Fault management method, system, vehicle and device for redundant circuit

CN122690907APending Publication Date: 2026-09-04DEEPAL AUTOMOBILE NANJING RESEARCH INSTITUTE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610919822.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-24
Publication Date
2026-09-04

AI Technical Summary

Technical Problem

[0004]本申请提供一种冗余电路的故障管理方法、系统、车辆及设备,以至少解决相关技术中的电路控制系统存在明显的单点失效问题,且缺乏有效的监控与诊断措施的技术问题

Benefits of technology

[0038] It should be noted that the technical effects of any of the implementation methods in aspects two through six can be found in the technical effects of the corresponding implementation methods in aspect one, and will not be repeated here.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122690907A_ABST
    Figure CN122690907A_ABST
Patent Text Reader

Abstract

The embodiment of the application relates to the technical field of electricity, and discloses a fault management method and system of a redundant circuit, a vehicle and equipment, and the method is applied to a first controller in a fault management system of a redundant circuit; the fault management system of the redundant circuit comprises a first redundant circuit and a second redundant circuit; the first redundant circuit comprises a first DCDC converter and the first controller; the second redundant circuit comprises a second DCDC converter and a second controller, and the method comprises the following steps: acquiring a state signal of the second DCDC converter; if the state signal indicates that the second DCDC converter is abnormal, determining a working state of the second redundant circuit; wherein the working state is used for indicating whether there is an electrical safety abnormality in the second redundant circuit; and a safety control strategy corresponding to the working state is executed to ensure the electrical safety of the second redundant circuit. Therefore, the single-point failure problem is avoided, and the accuracy of fault processing and the continuity of vehicle driving under the redundant architecture are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of electrical technology, and more particularly to the field of redundant circuit control technology, specifically to a method, system, vehicle, and equipment for fault management of redundant circuits. Background Technology

[0002] With the rapid development of automotive electrification, intelligence, connectivity, and autonomous driving technologies, the number of onboard electrical devices has increased significantly, chip computing power has continued to improve, and the power of drive motors in drive-by-wire systems has been increasing, leading to a substantial rise in the overall vehicle power demand. Statistics show that the power consumption of automotive electronic control units (ECUs) has increased from less than 1 kilowatt (kW) in traditional vehicles to the current 3 kW, and is expected to soon exceed 6 kW. Such high energy consumption places a heavy burden on the traditional 12-volt (V) power supply system, specifically manifested in increased battery capacity, larger wire diameters, increased vehicle weight, and intensified heat generation, which is detrimental to vehicle lightweighting and energy conservation. Therefore, upgrading the low-voltage electrical architecture from 12V to 48V to reduce wiring harness weight and power consumption has become an inevitable trend in the development of automotive low-voltage electrical systems.

[0003] Currently, the mainstream power supply solution for controllers used in 48V systems is to add a 48V to 12V DC-DC step-down chip to the traditional 12V solution. This first reduces the 48V voltage to 12V, and then uses the mature 12V power supply solution to power the control module. This solution can meet the basic functional requirements, but for controllers with high functional safety requirements, such as drive-by-wire steering, there is a significant single point of failure problem, and there is a lack of effective monitoring and diagnostic measures. Summary of the Invention

[0004] This application provides a fault management method, system, vehicle, and device for redundant circuits, to at least solve the technical problem in related technologies where circuit control systems suffer from significant single-point failures and lack effective monitoring and diagnostic measures. The technical solution of this application is as follows: In a first aspect, this application provides a fault management method for redundant circuits, applied to a first controller in a fault management system for redundant circuits; the fault management system for redundant circuits includes a first redundant circuit and a second redundant circuit; the first redundant circuit includes a first DC-DC converter and a first controller, the first DC-DC converter being electrically connected to the first controller; the second redundant circuit includes a second DC-DC converter and a second controller, the second DC-DC converter being electrically connected to the second controller; the first redundant circuit and the second redundant circuit are electrically isolated; the first controller and the second DC-DC converter are connected through an isolation device; the second controller and the first DC-DC converter are connected through an isolation device; the method includes: acquiring a status signal of the second DC-DC converter; if the status signal indicates that the second DC-DC converter is malfunctioning, determining the operating state of the second redundant circuit; wherein the operating state is used to indicate whether there is an electrical safety abnormality in the second redundant circuit; and executing a safety control strategy corresponding to the operating state to ensure the electrical safety of the second redundant circuit.

[0005] Based on the aforementioned technical means, this application constructs a bidirectional cross-monitoring fault handling mechanism by setting up two fully redundant circuits on the vehicle and having the first controller actively acquire the status signal of the second DC-DC converter. When the signal indicates an abnormality, it further determines whether there is an electrical safety anomaly in the second redundant circuit. Finally, based on the determination result, it executes a matching safety control strategy. This mechanism first uses the status signal as a trigger threshold, avoiding the single reaction of blindly shutting down at the first sign of an anomaly in related technologies. Second, by judging the working status, it filters out false alarms caused by transient interference or non-fatal faults in the status pin, avoiding unnecessary load cut-offs and function interruptions, allowing normal branches to assist in assessing the true danger level of faulty branches. At the same time, a strict safety control strategy is only activated when an electrical safety anomaly is confirmed, effectively compensating for the lack of effective monitoring and diagnostic measures in existing power supply solutions on vehicles, avoiding single-point failure problems, and improving the accuracy of fault handling and the continuity of vehicle operation under the redundant architecture.

[0006] In one possible implementation, the first controller is equipped with a watchdog timer, which is used to receive a watchdog signal from the second controller; determine the operating state of the second redundant circuit, including: if the status signal indicates that the second DC-DC converter is malfunctioning, determining the watchdog state of the second controller based on the watchdog signal received by the watchdog timer, and / or acquiring the output voltage of the second DC-DC converter; and determining the watchdog state and / or the output voltage as the operating state of the second redundant circuit.

[0007] Based on the above technical means, this application can receive the watchdog signal from the second controller by setting a watchdog timer in the first controller, and further obtain the watchdog status of the second controller and / or the output voltage of the second DC-DC converter when the second DC-DC converter is abnormal. These information are used together as the working status of the second redundant circuit, thereby introducing a parallel evaluation of the controller activity and power supply quality based on the status signal triggering, improving the accuracy of fault diagnosis and the reliability of the redundant circuit working together.

