Vehicle-mounted inertial measurement dual-link redundant acquisition communication circuit

The vehicle-mounted inertial measurement system with dual-link redundancy design solves the redundancy protection problem of power supply, control and communication links, realizes continuous output of inertial data and fault isolation, and improves system reliability and functional safety.

CN122143810APending Publication Date: 2026-06-05TIANJIN TRINOVA AUTOMOTIVE TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
TIANJIN TRINOVA AUTOMOTIVE TECH CO LTD
Filing Date
2026-05-08
Publication Date
2026-06-05

AI Technical Summary

Technical Problem

Existing vehicle-mounted inertial measurement systems lack effective redundancy protection in power supply, control, and communication, making it difficult to meet the requirements of high functional safety and system availability in vehicle-mounted application scenarios.

Method used

It adopts a dual-link redundancy design, including dual IMUs, dual MCUs, dual CAN transceivers and dual power supply links. Interconnection and mutual monitoring are achieved through SPI bus and digital isolation devices to ensure independent operation of data acquisition and communication, and to provide fault isolation and switching mechanisms.

Benefits of technology

It enables seamless switching in the event of a failure at any stage, ensuring continuous output of inertial data, reducing the risk of system-level failure, and improving system reliability and functional safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122143810A_ABST
    Figure CN122143810A_ABST
Patent Text Reader

Abstract

The present application relates to the field of automotive electronics, in particular to a vehicle-mounted inertial measurement dual-link redundant acquisition communication circuit, comprising: a power supply module including a first power supply link for outputting a first power supply and a second power supply link for outputing a second power supply; an inertial measurement module including a first IMU and a second IMU; an MCU module including a first MCU and a second MCU; a CAN transceiver module including a first CAN transceiver connected with the first MCU and providing a first physical CAN channel to the outside, and a second CAN transceiver connected with the second MCU and providing a second physical CAN channel to the outside; the present application ensures continuous output of inertial data and greatly reduces the risk of system-level failure.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of automotive electronics technology, and in particular to an onboard inertial measurement dual-link redundant acquisition and communication circuit. Background Technology

[0002] Inertial measurement units (IMUs) typically integrate three-axis accelerometers and three-axis gyroscopes, serving as core sensors for critical functions such as electronic stability control (ESC), air suspension attitude estimation, assisted driving trajectory calculation, and lidar pitch compensation. In existing technologies, redundancy at the sensor level has been implemented to improve the reliability of IMU data.

[0003] Chinese Patent Publication No. CN117864038A discloses an inertial sensor cluster system for vehicles, integrating low-precision and high-precision six-axis inertial sensors into a controller. Data is read by a single microcontroller (MCU) and output through a single controller area network (CAN) module. This solution allows for switching to a low-precision sensor as a backup when the high-precision sensor fails. However, while this existing solution addresses sensor redundancy, its data processing and communication output links still rely heavily on a single MCU and a single CAN module, posing a significant risk of single-point failure. Furthermore, it lacks effective redundancy protection in power supply, control, and communication, making it difficult to meet the higher functional safety and system availability requirements of in-vehicle applications. Summary of the Invention

[0004] This invention provides a dual-link redundant acquisition and communication circuit for vehicle-mounted inertial measurement, which overcomes the lack of effective redundancy protection in the power supply, control and communication links of existing vehicle-mounted inertial measurement technologies, making it difficult to meet the requirements of vehicle-mounted application scenarios with higher functional safety and system availability requirements.

[0005] To achieve the above objectives, the present invention provides a vehicle-mounted inertial measurement dual-link redundant acquisition and communication circuit, comprising: The power supply module includes a first power supply link for outputting a first power supply and a second power supply link for outputting a second power supply. An inertial measurement module, comprising a first IMU and a second IMU; The MCU module includes a first MCU and a second MCU; The CAN transceiver module includes a first CAN transceiver connected to the first MCU and providing a first physical CAN channel externally, and a second CAN transceiver connected to the second MCU and providing a second physical CAN channel externally. The first power supply link is connected to the power input terminals of the first IMU, the first MCU, and the first CAN transceiver, respectively; the second power supply link is connected to the power input terminals of the second IMU, the second MCU, and the second CAN transceiver, respectively. The first IMU is communicatively connected to both the first MCU and the second MCU; the second IMU is communicatively connected to both the first MCU and the second MCU; the first MCU and the second MCU are interconnected via a communication interface for status monitoring and information exchange. The first MCU is configured as a master controller, used to collect first inertial data through the first IMU connected to it, and to collect second inertial data through the second IMU connected to it for verification, and to output data through the first CAN transceiver; the second MCU is configured as a backup controller, used to monitor the health status of the first MCU and its power supply link and communication link, and to take over and output inertial data through the second CAN transceiver when it is determined that the first MCU or its link has failed.

