Vehicle control method, vehicle control system, and vehicle
Patent Information
- Application Number
- CN202610793034.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-03
- Publication Date
- 2026-09-15
- Estimated Expiration
- 2046-06-03
AI Technical Summary
然而现有的车辆控制系统中,无法确保在处理器核心出现计算错误的情况下,还能够保持发电机、发动机等系统持续有效地协同工作
[0017] In this embodiment, by setting time information for the mirror data to verify its continuity, replay attacks can be avoided; and by setting verification information for the mirror data, the integrity of the mirror data can be verified, thereby ensuring that the mirror data written to the independent memory area corresponding to the redundant backup core is valid mirror data, and thus the redundant backup core can correctly take over the control tasks of the processor core based on the valid mirror data.
Smart Images

Figure CN122324039B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of vehicle control technology, and in particular to a vehicle control method, a vehicle control system, and a vehicle. Background Technology
[0002] In today's advanced vehicle electronic and electrical architectures, vehicle control systems undertake increasingly complex control tasks, including but not limited to: powertrain (engine / motor) control, chassis dynamics (steering, braking) control, perception and decision-making by advanced driver assistance systems, graphics rendering and multimedia processing by in-vehicle infotainment systems, and real-time processing of vehicle-to-everything (V2X) communication protocol stacks. Therefore, to simultaneously meet requirements for high-performance computing, real-time response, functional safety (such as ASIL-D level in ISO 26262), and low power consumption, multi-core processors have become the mainstream choice for vehicle control systems. However, existing vehicle control systems cannot guarantee the continued effective collaborative operation of systems such as generators and engines even in the event of a computational error in the processor core. Summary of the Invention
[0003] This application provides a vehicle control method, a vehicle control system, and a vehicle, which can avoid the problem of failure of the coordinated operation of various actuators due to processor core calculation errors.
[0004] The technical solution of this application embodiment is implemented as follows: In a first aspect, embodiments of this application provide a vehicle control method applied to a main control chip in a vehicle. The main control chip includes multiple main control cores and an instruction arbitration core. The multiple main control cores are used to control multiple actuators in the vehicle. The method includes: determining a first control signal corresponding to each actuator based on a vehicle signal corresponding to each actuator through each main control core, and sending the vehicle signal and the first control signal corresponding to each actuator to the instruction arbitration core; determining a second control signal corresponding to each actuator based on the vehicle signal corresponding to each actuator through the instruction arbitration core, and determining whether the first control signal corresponding to each actuator is abnormal based on the second control signal corresponding to each actuator; in the case of an abnormal first control signal corresponding to a first actuator among the multiple actuators, sending the second control signal corresponding to the first actuator to a first main control core through the instruction arbitration core; the multiple main control cores include a first main control core; and controlling a first actuator based on the second control signal corresponding to the first actuator through the first main control core.
[0005] In this embodiment, the control signals output by multiple main control cores are verified by the instruction arbitration core. This can avoid the failure of the engine and generator in the vehicle to work together due to calculation errors of the main control core, and ensure that there are no risks such as mismatch, over-adjustment, or oscillation in the coordinated control of power, torque, and speed of the engine and generator.
[0006] In some implementations, the second control signal corresponding to each actuator is determined by the command arbitration core based on the vehicle signal corresponding to each actuator. This includes: determining the target control signal of the vehicle signal corresponding to each actuator in a preset mapping relationship by the command arbitration core; the preset mapping relationship includes preset vehicle signals and preset control signals corresponding to the preset vehicle signals, the preset vehicle signals include the vehicle signals corresponding to each actuator, and the preset control signals include the target control signals corresponding to each actuator; adjusting the target control signals based on the deviation between the first control signals corresponding to each actuator and the target control signals by the command arbitration core to obtain the second control signals corresponding to each actuator.
[0007] In this embodiment, the control signals output by each main control core can be cross-core heterogeneous verified through the instruction arbitration core to avoid sending erroneous control signals to the actuators, thereby ensuring that there are no risks such as mismatch, over-adjustment, or oscillation in the coordinated control of power, torque, and speed of each actuator.
[0008] In some embodiments, the method further includes: determining whether the first control signal corresponding to each actuator is valid through an instruction arbitration core; invalid first control signals corresponding to each actuator include at least one of the following: an out-of-bounds error signal, a signal exceeding the vehicle's physical limits, or a signal exceeding the vehicle's safety boundaries; if the first control signal corresponding to a second actuator among multiple actuators is invalid, sending a prohibition command to a second main control core through the instruction arbitration core; the prohibition command is used to prohibit the second main control core from controlling the second actuator based on the first control signal corresponding to the second actuator, and the multiple main control cores include the second main control core.
[0009] In this embodiment, the legality and safety threshold of the control commands output by each main control core can be verified by the instruction arbitration core to prevent obvious out-of-bounds signal output caused by software logic errors, memory out-of-bounds or external interference, and to intercept control signals that exceed physical limits or system safety boundaries. This ensures that there are no risks such as mismatch, over-adjustment or oscillation in the coordinated control of power, torque and speed of each actuator.
[0010] In some implementations, the method further includes: when the first control signal corresponding to each actuator is normal and valid, controlling each actuator through each main control core based on the first control signal corresponding to each actuator.
[0011] In this embodiment, the first control signal, which has undergone multi-level verification, is output to the corresponding actuator, which can avoid the risks of actuator mismatch, over-adjustment, oscillation, etc., thereby ensuring the safety of vehicle control.
[0012] In some implementations, each main control core determines a first control signal corresponding to each actuator based on the vehicle signal corresponding to each actuator. This includes: processing the vehicle signal corresponding to each actuator using a first control algorithm in the main path to obtain a first signal corresponding to each actuator; processing the vehicle signal corresponding to each actuator using a second control algorithm in the secondary path to obtain a second signal corresponding to each actuator; the first control algorithm and the second control algorithm are different; and when the first signal and the second signal corresponding to each actuator are the same, the first signal corresponding to each actuator is determined as the first control signal corresponding to each actuator.
[0013] In this embodiment, the main control core can determine the control signals of components such as generators or engines through dual-path parallel calculation, thereby comparing the consistency of the dual-path calculation results to ensure the correctness and effectiveness of the calculation results.
[0014] In some implementations, the multiple processor cores also include redundant backup cores, and the main control chip also includes independent memory regions accessed independently by the redundant backup cores and shared memory regions accessed by the multiple processor cores; the shared memory regions are used to store mirror data of each main control core and instruction arbitration core; the method further includes: reading mirror data from the shared memory region through the redundant backup cores and writing the mirror data into the independent memory region corresponding to the redundant backup cores; in the event of a failure of the target processor core, reading the target mirror data corresponding to the target processor core from the independent memory region through the redundant backup cores; the target processor core is at least one main control core and / or instruction arbitration core, and the target mirror data is mirror data of at least one main control core and / or instruction arbitration core; executing the target task of the target processor core based on the target mirror data corresponding to the target processor core through the redundant backup cores.
[0015] In this embodiment, when the processor core (such as the main control core or instruction arbitration core) in the main control chip fails, the redundant backup core can take over the control task of the failed processor core, thereby ensuring that the whole vehicle has no power interruption, no control jitter, and no functional degradation.
[0016] In some implementations, the shared memory region is used for the time information and verification information corresponding to the mirror data. Reading the mirror data from the shared memory region through the redundant backup core and writing the mirror data into the independent memory region corresponding to the redundant backup core includes: reading the mirror data, along with the time information and verification information of the mirror data, from the shared memory region through the redundant backup core; if the time information corresponding to the mirror data is continuous, determining valid mirror data in the mirror data through the redundant backup core based on a preset verification algorithm and the verification information corresponding to the mirror data; and writing the valid mirror data into the independent memory region corresponding to the redundant backup core through the redundant backup core.
[0017] In this embodiment, by setting time information for the mirror data to verify its continuity, replay attacks can be avoided; and by setting verification information for the mirror data, the integrity of the mirror data can be verified, thereby ensuring that the mirror data written to the independent memory area corresponding to the redundant backup core is valid mirror data, and thus the redundant backup core can correctly take over the control tasks of the processor core based on the valid mirror data.
[0018] In some implementations, the method further includes: when the target main control core determines that the vehicle is in an extreme operating condition based on the vehicle signal corresponding to the target actuator, sending a priority adjustment request to the main control chip; the multiple main control cores include the target main control core, and the multiple actuators include the target actuator; upon receiving the priority adjustment request from the target main control core, determining the task priority corresponding to the task of each processor core; the real-time task of the target main control core has the highest priority among all tasks of the target main control core.
[0019] In this embodiment, the task priority of each processor core can be adjusted under extreme operating conditions to ensure stable operation of the vehicle under all operating conditions.
[0020] In some implementations, the multiple processor cores also include redundant backup cores, and the main control chip also includes an independent memory region accessed independently by the redundant backup cores and a shared memory region accessed by the multiple processor cores; the shared memory region is used to store mirror data of each main control core and instruction arbitration core; the method further includes: determining whether the vehicle signal corresponding to the target actuator meets the task takeover conditions through the redundant backup cores; if the vehicle signal corresponding to the target actuator meets the task takeover conditions, reading the mirror data corresponding to the target main control core from the independent memory region through the redundant backup cores; and executing the target task of the target main control core based on the mirror data corresponding to the target main control core through the redundant backup cores.
[0021] In this embodiment, when the target main control core detects that the vehicle is under extreme operating conditions, the control tasks of the target main control core can be taken over by the redundant backup core to ensure the stable operation of the vehicle under all operating conditions and to ensure that the fusion control accuracy and system stability do not decrease under all operating conditions.
