed as preferred or advantageous over other aspects.

[0087] The methods disclosed herein include one or more steps or actions for implementing the described methods. The method steps and / or actions may be interchangeable without departing from the scope of the claims. In other words, unless a specific order of steps or actions is specified, the order and / or use of a particular step and / or action may be modified without departing from the scope of the claims.

[0088] As used herein, the phrase “at least one of the items” refers to any combination of those items, including a single member. For example, “at least one of a, b, or c” is intended to cover: a, b, c, ab, ac, bc, and abc, as well as any combination of multiples of the same element (e.g., aa, aaa, aab, aac, abb, acc, bb, bbb, bbb, cc, and ccc, or any other ordering of a, b, and c).

[0089] The preceding description is provided to enable any person skilled in the art to practice the various aspects described herein. Various modifications to these aspects will be apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects. Therefore, the claims are not intended to be limited to the aspects shown herein, but rather to be consistent with the full scope of the claims, wherein reference to the singular form of an element is not intended to mean “one and only one,” but rather “one or more.” Unless otherwise specifically stated, the term “some” refers to one or more. All structural and functional equivalents of elements pervading the various aspects described herein that are known or to be known by one of ordinary skill in the art are expressly incorporated herein by reference and are intended to be included by the claims. Furthermore, the disclosure herein is not intended to be offered to the public, whether or not such disclosure is expressly stated in the claims.

[0090] The term "System-on-a-Chip" (SOC) is used herein to refer to a set of interconnected circuits that typically includes one or more processors, memory, and communication interfaces. An SOC can include various types of processors and processor cores, such as general-purpose processors, central processing units (CPUs), digital signal processors (DSPs), graphics processing units (GPUs), accelerated processing units (APUs), subsystem processors, auxiliary processors, single-core processors, and multi-core processors. An SOC can also embody other hardware and hardware combinations, such as field-programmable gate arrays (FPGAs), configuration and status registers (CSRs), application-specific integrated circuits (ASICs), other programmable logic devices, discrete gate logic, transistor logic, registers, performance monitoring hardware, watchdog hardware, counters, and time references. An SOC can be an integrated circuit (IC) configured such that the components of the IC are located on the same substrate, such as a monolithic semiconductor material (e.g., silicon).

[0091] The various illustrative logic blocks, modules, and circuits described in connection with this invention may be implemented or executed using a general-purpose processor, digital signal processor (DSP), application-specific integrated circuit (ASIC), field-programmable gate array (FPGA) or other programmable logic device (PLD), discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. The general-purpose processor may be a microprocessor, but alternatively, the processor may be any commercially available processor, controller, microcontroller, or state machine. The processor may also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors combined with a DSP core, or any other such configuration.

[0092] If implemented in hardware, an example hardware configuration may include a processing controller in a wireless node. The processing controller may be implemented using a bus architecture. Depending on the specific application and overall design constraints of the processing controller, the bus may include any number of interconnected buses and bridges. The bus can link together various circuits, including processors, machine-readable media, and bus interfaces. The bus may also link various other circuits such as clock sources, peripherals, regulators, power management circuits, etc., which are well known in the art and therefore will not be described further. The processor may be implemented using one or more general-purpose processors and / or special-purpose processors. Examples include microprocessors, microcontrollers, DSP processors, and other circuits capable of executing software. Those skilled in the art will recognize that how best to implement the functions described for the processing controller depends on the specific application and the overall design constraints imposed on the controller.

[0093] If implemented in software, functionality can be stored or transmitted as one or more instructions or code on or through a computer-readable medium. Software should be broadly interpreted as instructions, data, or any combination thereof, whether referred to as software, firmware, middleware, microcode, hardware description language, or other terms. Computer-readable media includes computer storage media and communication media, wherein the communication media includes any medium that facilitates the transfer of a computer program from one place to another. The processor may be responsible for managing the bus and general-purpose processing, including the execution of software modules stored on the machine-readable storage medium. The computer-readable storage medium may be coupled to the processor so that the processor can read information from and write information to the storage medium. Alternatively, the storage medium may be integrated into the processor. For example, the machine-readable medium may include transmission lines, carrier waves modulated by data, and / or a separate computer-readable storage medium on which instructions are stored, all of which may be accessible to the processor via a bus interface. Alternatively or additionally, the machine-readable medium or any portion thereof may be integrated into the processor, such as in cases where it may have a cache and / or a general-purpose register file. For example, examples of machine-readable storage media may include RAM (random access memory), flash memory, ROM (read-only memory), PROM (programmable read-only memory), EPROM (erasable programmable read-only memory), EEPROM (electrically erasable programmable read-only memory), registers, disks, optical disks, hard disks, or any other suitable storage media or any combination thereof. Machine-readable media may be embodied in a computer program product.

