Secure backup system and synchronized exposure control method

CN122510982APending Publication Date: 2026-08-04SANY SPECIAL PURPOSE VEHICLE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610818567.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-08
Publication Date
2026-08-04

AI Technical Summary

Technical Problem

[0005]本申请实施例提供安全备份系统及同步曝光控制方法,用以解决现有技术中存在系统在ADAS控制器失效时,因数据存储单点故障和视频流中断导致的关键数据丢失的问题

Benefits of technology

[0034] This application provides a secure backup system and a synchronous exposure control method. The system includes an image acquisition module, a storage module, a first controller, a second controller, and a monitoring and control module. During vehicle operation, the image acquisition module continuously acquires video data from the front, rear, or surrounding environment of the vehicle and transmits it to the first and second controllers respectively. This enables the dual controllers to synchronously acquire video information from the same source, avoiding video data interruption caused by a single controller failure, thereby improving the reliability and continuity of video recording. The first storage unit in the first controller and the second storage unit in the second controller are used to store video data and vehicle operation data, respectively. A redundant backup mechanism is established between the first and second storage units. After data writing is completed in either storage unit, the corresponding data is synchronously backed up to the other storage unit, ensuring that both sides always maintain a consistent data copy. This allows for the recovery of complete data from the other storage unit even if one storage unit is damaged, loses power, or experiences a write failure. This enhances the system's data security and accident data preservation capabilities. A status monitoring connection is established between the first and second controllers via a monitoring and control module. This module uses a periodic heartbeat detection mechanism to determine if any controller anomalies exist. When a preset event is detected, a synchronization update operation between the first and second storage units is immediately triggered, forcibly synchronizing and saving critical video data and vehicle operation data before and after the event to ensure data integrity and consistency at critical moments. Through this approach, the system forms a distributed redundant data recording architecture based on dual controllers, dual storage units, and a status monitoring linkage mechanism. This not only enables stable acquisition and reliable storage of vehicle operation videos and data but also maintains normal system operation under single-point failure conditions and ensures that critical accident data is not lost, thereby effectively improving the safety, fault tolerance, and regulatory compliance of the intelligent driving DVR system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122510982A_ABST
    Figure CN122510982A_ABST
Patent Text Reader

Abstract

This application provides a secure backup system and a synchronous exposure control method. The system includes: an image acquisition module, a storage module, a first controller, a second controller, and a monitoring and control module. The image acquisition module is communicatively connected to both the first and second controllers and is used to acquire video data during vehicle operation. The storage module includes a first storage unit in the first controller and a second storage unit in the second controller. The first and second storage units are used to store video data and vehicle operation data, respectively, and are backed up synchronously in real time. The first and second controllers are connected via the monitoring and control module, which monitors the operating status of the first and second controllers and controls the first and second storage units to update synchronously when a preset event is triggered. This system avoids the risk of losing all data due to a single point of failure.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of vehicle data redundancy backup technology, and in particular to a secure backup system and a synchronous exposure control method. Background Technology

[0002] In intelligent driving systems, the collaborative operation of the Digital Video Recorder (DVR) and Advanced Driver Assistance Systems (ADAS) is crucial. Currently, intelligent driving vehicles need to collect and store multi-dimensional data in real time during operation, including forward-facing video, vehicle perception data, and bus signals, to meet regulatory requirements for the integrity of accident data. Especially in emergency events (such as Automatic Emergency Braking (AEB) triggering, collisions, and driver takeover), the system needs to record at least 8 seconds of complete data before and after the event to ensure accident liability determination, functional verification, and system optimization. However, to reduce hardware costs, the industry commonly uses the same camera for both ADAS cameras and DVR systems. However, existing solutions rely on Ethernet to transmit video streams and lack redundant design for camera exposure control, potentially leading to black screens or data loss when the ADAS controller malfunctions. Therefore, how to construct a DVR system with distributed storage, multi-source power supply redundancy, and simultaneous exposure dual-channel control has become a critical technical problem that urgently needs to be solved in the field of intelligent driving.

[0003] In existing technologies, most solutions employ a single storage unit and centralized power supply, meaning the entire system relies on a single hard drive or disk array as the sole recording storage medium, with video data from all channels written to this storage unit; meanwhile, a centralized power supply provides unified power to the DVR host, hard drive, cameras, and other peripheral devices.

[0004] However, existing solutions suffer from the problem of critical data loss due to single-point failures in data storage and interruptions in video streaming when the ADAS controller fails. Summary of the Invention

[0005] This application provides a security backup system and a synchronous exposure control method to solve the problem in the prior art where critical data is lost due to single-point failure of data storage and interruption of video stream when the ADAS controller fails.

[0006] In a first aspect, embodiments of this application provide a secure backup system, including: an image acquisition module, a storage module, a first controller, a second controller, and a monitoring and control module;

[0007] The image acquisition module is communicatively connected to the first controller and the second controller, respectively, and is used to acquire video data during vehicle operation.

[0008] The storage module includes a first storage unit disposed in a first controller and a second storage unit disposed in a second controller. The first storage unit and the second storage unit are respectively used to store video data and vehicle operation data, and are backed up synchronously in real time.

[0009] The first controller and the second controller are connected through the monitoring and control module. The monitoring and control module is used to monitor the working status of the first controller and the second controller, and control the first storage unit and the second storage unit to perform synchronous updates when a preset event is triggered.

[0010] In one possible implementation, the monitoring and control module is communicatively connected to the first controller and the second controller via an integrated circuit bus, respectively, to obtain the heartbeat status between the first controller and the second controller in order to determine whether the first controller or the second controller has failed.

[0011] In one possible implementation, the preset event includes at least one of the following: the monitoring and control module detecting a failure of the first controller, an automatic emergency braking event, a driver takeover event, a collision event, and an acceleration value exceeding a preset threshold event.