[0022] Secondly, embodiments of this application provide a vehicle control system. The system includes a main control chip and a drive circuit in the vehicle. The main control chip includes multiple processor cores, each of which includes multiple main control cores and an instruction arbitration core. The multiple main control cores are used to control the drive circuits of multiple actuators in the vehicle. Each main control core is configured to determine a first control signal corresponding to each actuator based on a vehicle signal corresponding to that actuator, and send the vehicle signal and the first control signal to the instruction arbitration core. The instruction arbitration core is configured to determine a second control signal corresponding to each actuator based on the vehicle signal corresponding to that actuator, and determine whether the first control signal corresponding to each actuator is abnormal based on the second control signal. Furthermore, if the first control signal corresponding to the first actuator is abnormal, the second control signal corresponding to the first actuator is sent to the first main control core. The multiple main control cores include the first main control core. Each main control core is also configured to send the second control signal corresponding to the first actuator to the drive circuit of the first actuator, and the drive circuit of the first actuator controls the operation of the first actuator based on the second control signal corresponding to the first actuator.
[0023] In some implementations, the multiple processor cores also include redundant backup cores, and the main control chip also includes independent memory regions accessed independently by the redundant backup cores and shared memory regions accessed by the multiple processor cores. The shared memory regions are used to store mirror data of each main control core and instruction arbitration core. The redundant backup cores are further configured to: read mirror data from the shared memory regions and write the mirror data to the independent memory regions corresponding to the redundant backup cores; in the event of a failure of the target processor core, read the target mirror data corresponding to the target processor core from the independent memory regions; the target processor core is at least one main control core and / or instruction arbitration core, and the target mirror data is mirror data of at least one main control core and / or instruction arbitration core; and execute the target task of the target processor core based on the target mirror data corresponding to the target processor core.
[0024] Thirdly, embodiments of this application provide a vehicle control device, comprising: a first determining module configured to determine a first control signal corresponding to each actuator based on a vehicle signal corresponding to each actuator via each main control core, and to send the vehicle signal and the first control signal corresponding to each actuator to an instruction arbitration core; a second determining module configured to determine a second control signal corresponding to each actuator based on the vehicle signal corresponding to each actuator via the instruction arbitration core, and to determine whether the first control signal corresponding to each actuator is abnormal based on the second control signal corresponding to each actuator; a first sending module configured to send the second control signal corresponding to the first actuator to a first main control core via the instruction arbitration core when the first control signal corresponding to the first actuator among multiple actuators is abnormal; the multiple main control cores include the first main control core; and a control module configured to control the first actuator via the first main control core based on the second control signal corresponding to the first actuator.
[0025] Fourthly, embodiments of this application provide a vehicle that includes a main control chip, which implements some or all of the steps in the vehicle control method.
[0026] Fifthly, embodiments of this application provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements some or all of the steps in the vehicle control method.
[0027] Sixthly, embodiments of this application provide a program product including a computer program or instructions, which, when executed by a processor, implement some or all of the steps in the vehicle control method.
[0028] It should be understood that the above general description and the following detailed description are merely exemplary and explanatory, and are not intended to limit the technical solutions of this application. Attached Figure Description
[0029] Figure 1 A schematic diagram of a vehicle provided for an embodiment of this application; Figure 2 A schematic diagram illustrating task allocation for a multiprocessor core, provided as an embodiment of this application; Figure 3 A schematic diagram illustrating inter-core isolation provided in an embodiment of this application; Figure 4 A flowchart illustrating the implementation of a vehicle control method provided in this application embodiment; Figure 5 A flowchart illustrating the implementation of a system overall operation method provided in this application embodiment; Figure 6 This is a schematic diagram of the composition structure of a vehicle control device provided in an embodiment of this application.
[0030] It should be noted that the terms "first" and "second" mentioned above are only used to distinguish between different options and do not represent the degree of superiority or inferiority of the options or their priority in the implementation process. Detailed Implementation
[0031] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application are further described in detail below with reference to the accompanying drawings and embodiments. The described embodiments should not be regarded as limitations on this application. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0032] In the following description, references to "some embodiments" refer to a subset of all possible embodiments. It is understood that "some embodiments" may be the same or different subsets of all possible embodiments and may be combined with each other without conflict. The terms "first / second / third" are used merely to distinguish similar objects and do not represent a specific ordering of objects. It is understood that "first / second / third" may be interchanged in a specific order or sequence where permitted, so that the embodiments of this application described herein can be implemented in an order other than that illustrated or described herein.
[0033] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains. The terminology used herein is for descriptive purposes only and is not intended to limit the scope of this application.
[0034] In related technologies, the engine controller and generator control controller of range-extended electric vehicles exist independently and are distributed, resulting in low utilization of the front compartment space and complex system layout. Signals are exchanged via Controller Area Network (CAN) / Local Interconnect Network (LIN) buses, leading to problems such as high communication latency, low synchronization accuracy, weak fault redundancy, and poor system integration. Existing vehicle control systems physically integrate the Power Electronics Unit (PEU) and Engine Control Unit (ECU) and use a Microcontroller Unit (MCU) for algorithmic control. However, existing vehicle control systems cannot ensure the continuous and effective collaborative operation of the generator, engine, and other systems even in the event of a computational error in the processor core.
[0035] Based on the above-mentioned technical problems, the embodiments of this application provide a vehicle control method, a vehicle control system, and a vehicle, which can maintain the continuous and effective collaborative work of each actuator even when a calculation error occurs in the processor core of the vehicle control system, so as to ensure that there are no risks such as mismatch, over-adjustment, or oscillation in the collaborative control of power, torque, speed, etc. of each actuator.
[0036] Figure 1 A schematic diagram of a vehicle provided in an embodiment of this application, such as... Figure 1 As shown, the vehicle 100 includes a vehicle control system 110, which includes a main control chip 120 and a drive circuit 130. The main control chip 110 includes multiple processor cores, which may include multiple main control cores 10 (such as main control core 01, main control core 02, etc.), an instruction arbitration core 11, and a redundant backup core 12.
[0037] In some embodiments, the vehicle 100 also includes multiple actuators, which may include an engine and a generator. Multiple main control cores 10 can be used to control the drive circuits 130 corresponding to the multiple actuators, such as main control core 01 controlling the engine drive circuit 130 and main control core 02 controlling the generator drive circuit 130. The engine drive circuit 130 is used to drive the engine, and the generator drive circuit 130 is used to drive the generator.
[0038] refer to Figure 2 The diagram shown illustrates task allocation across a multi-processor core. Figure 2 As shown, taking multiple main control cores 10, including main control core 01 (i.e., Core0) and main control core 02 (i.e., Core1), and multiple actuators including an engine and a generator as an example, the main control core 01 can be configured as the main control core of the engine controller, completely isolated from the related operations of the generator controller, only performing tasks related to engine control, and only authorized to access peripherals such as the engine-type analog-to-digital converter (ADC), general-purpose input / output (GPIO), pulse-width modulation (PWM), and instrument cluster unit (ICU), and prohibited from accessing peripherals related to the generator such as current loop control, power sampling, and bus control, so as to achieve strong software and hardware isolation.
[0039] Furthermore, the control tasks executed by the main control core 01 can be configured for hard real-time scheduling (e.g., 1ms) and the task priority can be set to the highest level in the system. Additionally, an independent watchdog timer, an independent self-test module, and an independent interrupt vector table can be configured. The control tasks executed by the main control core 01 can include engine intake airflow acquisition, fuel injection control, ignition timing control, idle speed closed-loop control, knock detection and suppression, emission closed-loop control, cylinder pressure monitoring, engine torque calculation, engine sensor signal acquisition, and actuator drive control tasks such as throttle body / injector / ignition coil.
[0040] For example, the main control chip may further include independent memory regions that are independently accessed by each main control core 10, instruction arbitration core 11, and redundant backup core 12, as well as a shared memory region that can be accessed by multiple processor cores. Each independent memory region is used to store data for its respective processor core, while the shared memory region is used to store mirror data for each main control core and instruction arbitration core.
[0041] For example, the main control core 02 can be configured as a dedicated main control core for the generator, completely isolated from the physical address space of the main control core 01. It does not execute any engine control logic and is only authorized to access generator peripherals such as current loop control, power sampling, and bus control, with no cross-access permissions to engine peripherals. Furthermore, the control tasks executed by the main control core 02 can be configured for hard real-time periodicity (e.g., 1ms), running in parallel and independently with the main control core 01 without interference. The control tasks executed by the main control core 02 can include actuator drive control tasks such as generator current loop control, output voltage, bus power closed-loop control, charging power distribution, current limiting protection control, and generator overcurrent, overvoltage, overtemperature, and insulation fault monitoring.
[0042] For example, the command arbitration core 11 (i.e., Core2) can be configured as a collaborative arbitration and data security core. This core can focus on inter-core interaction and control security without directly driving the actuators in the vehicle. The main tasks performed by the command arbitration core 11 may include inter-core data interaction management, system global clock synchronization, control timing calibration, collaborative matching of engine torque demand and generator output power, shared data cyclic redundancy check (CRC), digital filtering, abnormal data elimination and fault tolerance processing, system status acquisition, fault information aggregation and hierarchical management, and arbitration of the legality of generator and engine control commands and output permission determination.
[0043] For example, the redundant backup core 12 (i.e., Core 3) can be configured as an independent redundant backup (hot mirror) core. Under normal circumstances, this core can not participate in control operations and performs the following tasks: real-time monitoring of the running status of multiple main control cores 10 and instruction arbitration core 11; hot mirroring of data such as key parameters, task context, and control model running status; fault identification, priority preemption and seamless takeover; and execution of a lightweight and robust backup control model after a fault. The redundant backup core 12 has independent interrupts, independent memory, an independent scheduler, and an independent watchdog timer, and is isolated from other processor core software to ensure independent and reliable startup in the event of a fault.