[0006] Furthermore, the first IMU and the first MCU are connected via a first SPI bus; the first IMU and the second MCU are connected via a fourth SPI bus; the second IMU and the second MCU are connected via a second SPI bus; and the second IMU and the first MCU are connected via a third SPI bus.

[0007] Furthermore, the first MCU and the second MCU are interconnected and communicate via SPI0 and dual reset lines RST1 and RST2.

[0008] Furthermore, digital isolation devices are provided on the second SPI bus and the fourth SPI bus.

[0009] Furthermore, both the first power supply link and the second power supply link are electrically isolated power supplies.

[0010] Furthermore, the first MCU is also used to acquire the voltage signal of the second power supply link, and the second MCU is also used to acquire the voltage signal of the first power supply link.

[0011] Furthermore, the data frames sent out by the first MCU or the second MCU through its corresponding CAN transceiver include a health status frame, which is used to indicate the source of the currently output data, the current master control identifier, and the reason for system degradation.

[0012] Furthermore, the circuit's operating modes include master / standby mode, dual master mode, or domain-specific output mode.

[0013] Compared with the prior art, the beneficial effects of the present invention are that the technical solution of the present invention forms two complete links that can operate independently from power supply, data acquisition, data processing to data communication through the architecture of dual independent power supply, dual MCU interconnection and monitoring, dual IMU cross acquisition, and dual physical CAN channel output. When any link in either link fails, the other link can seamlessly take over, ensuring the continuous output of inertial data and greatly reducing the risk of system-level failure.

[0014] Furthermore, this invention uses dual MCUs to cross-acquire data from two IMUs, enabling cross-verification and diagnosis of the sensor itself, the acquisition link, and the MCU itself. When an anomaly occurs, the fault source can be quickly and accurately located, and fault isolation can be achieved to prevent the fault from spreading.

[0015] Furthermore, the adoption of dual independent power supply domains avoids the common-cause failure problem where a single power supply failure can paralyze the entire system. Simultaneously, through cross-power supply monitoring, each MCU can obtain real-time health status information for the other's power supply domain, providing a basis for fault switching decisions.

[0016] Furthermore, the dual physical CAN channel design ensures that even if one CAN bus experiences a short circuit, open circuit, or transceiver failure, critical inertial data and health status information can still be output through the other CAN channel, guaranteeing reliable communication with other electronic control units in the vehicle. Attached Figure Description

[0017] Figure 1 This is a unit connection diagram of the dual-link redundant acquisition and communication circuit for vehicle-mounted inertial measurement according to the present invention. Detailed Implementation

[0018] To make the objectives and advantages of the present invention clearer, the present invention will be further described below with reference to embodiments; it should be understood that the specific embodiments described herein are merely for explaining the present invention and are not intended to limit the present invention.

[0019] Preferred embodiments of the present invention will now be described with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are merely illustrative of the technical principles of the present invention and are not intended to limit the scope of protection of the present invention.

[0020] It should be noted that in the description of this invention, the terms "upper", "lower", "left", "right", "inner", "outer", etc., which indicate directions or positional relationships, are based on the directions or positional relationships shown in the accompanying drawings. This is only for the convenience of description and is not intended to indicate or imply that the device or element must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, it should not be construed as a limitation of this invention.

[0021] Please see Figure 1 The diagram shown is a unit connection diagram of the dual-link redundant acquisition and communication circuit for vehicle-mounted inertial measurement according to the present invention. The present invention provides a dual-link redundant acquisition and communication circuit for vehicle-mounted inertial measurement, comprising: The power supply module includes a first power supply link for outputting a first power supply and a second power supply link for outputting a second power supply. An inertial measurement module, comprising a first IMU and a second IMU; The MCU module includes a first MCU and a second MCU; The CAN transceiver module includes a first CAN transceiver connected to the first MCU and providing a first physical CAN channel externally, and a second CAN transceiver connected to the second MCU and providing a second physical CAN channel externally. The first power supply link is connected to the power input terminals of the first IMU, the first MCU, and the first CAN transceiver, respectively; the second power supply link is connected to the power input terminals of the second IMU, the second MCU, and the second CAN transceiver, respectively. The first IMU is communicatively connected to both the first MCU and the second MCU; the second IMU is communicatively connected to both the first MCU and the second MCU; the first MCU and the second MCU are interconnected via a communication interface for status monitoring and information exchange. The first MCU is configured as a master controller, used to collect first inertial data through the first IMU connected to it, and to collect second inertial data through the second IMU connected to it for verification, and to output data through the first CAN transceiver; the second MCU is configured as a backup controller, used to monitor the health status of the first MCU and its power supply link and communication link, and to take over and output inertial data through the second CAN transceiver when it is determined that the first MCU or its link has failed.