[0012] When the preset event is that the first controller is detected to have failed, the monitoring and control module controls the second controller to take over the exposure synchronization control of the image acquisition module to ensure the continuous output of the video data.

[0013] In one possible implementation, the first storage unit is a general-purpose flash memory, and the second storage unit is a secure digital card; and both the first storage unit and the second storage unit are configured to perform cyclic storage using a first-in-first-out (FIFO) strategy.

[0014] In one possible implementation, when the preset event is triggered, the first storage unit and the second storage unit respectively lock and store the video data and the vehicle operation data within a preset time before and after the event, and perform data locking protection.

[0015] In one possible implementation, the system further includes a power supply module; the power supply module includes a main power supply unit and a backup power supply unit;

[0016] The power supply module is electrically connected to the first controller, the second controller, and the image acquisition module, respectively, and is used to switch to the backup power supply unit when the main power supply unit fails.

[0017] In one possible implementation, the image acquisition module is connected to the first controller and the second controller respectively via coaxial cables to achieve camera multiplexing.

[0018] Secondly, embodiments of this application provide a synchronous exposure control method, including:

[0019] The image acquisition module collects video data during the vehicle's movement and sends the video data to the first controller and the second controller respectively.

[0020] The monitoring and control module acquires the heartbeat status between the first controller and the second controller;

[0021] When the heartbeat status indicates that the first controller has failed, the monitoring and control module controls the second controller to take over the exposure synchronization control of the image acquisition module in order to maintain the continuous output of the video data.

[0022] In one possible implementation, the heartbeat status indicating a failure of the first controller includes at least one of the following:

[0023] No heartbeat signal was received from the first controller within a preset time;

[0024] The received heartbeat signal indicates that the exposure synchronization function of the first controller is malfunctioning;

[0025] The video stream received by the second controller is interrupted, displays a distorted image, or has an abnormal frame rate.

[0026] In one possible implementation, the method further includes:

[0027] After the second controller takes over the exposure synchronization control, the monitoring and control module continues to monitor the recovery status of the first controller;

[0028] When the first controller returns to normal and its exposure synchronization accuracy meets the preset threshold, the monitoring and control module will switch the exposure synchronization control back to the first controller, or maintain the second controller as the current master device until the next system restart.

[0029] Thirdly, embodiments of this application provide an electronic device, including: a memory and a processor;

[0030] The memory stores computer-executed instructions;

[0031] The processor executes computer execution instructions stored in the memory, causing the processor to perform the second aspect and / or various possible implementations of the second aspect as described above.

[0032] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the second aspect and / or various possible implementations of the second aspect as described above.

[0033] Fifthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the second aspect and / or various possible implementations of the second aspect as described above.

[0034] This application provides a secure backup system and a synchronous exposure control method. The system includes an image acquisition module, a storage module, a first controller, a second controller, and a monitoring and control module. During vehicle operation, the image acquisition module continuously acquires video data from the front, rear, or surrounding environment of the vehicle and transmits it to the first and second controllers respectively. This enables the dual controllers to synchronously acquire video information from the same source, avoiding video data interruption caused by a single controller failure, thereby improving the reliability and continuity of video recording. The first storage unit in the first controller and the second storage unit in the second controller are used to store video data and vehicle operation data, respectively. A redundant backup mechanism is established between the first and second storage units. After data writing is completed in either storage unit, the corresponding data is synchronously backed up to the other storage unit, ensuring that both sides always maintain a consistent data copy. This allows for the recovery of complete data from the other storage unit even if one storage unit is damaged, loses power, or experiences a write failure. This enhances the system's data security and accident data preservation capabilities. A status monitoring connection is established between the first and second controllers via a monitoring and control module. This module uses a periodic heartbeat detection mechanism to determine if any controller anomalies exist. When a preset event is detected, a synchronization update operation between the first and second storage units is immediately triggered, forcibly synchronizing and saving critical video data and vehicle operation data before and after the event to ensure data integrity and consistency at critical moments. Through this approach, the system forms a distributed redundant data recording architecture based on dual controllers, dual storage units, and a status monitoring linkage mechanism. This not only enables stable acquisition and reliable storage of vehicle operation videos and data but also maintains normal system operation under single-point failure conditions and ensures that critical accident data is not lost, thereby effectively improving the safety, fault tolerance, and regulatory compliance of the intelligent driving DVR system. Attached Figure Description

[0035] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0036] Figure 1Schematic diagram of the security backup system provided in the embodiments of this application Figure 1 ;

[0037] Figure 2 Schematic diagram of the security backup system provided in the embodiments of this application Figure 2 ;

[0038] Figure 3 A schematic diagram of the module connections within the security backup system provided in this application embodiment;

[0039] Figure 4 A flowchart illustrating the synchronous exposure control method provided in an embodiment of this application;

[0040] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.

[0041] The accompanying drawings have illustrated specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to specific embodiments. Detailed Implementation

[0042] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application.

[0043] In intelligent driving systems, the collaborative operation of DVRs and ADAS is crucial. Currently, intelligent driving vehicles need to collect and store multi-dimensional data in real time during operation, including forward video, vehicle perception data, and bus signals, to meet regulatory requirements for the integrity of accident data. Especially in emergency events (such as AEB triggering, collision events, driver takeover, etc.), the system needs to record complete data for at least 8 seconds before and after the event to ensure accident liability determination, functional verification, and system optimization. However, to reduce hardware costs, the industry commonly uses the same camera for ADAS cameras and DVR systems. But existing solutions rely on Ethernet to transmit video streams and lack redundant design for camera exposure control, which may lead to black screens or data loss when the ADAS controller fails. Therefore, how to build a DVR system with distributed storage, multi-source power supply redundancy, and synchronous exposure dual-channel control has become a key technical problem that urgently needs to be solved in the field of intelligent driving.