[0008] In one possible implementation, the first redundant circuit further includes a first drive circuit and a first load, the first drive circuit being electrically connected to the first controller and the first load being electrically connected to the first drive circuit; the second redundant circuit further includes a second drive circuit and a second load, the second drive circuit being electrically connected to the second controller and the second load being electrically connected to the second drive circuit; the execution of a safety control strategy corresponding to the working state includes: if the dog-feeding state indicates that the second controller is feeding the dog normally, then sending a first indication message to the second controller; wherein the first indication message instructs the second controller to save data and control the second drive circuit to make the second load work in a safety mode.

[0009] Based on the aforementioned technical means, this application allows the first controller to send a first instruction message to the second controller, provided the second controller's dog-feeding is normal. The second controller then saves the data and switches its own load to a safe mode, delegating the fault response action to the faulty branch itself. This avoids control conflicts that might result from unauthorized intervention by the normal branch. Compared to related technologies that blindly cut off the load or power down the entire branch upon detecting a DC-DC anomaly, this approach achieves a smooth transition while the second controller remains healthy, reducing sudden impacts on vehicle operation and enabling fine-grained scheduling of redundant architecture resources.

[0010] In one possible implementation, the first controller and the second drive circuit are connected via an isolation device; the second controller and the first drive circuit are connected via an isolation device; the execution of the safety control strategy corresponding to the working state further includes: if the dog feeding state indicates that the second controller is malfunctioning, and / or the output voltage is not in the first voltage range, then controlling the second drive circuit to make the second load work in a safe mode.

[0011] Based on the aforementioned technical means, this application can establish a direct isolated connection between the first controller and the second drive circuit. This allows the first controller to bypass the failed or poorly powered second controller and directly control the second drive circuit to switch the second load to a safe mode when the second controller malfunctions (e.g., a dog feed error) or the output voltage of the second DC-DC converter deviates from the first voltage range. In other words, in a redundant architecture, a control channel independent of the local controller is set up for critical loads. When the second controller, originally responsible for controlling the load, fails to execute any instructions due to a crash, power loss, or program error, the first controller can still perform a safe shutdown or degradation operation on the second load from the outside. This avoids safety measures failing due to controller unresponsiveness and improves the reliability and fallback capability of the redundant circuit under extreme failure scenarios.

[0012] In one possible implementation, the safety control strategy corresponding to the working state further includes: if the output voltage is within a first voltage range, continuously acquiring the output voltage of the second DC-DC converter within a preset time to obtain an output voltage sequence; determining the changing trend of the output voltage of the second DC-DC converter based on the output voltage sequence; if the changing trend indicates that the output voltage of the second DC-DC converter is deteriorating, sending a first indication message to the second controller; wherein the first indication message instructs the second controller to save the data and control the second drive circuit to make the second load work in a safe mode.

[0013] Based on the aforementioned technical means, this application can continuously sample and analyze the changing trend of the output voltage while it is still within the first voltage range. This allows for the identification of performance degradation signs in the DC-DC converter before the voltage actually exceeds the normal range, thus providing an early warning to the second controller. This avoids the lag inherent in related technologies that rely solely on fixed thresholds to trigger safety measures, as well as the risk of runaway due to sudden drops or spikes in output voltage causing the load to be unable to respond in time. Simultaneously, the detection results of the deterioration trend prompt the second controller to systematically save data and switch the load to a safe mode in the early stages of the fault, achieving a shift from passive response to proactive warning and enhancing the redundancy circuit's defense capabilities against potential failures.

[0014] In one possible implementation, the first redundant circuit further includes a first power supply device, and the second redundant circuit further includes a second power supply device; the first controller and the second power supply device are connected through an isolation device; the second controller and the first power supply device are connected through an isolation device; the execution of the safety control strategy corresponding to the working state further includes: after controlling the second drive circuit to make the second load work in a safe mode, determining the supply voltage of the second power supply device; wherein, the second power supply device is a power supply device located in the same branch as the second DC-DC converter; if the supply voltage is within the second voltage range, then the second DC-DC converter is reset and restarted, and the number of restarts is accumulated; if the status signal of the second DC-DC converter after restarting still indicates that the second DC-DC converter is malfunctioning, and the number of restarts is less than or equal to a preset threshold, then the second DC-DC converter is repeatedly reset and restarted; if the status signal of the second DC-DC converter after restarting still indicates that the target DC-DC converter is malfunctioning, and the number of restarts is greater than the preset threshold, then the second DC-DC converter is determined to be faulty.

[0015] Based on the aforementioned technical means, this application can first confirm that the voltage of the second power supply equipment is within the normal range before attempting to reset and restart the second DC-DC converter, and accumulate the number of restarts. This ensures that the reset action targets only the DC-DC converter's own faults rather than power supply abnormalities, avoiding useless resets when the power supply voltage has deviated from the normal range. Simultaneously, allowing multiple restarts within a preset threshold effectively addresses anomalies caused by transient interference or soft faults, giving the DC-DC converter a chance to recover on its own and reducing unnecessary permanent fault determinations. Only when the number of restarts exceeds the threshold and the anomaly persists is it ultimately considered a permanent fault. This preserves the possibility of recovery from transient issues, improving the availability and fault tolerance of redundant circuits, while avoiding the oscillation risk caused by infinite restarts. It ensures that ineffective operations are stopped promptly when actual hardware failure occurs, providing a clear basis for subsequent maintenance or degraded operation.

[0016] In one possible implementation, the safety control strategy corresponding to the working state further includes: if the power supply voltage is not in the second voltage range, sending a second indication message to the second controller to cause the second controller to shut down the second power supply equipment; wherein the second indication message indicates a fault in the second power supply equipment.

[0017] Based on the aforementioned technical means, this application allows the first controller to send an instruction to the second controller when it detects that the voltage of the second power supply equipment deviates from the normal range. The second controller then actively shuts down the power supply equipment in its own branch, thereby accurately distinguishing the fault source from the DC-DC converter itself as a power supply equipment malfunction, avoiding ineffective reset operations on the DC-DC converter. This approach can promptly cut off unstable power sources, preventing abnormal load operation under undervoltage conditions or damage to subsequent circuits under overvoltage conditions. Simultaneously, the clear fault indication provides accurate diagnostic basis for subsequent maintenance or system degradation.

[0018] In one possible implementation, the safety control strategy corresponding to the working state further includes: if the trend indicates that the output voltage of the second DC-DC converter continues to decrease and the decrease is greater than a preset threshold, then it is determined that the output voltage of the second DC-DC converter is deteriorating.