[0022] Specifically, the first IMU and the first MCU communicate via a first SPI bus; the first IMU and the second MCU communicate via a fourth SPI bus; the second IMU and the second MCU communicate via a second SPI bus; and the second IMU and the first MCU communicate via a third SPI bus.

[0023] Specifically, the first MCU and the second MCU are interconnected and communicate via SPI0 and dual reset lines RST1 and RST2.

[0024] Specifically, digital isolation devices are provided on the second SPI bus and the fourth SPI bus.

[0025] Specifically, both the first power supply link and the second power supply link are electrically isolated power supplies.

[0026] Specifically, the first MCU is also used to acquire the voltage signal of the second power supply link, and the second MCU is also used to acquire the voltage signal of the first power supply link.

[0027] Specifically, the data frames sent out by the first MCU or the second MCU through its corresponding CAN transceiver include a health status frame. The health status frame is used to indicate the source of the currently output data, the current master control identifier, and the reason for system degradation.

[0028] Specifically, an access mutual exclusion control module is set on the SPI communication link between the first MCU and the second MCU accessing the same IMU to ensure that only one MCU is allowed to obtain SPI bus control at any given time. The mutual exclusion control module consists of AND gates and latches. The hardware gating strategy includes: the SPI clock signals SCLK, MOSI, MISO, and CS output by each MCU first enter the gate control circuit and then connect to the IMU. The gate control logic includes: when GRANT1=1, only the first MCU path is turned on. When GRANT2=1, only the second MCU path is turned on. GRANT1 and GRANT2 are hardware mutually exclusive and cannot be 1 at the same time. When the first MCU abnormally and continuously outputs a clock, since GRANT1 is canceled, its clock cannot enter the IMU, thus eliminating bus contention at its source.

[0029] Specifically, the circuit's operating modes include main / standby mode, dual-main mode, or domain-specific output mode.

[0030] In the implementation of the master / standby mode, after the vehicle is powered on, the first and second power supply links output stable VCC1 and VCC2 respectively. The first and second IMUs start up and establish communication via the SPI0 bus for initialization and state synchronization. By default, the first MCU is the master controller, and the master working link is VCC1-first IMU-first MCU-first CAN transceiver. The first MCU collects raw data from the first IMU in real time via SPI1 and performs filtering, attitude calculation, and other processing. At the same time, the first MCU periodically reads data from the second IMU via SPI3 for cross-validation with the data from the first IMU to diagnose whether the sensors or acquisition links are functioning properly. The first MCU encapsulates the processed inertial data into CAN frames, along with its own health status (such as heartbeat count, power supply voltage, and self-test results), and sends them to the vehicle's CAN network via the first CAN transceiver channel through the first CAN transceiver 5. The second MCU, as a hot standby, operates simultaneously. The second MCU collects data from the second IMU in real time via SPI2. The second MCU continuously monitors the heartbeat signal of the first MCU via SPI0 and monitors the status of its own power supply VCC2, while simultaneously monitoring the status of the main power supply VCC1 via its ADC channel. When the second MCU detects any of the following fault conditions, it will determine that the main link has failed and initiate a takeover process: First MCU heartbeat loss: If the first MCU's heartbeat signal is not received via SPI0 within a preset timeout period, the first MCU is determined to be frozen or reset. Main power supply abnormality: The ADC detects that the VCC1 voltage is lower or higher than the preset normal operating range. Main CAN channel failure: The first MCU notifies the second MCU via SPI0, or the second MCU discovers through other diagnostic methods (such as listening to the CAN bus) that the first CAN channel has been Bus-off for an extended period or is unable to send data. Takeover and Degraded Output: After determining that takeover is necessary, the second MCU immediately activates its own CAN2 channel and sends inertial data to the vehicle network via the second CAN transceiver 6. The output data selection strategy is: priority is given to outputting high-precision second IMU data collected within this link. If the second MCU detects an abnormality in the second IMU (such as excessive data drift), it switches to reading data from the first IMU via SPI4 for output, achieving degraded use. In the output CAN data frame, a "health status frame" is specifically defined, which includes: the current output data source (first IMU or second IMU), the currently operating master controller (first MCU or second MCU), and the reason code for takeover / degradation (such as "master MCU heartbeat lost", "main power supply undervoltage", "high-precision IMU failure", etc.) to facilitate high-level diagnosis and functional strategy adjustment of the whole vehicle.