[0044] In existing technologies, DVR systems mostly adopt a single storage unit and centralized power supply scheme. That is, the entire system relies on a single hard disk or disk array as the only recording storage medium, and video data from all channels is written to this storage unit. At the same time, a centralized power supply provides unified power to the DVR host, hard disk, cameras and other peripheral devices.

[0045] However, existing DVR systems have the risk of single point of failure in data storage, and cannot guarantee the continuity of video streams when the ADAS controller fails, resulting in interruption of real-time monitoring and loss of recording, which seriously reduces the continuous operation capability and data security of security monitoring systems.

[0046] To address the problems of existing DVR systems, such as reliance on a single storage medium for data storage and the susceptibility to video stream interruption and loss of critical recording data when the ADAS controller malfunctions or fails, the inventors have constructed a dual-controller collaborative architecture and a dual-storage unit redundant backup mechanism to achieve highly reliable recording of video data and vehicle operation data. Specifically, the system uses an image acquisition module to simultaneously output video streams to both the first and second controllers, enabling both controllers to synchronously acquire video data from the same source and store it through their respective first and second storage units. Simultaneously, a real-time synchronous backup mechanism is established between the two storage units, automatically performing a data mirror backup to the other side after data writing is completed on either side, thus avoiding the problem of unrecoverable data due to the failure of a single storage medium. Furthermore, the inventors have considered that the failure of the ADAS controller could lead to issues with camera exposure control and... To address the issue of abnormal video output, a monitoring and control module is introduced to monitor the operational status of the first and second controllers in real time. This module uses heartbeat detection, communication status detection, and video stream status detection to determine if a controller malfunctions. When an ADAS controller malfunction, communication interruption, or unstable video stream is detected, the second controller automatically takes over the camera's exposure control and video recording functions, triggering a synchronized update of critical data between the first and second storage units. This ensures the complete preservation of video and operational data before and after the incident. Through this approach, the system not only effectively solves the data loss problem caused by single-point storage failure in traditional DVR systems but also maintains continuous video stream output and recording operation even in the event of an ADAS controller malfunction. This significantly improves the stability, fault tolerance, and critical data security of the intelligent driving security monitoring system.

[0047] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0048] Figure 1 Schematic diagram of the security backup system provided in the embodiments of this application Figure 1 ; Figure 2 Schematic diagram of the security backup system provided in the embodiments of this application Figure 2 ;like Figure 1 , Figure 2 As shown, the system includes: an image acquisition module 10, a storage module 20, a first controller 30, a second controller 40, a monitoring and control module 50, and a power supply module 60. The storage module 20 includes a first storage unit 201 located in the first controller 30 and a second storage unit 202 located in the second controller 40. The power supply module 60 includes a main power supply unit 601 and a backup power supply unit 602. The modules are connected via a communication bus and power supply lines, collectively forming a low-cost intelligent driving DVR safety backup system for achieving highly reliable acquisition, storage, backup, and fault tolerance of video data and vehicle operation data.

[0049] The image acquisition module 10 is communicatively connected to the first controller 30 and the second controller 40, respectively, and is used to acquire video data during vehicle operation. In this embodiment, the image acquisition module 10 can be a forward-looking camera, a surround-view camera, or other vehicle-mounted image sensors. To reduce system costs and avoid redundant camera resource configuration, the image acquisition module 10 is connected to the first controller 30 and the second controller 40 via coaxial cables, achieving camera resource reuse. Specifically, the video signal output by the camera is simultaneously transmitted to the first controller 30 and the second controller 40 after passing through a distribution circuit, enabling the two controllers to synchronously acquire the same video data. For example, during normal vehicle operation, the ADAS controller, acting as the first controller 30, performs intelligent driving functions such as target recognition and lane detection, while the second controller 40 performs DVR recording functions, and both share the video data acquired by the same camera. This design not only reduces hardware configuration costs but also avoids the problems of increased installation space and system complexity caused by using multiple independent cameras, achieving the effects of resource reuse and cost optimization.

[0050] The first controller 30 and the second controller 40 respectively receive video data output from the image acquisition module 10 and execute corresponding data processing tasks. The first controller 30 is preferably an ADAS controller, used for environmental perception, target detection, and intelligent driving decision-making functions; the second controller 40 is preferably a vehicle controller or DVR controller, used for video recording, display, and storage management functions. Under normal system operation, the first controller 30 acts as the main controller for camera exposure synchronization, sending frame synchronization signals and exposure control parameters to achieve unified control of the image acquisition module 10, while the second controller 40 synchronously receives the video stream and executes recording tasks. This design ensures consistency between the video processed by the ADAS algorithm and the recorded video, improving the accuracy of subsequent accident analysis and event tracing.

[0051] The storage module 20 includes a first storage unit 201 and a second storage unit 202, wherein the first storage unit 201 is located inside the first controller 30, and the second storage unit 202 is located inside the second controller 40. Preferably, the first storage unit 201 uses a general-purpose flash memory (UFS), and the second storage unit 202 uses a secure digital storage card (SD card). The first storage unit 201 is mainly used to store vehicle operation data, perception result data, and key event data, while the second storage unit 202 is mainly used to store long-term continuous video recording data. Simultaneously, a data redundancy backup mechanism is established between the first storage unit 201 and the second storage unit 202. When data is written to either side, key data can be synchronized to the other side for backup. For example, when the vehicle triggers an automatic emergency braking event, the ADAS controller stores the event data in the UFS and simultaneously synchronizes the corresponding data to the SD card; conversely, when the SD card stores video, the key video index can also be synchronized to the UFS. With a dual-storage-media collaborative backup design, even if one storage unit is damaged, loses power, or experiences a write failure, the other storage unit can still retain complete data, thereby significantly improving the system's data reliability and ability to preserve evidence of accidents.