[0094] Software modules may include a single instruction or a number of instructions, and may be distributed across several different code segments, across different programs, or across multiple storage media. Computer-readable media may include multiple software modules. When executed by a device such as a processor, a software module includes instructions that cause the processing controller to perform various functions. Software modules may include sending modules and receiving modules. Software modules may reside on a single storage device or be distributed across multiple storage devices. For example, when a triggering event occurs, a software module may be loaded from a hard disk into RAM. During the execution of a software module, the processor may load some of these instructions into a cache to speed up access. Subsequently, one or more cache lines may be loaded into a general-purpose register file for execution by the processor. When referring to the functionality of a software module as described below, it will be understood that such functionality is implemented by the processor when instructions from that software module are executed.

[0095] Certain aspects described herein may include computer program products for performing the operations set forth herein. For example, such computer program products may include computer-readable media having instructions stored thereon (and / or encoded thereon) and instructions executable by one or more processors to perform the operations described herein.

[0096] It should be understood that the claims are not limited to the precise configurations and components described above. Various modifications, alterations, and variations may be made to the arrangement, operation, and details of the methods and apparatus described above without departing from the scope of the claims.

Claims

1. A method executed by a display controller of a vehicle, the method comprising: Detect display-related faults occurring within the display controller; as well as Based on the type of the detected fault, an operation corresponding to the type of fault is triggered to keep the display connected to the display controller in a display state.

2. The method according to claim 1, wherein, Detecting the display-related fault occurring within the display controller includes: detecting the fault via a monitor within a first control unit of the display controller, the fault including a transient hardware fault located within a second control unit of the display controller or a rendering fault of a first rendering module within the second control unit, and wherein the operation includes: rendering warning data via a second rendering module within the second control unit, wherein a first rendering path associated with the first rendering module and a second rendering path associated with the second rendering module are at least partially decoupled.

3. The method according to claim 1, wherein, Detecting the display-related fault occurring within the display controller includes: detecting the fault via a monitor within a second control unit in the display controller, the fault including delay or loss of at least one module among modules registered to the monitor located within the second control unit in the display controller, and wherein the operation includes: when a delay or loss of the at least one module is detected, resetting the at least one module within a fault detection time interval (FDTI) to restore normal operation of the module within the FDTI.

4. The method according to claim 3, wherein, The at least one module includes at least one of the rendering module or the verification module within the second control unit.

5. The method according to claim 3, wherein, The module includes a first rendering module and one or more additional rendering modules, the output of the first rendering module corresponding to a first layer of the display, and the output of the one or more additional rendering modules corresponding to one or more additional layers of the display, wherein the fault includes delay or loss of the first rendering module.

6. A device for controlling a vehicle display, comprising: One or more monitors are configured to: Detecting display-related faults occurring within the device; as well as Based on the type of the detected fault, an operation corresponding to the type of fault is triggered to keep the display connected to the device in a display state.

7. The apparatus according to claim 6, wherein, Detecting the display-related fault occurring within the device includes: detecting the fault via a monitor within a first control unit in the device, the fault including a transient hardware fault located within a second control unit in the device or a rendering fault of a first rendering module within the second control unit, and wherein the operation includes: rendering warning data via a second rendering module within the second control unit, wherein a first rendering path associated with the first rendering module and a second rendering path associated with the second rendering module are at least partially decoupled.

8. The apparatus according to claim 6, wherein, Detecting the display-related fault occurring within the device includes: detecting the fault via a monitor within a second control unit in the device, the fault including delay or loss of at least one module among modules registered to the monitor located within the second control unit in the device, and wherein the operation includes: when a delay or loss of the at least one module is detected, resetting the at least one module within a fault detection time interval (FDTI) to restore normal operation of the module within the FDTI.

9. The apparatus according to claim 8, wherein, The at least one module includes a rendering module or a verification module inside the second control unit.

10. The apparatus according to claim 8, wherein, The module includes a first rendering module and one or more additional rendering modules, the output of the first rendering module corresponding to a first layer of the display, and the output of the one or more additional rendering modules corresponding to one or more additional layers of the display, wherein the fault includes delay or loss of the first rendering module.

11. A method executed by a display controller of a vehicle, the method comprising: The partitioning mechanism is applied to at least one of the rendering module or the verification module located within the control unit of the display controller, wherein the partitioning mechanism includes at least one of the following: Allocate dedicated central processing unit (CPU) bandwidth to at least one of the rendering module and the verification module; and The application memory management unit (MMU) allocates storage resources to at least one of the rendering module and the verification module, wherein the storage resources are configured to store security-related information.

12. A device for controlling a display of a vehicle, comprising: The control unit is configured as follows: The partitioning mechanism is applied to at least one of the rendering module or the verification module located within the control unit of the device, wherein the partitioning mechanism includes at least one of the following: Allocate dedicated central processing unit (CPU) bandwidth to at least one of the rendering module and the verification module; and The application memory management unit (MMU) allocates dedicated storage resources to at least one of the rendering module and the verification module, wherein the dedicated storage resources are configured to store security-related information.

13. A computer-readable medium storing computer-executable instructions that, when executed, cause one or more processors to perform the method as described in any one of claims 1-5 and 11.

14. A computer program product comprising computer-executable instructions that, when executed, cause one or more processors to perform the method as described in any one of claims 1-5 and 11.