[0019] Based on the aforementioned technical means, this application can use a continuously decreasing output voltage exceeding a preset threshold as a specific condition for judging a deterioration trend, transforming the output voltage change trend from an abstract qualitative description into a quantifiable judgment criterion. This avoids frequent warnings triggered by minor fluctuations under normal operating conditions and accurately captures early signs of gradual performance degradation in DC-DC converters, such as a slow voltage decline caused by aging output filter capacitors or a deterioration in load regulation caused by increased power transistor on-resistance. Compared to the traditional approach of relying solely on fixed voltage thresholds, this method can identify sub-healthy states where the voltage has not yet exceeded the normal range but has already shown an irreversible downward trend. This provides a valuable time window for subsequent data storage and load switching, transforming fault response from passively waiting for out-of-bounds conditions to actively capturing the degradation process.

[0020] In one possible implementation, the watchdog timer is used to determine the watchdog feeding status of the second controller, and further includes: if no watchdog feeding signal is received from the second controller within a preset time, then the watchdog feeding of the second controller is determined to be abnormal.

[0021] Based on the aforementioned technical means, this application can set a preset time as the receiving window for the dog-feeding signal. If the first controller does not receive the dog-feeding signal from the second controller within this time window, it is determined that the second controller's dog-feeding is abnormal. This monitoring method based on timeout judgment transforms whether the controller is operating normally into a quantifiable time condition, avoiding reliance on complex status message parsing or additional handshake interactions, and reducing the implementation overhead of the monitoring logic itself.

[0022] Secondly, this application provides a fault management system for redundant circuits, including a first redundant circuit and a second redundant circuit. The first redundant circuit includes a first DC-DC converter and a first controller, with the first DC-DC converter electrically connected to the first controller. The second redundant circuit includes a second DC-DC converter and a second controller, with the second DC-DC converter electrically connected to the second controller. The first redundant circuit and the second redundant circuit are electrically isolated. The first controller and the second DC-DC converter are connected via an isolation device. The second controller and the first DC-DC converter are connected via an isolation device. The first controller is configured to: acquire a status signal of the second DC-DC converter; if the status signal indicates that the second DC-DC converter is malfunctioning, determine the operating state of the second redundant circuit; wherein the operating state is used to indicate whether there is an electrical safety abnormality in the second redundant circuit; and execute a safety control strategy corresponding to the operating state to ensure the electrical safety of the second redundant circuit.

[0023] In one possible implementation, the first controller is equipped with a watchdog timer, which is used to receive a watchdog signal from the second controller. Specifically, the first controller is configured to: determine the watchdog state of the second controller based on the watchdog signal received by the watchdog timer if a status signal indicates that the second DC-DC converter is malfunctioning, and / or acquire the output voltage of the second DC-DC converter; and determine the watchdog state and / or output voltage as the operating state of the second redundant circuit.

[0024] In one possible implementation, the first redundant circuit further includes a first drive circuit and a first load, the first drive circuit being electrically connected to the first controller and the first load being electrically connected to the first drive circuit; the second redundant circuit further includes a second drive circuit and a second load, the second drive circuit being electrically connected to the second controller and the second load being electrically connected to the second drive circuit; the first controller is specifically configured to: if the dog-feeding status indicates that the second controller is feeding the dog normally, send a first indication message to the second controller; wherein the first indication message instructs the second controller to save data and control the second drive circuit to make the second load work in a safe mode.

[0025] In one possible implementation, the first controller is connected to the second drive circuit via an isolation device; the second controller is connected to the first drive circuit via an isolation device; the first controller is specifically configured to: if the dog feeding status indicates that the second controller's dog feeding is abnormal, and / or the output voltage is not in the first voltage range, control the second drive circuit to make the second load operate in a safe mode.

[0026] In one possible implementation, the first controller is specifically configured to: if the output voltage is within a first voltage range, continuously acquire the output voltage of the second DC-DC converter within a preset time to obtain an output voltage sequence; determine the changing trend of the output voltage of the second DC-DC converter based on the output voltage sequence; if the changing trend indicates that the output voltage of the second DC-DC converter is deteriorating, send a first indication message to the second controller; wherein the first indication message instructs the second controller to save the data and control the second drive circuit to make the second load work in a safe mode.

[0027] In one possible implementation, the first redundant circuit further includes a first power supply device, and the second redundant circuit further includes a second power supply device; the first controller is connected to the second power supply device via an isolation device; the second controller is connected to the first power supply device via an isolation device; the first controller is specifically configured to: after controlling the second drive circuit to make the second load operate in a safe mode, determine the supply voltage of the second power supply device; wherein, the second power supply device is a power supply device located in the same branch as the second DC-DC converter; if the supply voltage is within a second voltage range, then reset and restart the second DC-DC converter, and accumulate the number of restarts; if the status signal of the second DC-DC converter after restarting still indicates that the second DC-DC converter is malfunctioning, and the number of restarts is less than or equal to a preset threshold, then repeatedly reset and restart the second DC-DC converter; if the status signal of the second DC-DC converter after restarting still indicates that the target DC-DC converter is malfunctioning, and the number of restarts is greater than a preset threshold, then determine that the second DC-DC converter is faulty.

[0028] In one possible implementation, the safety control strategy corresponding to the working state further includes: if the power supply voltage is not in the second voltage range, sending a second indication message to the second controller to cause the second controller to shut down the second power supply equipment; wherein the second indication message indicates a fault in the second power supply equipment.

[0029] If the power supply voltage is not within the second voltage range, a second indication message is sent to the second controller to cause the second controller to shut down the second power supply equipment; wherein, the second indication message indicates a fault in the second power supply equipment.

[0030] In one possible implementation, the first controller is specifically configured to execute a safety control strategy corresponding to the working state, and further includes sending a second indication message to the second controller if the power supply voltage is not in the second voltage range, so that the second controller shuts down the second power supply device; wherein the second indication message indicates a fault in the second power supply device.

[0031] In one possible implementation, the first controller is specifically configured to determine that the output voltage of the second DC-DC converter is deteriorating if the trend indicates that the output voltage of the second DC-DC converter is continuously decreasing and the decrease is greater than a preset threshold.

[0032] In one possible implementation, the first controller is specifically configured to determine that the second controller's dog feeding is abnormal if it does not receive a dog feeding signal from the second controller within a preset time.