[0052] Furthermore, both the first storage unit 201 and the second storage unit 202 employ a First-In-First-Out (FIFO) circular storage strategy. When the storage space is not full, the system continuously records video data and vehicle operation data in chronological order; when the storage space reaches its capacity limit, the system automatically overwrites the oldest unprotected data, thus ensuring that new data can be continuously written. For example, in a continuous 24 / 7 recording scenario, the SD card can cyclically overwrite historical ordinary video files without affecting the system's continuous recording function. Through the FIFO circular storage mechanism, recording interruptions caused by storage space exhaustion are avoided, storage resource utilization is improved, and long-term stable operation is achieved.

[0053] The monitoring and control module 50 is communicatively connected to the first controller 30 and the second controller 40, respectively, for real-time monitoring of the operating status of the two controllers. In this embodiment, the monitoring and control module 50 establishes communication connections with the first controller 30 and the second controller 40 via the integrated circuit bus I²C, and periodically acquires the heartbeat signals sent by both. Specifically, the first controller 30 and the second controller 40 send status information to the monitoring and control module 50 at preset time intervals. The monitoring and control module 50 determines whether the corresponding controller has an anomaly based on whether the heartbeat signal responds normally. For example, if the monitoring and control module 50 does not receive heartbeat information from the first controller 30 for several consecutive detection cycles, it can determine that the first controller 30 has failed. Through this real-time monitoring mechanism, the system can quickly identify the controller failure state, providing a basic guarantee for subsequent fault takeover, thereby improving the overall operational reliability of the system.

[0054] In one specific implementation, the preset events include at least one of the following: a first controller 30 failure event, an automatic emergency braking (AEB) event, a driver takeover event, a vehicle collision event, and an acceleration value exceeding a preset threshold event. When the monitoring and control module 50 detects any of the above preset events, it will trigger a critical data protection mechanism. For example, when a vehicle collision occurs and the vehicle acceleration sensor detects an impact signal exceeding a set threshold, the monitoring and control module 50 immediately sends a data protection command to the first controller 30 and the second controller 40; or when the ADAS system triggers AEB braking, the monitoring and control module 50 also initiates the event recording process. Through the combined design of multiple triggering mechanisms, it is possible to ensure that critical data before and after an accident is saved in a timely manner, improving the data integrity of accident analysis and liability determination.

[0055] When a preset event is triggered, the monitoring and control module 50 controls the first storage unit 201 and the second storage unit 202 to perform a synchronous update operation. Specifically, the first storage unit 201 and the second storage unit 202 respectively lock video data and vehicle operation data within a preset time range before and after the event, such as locking data 8 seconds before and 8 seconds after the accident, and setting a read-only protection flag for the locked data to prevent subsequent FIFO loop overwriting. By locking and protecting the data in key time windows, important evidence such as accident-related videos, vehicle status parameters, and driving operation information can be preserved for a long time, avoiding data loss caused by loop storage overwriting, thereby improving the system's evidence collection capabilities and data security.

[0056] It should be noted that the DVR system is equipped with an independent G-sensor and can also acquire acceleration data from other vehicle control units via the vehicle communication bus, thus forming a dual acceleration information acquisition mechanism and achieving G-value data redundancy design. The independent G-sensor is directly installed inside the DVR controller or connected to it, and is used to detect real-time acceleration changes in the X, Y, and Z axes. In practice, during normal vehicle operation, the internal G-sensor continuously collects dynamic information such as vehicle vibration, rapid acceleration, rapid deceleration, and collision impacts, while the DVR controller periodically reads the overall vehicle acceleration data from the vehicle bus. When the system detects an anomaly in one G-value data source, it can automatically use another data source as a reference.

[0057] For example, when the internal G-sensor of the DVR experiences output abnormalities due to hardware failure, connection issues, or electromagnetic interference, the system can still acquire valid acceleration data via the vehicle bus. Conversely, when bus communication is abnormal or the vehicle controller malfunctions, resulting in data loss, the internal G-sensor of the DVR can still independently complete vehicle collision and impact detection. Through mutual verification and backup of dual data sources, event omissions or misjudgments due to a single sensor failure are avoided. This dual redundancy design improves the accuracy and reliability of identifying abnormal events such as vehicle collisions, emergency braking, and rollovers, reducing the risk of false triggers and missed triggers. Furthermore, it enhances the system's fault tolerance to sensor failures, bus failures, and data anomalies under complex operating conditions, ensuring the DVR system can stably and accurately trigger critical event recording and data protection functions, thereby improving the integrity and reliability of accident evidence data.

[0058] When the monitoring and control module 50 detects a failure in the first controller 30, the system enters a fault-tolerant mode. Under normal circumstances, the first controller 30 is responsible for the exposure synchronization control of the image acquisition module 10; however, when the monitoring and control module 50 confirms a failure in the first controller 30, it will control the second controller 40 to automatically take over the exposure synchronization control function of the image acquisition module 10. Specifically, the second controller 40 sends exposure parameters and synchronization timing control signals to the image acquisition module 10, causing the camera to switch from the first controller control mode to the second controller control mode. For example, when the ADAS controller crashes, loses power, or experiences a communication interruption, the second controller 40 can complete the control switch in a very short time and continue to control the camera to output video stream normally. This fault takeover mechanism avoids the problem of the camera stopping video output due to ADAS controller failure in traditional systems, ensuring the continuity and integrity of the DVR recording function.

[0059] The power supply module 60 is electrically connected to the first controller 30, the second controller 40, and the image acquisition module 10, respectively, to provide a stable power supply for the system. The main power supply unit 601 is preferably the vehicle's main power supply or a DC / DC power supply module, and the backup power supply unit 602 is preferably a backup battery or a supercapacitor module. During normal system operation, the main power supply unit 601 supplies power to each functional module; when a power outage, voltage abnormality, or power supply failure is detected in the main power supply unit 601, the power supply module 60 automatically switches to the backup power supply unit 602. For example, if a vehicle collision damages the main power line, the backup power supply unit 602 can still maintain system operation for a preset time, ensuring the preservation and backup of critical video data and vehicle operation data. This redundancy design of the main and backup power supplies effectively improves the system's data preservation capability and operational continuity under extreme conditions.