[0044] refer to Figure 3 The diagram shown illustrates internuclear isolation, as follows: Figure 3 As shown, based on the memory protection and software partitioning technology of the hardware memory protection unit (MPU), independent program flash, independent random access memory (RAM) data stack, independent interrupt vector table, and independent peripheral access permissions can be allocated to multiple processor cores, prohibiting illegal cross-core access, cross-core instruction calls, and shared peripheral conflicts. When any processor core experiences a fault such as program crash, data overflow, computational freeze, or watchdog overflow, the memory protection unit can immediately lock the resources of the faulty processor core and cut off its control over peripherals and the system bus, thus locking the fault within that processor core and preventing it from spreading to other processor cores. This achieves the high robustness goal of preventing global paralysis from a single point of failure. Subsequently, the redundant backup core 12 can take over the control tasks of the faulty processor core to ensure the vehicle can operate normally.
[0045] Figure 4 The flowchart illustrating a vehicle control method provided in this application embodiment can be executed by a main control chip in the vehicle. This main control chip includes multiple processor cores, including multiple main control cores and an instruction arbitration core. The multiple main control cores are used to control multiple actuators in the vehicle. Figure 4 As shown, the method includes S401 to S404: S401 determines the first control signal corresponding to each actuator based on the vehicle signal corresponding to each actuator through each main control core, and sends the vehicle signal and the first control signal corresponding to each actuator to the instruction arbitration core through the inter-core communication channel.
[0046] In some implementations, each main control core in the vehicle can acquire vehicle signals related to each actuator in real time during the current control cycle, such as engine speed, torque, bus voltage, bus current, and insulated-gate bipolar transistor (IGBT) temperature. For example, main control core 01 can acquire vehicle signals related to the engine in real time during the current control cycle, and main control core 02 can acquire vehicle signals related to the generator in real time during the current control cycle. It should be noted that the following embodiments refer to the processing of vehicle signals and control signals in the current control cycle, and therefore will not be elaborated further below.
[0047] In some implementations, after acquiring the vehicle signal corresponding to each actuator, each main control core can determine the control signal (hereinafter referred to as the first control signal) corresponding to each actuator based on the vehicle signal corresponding to each actuator. For example, the method of determining the first control signal corresponding to each actuator may include prediction based on a preset model, or calculation based on a preset algorithm, preset control strategy, etc., which is not limited in the embodiments of this application.
[0048] In some implementations, after determining the first control signal corresponding to each actuator, each main control core can send the first control signal corresponding to each actuator to the command arbitration core 11 through the inter-processor communication (IPC) channel. For example, main control core 01 can send the first control signal of the current control cycle corresponding to the engine to the command arbitration core 11 through the IPC channel, and main control core 02 can send the first control signal of the current control cycle corresponding to the generator to the command arbitration core 11 through the IPC channel.
[0049] S402, through the command arbitration core, determines the second control signal corresponding to each actuator based on the vehicle signal corresponding to each actuator, and determines whether the first control signal corresponding to each actuator is abnormal based on the second control signal corresponding to each actuator.
[0050] In some implementations, after receiving the first control signal corresponding to each actuator, the instruction arbitration core 11 can determine the correctness of the first control signal corresponding to each actuator (i.e., whether there is an anomaly) to prevent control errors caused by algorithm deviations or data anomalies.
[0051] For example, the command arbitration core 11 can determine the control signal (hereinafter referred to as the second control signal) corresponding to each actuator based on the vehicle signal corresponding to each actuator. The method by which the command arbitration core 11 determines the second control signal corresponding to each actuator may include prediction based on a preset model, or calculation based on a preset algorithm, preset control strategy, etc., which is not limited in this embodiment; and the method by which the command arbitration core 11 determines the second control signal may be different from the method by which the main control core determines the first control signal.
[0052] In some implementations, after determining the second control signal corresponding to each actuator, the instruction arbitration core 11 can compare the first and second control signals corresponding to each actuator to determine whether the first control signal is abnormal based on the second control signal. If the first and second control signals corresponding to each actuator are consistent, or the deviation between them is less than or equal to a preset threshold, the first control signal can be determined to be normal; if the first and second control signals corresponding to each actuator are inconsistent, or the deviation between them is greater than the preset threshold, the first control signal can be determined to be abnormal.
[0053] S403, in the event of an abnormal first control signal corresponding to the first actuator among multiple actuators, the second control signal corresponding to the first actuator is sent to the first main control core through the instruction arbitration core.
[0054] In some implementations, if the first control signal corresponding to one or more actuators (hereinafter referred to as the first actuator) is abnormal, the instruction arbitration core 11 can send the determined second control signal to the corresponding main control core (hereinafter referred to as the first main control core) through the inter-core communication channel. For example, if the first control signal calculated by the main control core 01 is abnormal, the instruction arbitration core 11 can send the second control signal corresponding to the engine to the main control core 01 through the IPC channel; if the first control signal calculated by the main control core 02 is abnormal, the instruction arbitration core 11 can send the first control signal corresponding to the generator to the main control core 02 through the IPC channel.
[0055] S404 controls the first actuator through the first main control core based on the second control signal corresponding to the first actuator.
[0056] In some implementations, after receiving a second control signal corresponding to the first actuator in the current control cycle, the first main control core can control the first actuator based on the second control signal. For example, main control core 01 can send the received second control signal corresponding to the engine to the drive circuit corresponding to the engine, so that the drive circuit drives the engine to run; main control core 02 can send the received second control signal corresponding to the generator to the drive circuit corresponding to the generator, so that the drive circuit drives the generator to run.
[0057] In this embodiment, the control signals output by multiple main control cores are verified by the instruction arbitration core. This can avoid the failure of the engine and generator in the vehicle to work together due to calculation errors of the main control core, and ensure that there are no risks such as mismatch, over-adjustment, or oscillation in the coordinated control of power, torque, and speed of the engine and generator.
[0058] In some implementations, each main control core determines a first control signal corresponding to each actuator based on the vehicle signal corresponding to each actuator. This includes: processing the vehicle signal corresponding to each actuator using a first control algorithm in the main path to obtain a first signal corresponding to each actuator; processing the vehicle signal corresponding to each actuator using a second control algorithm in the secondary path to obtain a second signal corresponding to each actuator; the first control algorithm and the second control algorithm are different; and when the first signal and the second signal corresponding to each actuator are the same, the first signal corresponding to each actuator is determined as the first control signal corresponding to each actuator.
[0059] For example, the process of generating control signals for each actuator from each main control core can be subject to multi-level verification to ensure the correctness of the control signals. For instance, a three-level verification can be set up. The first-level verification can perform path consistency comparison on the control signals output by the main control core within the current control cycle to ensure the validity of the output results; the second-level verification can perform a safety threshold judgment on the control signals; and the third-level verification can perform cross-core heterogeneous verification of the control signals. In some examples, the first-level verification can be performed before the second-level and third-level verifications; the second-level and third-level verifications can be executed in parallel or sequentially; in the case of sequential execution, the second-level verification can be performed first, followed by the third-level verification, or vice versa. This application does not limit the execution order of the second-level and third-level verifications.
[0060] For example, in the first-level verification, each main control core can perform dual-path parallel calculation based on the vehicle signal corresponding to each actuator. That is, it determines the corresponding control signal based on different control algorithms through the main path and the secondary path, and compares the control signal determined by the main path (hereinafter referred to as the first signal) and the control signal determined by the secondary path (hereinafter referred to as the second signal) to determine whether the first signal determined by the main path is correct. The control algorithm used by the main path (hereinafter referred to as the first control algorithm) can be a model-based predictive algorithm, such as the Model Predictive Control (MPC) algorithm; the control algorithm used by the secondary path (hereinafter referred to as the second control algorithm) can be a Proportional-Integral-Derivative Controller (PID), current clamping, etc. In this embodiment, the first control algorithm and the second control algorithm are not limited; the first control algorithm and the second control algorithm are different control algorithms.
[0061] In the current control cycle, if the first signal determined by the main path is consistent with the second signal determined by the secondary path, the main control core can determine the first signal obtained by the main path as the first control signal. If the control signals output by the main path and the secondary path are consistent, the main control core can determine that the calculation result of the main path is reliable and send the control signal corresponding to the actuator output by the main path (i.e., the first control signal) to the drive circuit of the actuator, or send the first control signal corresponding to the actuator to the command arbitration core to continue to perform secondary and tertiary verification on the first control signal through the command arbitration core; if the control signals corresponding to the actuator output by the main path and the secondary path are inconsistent, the main control core can determine that the calculation result of the main path is unreliable. At this time, the first control signal is not sent to the engine power drive circuit, and the calculation can be re-performed and / or the calculation abnormality status can be reported.
[0062] For example, taking the generator control process of the main control core 02 as an example, under high-current charging conditions, the generator needs to quickly convert kinetic energy into electrical energy to charge the battery. At this time, the bus current increases instantaneously, which poses an overcurrent risk. Therefore, it is necessary to precisely control the IGBT duty cycle to maintain the bus voltage stability and prevent overcurrent. The specific dual-path parallel solution architecture is shown in Table 1: Table 1 Comparison of Dual-Path Parallel Solving Architectures
[0063] In some examples, the main control core 02 can first acquire vehicle signals corresponding to the current control cycle, such as bus voltage, bus current, IGBT temperature, and engine speed. The main control core 02 can predict the bus changes for the next 5 control cycles based on the generator state-space model through the main path, and solve for the optimal control sequence to minimize voltage error and prevent it from exceeding limits. Furthermore, it can set the target bus voltage and adjust the deviation by combining the real-time sampled values through the secondary path based on a constant voltage PID control strategy. At the same time, it can configure an overcurrent clamping mechanism so that when the bus current exceeds the safety threshold, the duty cycle command can be reduced immediately to prevent IGBT overheating or battery overcharging. If the control signals output by the main path and the secondary path are consistent, the calculation result of the main path can be determined to be reliable, and the control signal output by the main path (i.e., the first control signal) is sent to the generator power drive circuit, or the first control signal is further verified by the instruction arbitration core for secondary and tertiary verification. If the control signals output by the main path and the secondary path are inconsistent, the calculation result of the main path can be determined to be unreliable. At this time, the main control core 02 does not send the first control signal to the engine power drive circuit, and can recalculate and / or report the abnormal calculation status.