[0033] In one possible implementation, the isolation device includes a digital isolator and / or an analog isolator; wherein the first controller is connected to the second DC-DC converter via a digital isolator and / or an analog isolator; the second controller is connected to the first DC-DC converter via a digital isolator and / or an analog isolator; and the first controller is connected to the second controller via a digital isolator.

[0034] Thirdly, this application provides a vehicle with a fault management system including redundant circuitry as described in any of the second aspects.

[0035] Fourthly, this application provides an electronic device including a processor and a memory, the processor being connected to the memory, the memory storing computer instructions, which, when executed on the electronic device, cause the electronic device to perform the method as described in the first aspect.

[0036] Fifthly, this application provides a computer-readable storage medium that, when the instructions in the computer-readable storage medium are executed by a processor of an electronic device, enables the electronic device to perform the methods described in the first aspect and any of their possible implementations.

[0037] Sixthly, this application provides a computer program product including computer instructions that, when executed on an electronic device, cause the electronic device to perform the method described in the first aspect and any possible implementation thereof.

[0038] It should be noted that the technical effects of any of the implementation methods in aspects two through six can be found in the technical effects of the corresponding implementation methods in aspect one, and will not be repeated here.

[0039] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description

[0040] To more clearly illustrate the technical solutions in the embodiments of this application or the background art, the accompanying drawings used in the embodiments of this application will be described below.

[0041] Figure 1 This is a schematic diagram illustrating the structure of a fault management system for a redundant circuit according to an exemplary embodiment; Figure 2 This is a schematic diagram of the structure of another fault management system for redundant circuits according to an exemplary embodiment; Figure 3 This is a flowchart illustrating a fault management method for redundant circuits according to an exemplary embodiment; Figure 4 This is a schematic diagram of the structure of another fault management system for redundant circuits according to an exemplary embodiment; Figure 5 This is a schematic diagram illustrating a fault management process for a redundant circuit according to an exemplary embodiment; Figure 6 This is a schematic diagram illustrating a fault management process for another redundant circuit according to an exemplary embodiment; Figure 7 This is a schematic diagram of an electronic device according to an exemplary embodiment. Detailed Implementation

[0042] To enable those skilled in the art to better understand the technical solutions of this application, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings.

[0043] It should be noted that the terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0044] The embodiments of this application are described below with reference to the accompanying drawings.

[0045] It should be understood that the application of this application is not limited to the examples above. Those skilled in the art can make improvements or modifications based on the above description, and all such improvements and modifications should fall within the protection scope of the appended claims. Those skilled in the art can understand that implementing all or part of the processes of the above embodiments and making equivalent changes according to the claims of this application still fall within the scope of this application.

[0046] In the description of the embodiments of this application, unless otherwise expressly specified and limited, the terms "installation" and "connection" should be interpreted broadly. For example, "connection" can be a detachable connection or a non-detachable connection; it can be a direct connection or an indirect connection through an intermediate medium. "Fixed connection" refers to a connection where the relative positional relationship remains unchanged after connection. "Rotary connection" refers to a connection where the two parts can rotate relative to each other after connection. "Sliding connection" refers to a connection where the two parts can slide relative to each other after connection.

[0047] In the embodiments of this application, "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this document generally indicates that the preceding and following related objects have an "or" relationship.

[0048] The embodiments of this application are described below with reference to the accompanying drawings.

[0049] The redundant circuit fault management system provided in this application embodiment can be applied to controller systems within a vehicle's electrical architecture, such as steer-by-wire systems, brake-by-wire systems, or active suspension systems. Please refer to... Figure 1 The fault management system includes: a first redundant circuit and a second redundant circuit.

[0050] The first redundant circuit includes a first DC-DC converter 11 and a first controller 12. The first DC-DC converter 11 may be a DC-DC buck converter used to convert the 48V input voltage of the power supply device into a 12V output voltage. The first controller 12 is a processor chip responsible for executing the load control algorithm of the first redundant circuit. The first DC-DC converter 11 and the first controller 12 can be directly electrically connected by wires to provide 12V operating power to the first controller.

[0051] The second redundant circuit includes a second DC-DC converter 21 and a second controller 22. Similarly, the second DC-DC converter 21 and the second controller 22 can be directly electrically connected by wires to power the second controller 22. Electrical isolation is achieved between the first and second redundant circuits, meaning that there is no direct current path between the two branches, and the DC resistance between any two nodes is infinite.

[0052] Optionally, the first controller 12 and the second controller 22 can be a microcontroller unit (MCU), a digital signal processor (DSP), a field-programmable gate array (FPGA), or an application-specific integrated circuit (ASIC), or other forms of electronic equipment. This application does not impose specific limitations in this regard.

[0053] In one possible implementation, the first controller 12 and the second DC-DC converter 21 can be connected via an isolation device. The second controller 22 and the first DC-DC converter 11 can also be connected via an isolation device. An isolation device is an electronic component capable of transmitting electrical signals but blocking the path of direct current.

[0054] In this embodiment, the first redundant circuit and the second redundant circuit are electrically isolated and functionally and structurally symmetrical, serving as backups for each other. That is, the functions that the first controller 12 can perform can also be symmetrically implemented by the second controller 22. Specifically, the second controller 22 can monitor the status of the first DC-DC converter 11 and the first controller 12 in the first redundant circuit and execute corresponding safety control strategies when an anomaly is detected. It should be understood that this embodiment does not limit the specific type of isolation device; for example, a multi-channel integrated isolation chip, a single-channel isolation chip, or a combination of discrete isolation circuits can be used. Isolation devices include digital isolators and analog isolators, where digital isolators are used to transmit digital status signals, control signals, watchdog signals, and communication data, and analog isolators are used to transmit analog sampling signals (such as voltage and current). For example, the first controller 12 and the second DC-DC converter 21 are connected via digital isolators and / or analog isolators. The second controller 22 and the first DC-DC converter 11 are connected via digital isolators and / or analog isolators. The first controller 12 and the second controller 22 are connected via digital isolators.

[0055] In this embodiment, the first controller 12 is configured to acquire the status signal of the second DC-DC converter 21. Then, if the status signal indicates that the second DC-DC converter 21 is malfunctioning, the operating state of the second redundant circuit is determined, and the corresponding safety control strategy is executed to ensure the electrical safety of the second redundant circuit.