[0060] It should be noted that when the system powers on, the first controller (i.e., ADAS controller) 30 is selected as the master controller by default. During the system initialization phase, the first controller 30 first completes its own hardware and software self-test and sends master control status information to the second controller 40 through the monitoring and control module 50. After the monitoring and control module 50 confirms that the first controller 30 is in normal working condition, it sets the first controller 30 as the master control device of the image acquisition module 10. The first controller 30 is responsible for sending exposure parameters, frame synchronization signals, and image configuration parameters to the image acquisition module 10, thereby realizing unified control of the video acquisition process of the image acquisition module 10. At the same time, the second controller 40 is in a subordinate working state, mainly responsible for receiving video data output by the image acquisition module 10 and performing operations such as video display, recording storage, and data backup, without participating in the exposure control of the image acquisition module 10.

[0061] Understandably, by setting the ADAS controller as the default master controller, the video parameters output by the camera can be made to prioritize meeting the requirements of the intelligent driving perception algorithm for image quality, exposure consistency, and time synchronization accuracy, thus ensuring the normal operation of functions such as environmental perception, target recognition, and driving decision-making. At the same time, since the second controller 40 can synchronously acquire video stream data consistent with the ADAS controller, it can also ensure that the recorded data and the intelligent driving perception data are synchronized in time and consistent in content, thereby improving the accuracy and reliability of subsequent accident analysis, fault tracing, and safety evidence collection.

[0062] In summary, this invention constructs a highly reliable, highly secure, and low-cost intelligent driving DVR safety backup system through the coordinated operation of a camera multiplexing architecture, a dual-controller collaborative mechanism, a dual-storage redundancy backup mechanism, a fault monitoring and automatic takeover mechanism, and a primary / backup power supply redundancy mechanism. This system not only enables continuous video recording and critical data protection during vehicle operation but also maintains normal system operation in single-point failure scenarios such as controller failure, storage anomalies, and power supply failures, thereby significantly improving the data security and regulatory compliance of the intelligent driving system.

[0063] This application provides a secure backup system. During vehicle operation, the image acquisition module continuously collects video data from the front, rear, and surrounding environment of the vehicle and transmits it to a first controller and a second controller. This allows both controllers to synchronously acquire video information from the same source, avoiding video data interruption caused by a single controller failure, thereby improving the reliability and continuity of video recording. The first storage unit in the first controller and the second storage unit in the second controller are used to store video data and vehicle operation data, respectively. A redundant backup mechanism is established between the first and second storage units. After data is written to either storage unit, the corresponding data is synchronously backed up to the other storage unit, ensuring that both sides always maintain a consistent data copy. This allows for the recovery of complete data from the other storage unit even if one storage unit is damaged, loses power, or experiences a write failure, thereby improving the system's data security and reducing the number of incidents. According to the data preservation capabilities, the first and second controllers establish a status monitoring connection through a monitoring and control module. The monitoring and control module uses a periodic heartbeat detection mechanism to determine whether there are any abnormalities in the controllers. When a preset event is detected, a synchronization update operation between the first and second storage units is immediately triggered to forcibly synchronize and save key video data and vehicle operation data before and after the event, ensuring data integrity and consistency at critical moments. Through the above methods, the system forms a distributed redundant data recording architecture based on dual controllers, dual storage units, and a status monitoring linkage mechanism. This not only enables stable acquisition and reliable storage of vehicle operation videos and operation data, but also maintains normal system operation in the event of a single point of failure and ensures that critical accident data is not lost, thereby effectively improving the safety, fault tolerance, and regulatory compliance of the intelligent driving DVR system.

[0064] Figure 3 This is a schematic diagram of the module connections within the security backup system provided in the embodiments of this application; as shown below. Figure 3 As shown, the security backup system mainly includes a large battery (main power supply unit), a small battery (backup power supply unit), a controller (monitoring and control module), an ADAS controller (first controller), a second controller (DVR controller), and storage modules (UFS, SD).

[0065] Specifically, the vehicle's large battery and the DC / DC power conversion module connected to it are the main power supply units. The high-voltage electricity output from the vehicle's large battery is converted by the DC / DC converter to form a 24V or 12V low-voltage power supply bus, which supplies power to the first controller, the second controller, and other electronic control units (ECUs) of the vehicle, respectively. In the diagram, the thick black solid lines represent the 24V / 12V low-voltage power supply lines, and the gray lines represent the high-voltage power supply lines. Through a unified low-voltage power supply bus, a stable power supply can be ensured for all functional modules of the system.

[0066] To improve the reliability of the system's power supply, the system is also equipped with small batteries, i.e., backup power supply units. For example... Figure 3 As shown, the backup power supply unit is connected to the system power supply network through a monitoring and control module. The monitoring and control module monitors the output status of the main power supply unit in real time. When it detects an abnormal DC / DC output, a power outage of the vehicle's main power supply, or a supply voltage below a preset threshold, the monitoring and control module controls the backup power supply unit to connect to the power supply circuit, allowing the system to continue receiving power from the backup power supply unit. Through this redundant power supply architecture combining the main and backup power supplies, even if a vehicle collision causes a power outage, the system can still maintain normal operation for a preset time to save critical video and operational data, thereby preventing data loss during an accident.

[0067] The monitoring and control module is communicatively connected to the first and second controllers, enabling it to acquire their operating status information and perform operations such as power supply switching, fault handling, and control transfer based on the monitoring results. The monitoring and control module can also acquire operating status data sent by other ECUs in the vehicle via the communication bus and combine this data with the system's operating status for comprehensive judgment, thereby improving the accuracy and reliability of fault detection.