[0064] In this embodiment, the main control core can determine the control signals of components such as generators or engines through dual-path parallel calculation, thereby comparing the consistency of the dual-path calculation results to ensure the correctness and effectiveness of the calculation results.
[0065] In some implementations, the first control signal corresponding to each actuator is determined to be valid by the instruction arbitration core; if the first control signal corresponding to the second actuator is invalid among multiple actuators, the instruction arbitration core sends a prohibition instruction to the second main control core.
[0066] For example, after the first-level verification passes, each main control core can send the first control signal corresponding to each actuator to the command arbitration core via the IPC channel, so that the command arbitration core can perform a second-level verification on the first control signal corresponding to each actuator. The second-level verification can verify the legality of the first control signal output by each main control core. Invalid first control signals corresponding to each actuator include at least one of the following: an out-of-bounds error signal, a signal exceeding the vehicle's physical limits, or a signal exceeding the vehicle's safety boundaries. This includes interference causing obvious out-of-bounds command output, or intercepting control commands exceeding physical limits or system safety boundaries.
[0067] For example, the instruction arbitration core can determine whether the parameters in the first control signal corresponding to each actuator exceed a preset safety threshold. If the parameters in the first control signal corresponding to one or more actuators (hereinafter referred to as the second actuators) exceed the preset safety threshold, then the first control signal corresponding to the second actuator is determined to be invalid. In the case that the first control signal corresponding to the second actuator is invalid among multiple actuators, the instruction arbitration core can send a prohibition command to the second main control core to prohibit the second main control core from controlling the second actuator based on the first control signal corresponding to the second actuator.
[0068] For example, at the end of the current control cycle, main control cores 01 and 02 can respectively send the first control signal corresponding to the current control cycle to the instruction arbitration core via the IPC channel. The instruction arbitration core can determine whether the parameters in the first control signals corresponding to main control cores 01 and 02 exceed a preset safety threshold. If any parameter exceeds the preset safety threshold, the instruction arbitration core can immediately set the "instruction illegal" flag and notify the main control core with the calculation anomaly to perform a self-check via IPC; at the same time, the instruction arbitration core can prevent the abnormal first control signal from being sent to the corresponding second actuator.
[0069] In this embodiment, the legality and safety threshold of the control commands output by each main control core can be verified by the instruction arbitration core to prevent obvious out-of-bounds signal output caused by software logic errors, memory out-of-bounds or external interference, and to intercept control signals that exceed physical limits or system safety boundaries. This ensures that there are no risks such as mismatch, over-adjustment or oscillation in the coordinated control of power, torque and speed of each actuator.
[0070] In some implementations, the second control signal corresponding to each actuator is determined by the command arbitration core based on the vehicle signal corresponding to each actuator. This includes: determining the target control signal of the vehicle signal corresponding to each actuator in a preset mapping relationship by the command arbitration core; and adjusting the target control signal based on the deviation between the first control signal corresponding to each actuator and the target control signal by the command arbitration core to obtain the second control signal corresponding to each actuator.
[0071] For example, after the first-level verification passes, the instruction arbitration core can also perform a third-level verification on the first control signal corresponding to each actuator. This third-level verification can monitor the correctness of the calculation results output by each main control core in real time, preventing control errors caused by algorithm deviations or data anomalies.
[0072] For example, the ideal control signals (such as fuel injection quantity, ignition angle, target power, etc.) of each actuator in the vehicle under various operating conditions can be pre-calibrated experimentally, and the pre-defined mapping relationship between the preset vehicle signals corresponding to each operating condition and the preset control signals (i.e., ideal control signals) corresponding to each preset vehicle signal can be stored as a multi-dimensional lookup table. Thus, the command arbitration core can look up the target control signal corresponding to each actuator's vehicle signal in this multi-dimensional lookup table using a lookup method. Here, the preset vehicle signals include the vehicle signals corresponding to each actuator, and the preset control signals include the target control signals corresponding to each actuator. Furthermore, the command arbitration core can also perform proportional-integral (PI) correction on the target control signal based on the deviation between the first control signal and the target control signal corresponding to each actuator to obtain the second control signal corresponding to each actuator. The PI correction is used to introduce a feedback control mechanism based on the lookup method, dynamically micro-checking the lookup result (i.e., the target control signal) according to the deviation between the actual output (e.g., the first control signal) and the target value (e.g., the target control signal).
[0073] For example, the command arbitration core can receive control signals sent by the main control core 01 / 02 in real time via the IPC channel and maintain data synchronization with the main control core 01 / 02, using the same timestamp to align the data of each core to ensure consistent comparison benchmarks. The command arbitration core can redetermine the second control signal corresponding to each actuator based on the same vehicle signals (such as engine speed and air intake volume) but using different algorithm paths than the main control cores in determining the first control signal. For example, if the main control core determines the first control signal based on the MPC model using the main path, the command arbitration core can determine the second control signal corresponding to each actuator using a secondary path based on lookup tables and PI correction. If the command arbitration core determines that the first control signal corresponding to each actuator is abnormal, it can trigger an alarm message indicating a calculation error and send a rejection signal to the arbitration module deployed in the main control chip to prevent the abnormal first control signal from being sent to the actuator's drive circuit.
[0074] In this embodiment, the control signals output by each main control core can be cross-core heterogeneous verified through the instruction arbitration core to avoid sending erroneous control signals to the actuators, thereby ensuring that there are no risks such as mismatch, over-adjustment, or oscillation in the coordinated control of power, torque, and speed of each actuator.
[0075] In some implementations, the method further includes: when the first control signal corresponding to each actuator is normal and valid, controlling each actuator through each main control core based on the first control signal corresponding to each actuator.
[0076] For example, if the instruction arbitration core determines that the first control signal corresponding to each actuator is normal based on the second control signal corresponding to each actuator, and the parameters in the first control signal corresponding to each actuator do not exceed the preset safety threshold, then each main control core can control each actuator based on the first control signal corresponding to each actuator.
[0077] In this embodiment, the first control signal, which has undergone multi-level verification, is output to the corresponding actuator, which can avoid the risks of actuator mismatch, over-adjustment, oscillation, etc., thereby ensuring the safety of vehicle control.
[0078] In some implementations, the method further includes: reading image data from a shared memory region via a redundant backup core and writing the image data into an independent memory region corresponding to the redundant backup core; in the event of a failure of the target processor core, reading the target image data corresponding to the target processor core from the independent memory region via the redundant backup core; and executing the target task of the target processor core based on the target image data corresponding to the target processor core via the redundant backup core.
[0079] For example, the main control chip can allocate read-only mirror buffers for each main control core and instruction arbitration core in the shared memory area. That is, the shared memory area includes read-only mirror buffers corresponding to each main control core (e.g., main control core 01, main control core 02) and instruction arbitration core. During each control cycle, each main control core and instruction arbitration core can package the current control context (i.e., mirror data) and write it to the corresponding read-only mirror buffer via IPC. In some examples, the mirror data for the main control core corresponding to the engine may include intake airflow acquisition, fuel injection control, ignition timing control, task execution time, watchdog timer status, etc.; the mirror data for the main control core corresponding to the generator may include current loop control, power sampling, bus control, etc.; and the mirror data for the instruction arbitration core may include instruction arbitration results, fault summary levels, inter-core communication latency statistics, data verification failure counts, etc.
[0080] In some examples, all write operations on mirrored data can be atomic to prevent data inconsistencies caused by interruptions. Furthermore, shared memory regions (or shared memory buffers) can employ a double-buffering mechanism (Ping-Pong Buffer) to separate writes from reads, thereby avoiding resource contention.
[0081] For example, during each control cycle, the redundant backup core can synchronize the mirror data of each main control core and instruction arbitration core from the shared memory region to the independent memory region corresponding to the redundant backup core in real time. In some examples, the redundant backup core can poll the IPC interrupt at a fixed period, that is, continuously check whether there is new mirror data or status update written by other processor cores via IPC. If there is newly written mirror data in the shared memory region, the redundant backup core reads the corresponding mirror data from the shared memory region and writes it to the independent memory region corresponding to the redundant backup core. In some examples, if the redundant backup core does not receive mirror data from any processor core for several consecutive times (e.g., 3 times), it can trigger a core unresponsive fault flag.
[0082] For example, in the event of a failure in any main control core and / or instruction arbitration core (hereinafter referred to as the target processor core), the redundant backup core can read the target image data corresponding to the target processor core from its independent memory area. The target processor core is at least one main control core and / or instruction arbitration core, and the target image data is the image data of at least one main control core and / or instruction arbitration core. Failures to the processor core may include task timeouts, data CRC check errors, no response from the processor core, processor core temperature exceeding limits, abnormal power supply voltage, etc., which are not limited in this embodiment. After obtaining the target image data corresponding to the target processor core, the redundant backup core can take over the target processor core and execute the corresponding target task based on the target image data.
[0083] In some examples, when the target processor core fails, the redundant backup core can immediately cut off the target processor core's output permissions and seize control to directly take over the target processor core's control tasks, thereby ensuring that the vehicle experiences no power interruption, no control jitter, and no functional degradation. For example, if the engine continuously outputs power while the vehicle is traveling at high speed, and the main control core corresponding to the engine malfunctions due to a program crash causing the watchdog timer to fail to feed on time, triggering an overflow, the redundant backup core can take over the main control core and broadcast the power system degradation status flag to the vehicle network via CAN communication to ensure normal vehicle operation. The takeover process of the redundant backup core is shown in Table 2. Table 2 Redundant Backup Core Takeover Process Table
[0084] The redundancy control model can be a simplified, highly robust actuator (such as engine) control strategy enabled by the redundant backup core. It should be noted that the takeover process of the redundant backup core described above is merely an example, and the specific takeover method is not limited in this embodiment.