[0056] The operating status is used to indicate whether there is an electrical safety abnormality in the second redundant circuit. The status signal can be a level signal provided by the status output pin of the DC-DC converter; for example, a high level indicates normal operation, and a low level indicates an abnormal operation. The operating status may include the dog-feeding status of the second controller 22 in the second redundant circuit, the output voltage value of the second DC-DC converter 21, and the voltage value of the power supply equipment, etc. Safety control strategies may include instructing the second controller 22 to save data, controlling the load to enter a safe mode, resetting and restarting the DC-DC converter, or identifying a permanent fault, etc. This application does not impose specific limitations in this regard.

[0057] As can be seen, the embodiments of this application can construct a bidirectional cross-monitoring fault handling mechanism by setting two fully redundant circuits on the vehicle and having the first controller actively acquire the status signal of the second DC-DC converter. When the signal indicates an abnormality, it further determines whether there is an electrical safety abnormality in the second redundant circuit. Finally, based on the determination result, a matching safety control strategy is executed. This mechanism first uses the status signal as a trigger threshold to avoid the single reaction of blindly shutting down at the first sign of an abnormality in related technologies. Secondly, by judging the working status, it filters out false alarms caused by transient interference or non-fatal faults in the status pin, avoiding unnecessary load cut-offs and function interruptions, and enabling normal branches to assist in assessing the true danger level of faulty branches. At the same time, a strict safety control strategy is only activated when an electrical safety abnormality is confirmed, effectively making up for the lack of effective monitoring and diagnostic measures in existing power supply solutions on vehicles, avoiding single point of failure, and improving the accuracy of fault handling and the continuity of vehicle operation under the redundant architecture.

[0058] Reference Figure 2 The first redundant circuit also includes a first drive circuit 13 and a first load 14. The input terminal of the first drive circuit 13 is electrically connected to the output terminal of the first controller 12, and is used to receive drive control signals issued by the first controller 12. The power supply terminal of the first drive circuit 13 is directly or indirectly electrically connected to the first DC-DC converter 11 to obtain the electrical energy required for drive. The first load 14 is electrically connected to the output terminal of the first drive circuit 13. The first load 14 can be a steering motor of a steer-by-wire system, a brake actuator of a brake-by-wire system, or a solenoid valve of an active suspension system, etc. The first controller 12 can generate pulse width modulation signals or switching signals according to a control algorithm, and drive the first load 14 to work according to the target torque, target position, or target force through the first drive circuit 13.

[0059] Similarly, the second redundant circuit also includes a second drive circuit 23 and a second load 24. The second drive circuit 23 is electrically connected to the second controller 22, and the second load 24 is electrically connected to the second drive circuit 23. The drive and load of the second redundant circuit are symmetrical to the first redundant circuit in function and structure, that is, the second controller 22 can control the second drive circuit 23, thereby driving the second load 24.

[0060] Optionally, the first drive circuit 13 and the second drive circuit 23 can be integrated motor drivers (such as three-phase bridge inverters) or combinations of discrete power switching transistors and their gate drive chips. The first load 14 and the second load 24 can be two independent windings of the same actuator or two independent actuators with the same function to achieve redundancy. This application does not limit the specific topology of the drive circuits.

[0061] As a feasible implementation, when the redundant circuit is in normal working condition, the first controller 12 can control the first drive circuit 13 to make the first load 14 work, and the second controller 22 can control the second drive circuit 23 to make the second load 24 work, with the two branches operating independently. When a branch fails (for example, the first DC-DC converter 11 malfunctions), the controller of the other branch (i.e., the second controller 22) sends a command to the first controller 12 through an isolation device according to the fault management strategy, or directly takes over the control of the first drive circuit 13 through the redundant control path (for example, the output port of the second controller 22 is connected to the control terminal of the first drive circuit 13 through a digital isolator), so that the first load 14 enters a safe state (such as zero torque output, maintaining the current position, or switching to passive damping mode).

[0062] As can be seen, in this embodiment, by setting two fully redundant circuits on the vehicle and having the first controller 12 actively acquire the status signal of the second DC-DC converter 21, and further determining whether there is an electrical safety anomaly in the second redundant circuit when the signal indicates an anomaly, a matching safety control strategy is finally executed based on the determination result, thus constructing a bidirectional cross-monitoring fault handling mechanism. This mechanism first uses the status signal as a trigger threshold to avoid the single reaction of blindly shutting down at the first sign of an anomaly in related technologies. Secondly, by judging the working status, false alarms caused by transient interference or non-fatal faults in the status pin are filtered out, avoiding unnecessary load cut-offs and function interruptions, allowing normal branches to assist in assessing the true danger level of faulty branches. At the same time, strict safety measures are only activated when an electrical safety anomaly is confirmed, effectively compensating for the lack of effective monitoring and diagnostic measures in existing power supply schemes on vehicles, avoiding obvious single-point failure problems, and improving the accuracy of fault handling and the continuity of vehicle operation under the redundant architecture.

[0063] In some implementations, refer to Figure 2 The first redundant circuit further includes a first power supply device 15, and the second redundant circuit further includes a second power supply device 25. The first power supply device 15 and the second power supply device 25 are independent of each other, and there is no direct electrical connection between them, thereby achieving dual-path redundancy on the power supply side. In the embodiments of this application, the first power supply device 15 and the second power supply device 25 can be different output terminals of the same battery under the vehicle's electrical architecture, or they can be two independent energy storage units (e.g., a 48V main battery and a 48V backup battery), or they can be a combination of a battery and a DC-DC converter. This application does not limit the specific form of the power supply device, as long as it can provide the nominal rated voltage to the corresponding branch. This application does not impose specific limitations in this regard.

[0064] In one possible configuration, the output of the first power supply device 15 is connected to the first DC-DC converter 11 to provide raw power to the first redundant circuit. Similarly, the output of the second power supply device 25 is connected to the second DC-DC converter 21 to provide raw power to the second redundant circuit.

[0065] To achieve cross-monitoring of the power supply voltage, the first controller 11 and the second power supply device 25 can be connected via an isolation device. Specifically, the output voltage of the second power supply device 25 can be processed by a signal conditioning circuit (e.g., a resistor divider network or an operational amplifier follower) and then transmitted to the analog-to-digital converter pin of the first controller 11 via an analog isolator (e.g., a linear optocoupler or an isolation amplifier). In this way, the first controller 11 can acquire the voltage value of the second power supply device 25 in real time and determine whether it is within a preset voltage operating range (e.g., 36V to 52V). If the second power supply voltage is abnormal, the first controller 12 can take corresponding safety measures according to a preset strategy.