[0068] The second controller integrates a G-Sensor module and a second storage unit. The G-Sensor is used to detect real-time changes in vehicle acceleration, including parameters such as longitudinal, lateral, and vertical acceleration. Simultaneously, the second controller can also acquire acceleration data from other ECUs via the vehicle bus, achieving dual-channel G-value data acquisition. The second storage unit is used for continuous, all-weather video recording and storage. When the vehicle is driving normally, the second controller continuously writes video data acquired by the image acquisition module to the SD card, employing a FIFO (First-In, First-Out) cyclic overwrite strategy for storage management.

[0069] The first controller has a built-in first storage unit for storing ADAS perception data, vehicle operation data, and event triggering data. For example, when the system triggers Automatic Emergency Braking (AEB), driver takeover, collision warning, or when the G-force exceeds a preset threshold, the first controller stores the corresponding environmental perception data, target recognition results, vehicle status parameters, and control decision information in the first storage unit. Because UFS has high-speed read / write capabilities, it can meet the ADAS system's requirement for high real-time data recording.

[0070] A data redundancy backup mechanism is established between the first and second storage units. When the system detects a collision event, emergency braking event, or other preset event, the first and second controllers respectively save the corresponding key data to their local storage units and simultaneously perform data synchronization backup operations. For example, the perception data and vehicle operation data recorded by the ADAS controller can be synchronously backed up to the SD card, while the video data recorded by the DVR controller can also be synchronously backed up to the UFS storage. Through mutual backup between the two storage units, even if one storage medium is damaged, runs out of storage space, or fails to write, the other storage unit can still retain complete key data, thereby improving the system's data security and fault tolerance.

[0071] In addition, "Other ECUs" in the diagram refer to other electronic control units in the vehicle, such as the Vehicle Control Unit (VCU), Body Control Module (BCM), Electronic Stability Control (ESC), Airbag Control Unit (ACU), and Inertial Measurement Unit (IMU). These other ECUs interact with the first controller, second controller, and monitoring and control module via the vehicle communication bus to provide the system with data such as vehicle operating status, acceleration information, collision status, and fault status. For example, when the airbag controller detects a collision event, it can send a collision trigger signal to the monitoring and control module. The monitoring and control module then controls the first and second storage units to lock the data within a preset time period before and after the accident, preventing subsequent overwriting, thus achieving accident data protection.

[0072] In summary, Figure 3 The security backup system shown provides power supply assurance through a dual-path primary and backup system, achieves system status monitoring and fault management through a monitoring and control module, constructs a dual-controller collaborative architecture through a first controller and a second controller, and forms a distributed redundant storage system by combining the first storage unit and the second storage unit, thereby realizing reliable recording and secure backup of video data, vehicle operation data and event data, effectively solving the technical problems of single point of failure, data loss and recording interruption in traditional DVR systems.

[0073] Figure 4 This is a flowchart illustrating the synchronous exposure control method provided in the embodiments of this application; as shown below. Figure 4 As shown, the method includes:

[0074] S401, the image acquisition module acquires video data during the vehicle's driving process.

[0075] It should be understood that, in this embodiment, the image acquisition module is used to acquire environmental image information during vehicle operation. Specifically, the image acquisition module can be installed on the inside of the vehicle's windshield, the outside of the vehicle body, or other preset locations. When the vehicle starts, the image acquisition module begins to continuously acquire video data of the road ahead, surrounding traffic participants, and the road environment at a preset frame rate, and outputs the acquired raw video stream in real time. In one specific implementation, the camera can continuously acquire data at a frame rate of 30fps or 60fps to meet the dual needs of intelligent driving perception and DVR recording. For example, when the vehicle is driving on urban roads, the image acquisition module continuously acquires image information of vehicles, pedestrians, and traffic signs ahead, providing a basic data source for subsequent intelligent driving decisions and video recording. Through the continuous video acquisition mechanism, the complete recording of scene information during vehicle operation can be ensured, providing a reliable data foundation for the operation of intelligent driving functions and accident tracing analysis.

[0076] S402, the first controller and the second controller respectively acquire video data.

[0077] It should be understood that after acquiring video data, the image acquisition module establishes communication connections with both the first and second controllers simultaneously via coaxial cable and signal distribution link, thereby enabling the reuse of the same camera resource. Specifically, the video stream output from the camera is transmitted to both the first and second controllers via a Gigabit Multimedia Serial Link (GMSL) or other high-speed video transmission links, allowing both controllers to receive the same video data synchronously. For example, under normal operating conditions, the ADAS controller uses the video stream to perform functions such as forward collision warning and automatic emergency braking, while the DVR controller simultaneously records and saves the video. By having one camera serve both controllers simultaneously, not only are hardware configuration costs reduced, but the consistency between ADAS perception data and recorded data sources is also ensured, improving the consistency and accuracy of subsequent accident analysis data.

[0078] S403, the first controller and the second controller periodically send heartbeat status to each other through the communication channel.

[0079] It's important to note that in low-cost solutions that reuse a single camera, the ADAS controller is the default master controller for exposure synchronization, with the vehicle's infotainment system passively receiving the video stream. However, the ADAS controller may fail due to software crashes, hardware malfunctions, or power supply anomalies, causing the camera to lose its exposure timing and the video stream to be interrupted. To prevent DVR functionality loss, a mutual monitoring mechanism between the master and backup controllers needs to be established, allowing the backup controller to seamlessly take over in the event of master controller failure. This involves transmitting heartbeat signals via a bus to achieve status awareness and utilizing the vehicle's infotainment system's (SOC) shared camera control interface to enable takeover capability.