[0085] In this embodiment, when the processor core (such as the main control core or instruction arbitration core) in the main control chip fails, the redundant backup core can take over the control task of the failed processor core, thereby ensuring that the whole vehicle has no power interruption, no control jitter, and no functional degradation.
[0086] In some implementations, the redundant backup core reads image data from the shared memory region and writes the image data into the independent memory region corresponding to the redundant backup core. This includes: reading the image data corresponding to the current control cycle, as well as the time information and verification information of the image data, from the shared memory region via the redundant backup core; if the time information corresponding to the image data is continuous, determining valid image data in the image data based on a preset verification algorithm and the verification information corresponding to the image data via the redundant backup core; and writing the valid image data into the independent memory region corresponding to the redundant backup core via the redundant backup core.
[0087] For example, the shared memory area can also store the time information and verification information of the image data corresponding to the current control cycle. That is, each main control core and instruction arbitration core can package the current image data into the corresponding buffer in each control cycle, and attach the time information (such as a timestamp) and verification information (such as a CRC32 checksum) corresponding to the image data. The verification information corresponding to the image data can be obtained by processing the image data based on a preset verification algorithm.
[0088] For example, after reading the image data of each core from the shared memory area, the redundant backup core can verify whether the time information corresponding to each image data is continuous. For instance, if the difference between the timestamps of the image data corresponding to the current control cycle and the previous control cycle is equal to a preset time difference, then the time information corresponding to the image data can be determined to be continuous; otherwise, it is not continuous. Next, if the time information corresponding to each image data is continuous, the integrity of the image data can be verified based on a preset verification algorithm and the verification information corresponding to the image data, and valid image data can be identified to discard corrupted data. Then, the redundant backup core can write the valid image data into the independent memory area corresponding to the redundant backup core, thereby completing the backup of the image data of each main control core and instruction arbitration core.
[0089] In this embodiment, by setting time information for the mirror data to verify its continuity, replay attacks can be avoided; and by setting verification information for the mirror data, the integrity of the mirror data can be verified, thereby ensuring that the mirror data written to the independent memory area corresponding to the redundant backup core is valid mirror data, and thus the redundant backup core can correctly take over the control tasks of the processor core based on the valid mirror data.
[0090] In some implementations, the method further includes: when the target main control core determines that the vehicle is in an extreme operating condition based on the vehicle signal corresponding to the target actuator, sending a priority adjustment request to the main control chip; and upon receiving the priority adjustment request from the target main control core, determining the task priority corresponding to the task of each processor core.
[0091] For example, when one or more main control cores (hereinafter referred to as target main control cores) detect that the vehicle is under extreme operating conditions based on vehicle signals from their corresponding actuators (hereinafter referred to as target actuators), the main control chip can adjust the task priorities corresponding to the tasks of each processor core. Here, multiple main control cores include target main control cores, and multiple actuators include target actuators; extreme operating conditions can include cold start, rapid acceleration, high-current charging, etc. For example, the target main control core can send a priority adjustment request to the main control chip. Upon receiving the priority adjustment request from the target main control core, the main control chip can adjust the task priorities corresponding to the tasks of each processor core, and among all tasks of the target main control core, adjust the priority of the real-time tasks of the target main control core to the highest priority to avoid resource contention between the non-real-time tasks of the target main control core and the real-time tasks. The non-real-time tasks are non-hard real-time control tasks such as diagnostics, logging, and communication of the main control core, and can include tasks such as open-loop lookup table control (e.g., fuel injection map, torque map, fixed parameter PI adjustment).
[0092] In some examples, the method for adjusting the task priorities corresponding to tasks on each processor core can be seen in Table 3: Table 3 Processor Core Task Priority Description
[0093] It should be noted that the priority levels corresponding to the above task types are merely examples, and are not limited in this embodiment.
[0094] In this embodiment, the task priority of each processor core can be adjusted under extreme operating conditions to ensure stable operation of the vehicle under all operating conditions.
[0095] In some implementations, the method further includes: determining whether the vehicle signal corresponding to the target actuator meets the task takeover conditions through a redundant backup core; if the vehicle signal corresponding to the target actuator meets the task takeover conditions, reading the mirror data corresponding to the target main control core from an independent memory area through the redundant backup core; and executing the target task of the target main control core based on the mirror data corresponding to the target main control core through the redundant backup core.
[0096] For example, when one or more main control cores (hereinafter referred to as the target main control core) detect that the vehicle is under extreme operating conditions, a preset simplified control strategy can be loaded into its independent memory area through a redundant backup core. Based on the simplified control strategy, the backup core can determine whether the vehicle signal corresponding to the target actuator meets the task takeover conditions (e.g., temperature < 5°C, acceleration > 0.3g). If the vehicle signal corresponding to the target actuator meets the task takeover conditions, the redundant backup core can take over the control task of the target main control core. It is understood that the method by which the redundant backup core takes over the control task of the target main control core can be referred to the description in the above embodiments, and will not be repeated here. For example, in cold start mode, the redundant backup core can obtain mirror data such as open-loop fuel injection and ignition angle, and execute the target task of the target main control core based on the mirror data corresponding to the target main control core, without recalculation or loading.
[0097] In addition, on the hardware side, timers can synchronize the local clocks of each processor core, and IPC communication can adopt interrupt and Direct Memory Access (DMA) modes to avoid polling delays between processor cores. Regarding scheduling strategies, the priority of inter-core communication can be elevated to the highest level. Furthermore, the arbitration tasks of the instruction arbitration core can be aligned with the control cycles of each main control core to ensure that the accuracy of fused control and system stability do not degrade under all operating conditions. For example, the rhythm of tasks such as data verification, instruction arbitration, and collaborative control decision-making performed by the instruction arbitration core is completely synchronized with the hard real-time control cycles of each main control core, ensuring that the instruction arbitration core can receive, process, and feedback arbitration results in a timely manner within each control cycle, without affecting system operation.
[0098] In this embodiment, when the target main control core detects that the vehicle is under extreme operating conditions, the control tasks of the target main control core can be taken over by the redundant backup core to ensure the stable operation of the vehicle under all operating conditions and to ensure that the fusion control accuracy and system stability do not decrease under all operating conditions.
[0099] Based on the above embodiments, this application also provides a method for the robustness of an engine control and generator control fusion system. This method uses a quad-core or higher performance processor as the hardware foundation. Taking a quad-core main control chip as an example, it constructs an integrated architecture with quad-core independent scheduling, fault isolation, hot mirroring redundancy, and collaborative arbitration.
[0100] First, the functions of the quad-core main control chip are defined: Core0 is the dedicated main control core for the ECU, independently handling ECU tasks and not participating in any PEU calculations, achieving strong software isolation for the ECU control logic. Core1 is the dedicated main control core for the PEU, independently handling PEU tasks and not participating in any ECU calculations, and is physically isolated from Core0. Core2 is the collaborative arbitration and data interaction core, not directly driving actuators, focusing on ECU and PEU fusion and collaboration and data security. Core3 is an independent backup redundant core (hot mirror), which does not perform main control tasks under normal circumstances, but continuously performs lightweight computing tasks such as status monitoring, data verification, and hot mirror synchronization of the critical operating states of Core0, Core1, and Core2, possessing immediate takeover capabilities to ensure independent and reliable startup in fault conditions.
[0101] Four mechanisms for achieving software robustness: 1. Independent standby core hot mirroring and seamless switching mechanism: Core3 adopts a hot mirroring synchronization mechanism to mirror the engine operating conditions, generator status, collaborative parameters and control models of the other three cores in real time.
[0102] 2. Collaborative control cross-validation and redundant solution mechanism.
[0103] 3. To avoid single-core calculation errors, the system is equipped with a triple security check mechanism that adapts to extreme working conditions and ensures computing power.
[0104] 4. Extreme Condition Adaptive and Computational Power Guarantee Mechanism: For extreme conditions such as cold start, rapid acceleration, and high-current charging, the system scheduler automatically locks the highest priority of the ECU and PEU cores, prohibiting non-real-time task preemption. The priority adjustment methods for various control tasks are shown in Table 3, where the highest priority refers to the highest priority within its respective task type. Actual scheduling achieves hierarchical management through hardware interrupt nesting and RTOS priority queues. Core3 preloads an extreme condition redundancy strategy, maintaining low jitter and low latency in inter-core scheduling to ensure that the fusion control accuracy and system stability do not degrade under all operating conditions. All highest priorities refer to the highest priority within their respective categories; actual scheduling achieves hierarchical management through hardware interrupt nesting and RTOS priority queues.
[0105] This application embodiment builds a hardware platform for a range-extended new energy vehicle engine control and generator control integrated control system based on a quad-core processor core in the main control chip. This system hardware may include: a main control chip, a power management module, an engine sensor signal conditioning circuit, an engine actuator drive circuit, a generator power drive circuit, a bus voltage / current sampling circuit, an insulation monitoring circuit, a storage circuit, and a communication interface circuit. The main control chip incorporates a hardware MPU memory protection unit, a multi-core independent watchdog timer, a multi-core interrupt manager, and a hardware inter-core communication IPC channel to provide hardware support for inter-core isolation, fault isolation, redundancy backup, and collaborative control of the system.