[0066] Similarly, the second controller 22 is connected to the first power supply device 15 via an isolation device. The output voltage of the first power supply device 15 is input to the second controller 22 via a signal conditioning circuit and an analog isolator, enabling the second controller 22 to monitor the voltage status of the first power supply device 15 in real time. Since the first redundant circuit and the second redundant circuit are symmetrical in structure and function, the way the first controller 12 monitors the second power supply device 25 is exactly the same as the way the second controller 22 monitors the first power supply device 15.

[0067] It should be noted that the signal conditioning circuit may include passive components such as voltage divider resistors, filter capacitors, and clamping diodes, used to convert the voltage output from the power supply equipment into a range suitable for the analog isolator input (e.g., 0–5V). The analog isolator can employ an isolation amplifier with high common-mode rejection ratio and low nonlinearity error to ensure sampling accuracy.

[0068] In this way, through the cross control paths in the redundant architecture, the embodiments of this application can still ensure that the other side can safely take over or shut down the load on the faulty side when the power supply or controller on one side fails, thereby improving the electrical safety of the entire redundant circuit.

[0069] The fault management method for redundant circuits provided in this application embodiment can be applied to... Figure 1 The first controller shown in this application is not limited in this embodiment. For ease of description, this application uses a vehicle control method... Figure 1 The first controller shown is used as an example for explanation.

[0070] Please see Figure 3 , Figure 3 This is a flowchart illustrating a fault management method for redundant circuits provided in an embodiment of this application. Figure 3 As shown, the fault management method includes: S301-S302.

[0071] S301. Obtain the status signal of the second DC-DC converter.

[0072] As a feasible implementation, after the vehicle is powered on and initialized, the first controller can continuously read the status signal of the second DC-DC converter. If the status signal indicates that the second DC-DC converter is working normally, the second redundant circuit works normally, the second controller controls the second drive circuit to drive the second load, and the first controller continues to monitor.

[0073] S302. If the status signal indicates that the second DC-DC converter is malfunctioning, the operating status of the second redundant circuit is determined, and the safety control strategy corresponding to the operating status is executed.

[0074] As a possible implementation, if the status signal indicates that the second DC-DC converter is malfunctioning, the first controller can further monitor the watchdog status of the second controller via a watchdog timer. Specifically, the second controller periodically sends a watchdog signal to the first controller through an isolation device. If the first controller does not receive a watchdog signal for a preset time, it determines that the second controller's watchdog feeding is malfunctioning; otherwise, it determines that the watchdog feeding is normal.

[0075] Optionally, the dog feed signal can be a series of fixed-width pulses, a specific field in a serial data frame, or implemented by toggling the level of a dedicated input / output (I / O) pin. This application does not impose any specific limitations on this.

[0076] For example, the second controller sends a 1-millisecond positive pulse as a watchdog signal to the first controller every 50 milliseconds via an isolation device. The first controller has an internal watchdog timer with a timeout period set to 200 milliseconds. If no watchdog signal is received within 200 milliseconds, the first controller determines that the second controller's watchdog feeding is abnormal; if a watchdog signal is received, the watchdog feeding is normal.

[0077] If the dog-feeding status indicates that the second controller is feeding the dog normally, it means that the second controller still has computing and control capabilities. At this time, the first controller sends a first instruction message to the second controller via a digital isolator. After receiving the first instruction message, the second controller writes the key data of its current operation (such as the rotor position of the steering motor, torque command, and system state machine variables) into its memory and controls the second drive circuit on the same branch to put the second load into a safe mode (e.g., the steering-by-wire actuator motor is reduced to 30% of its maximum speed and its output torque is limited). After completing the above operations, the second controller synchronizes its status with the first controller and then enters a reset state. If the dog-feeding status indicates that the second controller is feeding the dog abnormally, it means that the second controller has failed. At this time, the first controller can directly control the second drive circuit through the isolation device to put the second load into a safe mode without waiting for a response from the second controller.

[0078] For example, when the second load is the steering motor of the steer-by-wire system, the safety mode may include: controlling the steering motor to output zero torque, locking the steering wheels in the current position, or switching to manual standby steering mode. When the second load is the brake actuator of the brake-by-wire system, the safety mode may include: controlling the braking pressure to perform emergency braking at maximum deceleration, or releasing the braking pressure to allow the vehicle to rely on regenerative braking or mechanical backup. The above safety control strategies can be pre-set according to specific application scenarios and stored in the non-volatile memory of the first controller.

[0079] For example, taking a steer-by-wire system as an example, the I / O pins of the first controller are connected to the EN pin of the second drive circuit (e.g., a three-phase bridge inverter) via an isolation device. Under normal operating conditions, the second controller controls the EN pin of the second drive circuit to a high level through its own I / O pins, ensuring the second drive circuit operates normally; simultaneously, the I / O pins of the first controller remain in a high-impedance state or output a high level (this does not affect the EN pin of the second drive circuit after passing through the isolation device). If the first controller determines that the second controller's watchdog timer is malfunctioning (i.e., the second controller has failed), the first controller immediately pulls its I / O pin low, outputting a low-level signal. This low-level signal is transmitted to the EN pin of the second drive circuit through the isolation device, forcibly pulling the EN pin low. When the EN pin of the second drive circuit is low, the gate drive outputs of all power switching transistors (Metal-Oxide-Semiconductor Field-Effect Transistor (MOSFET) or Insulated Gate Bipolar Transistor (IGBT)) are turned off, the second drive circuit enters a high-impedance state, the second load (e.g., steering motor) no longer outputs torque, and enters free-coasting or passive damping mode.

[0080] Furthermore, before outputting control signals, the first controller can first read the fault feedback pin of the second drive circuit through an isolation device to confirm the absence of secondary faults such as short circuits. Then, it pulls the EN pin of the second drive circuit low and holds it until the vehicle is powered off or a recovery command is received from the vehicle controller. It can be seen that by setting a watchdog timer to receive the watchdog signal from the second controller, and further acquiring the watchdog status of the second controller and / or the output voltage of the second DC-DC converter when the second DC-DC converter is abnormal, this information is used together as the operating status of the second redundant circuit. This introduces parallel evaluation of controller activity and power supply quality based on status signal triggering, improving the accuracy of fault diagnosis and the reliability of redundant circuit collaborative operation.

[0081] As another feasible implementation, the first controller is also configured to acquire the output voltage of the second DC-DC converter if a status signal indicates that the second DC-DC converter is malfunctioning. Specifically, the output terminal of the second DC-DC converter can be connected to the analog-to-digital conversion pin of the first controller via a voltage divider resistor network or an isolation operational amplifier, thereby enabling the first controller to read the output voltage value of the second DC-DC converter in real time.

