Complete vehicle multi-domain hierarchical pure hardware safety island architecture and management and control method
By implementing electrical isolation and fault solidification in a dual-layer hardware architecture at the vehicle and domain levels, the problems of monitoring failure and response delay caused by software dependence in existing technologies are solved, enabling rapid fault handling and highly reliable vehicle functional safety monitoring with high isolation.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- 陈立波
- Filing Date
- 2026-04-13
- Publication Date
- 2026-05-19
AI Technical Summary
Existing vehicle functional safety monitoring systems rely on software watchdogs and processor diagnostics, which are prone to failure and have response delays, making it difficult to meet high-level functional safety requirements, and lack a pure hardware-based hierarchical safety monitoring architecture.
It adopts a dual-layer hardware architecture at the vehicle and domain levels, with independent power clocks and electrical isolation for all safety islands. It monitors heartbeat, power rail, and clock signals in real time, solidifies fault rules, and implements three-level hardware handling, eliminating software decision-making and caching delays.
It achieves independent operation capability, rapid fault handling, full-domain electrical isolation and hierarchical control, improving the reliability and response speed of vehicle safety monitoring and reducing the risk of loss of control.
Abstract
Description
Technical Field
[0001] This invention relates to the field of vehicle functional safety technology, specifically to a multi-domain hierarchical pure hardware safety island architecture and control method for a vehicle. Background Technology
[0002] Vehicle functional safety monitoring largely relies on software watchdogs and processor diagnostic programs, which suffer from three main problems: monitoring failures, response delays, and false fault diagnoses. Software monitoring is susceptible to system crashes and program tampering, and serious faults are difficult to handle quickly, potentially leading to loss of vehicle control. Existing safety islands often integrate processors and firmware, lacking a purely hardware-based hierarchical safety monitoring architecture, making it difficult to meet the high-level functional safety requirements of vehicles. Summary of the Invention
[0003] This invention provides a multi-domain hierarchical pure hardware security island architecture and control method, employing a dual-layer hardware architecture at the vehicle and domain levels, with all modules having independent power supplies and clocks and electrical isolation. Hardware circuits provide real-time direct monitoring of heartbeat, power rail, and clock signals; fault rules are fixed by fuses; and hardware handling is implemented according to a three-level hierarchy, eliminating software decisions and buffer delays. An independent backup power supply ensures continuous monitoring operation, improving the reliability of vehicle safety monitoring.
[0004] Comparison with existing technologies and competing products 1. Existing competing products use a processor paired with software diagnostics, and monitoring depends on system operation, which makes them prone to crashes and failures; this invention is pure hardware without a processor, has a two-level hierarchical structure, and independent power supply, and can run independently without relying on the main system.
[0005] 2. Existing solutions have high fault response latency, while the present invention provides instantaneous hardware processing and fast response speed.
[0006] 3. This technology differs from existing software monitoring architectures, offering superior functional safety performance and demonstrating innovation. Beneficial effects
[0007] 1. Independent operation capability: No firmware or system required, does not depend on the main controller, and can still perform monitoring even if the vehicle crashes; 2. Rapid Fault Handling: Real-time detection of level cut-through enables rapid hardware response to faults, reducing the risk of loss of control; 3. High isolation reliability: Full-domain electrical isolation reduces the impact of single-point failures on other domains; 4. Tiered management and control capability: Three-level hardware handling, balancing operational stability and fault safety; 5. Anti-tampering protection: Security logic is physically solidified, reducing the probability of fault rules being modified. Detailed Implementation
[0008] This invention is applied to a vehicle-wide functional safety monitoring system, which sets up a vehicle-level hardware safety root and five domain-level hardware safety islands, corresponding to the chassis domain, powertrain domain, body domain, intelligent driving domain, and intelligent cockpit domain, respectively. All safety islands are equipped with independent crystal oscillators and independent backup power supplies, are electrically isolated from the main system, and have no common ground coupling.
[0009] Domain-level security islands are directly connected to the main control unit of the domain via hardwired connections, enabling real-time level monitoring of heartbeat signals, power supply voltage, and clock frequency without sampling conversion or data buffering. Security islands are interconnected via hardware signal lines, broadcasting fault status levels without software communication relay.
[0010] Fault classification response circuit factory-fixed handling rules: minor faults, hardware records the status; serious faults, hardware degrades the power of the local domain; fatal faults, hardware shuts off the power supply of the local domain; the whole vehicle safety root polls and monitors the entire domain, and when a serious fault is detected, it controls the whole vehicle to enter a preset safety state.
[0011] The backup power supply integrates a capacity monitoring circuit, providing hardware warnings in case of undervoltage and automatic switching in case of main power failure. Unauthorized access is directly blocked by hardware, with no software permission mechanism. This architecture is entirely hardware-based, adapting to vehicle functional safety requirements and compatible with both passenger and commercial vehicles.
Claims
1. A multi-domain hierarchical pure hardware security island architecture for vehicle functional safety, characterized in that, The system consists of pure hardware logic circuits without firmware; including: a vehicle-level hardware security root with an independent clock power supply to monitor the status of the entire security island; at least two functional domain hardware security islands with independent clock power supplies to monitor the heartbeat, power supply, clock, and faults of their respective domains; and a hardware fault classification response circuit that executes hardware classification handling according to fixed rules.
2. A multi-domain hierarchical pure hardware security island management method, applied to the architecture described in claim 1, characterized in that, Pure hardware execution without software; including: real-time monitoring of the domain status by the domain-level security island hardware; hierarchical hardware response to fault triggering; full-domain security root monitoring of the entire vehicle's status; and hardware forcing the domain into a safe state in case of a fatal fault.
3. The architecture according to claim 1 or the method according to claim 2, characterized in that, The safety island features interconnected hardware signal lines for fault broadcasting, and integrates dual redundant timeout timers, independent backup power supplies and automatic switching circuits, and hardware storage protection units.
4. The architecture according to claim 1 or the method according to claim 2, characterized in that, The fault response execution includes three levels of hardware actions: recording, degradation, and shutdown. The backup power supply integrates hardware monitoring of capacity and threshold early warning circuitry.
5. The architecture according to claim 1 or the method according to claim 2, characterized in that, Fault rules and thresholds are fixed in hardware at once, unauthorized access is physically blocked, and there is no software-based permission logic.
6. The architecture or method according to any one of claims 1-5, characterized in that, The safety island features complete electrical isolation, with no grounding coupling or crosstalk interference, preventing single-point faults from propagating.
7. The architecture or method according to any one of claims 1-5, characterized in that, Fault detection is achieved through direct-through real-time monitoring, with no sampling delay and no data buffering.
8. The architecture or method according to any one of claims 1-5, characterized in that, The switch from safe mode to hard-wired execution is instantaneous, with no software decision-making or transition delay.
9. The architecture or method according to any one of claims 1-8, characterized in that, The entire architecture is firmware-free and has no programming interface; the security logic is physically fixed and cannot be tampered with.
10. A vehicle, characterized in that, It can be equipped with the architecture described in any one of claims 1-9, or perform the method described in any one of claims 2-9.