[0106] like Figure 2 As shown, the quad-core main control chip can adopt independent scheduling, independent stack, independent peripherals, and independent watchdog mode, with fixed task division, no cross-calling, and no resource preemption. Core0 is defined as a dedicated main control core for the ECU, completely isolated from PEU operations. It only executes engine control-related tasks and is only authorized to access engine-related peripherals such as ADC, GPIO, PWM, and ICU. Access to PEU-related peripherals such as generator current loop control, power sampling, and bus control is prohibited, achieving strong software and hardware isolation. Tasks are configured with a 1ms hard real-time cycle scheduling, with real-time control tasks set to the highest priority in the system. It is configured with an independent watchdog, independent self-test module, and independent interrupt vector table. It is mainly responsible for engine intake airflow acquisition, fuel injection control, ignition timing control, idle speed closed-loop control, knock detection and suppression, emission closed-loop control, cylinder pressure monitoring, engine torque calculation, engine sensor signal acquisition, and actuator drive control such as throttle body / injector / ignition coil.
[0107] Core1 is defined as a dedicated main control core for the PEU, completely isolated from Core0's physical address space. It does not execute any ECU control logic and is only authorized to access PEU-type peripherals such as generator current loop control, power sampling, and bus control. It has no cross-access permissions with engine peripherals. Tasks are also configured for 1ms hard real-time cycle scheduling, running independently and in parallel with Core0 without interference. Its main responsibilities include generator current loop control, output voltage, bus power closed-loop control, charging power distribution, current limiting protection control, and generator overcurrent, overvoltage, overtemperature, and insulation fault monitoring.
[0108] Core2 is defined as the core for collaborative arbitration and data security. It does not directly drive any actuators and focuses on inter-core interaction and control security. Its main tasks include inter-core data interaction management, system global clock synchronization, and control timing calibration; collaborative matching of engine torque demand and generator output power; shared data CRC verification, digital filtering, abnormal data removal and fault tolerance processing; system status acquisition, fault information aggregation and hierarchical management; and arbitration of the legality of ECU and PEU control commands and determination of output permission.
[0109] Core3 is an independent, redundant backup core (hot mirror). Under normal circumstances, it does not participate in control operations and only performs the following functions: real-time monitoring of the running status of Core0 / Core1 / Core2; hot mirroring mechanism for key parameters, task context, and control model running status; fault identification, priority preemption, and seamless takeover; and lightweight, highly robust backup control model execution after a fault. Core3 has independent interrupts, independent memory, an independent scheduler, and an independent watchdog timer, and is completely software isolated from the other three cores, ensuring independent and reliable startup in the event of a fault.
[0110] 1. Strong internuclear isolation and fault nonproliferation mechanism.
[0111] like Figure 3 As shown, based on hardware MPU memory protection and software partitioning technology, technicians can allocate independent program Flash, independent RAM data stack, independent interrupt vector table, and independent peripheral access permissions to the four cores, strictly prohibiting unauthorized cross-core access, cross-core instruction calls, and shared peripheral conflicts. When any core experiences a fault such as program crash, data overflow, computational freeze, or watchdog overflow, the MPU hardware immediately locks the faulty core's resources, cutting off its control over peripherals and the system bus. The fault is locked within its own core and does not spread to other cores, achieving a high degree of robustness where a single point of failure does not paralyze the entire system.
[0112] Independent backup core hot mirroring and seamless failover mechanism: Core3 adopts a running state hot mirroring mechanism, which uses hardware IPC channels + shared memory buffers + timestamps and CRC checks to achieve periodic running state hot mirroring of the critical running states of Core0, Core1, and Core2. The main control model is deployed on Core0 and Core1, the redundant control model is deployed on Core3, and only a lightweight, highly robust backup model is saved to ensure seamless takeover of control tasks in the event of a failure. The specific implementation is as follows: (1) Synchronization mechanism architecture: The engine-generator fusion control system divides multiple read-only mirror buffers in the shared SRAM of the main control chip, which correspond to the key status data of Core0, Core1 and Core2 respectively; at the end of each control cycle, each main core (Core0 / 1 / 2) packages the current control context and writes it into the corresponding buffer, and attaches a timestamp and CRC32 check code.
[0113] (2) Synchronize data content: Real-time synchronization of current mirror data of Core0, Core1, and Core2, such as intake flow acquisition, fuel injection control, ignition timing control, task execution time, watchdog feeding status, etc. of Core0; current loop control, power sampling, bus control, etc. of Core1; instruction arbitration results, fault summary level, inter-core communication delay statistics, number of data verification failures, etc. of Core2; Core3 polls IPC interrupts at fixed intervals, that is, it continuously checks whether there is new data or status updates sent from other cores (such as Core0, Core1, and Core2) through the inter-core communication channel (IPC). First, read the corresponding buffer data; then verify whether the timestamp is continuous (to prevent replay attacks); then verify CRC32 and discard corrupted data; then copy the valid data to the "hot mirror copy area" of Core3's local RAM. If no data is received from a certain core for several consecutive times (such as 3 times), the "core no response" fault flag is triggered.
[0114] (3) Synchronization guarantee mechanism: All mirror write operations are atomic operations to prevent interruption from causing data inconsistency; the buffer adopts a double buffering mechanism, separating writing and reading to avoid contention.
[0115] Through a distributed fault monitoring and diagnosis mechanism, failure modes such as task timeout, data CRC check errors, core no response, core temperature exceeding limits, and abnormal power supply voltage are monitored in real time. When the fault determination is valid, Core3 immediately takes over without interruption: immediately cuts off the output permission of the faulty core, seizes control permission, and directly takes over the corresponding core control task, ensuring no power interruption, no control jitter, and no functional degradation of the entire vehicle. If the vehicle is traveling at high speed and the engine is continuously outputting power generation, and Core0's program crashes, causing the watchdog timer to fail to feed on time and triggering an overflow, Core3 begins to take over and broadcasts the "power system degradation" status to the vehicle network via CAN communication to ensure normal vehicle operation. The takeover process can be referred to in Table 2 and will not be elaborated here.
[0116] 2. Collaborative control cross-validation and redundant solution mechanism.
[0117] The system can be configured with triple safety checks to prevent collaborative failures caused by errors in a single core calculation, ensuring that there are no risks such as mismatch, overshoot, or oscillation in the coordinated control of power, torque, and speed between the engine and generator. The first-level check is completed first, while the second and third-level checks are executed in parallel. The first-level check performs path consistency comparison within the control cycle to ensure the validity of the output results; the second-level check performs a safety threshold judgment before the command is issued; and the third-level check performs cross-core heterogeneous verification after the command is generated.
[0118] (1) First-level verification: The fusion control model adopts dual-path parallel calculation, and dual-path parallel calculation is implemented in Core0 or Core1. Taking Core1 generator control as an example, under high-current charging conditions, the generator needs to quickly convert kinetic energy into electrical energy to charge the battery. The bus current rises instantaneously, and there is a risk of overcurrent. Therefore, it is necessary to accurately control the IGBT duty cycle to maintain the bus voltage stability and prevent overcurrent. The specific dual-path parallel calculation architecture can be referred to Table 1. First, the current operating parameters such as bus voltage, bus current, IGBT temperature and engine speed can be collected. The main path predicts the bus changes in the next 5 cycles through the generator state space model and solves the optimal control sequence to minimize the voltage error and prevent it from exceeding the limit. The secondary path adopts a constant voltage PID control strategy, sets the target bus voltage and combines it with real-time sampling values for deviation adjustment, and configures an overcurrent clamping mechanism. When the bus current is detected to exceed the safety threshold, the duty cycle command is immediately reduced to prevent IGBT overheating or battery overcharging. If the two outputs are consistent, the main path calculation is considered reliable, and the main path result is output to the power drive circuit.
[0119] (2) Secondary verification: The control instructions output by Core0 and Core1 are first sent to Core2 for legality and security threshold verification. That is, at the end of each control cycle, Core0 / 1 sends the generated control instructions to Core2 through the hardware IPC channel. If any parameter exceeds the limit, Core2 immediately sets the "instruction illegal" flag and notifies Core0 / 1 to perform a self-check through IPC. At the same time, it prevents the instruction from being sent to the executor, preventing the output of obvious out-of-bounds instructions due to software logic errors, memory out-of-bounds or external interference, or intercepting control commands that exceed physical limits or system security boundaries.
[0120] (3) Three-level verification: Core2 receives input signals (such as engine speed, intake air flow, bus current, etc.) from Core0 / Core1 in real time via IPC, keeps data synchronized with the main core Core0 / 1, and uses the same timestamp to align the data of each core to ensure consistent comparison benchmark. If Core2 uses the same input signal (such as speed, intake air flow) but recalculates using different algorithm paths, the main path (Core0) is based on MPC model predictive control, and the secondary path (Core2) is based on lookup table method (the ideal control parameters of the engine or generator under various operating conditions (such as fuel injection quantity, ignition angle, target power, etc.) are pre-calibrated experimentally and stored as a multi-dimensional lookup table) and PI correction (based on the lookup table method, a feedback control mechanism is introduced to dynamically adjust the lookup table results according to the deviation between the actual output and the target value). If Core2 determines that Core0 output is abnormal, it triggers a "calculation abnormality" alarm and sends a "reject arbitration" signal to the system arbitration module to prevent the issuance of erroneous instructions.
[0121] 3. Extreme Condition Adaptation and Computational Power Guarantee Mechanism: When Core0 or Core1 detects extreme conditions such as cold start, rapid acceleration, or high-current charging, it sends a high-priority request to the fusion control system (i.e., the complete control platform composed of four cores of the main control chip working collaboratively). The system scheduler automatically locks all control tasks of Core0 and Core1 as the highest priority, prohibiting non-real-time tasks from preempting CPU resources. During the motor controller initialization phase after the vehicle is powered on, Core3 first performs CRC verification on the simplified control strategy stored in Flash. After successful verification, it is loaded into the working RAM to ensure the complete availability of redundant strategies. At the same time, each strategy comes with operating condition identification conditions (such as temperature <5℃, acceleration >0.3g) for quick matching and activation after takeover. For example, in cold start mode: open-loop fuel injection + fixed ignition angle, it can be immediately invoked once takeover is initiated, without recalculation or loading. In terms of hardware, the timer synchronizes the local clock of each core, and IPC communication adopts interrupt and DMA modes to avoid CPU polling delay. In terms of scheduling strategy, the priority of inter-core communication is raised to the highest level, and the arbitration task of Core2 is strictly aligned with the control cycle of Core0 / 1 to ensure that the fusion control accuracy and system stability do not degrade under all operating conditions.