[0082] The first controller can determine whether the output voltage is within a first voltage range. This first voltage range is pre-calibrated based on the normal operating voltage range of the power management module or controller in the target branch. For example, when the rated output voltage of the second DC-DC converter is 12V, the first voltage range can be set to 9V to 16V. If the output voltage is within the first voltage range, it indicates that the output voltage of the target DC-DC converter is basically normal, and the second controller can continue to maintain the current operating state of the first redundant circuit or perform further diagnostics.

[0083] It can be understood that the electronic components in the second redundant circuit, such as the second controller, second drive circuit, and second load, all have rated operating voltage ranges. If the output voltage is lower than the first voltage range, the electronic components in the second redundant circuit may experience undervoltage reset or logic malfunction due to insufficient power supply. For example, the second drive circuit may fail to effectively drive the load (e.g., insufficient output torque from the steering motor or slow brake pressure build-up). If the output voltage is higher than this range, it may exceed the tolerance limit of the internal voltage regulation modules of each electronic component in the second redundant circuit, leading to overheating, breakdown, or permanent damage. For example, excessive voltage may cause the gate of the power switch in the second drive circuit to be overvoltage-damped and broken down. Therefore, maintaining the output voltage within the first voltage range is a prerequisite for ensuring the electrical safety and functional integrity of the second redundant circuit and avoiding secondary failures. The first controller can determine whether the DC-DC converter is providing adequate power by detecting whether the output voltage deviates from this range, thereby deciding whether to activate the safety control strategy.

[0084] Specifically, if the output voltage is not within the first voltage range, the first controller determines that the target DC-DC converter is unable to provide stable and safe power to the second controller, second drive circuit, and second load in its branch. At this time, the first controller sends a control command to the drive circuit of the target branch through an isolation device, controlling the second drive circuit to make the second load work in a safe mode.

[0085] Alternatively, if the output voltage is within the first voltage range, the output voltage of the second DC-DC converter is continuously sampled within a preset time period to obtain an output voltage sequence. For example, the preset time period can be set to 100 milliseconds. Then, based on the output voltage sequence, the changing trend of the output voltage of the second DC-DC converter is determined. If the changing trend indicates that the output voltage of the second DC-DC converter is deteriorating, a first indication message is sent to the second controller to notify the second controller to save the data and control the target drive circuit to make the target load operate in a safe mode.

[0086] For example, the first controller detects that the output voltage of the second DC-DC converter is 14V, within a first voltage range, and the second DC-DC converter is at a low level. To further rule out potential failures, the first controller can collect 20 output voltages within a preset time, forming an output voltage sequence: 14.1V, 14.0V, 13.9V, 12.8V, ..., 11.2V. The total drop is 1.9V. If the first controller determines that the drop is greater than a preset threshold (e.g., 1.0V), and each sampled value in the sequence is less than the previous value (no rebound), then it determines that the output voltage is deteriorating. This deterioration trend usually indicates that the power MOSFET, output inductor, or filter capacitor inside the DC-DC converter is aging or damaged, and may fail completely within minutes. Therefore, the first controller can send a first indication message to the second controller, triggering the second controller to save data, put the load into a safe mode, and reset. Through this predictive diagnostic, the load power can be proactively reduced before the faulty DC-DC converter completely fails, avoiding the danger of sudden power outages during driving.

[0087] For example, taking the second redundant circuit as a steer-by-wire system, if a deteriorating trend in the output voltage of the second DC-DC converter is detected, the first controller sends a first instruction message to the second controller during the isolation period. Upon receiving the first instruction message, the second controller, within a few minutes before the power supply to the second redundant circuit is interrupted, quickly saves key states such as the current steering wheel angle, vehicle speed, and steering motor rotor position to non-volatile memory, and linearly reduces the steering motor torque command from its current value to 20% of the maximum output torque. Simultaneously, the second controller can send a prompt message to the vehicle controller, prompting the vehicle controller to illuminate the "Steering system malfunction, please drive with caution" warning light on the vehicle's instrument panel. Subsequently, the second controller actively switches the motor mode to passive damping mode, allowing the steering wheels to automatically return to center based on road feedback without causing any sudden changes in power assist. If the voltage continues to deteriorate, the first controller directly forces the enable pin of the second drive circuit to shut down via the first isolation device, causing the steering motor to enter a high-resistance state. The driver can still safely pull over using the mechanical steering column (if equipped) or the remaining single-sided steering force. This predictive, progressive degradation strategy allows the vehicle to safely transition from full power steering to power limiting and then to manual mode before the DC-DC converter completely fails, avoiding the dangers caused by a sudden loss of power steering while driving.

[0088] In some embodiments, to enable the redundant circuit to recover, this application also designs a reset and restart mechanism for the DC-DC converter. Taking the first controller monitoring the second redundant circuit as an example, after the first controller controls the second load to enter a safe mode, the first controller collects the supply voltage of the second power supply device (e.g., the 48V voltage provided by the second power supply device) through an isolation device. If the second supply voltage is within a preset first voltage range (e.g., 36V~52V), it indicates that the input voltage is normal, and the fault may originate from the second DC-DC converter itself. At this time, the first controller sends a reset signal to the second DC-DC converter through a digital isolator, attempts to restart the second DC-DC converter, and accumulates the number of restarts. If the status signal of the second DC-DC converter still indicates that the second DC-DC converter is malfunctioning after restarting, and the number of restarts is less than or equal to a preset threshold, then the reset and restart of the second DC-DC converter is repeated. Alternatively, if the status signal of the second DC-DC converter still indicates that the second DC-DC converter is malfunctioning after restarting, and the number of restarts is greater than the preset threshold, then the second DC-DC converter is determined to be faulty. For example, the preset threshold can be set to 3 times, with an initial count of 0; this application does not impose specific limitations on this.