[0031] In dual-master mode, the first and second MCUs operate simultaneously, transmitting data via the first CAN transceiver and CAN2 respectively. The receiving end (such as a domain controller) simultaneously verifies and merges the two data streams. This mode provides higher data bandwidth and security.

[0032] In the domain-separated output mode, the first MCU is responsible for outputting inertial data for vehicle stability control, and the second MCU is responsible for outputting inertial data for assisted driving positioning, thus achieving functional isolation.

[0033] The technical solution of the present invention has been described above with reference to the preferred embodiments shown in the accompanying drawings. However, it will be readily understood by those skilled in the art that the scope of protection of the present invention is obviously not limited to these specific embodiments. Without departing from the principles of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will all fall within the scope of protection of the present invention.

[0034] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A vehicle-mounted inertial measurement dual-link redundant acquisition and communication circuit, characterized in that, include: The power supply module includes a first power supply link for outputting a first power supply and a second power supply link for outputting a second power supply. An inertial measurement module, comprising a first IMU and a second IMU; The MCU module includes a first MCU and a second MCU; The CAN transceiver module includes a first CAN transceiver connected to the first MCU and providing a first physical CAN channel externally, and a second CAN transceiver connected to the second MCU and providing a second physical CAN channel externally. The first power supply link is connected to the power input terminals of the first IMU, the first MCU, and the first CAN transceiver, respectively; the second power supply link is connected to the power input terminals of the second IMU, the second MCU, and the second CAN transceiver, respectively. The first IMU is communicatively connected to both the first MCU and the second MCU; the second IMU is communicatively connected to both the first MCU and the second MCU; the first MCU and the second MCU are interconnected via a communication interface for status monitoring and information exchange. The first MCU is configured as a master controller, used to collect first inertial data through the first IMU connected to it, and to collect second inertial data through the second IMU connected to it for verification, and to output data through the first CAN transceiver; the second MCU is configured as a backup controller, used to monitor the health status of the first MCU and its power supply link and communication link, and to take over and output inertial data through the second CAN transceiver when it is determined that the first MCU or its link has failed.

2. The vehicle-mounted inertial measurement dual-link redundant acquisition and communication circuit according to claim 1, characterized in that, The first IMU and the first MCU communicate via a first SPI bus; the first IMU and the second MCU communicate via a fourth SPI bus; the second IMU and the second MCU communicate via a second SPI bus; and the second IMU and the first MCU communicate via a third SPI bus.

3. The vehicle-mounted inertial measurement dual-link redundant acquisition and communication circuit according to claim 2, characterized in that, The first MCU and the second MCU communicate with each other via SPI0 and dual reset lines RST1 and RST2.

4. The vehicle-mounted inertial measurement dual-link redundant acquisition and communication circuit according to claim 3, characterized in that, Digital isolation devices are provided on the second SPI bus and the fourth SPI bus.

5. The vehicle-mounted inertial measurement dual-link redundant acquisition and communication circuit according to claim 4, characterized in that, Both the first power supply link and the second power supply link are electrically isolated power supplies.

6. The vehicle-mounted inertial measurement dual-link redundant acquisition and communication circuit according to claim 5, characterized in that, The first MCU is also used to acquire the voltage signal of the second power supply link, and the second MCU is also used to acquire the voltage signal of the first power supply link.

7. The vehicle-mounted inertial measurement dual-link redundant acquisition and communication circuit according to claim 6, characterized in that, The data frames sent out by the first MCU or the second MCU through its corresponding CAN transceiver include a health status frame. The health status frame is used to indicate the source of the currently output data, the current master control identifier, and the reason for system degradation.

8. The vehicle-mounted inertial measurement dual-link redundant acquisition and communication circuit according to claim 7, characterized in that, The circuit operates in multiple modes, including main / standby mode, dual main mode, or domain-specific output mode.

Citation Information

Patent Citations

  • Vehicle-mounted inertial sensor cluster system

    CN117864038A