[0122] refer to Figure 5 The flowchart shown is an implementation flowchart of a system overall operation method, as follows: Figure 5 As shown, the method includes S501-S516: S501: System power-on initialization.
[0123] S502: Vehicle starts the range extender and engine.
[0124] S503: Core0 / Core1 / Core2 / Core3 are running normally.
[0125] S504: Core3 real-time monitoring and hot mirror synchronization.
[0126] S505: Determine if the task has timed out.
[0127] For example, if the task times out, S510 is executed; if the task does not time out, S504 is executed.
[0128] S506: Determine if the check is incorrect.
[0129] For example, if a verification error occurs, S510 is executed; if no verification error occurs, S504 is executed.
[0130] S507: Determine if the core is unresponsive.
[0131] For example, if the processor core does not respond, S510 is executed; if the processor core responds, S504 is executed.
[0132] S508: Determine if the temperature exceeds the limit.
[0133] For example, if the temperature exceeds the limit, S510 is executed; if the temperature does not exceed the limit, S504 is executed.
[0134] S509: Determine if there are any failure modes such as abnormal power supply voltage.
[0135] For example, if a failure mode such as abnormal power supply voltage exists, S510 is executed; if a failure mode such as abnormal power supply voltage does not exist, S504 is executed.
[0136] S510: Access control preemption and output locking.
[0137] S511: Core3 performs control tasks.
[0138] S512: The vehicle is operating normally.
[0139] S513: Fault Isolation and Storage.
[0140] S514: The system is running stably.
[0141] S515: Determine if extreme operating conditions have been entered.
[0142] For example, if the vehicle enters an extreme operating condition, S516 is executed; if the vehicle does not enter an extreme operating condition, S503 is executed.
[0143] S516: Dynamically increase task priority (lock Core0 and Core1 to control tasks to the highest priority).
[0144] In some embodiments, after the system is powered on and initialized and the range extender and engine are detected to start, the four cores of the controller main control chip start up and run independently: (1) Core0 and Core1 enter the hard real-time control loop and independently execute engine and generator control respectively. Core2 performs real-time data interaction between cores, power and torque coordination, instruction arbitration and fault information summary; (2) Core3 continuously monitors the running status of the three cores and executes the running status hot mirroring mechanism. The detection module monitors the failure modes such as task timeout, data CRC check error, core no response, core temperature exceeding the limit, and abnormal power supply voltage in real time, and maintains the standby takeover state; (3) When any main core other than Core3 fails, the permission is preempted and the output is locked. Core3 immediately takes over seamlessly, first ensuring normal operation, and simultaneously isolating and storing the fault for subsequent troubleshooting; (4) If extreme working conditions are detected during the normal operation of the four cores, the system automatically increases the priority of the control task. The system scheduler automatically locks all control tasks of Core0 and Core1 as the highest priority and prohibits non-real-time tasks from preempting CPU resources. Core3 preloads a lightweight, highly robust backup control model for extreme operating conditions, and maintains low jitter and low latency in inter-core scheduling to ensure stable system operation.
[0145] Based on the foregoing embodiments, this application provides a vehicle control device, which includes various units and modules included in each unit. It can be implemented by a main control chip in the vehicle; of course, it can also be implemented by specific logic circuits. In the implementation process, the processor can be a central processing unit (CPU), a microprocessor unit (MPU), a digital signal processor (DSP), or a field programmable gate array (FPGA), etc.
[0146] Figure 6 This is a schematic diagram of the composition structure of a vehicle control device provided in an embodiment of this application, as shown below. Figure 6 As shown, the vehicle control device 600 can be configured on a main control chip, which includes multiple main control cores and command arbitration cores; the multiple main control cores are used to control multiple actuators in the vehicle. The vehicle control device 600 includes: a first determining module 610, a second determining module 620, a first sending module 630, and a control module 640, wherein: The first determining module 610 is configured to determine the first control signal corresponding to each actuator based on the vehicle signal corresponding to each actuator through each main control core, and send the vehicle signal and the first control signal corresponding to each actuator to the instruction arbitration core.
[0147] The second determining module 620 is configured to determine the second control signal corresponding to each actuator based on the vehicle signal corresponding to each actuator through the instruction arbitration core, and to determine whether the first control signal corresponding to each actuator is abnormal based on the second control signal corresponding to each actuator.
[0148] The first sending module 630 is configured to send the second control signal corresponding to the first actuator to the first main control core through the instruction arbitration core when the first control signal corresponding to the first actuator among multiple actuators is abnormal; the multiple main control cores include the first main control core.
[0149] The control module 640 is configured to control the first actuator through the first main control core based on the second control signal corresponding to the first actuator.
[0150] In some embodiments, the second determining module 620 is specifically configured to: determine the target control signal of the vehicle signal corresponding to each actuator in a preset mapping relationship through the instruction arbitration core; the preset mapping relationship includes preset vehicle signals and preset control signals corresponding to the preset vehicle signals, the preset vehicle signals include the vehicle signals corresponding to each actuator, and the preset control signals include the target control signals corresponding to each actuator; and adjust the target control signals based on the deviation between the first control signals corresponding to each actuator and the target control signals through the instruction arbitration core to obtain the second control signals corresponding to each actuator.
[0151] In some embodiments, the second determining module 620 is further configured to: determine whether the first control signal corresponding to each actuator is legal through the instruction arbitration core; the illegality of the first control signal corresponding to each actuator includes at least one of the following: the first control signal corresponding to each actuator is an out-of-bounds error signal, a signal exceeding the vehicle's physical limits, or a signal exceeding the vehicle's safety boundaries; the first sending module 630 is further configured to: send a prohibition command to the second main control core through the instruction arbitration core when the first control signal corresponding to the second actuator among the multiple actuators is illegal; the prohibition command is used to prohibit the second main control core from controlling the second actuator based on the first control signal corresponding to the second actuator, and the multiple main control cores include the second main control core.
[0152] In some implementations, the control module 640 is further configured to control each actuator based on the first control signal corresponding to each actuator, provided that the first control signal corresponding to each actuator is normal and valid.
[0153] In some implementations, the first determining module 610 is specifically configured to: process the vehicle signals corresponding to each actuator using a first control algorithm in the main path, and obtain a first signal corresponding to each actuator; process the vehicle signals corresponding to each actuator using a second control algorithm in the secondary path, and obtain a second signal corresponding to each actuator; the first control algorithm and the second control algorithm are different; when the first signal and the second signal corresponding to each actuator are the same, the first signal corresponding to each actuator is determined as the first control signal corresponding to each actuator.
[0154] like Figure 6 As shown, the device also includes a reading module 650 and an execution module 660.
[0155] In some implementations, the multiple processor cores also include redundant backup cores, and the main control chip also includes independent memory regions accessed independently by the redundant backup cores and shared memory regions accessed by the multiple processor cores. The shared memory regions are used to store mirror data of each main control core and instruction arbitration core. The read module 650 is configured to: read mirror data from the shared memory region through the redundant backup cores and write the mirror data into the independent memory region corresponding to the redundant backup cores; in the event of a failure of the target processor core, read the target mirror data corresponding to the target processor core from the independent memory region through the redundant backup cores; the target processor core is at least one main control core and / or instruction arbitration core, and the target mirror data is mirror data of at least one main control core and / or instruction arbitration core; the execution module 660 is configured to: execute the target task of the target processor core based on the target mirror data corresponding to the target processor core through the redundant backup cores.
[0156] In some implementations, the shared memory region is used for the time information and verification information corresponding to the mirror data; the reading module 650 is specifically configured to: read the mirror data, as well as the time information and verification information of the mirror data, from the shared memory region through the redundant backup core; if the time information corresponding to the mirror data is continuous, determine the valid mirror data in the mirror data through the redundant backup core based on the preset verification algorithm and the verification information corresponding to the mirror data; and write the valid mirror data into the independent memory region corresponding to the redundant backup core through the redundant backup core.
[0157] like Figure 6 As shown, the device also includes a second transmitting module 670 and a third determining module 680.
[0158] In some implementations, the second sending module 670 is configured to: send a priority adjustment request to the main control chip when the target main control core determines that the vehicle is in an extreme operating condition based on the vehicle signal corresponding to the target actuator; the multiple main control cores include the target main control core, and the multiple actuators include the target actuator; the third determining module 680 is configured to: determine the task priority corresponding to the task of each processor core when the priority adjustment request of the target main control core is received; the real-time task of the target main control core has the highest priority among all tasks of the target main control core.
[0159] like Figure 6 As shown, the device also includes a fourth determining module 690.
[0160] In some implementations, the multiple processor cores also include redundant backup cores, and the main control chip also includes an independent memory region accessed independently by the redundant backup cores and a shared memory region accessed by the multiple processor cores; the shared memory region is used to store mirror data of each main control core and instruction arbitration core; the fourth determining module 690 is configured to: determine whether the vehicle signal corresponding to the target actuator meets the task takeover conditions through the redundant backup cores; the reading module 650 is configured to: read the mirror data corresponding to the target main control core from the independent memory region through the redundant backup cores when the vehicle signal corresponding to the target actuator meets the task takeover conditions; the execution module 660 is configured to: execute the target task of the target main control core based on the mirror data corresponding to the target main control core through the redundant backup cores.
[0161] The descriptions of the apparatus embodiments above are similar to those of the method embodiments above, and have similar beneficial effects. In some embodiments, the functions or modules included in the apparatus provided in this application can be used to perform the methods described in the method embodiments above. For technical details not disclosed in the apparatus embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.