[0080] It should be understood that, in order to achieve status monitoring between the two controllers, the first and second controllers establish a status interaction mechanism through a communication channel. Preferably, the communication channel can use an I²C bus, CAN bus, SPI bus, or Ethernet communication link. During system operation, the first and second controllers send heartbeat status information to each other at preset time intervals. The heartbeat status information includes not only the device online status but also key operating parameters such as exposure synchronization status, CPU running status, storage status, and video output status. For example, a heartbeat packet is sent every 100ms, carrying the current exposure synchronization control status and system health status information. Through periodic status interaction, the two controllers can monitor each other's operation in real time, providing a basis for subsequent fault diagnosis and automatic takeover, thereby improving the overall fault perception capability of the system.

[0081] S404, the monitoring and control module monitors the heartbeat status.

[0082] The monitoring and control module continuously receives and analyzes heartbeat status information sent by the first and second controllers to determine whether the system is operating normally. Specifically, the monitoring and control module can establish a heartbeat monitoring timer, timestamp each received heartbeat signal, and perform status analysis based on the heartbeat data. When the monitoring and control module detects that the heartbeat signal arrives normally and the exposure synchronization status is normal, it maintains the current control mode; when it detects an abnormal heartbeat or abnormal status parameters, it triggers a fault determination process. For example, if the monitoring and control module does not receive heartbeat information from the first controller for several consecutive detection cycles, it can determine that the first controller has crashed or experienced a communication failure; or, although it can receive heartbeat signals, if the heartbeat status indicates an abnormal exposure synchronization, it can determine that the first controller has lost its exposure control capability. Through the real-time monitoring mechanism, potential faults can be detected in advance, preventing the fault from escalating and causing recording interruptions, thus improving the stability of system operation.

[0083] S405. When the heartbeat status indicates that the first controller has failed, the monitoring and control module controls the second controller to take over the exposure synchronization control of the image acquisition module in order to maintain the continuous output of video data.

[0084] Upon confirming the failure of the first controller, the monitoring and control module immediately initiates a fault takeover process, with the second controller taking over the camera exposure synchronization control function. In practice, the monitoring and control module sends a control switch command to the second controller. Based on its own clock signal and exposure control strategy, the second controller sends exposure parameters, frame synchronization signals, and image configuration parameters to the image acquisition module, switching the camera to a working mode controlled by the second controller. For example, if the ADAS controller stops outputting the FSYN synchronization signal due to a software crash, the second controller can take over exposure control in a very short time, continuing to maintain a stable video stream output from the camera. Through this automatic fault takeover mechanism, even if the ADAS controller completely fails, the DVR system can still continuously acquire video data, avoiding the problems of video stream interruption and recording loss caused by single-point controller failure in traditional solutions, thus significantly improving system security and reliability.

[0085] In one possible implementation, the heartbeat status indicates a failure of the first controller in at least one of the following situations:

[0086] No heartbeat signal was received from the first controller after a preset time;

[0087] The received heartbeat signal indicates that the exposure synchronization function of the first controller is malfunctioning;

[0088] The video stream received by the second controller is interrupted, displays distorted images, or has an abnormal frame rate.

[0089] In one specific implementation, the monitoring and control module can determine that the first controller has failed based on at least one of the following conditions.

[0090] The first scenario is when a heartbeat signal from the first controller is not received within a preset time. For example, if the system specifies that a heartbeat message must be received within 500ms, and no heartbeat packet is received after 500ms, the first controller is considered to be offline or experiencing a communication failure.

[0091] The second scenario is when the received heartbeat signal indicates an abnormality in the exposure synchronization function of the first controller. For example, the first controller may actively report fault information such as FSYN abnormality, exposure control failure, or camera sensor (ISP) control abnormality in the heartbeat status data. In this case, the monitoring and control module directly determines that the exposure control capability has failed.

[0092] The third scenario is when the video stream received by the second controller is interrupted, displays glitches, or has an abnormal frame rate. For example, if video frames are lost consecutively, the video stream bitrate drops abnormally, or the frame rate drops from 30fps to below 10fps, the monitoring and control module, based on the video quality detection results, determines that the first controller is no longer able to maintain normal exposure synchronization control.

[0093] Understandably, a multi-dimensional fault determination mechanism can avoid misjudgments caused by relying solely on heartbeat signals, thereby improving the accuracy of fault detection and the reliability of the system.

[0094] In one possible implementation, the method further includes:

[0095] After the second controller takes over the exposure synchronization control, the monitoring and control module continues to monitor the recovery status of the first controller; and when the first controller recovers to normal and its exposure synchronization accuracy meets the preset threshold, the monitoring and control module switches the exposure synchronization control back to the first controller, or maintains the second controller as the current master device until the next system restart.

[0096] It should be understood that after the second controller takes over exposure synchronization control, the monitoring and control module does not stop monitoring the status of the first controller, but continues to monitor its recovery. Specifically, the monitoring and control module continues to receive the heartbeat signal resent by the first controller and checks whether its exposure synchronization function has returned to normal. When the first controller is detected to be back online and running normally for several consecutive cycles, its exposure synchronization accuracy is further verified, for example, by checking whether its frame synchronization error, exposure control error, and video output stability meet the preset threshold requirements.

[0097] When the detection results indicate that the first controller has returned to normal operation, the monitoring and control module can perform a control switchback operation, transferring the exposure synchronization control of the image acquisition module back to the first controller, allowing the ADAS controller to resume its primary control role. For example, if the ADAS controller resumes normal operation after a software malfunction and its synchronization error is verified to be within the allowable range, the system automatically restores its original control architecture.

[0098] In another implementation, even if the first controller recovers, the system can maintain the second controller as the current master controller until the vehicle is powered on and restarted, at which point the default master controller configuration will be restored. This approach avoids system instability caused by frequent switching of control, improving the continuity and reliability of operation.