[0162] It should be noted that, in the embodiments of this application, if the above-described vehicle control method is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiments of this application, or the part that contributes to the related technology, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), magnetic disks, or optical disks. Thus, the embodiments of this application are not limited to any specific hardware, software, or firmware, or any combination of hardware, software, and firmware.
[0163] This application provides a computer-readable storage medium storing a computer program that, when executed by a main control chip in a vehicle, implements some or all of the steps in the above-described method. The computer-readable storage medium can be transient or non-transient.
[0164] This application provides a computer program including computer-readable code. When the computer-readable code runs in a main control chip in a vehicle, the main control chip performs some or all of the steps in the above method.
[0165] This application provides a computer program product, which includes a non-transitory computer-readable storage medium storing a computer program. When the computer program is read and executed by the main control chip in a vehicle, it implements some or all of the steps in the above-described method. This computer program product can be implemented specifically through hardware, software, or a combination thereof. In some embodiments, the computer program product is specifically embodied as a computer storage medium; in other embodiments, the computer program product is specifically embodied as a software product, such as a software development kit (SDK), etc.
[0166] It should be noted that the descriptions of the various embodiments above tend to emphasize the differences between them, while their similarities or commonalities can be referred to interchangeably. The descriptions of the above embodiments of the device, storage medium, computer program, and computer program product are similar to the descriptions of the above method embodiments and have similar beneficial effects. For technical details not disclosed in the embodiments of the device, storage medium, computer program, and computer program product of this application, please refer to the descriptions of the method embodiments of this application for understanding.
[0167] This application provides a computer storage medium that stores one or more programs that can be executed by a processor to implement the steps of the vehicle control method described above.
[0168] It should be noted that the descriptions of the storage medium and device embodiments above are similar to the descriptions of the method embodiments above, and have similar beneficial effects. For technical details not disclosed in the storage medium and device embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.
[0169] The aforementioned computer storage media / memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic random access memory (FRAM), flash memory, magnetic surface memory, optical disc, or compact disc read-only memory (CD-ROM), etc.; or it can be various terminals that include one or any combination of the above-mentioned memories, such as mobile phones, computers, tablet devices, personal digital assistants, etc.
[0170] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, and improvements made within the spirit and scope of this application are included within the scope of protection of this application.
Claims
1. A vehicle control method, characterized in that, A main control chip used in a vehicle, the main control chip including multiple main control cores and an instruction arbitration core; the multiple main control cores are used to control multiple actuators in the vehicle; the method includes: Each main control core determines the first control signal corresponding to each actuator based on the vehicle signal corresponding to each actuator, and sends the vehicle signal and the first control signal corresponding to each actuator to the instruction arbitration core. The core of the instruction arbitration determines the target control signal of the vehicle signal corresponding to each actuator in the preset mapping relationship; the preset mapping relationship includes preset vehicle signals and preset control signals corresponding to the preset vehicle signals, the preset vehicle signals include the vehicle signals corresponding to each actuator, and the preset control signals include the target control signals corresponding to each actuator. The instruction arbitration core adjusts the target control signal based on the deviation between the first control signal corresponding to each actuator and the target control signal to obtain the second control signal corresponding to each actuator. Determine whether the first control signal corresponding to each actuator is abnormal based on the second control signal corresponding to each actuator. In the event of an abnormal first control signal corresponding to the first actuator among the plurality of actuators, the second control signal corresponding to the first actuator is sent to the first main control core through the instruction arbitration core; the plurality of main control cores include the first main control core; The first main control core controls the first actuator based on the second control signal corresponding to the first actuator.
2. The method according to claim 1, characterized in that, The method further includes: The instruction arbitration core determines whether the first control signal corresponding to each actuator is valid; invalid first control signals corresponding to each actuator include at least one of the following: an out-of-bounds error signal, a signal exceeding the vehicle's physical limits, or a signal exceeding the vehicle's safety boundaries. If the first control signal corresponding to the second actuator among the plurality of actuators is invalid, the instruction arbitration core sends a prohibition instruction to the second main control core; the prohibition instruction is used to prohibit the second main control core from controlling the second actuator based on the first control signal corresponding to the second actuator, and the plurality of main control cores include the second main control core.
3. The method according to claim 2, characterized in that, The method further includes: When the first control signal corresponding to each actuator is normal and valid, each main control core controls each actuator based on the first control signal corresponding to each actuator.
4. The method according to claim 1, characterized in that, The step of determining the first control signal corresponding to each actuator based on the vehicle signal corresponding to each actuator by each main control core includes: Each main control core processes the vehicle signals corresponding to each actuator based on the first control algorithm in the main path to obtain the first signal corresponding to each actuator; Each main control core processes the vehicle signals corresponding to each actuator based on the second control algorithm in the secondary path to obtain the second signal corresponding to each actuator; the first control algorithm is different from the second control algorithm; When the first signal and the second signal corresponding to each actuator are the same, the first signal corresponding to each actuator is determined as the first control signal corresponding to each actuator.
5. The method according to claim 1, characterized in that, The main control chip also includes redundant backup cores among its multiple processor cores. The main control chip also includes independent memory regions accessed independently by the redundant backup cores and shared memory regions accessed by the multiple processor cores. The shared memory region is used to store the mirror data of each of the main control cores and the instruction arbitration core; The method further includes: The redundant backup core reads the image data from the shared memory area and writes the image data into the independent memory area corresponding to the redundant backup core. In the event of a failure of the target processor core, the target image data corresponding to the target processor core is read from the independent memory region through the redundant backup core; the target processor core is at least one of the main control cores and / or the instruction arbitration cores, and the target image data is image data of at least one of the main control cores and / or the instruction arbitration cores; The redundant backup core executes the target task of the target processor core based on the target image data corresponding to the target processor core.
6. The method according to claim 5, characterized in that, The shared memory region is used for the time information and verification information corresponding to the image data; the redundant backup core reads the image data from the shared memory region and writes the image data into the independent memory region corresponding to the redundant backup core, including: The redundant backup core reads the image data, along with the time and verification information of the image data, from the shared memory region. When the time information corresponding to the mirror data is continuous, the redundant backup core determines the valid mirror data in the mirror data based on the preset verification algorithm and the verification information corresponding to the mirror data. The valid image data is written into the independent memory area corresponding to the redundant backup core through the redundant backup core.
7. The method according to any one of claims 1-6, characterized in that, The method further includes: When the target main control core determines that the vehicle is in an extreme operating condition based on the vehicle signal corresponding to the target actuator, it sends a priority adjustment request to the main control chip; the multiple main control cores include the target main control core, and the multiple actuators include the target actuator; Upon receiving a priority adjustment request from the target main control core, the task priority corresponding to the task of each processor core is determined; the real-time task of the target main control core has the highest priority among all tasks of the target main control core.
8. The method according to claim 7, characterized in that, The processor cores also include redundant backup cores, and the main control chip also includes independent memory regions accessed independently by the redundant backup cores and shared memory regions accessed by the processor cores. The shared memory region is used to store the mirror data of each of the main control cores and the instruction arbitration core; The method further includes: The redundant backup core determines whether the vehicle signal corresponding to the target actuator meets the task takeover conditions. When the vehicle signal corresponding to the target actuator meets the task takeover conditions, the mirror data corresponding to the target main control core is read from the independent memory area through the redundant backup core. The redundant backup core executes the target task of the target main control core based on the mirror data corresponding to the target main control core.
9. A vehicle control system, characterized in that, The system includes a main control chip and drive circuitry in the vehicle. The main control chip includes multiple processor cores, each of which includes multiple main control cores and an instruction arbitration core. The multiple main control cores are used to control the drive circuitry of multiple actuators in the vehicle. Each of the main control cores is configured to determine a first control signal corresponding to each actuator based on the vehicle signal corresponding to each actuator, and send the vehicle signal and the first control signal corresponding to each actuator to the instruction arbitration core; The command arbitration core is configured to determine the target control signal for each actuator's corresponding vehicle signal within a preset mapping relationship. The preset mapping relationship includes preset vehicle signals and preset control signals corresponding to those preset vehicle signals. The preset vehicle signals include vehicle signals corresponding to each actuator, and the preset control signals include target control signals corresponding to each actuator. The command arbitration core adjusts the target control signals based on the deviation between the first control signal and the target control signal corresponding to each actuator to obtain a second control signal corresponding to each actuator. Based on the second control signal, it is determined whether the first control signal corresponding to each actuator is abnormal. In the event of an abnormal first control signal corresponding to the first actuator among the plurality of actuators, the second control signal corresponding to the first actuator is sent to the first main control core; the plurality of main control cores include the first main control core; Each of the main control cores is further configured to send a second control signal corresponding to the first actuator to the drive circuit of the first actuator, and the drive circuit of the first actuator controls the operation of the first actuator based on the second control signal corresponding to the first actuator.
10. The system according to claim 9, characterized in that, The processor cores also include redundant backup cores, and the main control chip also includes an independent memory region accessed independently by the redundant backup cores, and a shared memory region accessed by the processor cores; the shared memory region is used to store mirror data of each of the main control cores and the instruction arbitration core; The redundant backup core is also configured as follows: The image data is read from the shared memory region and written into the independent memory region corresponding to the redundant backup core; In the event of a failure in the target processor core, the target image data corresponding to the target processor core is read from the independent memory region; The target processor core is at least one of the main control core and / or the instruction arbitration core, and the target image data is image data of at least one of the main control core and / or the instruction arbitration core; The target task of the target processor core is executed based on the target image data corresponding to the target processor core.
11. A vehicle, characterized in that, The vehicle includes a main control chip, which is used to perform the method of any one of claims 1-8.
Citation Information
Patent Citations
Image backup method for dual-core control of core controlled system
CN101043310A
Electric automobile main controlling device
CN108016385A
Vehicle communication redundancy system and vehicle communication redundancy control method
CN117706905A