[0099] Understandably, through the aforementioned automatic takeover and recovery switching mechanism, the system forms a complete fault-tolerant closed loop, which not only ensures continuous video stream output when the ADAS controller fails, but also restores control capabilities after the fault is cleared, thereby further improving the stability, reliability, and safety redundancy of the intelligent driving DVR system.

[0100] Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 5As shown, the electronic device 50 provided in this embodiment includes at least one processor 501 and a memory 502. Optionally, the device 50 further includes a communication component 503. The processor 501, memory 502, and communication component 503 are connected via a bus 504.

[0101] In a specific implementation, at least one processor 501 executes computer execution instructions stored in memory 502, causing at least one processor 501 to perform the above-described method.

[0102] The specific implementation process of processor 501 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.

[0103] In the above embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.

[0104] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.

[0105] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.

[0106] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.

[0107] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the above-described method.

[0108] The aforementioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.

[0109] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in the device.

[0110] The division of units is merely a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.

[0111] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0112] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0113] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0114] Based on the above disclosure, those skilled in the art will understand that the computer-readable storage medium and its related implementation methods provided in the embodiments of the present invention are not limited to the specific hardware or logical partitioning forms described above. In actual product or system deployments, computer execution instructions can be encapsulated in different software distribution packages or firmware modules and distributed via networks, optical discs, or mobile storage devices. When computer execution instructions are loaded and executed by one or more processors, in addition to implementing the aforementioned method steps, hardware resource configurations can be automatically identified according to specific application scenarios, and thread priorities or memory allocation strategies can be dynamically adjusted to optimize execution efficiency without manual intervention. Furthermore, the computer-readable storage medium can also be integrated into IoT terminals, edge computing nodes, or cloud servers to form a distributed instruction storage and collaborative execution system to meet differentiated needs such as high concurrency, low latency, or data privacy protection.

[0115] Furthermore, it should be emphasized that the logical functions corresponding to the methods, units, modules, and storage media in this application, without departing from the core idea of ​​this invention, allow developers to make equivalent refactoring, renaming, or re-division based on specific programming languages ​​(such as C++, Java, Python, etc.) or framework characteristics. For example, the functions of multiple "units" can be merged into a single service process, or message queues or pipe communication can be used instead of direct function calls. Even if these implementation details are not completely the same as the foregoing embodiments, as long as they ultimately achieve the same technical effect and no creative effort is required, they should all be considered to fall within the protection scope of this invention. Similarly, any intermediate data processing forms, exception handling mechanisms, or logging methods embodied in the instructions in the computer-readable storage medium when executed are also derivative technologies of this invention and should not be construed as substantial limitations on the original solution.

[0116] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.

[0117] Finally, it should be noted that other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This invention is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein, and is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope.

Claims

1. A secure backup system, characterized by Its features include: an image acquisition module, a storage module, a first controller, a second controller, and a monitoring and control module; The image acquisition module is communicatively connected to the first controller and the second controller, respectively, and is used to acquire video data during vehicle operation. The storage module includes a first storage unit disposed in a first controller and a second storage unit disposed in a second controller. The first storage unit and the second storage unit are respectively used to store video data and vehicle operation data, and are backed up synchronously in real time. The first controller and the second controller are connected through the monitoring and control module. The monitoring and control module is used to monitor the working status of the first controller and the second controller, and control the first storage unit and the second storage unit to perform synchronous updates when a preset event is triggered.

2. The system of claim 1, wherein, The monitoring and control module is connected to the first controller and the second controller via an integrated circuit bus to obtain the heartbeat status between the first controller and the second controller in order to determine whether the first controller or the second controller has failed.

3. The system of claim 2, wherein, The preset events include at least one of the following: the monitoring and control module detects that the first controller has failed; automatic emergency braking event; driver takeover event; collision event; and acceleration value exceeding a preset threshold event. When the preset event is that the first controller is detected to have failed, the monitoring and control module controls the second controller to take over the exposure synchronization control of the image acquisition module to ensure the continuous output of the video data.

4. The system of claim 2, wherein, The first storage unit is a general-purpose flash memory, and the second storage unit is a secure digital card; both the first and second storage units are configured to use a first-in-first-out (FIFO) strategy for cyclic storage.

5. The system of claim 4, wherein, When the preset event is triggered, the first storage unit and the second storage unit respectively lock and store the video data and the vehicle operation data within a preset time before and after the event, and perform data locking protection.

6. The system of claim 5, wherein, The system also includes a power supply module; the power supply module includes a main power supply unit and a backup power supply unit. The power supply module is electrically connected to the first controller, the second controller, and the image acquisition module, respectively, and is used to switch to the backup power supply unit when the main power supply unit fails.

7. The system of claim 1, wherein, The image acquisition module is connected to the first controller and the second controller via coaxial cables to enable camera reuse.

8. A method of synchronizing exposure control, characterized by, Applied to the security backup system according to any one of claims 1-7, the method comprises: The image acquisition module collects video data during the vehicle's movement and sends the video data to the first controller and the second controller respectively. The monitoring and control module acquires the heartbeat status between the first controller and the second controller; When the heartbeat status indicates that the first controller has failed, the monitoring and control module controls the second controller to take over the exposure synchronization control of the image acquisition module in order to maintain the continuous output of the video data.

9. The method according to claim 8, characterized in that, The heartbeat status indicates that the first controller has failed in at least one of the following situations: No heartbeat signal was received from the first controller within a preset time; The received heartbeat signal indicates that the exposure synchronization function of the first controller is malfunctioning; The video stream received by the second controller is interrupted, displays a distorted image, or has an abnormal frame rate.

10. The method according to claim 8, characterized in that, The method further includes: After the second controller takes over the exposure synchronization control, the monitoring and control module continues to monitor the recovery status of the first controller; When the first controller returns to normal and its exposure synchronization accuracy meets the preset threshold, the monitoring and control module will switch the exposure synchronization control back to the first controller, or maintain the second controller as the current master device until the next system restart.