[0089] Understandably, if the supply voltage of the second power supply device deviates from the second voltage range, it indicates a fault in the second power supply device itself (such as a depleted battery, poor connector contact leading to excessive voltage drop, or generator voltage regulation failure causing overvoltage). In this case, even if the DC-DC converter itself is intact, it cannot operate normally, and the faulty power supply device needs to be shut down or isolated in time to prevent undervoltage or overvoltage from further damaging other electronic components in the second redundant circuit. Furthermore, the normal operation of the second DC-DC converter depends on the input voltage being within its design limits. If the supply voltage is low, the undervoltage lockout circuit of the second DC-DC converter will prevent it from starting. Sending a reset signal in this case will not restore the converter's operation; instead, repeated attempts to start may cause the switching transistor to operate abnormally and be damaged. If the input voltage is high, exceeding the maximum rated input value of the second DC-DC converter, the transient current or voltage spike generated during reset and restart may break down the input filter capacitor or power semiconductor devices. Therefore, a reset and restart operation is only physically feasible when the supply voltage is within the second voltage range.

[0090] For example, taking a preset threshold of 3 times and an initial count of 0 as an example. If, after the first restart, the first controller rereads the status signal of the second DC-DC converter, and the status returns to normal, the second redundant circuit continues to operate normally. If it is still abnormal, it is reset and restarted again until the number of restarts exceeds 3. If the status signal is still abnormal after more than 3 restarts, the first controller determines that the second DC-DC converter has suffered a permanent failure, reports the fault information, and maintains the second load operating in a safe mode.

[0091] In another possible implementation, if the first controller detects that the supply voltage of the second power supply device exceeds a second voltage range (e.g., below 36V or above 52V), it determines that the second power supply device is faulty. In this case, the first controller sends a second indication message to the second controller (if the second controller is still operational) through an isolation device, indicating that the second power supply device is faulty; if the second controller has failed, the first controller records the fault and maintains a safe mode.

[0092] Based on the above technical solution, this application constructs a bidirectional cross-monitoring fault handling mechanism by setting two fully redundant circuits on the vehicle and having the first controller actively acquire the status signal of the second DC-DC converter. When the signal indicates an abnormality, it further determines whether there is an electrical safety anomaly in the second redundant circuit. Finally, based on the determination result, it executes a matching safety control strategy. This mechanism first uses the status signal as a trigger threshold, avoiding the single reaction of blindly shutting down at the first sign of an anomaly in related technologies. Second, by judging the working status, it filters out false alarms caused by transient interference or non-fatal faults in the status pin, avoiding unnecessary load cut-offs and function interruptions, allowing normal branches to assist in assessing the true danger level of faulty branches. At the same time, strict safety measures are only activated when an electrical safety anomaly is confirmed, effectively compensating for the lack of effective monitoring and diagnostic measures in existing power supply solutions on vehicles, avoiding obvious single point of failure problems, and improving the accuracy of fault handling and the continuity of vehicle operation under the redundant architecture.

[0093] In some embodiments, the fault management method for redundant circuits provided in this application, taking the monitoring of a second redundant circuit by a first controller as an example, can be implemented through the following steps: S1. When the vehicle is powered on, the first controller establishes communication with each isolation device and completes initialization.

[0094] It should be understood that after the vehicle is powered on, the second DC-DC converter and the first DC-DC converter start working respectively, and the output voltage supplies power to the controller of their respective branches.

[0095] S2. The first controller acquires the status signal of the second DC-DC converter.

[0096] S3. If the status signal indicates that the second DC-DC converter is working normally, return to S2 for continuous monitoring.

[0097] S4. If the status signal indicates that the second DC-DC converter is malfunctioning, the second controller determines the operating status of the second redundant circuit.

[0098] Specifically, the first controller monitors the watchdog status of the second controller via a watchdog timer, and / or by acquiring the output voltage of the second DC-DC converter.

[0099] S5. The first controller executes the corresponding safety control strategy according to the working status.

[0100] For example, if the dog-feeding status indicates that the second controller is feeding the dog normally, the first controller sends a first instruction message to the second controller. This first instruction message instructs the second controller to save the data and control the second drive circuit to operate the second load in a safe mode.

[0101] If the dog-feeding status indicates an abnormality in the second controller's dog-feeding, and / or the output voltage of the second DC-DC converter is not within the second voltage range, the first controller controls the second drive circuit through an isolation device to put the second load into a safe mode, without relying on the response of the second controller. This ensures that the load can still be safely shut off even if the second controller has crashed or there is a serious power supply abnormality.

[0102] S6. When the output voltage of the second DC-DC converter is within the first voltage range, the first controller further determines the trend of the output voltage change.

[0103] In one preferred implementation, if the output voltage is within a first voltage range, the first controller continuously acquires the output voltage of the second DC-DC converter within a preset time period to obtain an output voltage sequence. Then, based on this sequence, the trend of output voltage change is determined, for example, by calculating the slope through linear regression or by comparing moving averages.

[0104] If the trend indicates that the output voltage is deteriorating (e.g., the output voltage continues to drop and the drop is greater than a preset threshold), the first controller sends a first indication message to the second controller.

[0105] S7. After executing the safety mode, the first controller determines the power supply voltage of the second power supply device.

[0106] In one possible implementation, if the supply voltage is within the second voltage range, it indicates that the supply is normal, and the fault may originate from the second DC-DC converter itself. The first controller sends a reset signal to the second DC-DC converter to attempt to reset and restart it, and accumulates the number of restarts. If the status signal of the second DC-DC converter still indicates abnormal operation after restarting, and the number of restarts is less than or equal to a preset threshold, the reset and restart operation is repeated. If the number of restarts exceeds the preset threshold, a permanent fault in the second DC-DC converter is determined, and the issue is reported to the vehicle controller.

[0107] Alternatively, if the supply voltage is not within the second voltage range, it indicates a fault in the power supply equipment or wiring harness. The first controller sends a second instruction message to the second controller, instructing the second controller to shut down the second power supply equipment (e.g., disconnect the power supply relay) and report a power supply equipment fault.

[0108] S8. The first controller decides whether to completely exit or degrade operation based on the severity of the fault.

[0109] If the second DC-DC converter is determined to be permanently faulty, or the second power supply is shut down, the second redundant circuitry will completely cease operation. The first redundant circuitry will continue to perform critical functions (such as unilateral steering or braking) or cease operation in a safe state (such as zero torque, parking) until the fault is resolved.

[0110] Through the aforementioned fault diagnosis and graded failure safety control, this application introduces multi-dimensional diagnostic information, such as cross-branch sampling, dog-feeding status fusion, output voltage trend analysis, and power supply voltage judgment, compared to related technologies that rely solely on the DC-DC converter's own status signals or single threshold judgments. This improves the diagnostic coverage for both single-point and multi-point faults, avoids unnecessary circuit shutdowns, and maximizes the availability of redundant circuits while ensuring functional safety, thus guaranteeing the vehicle's basic functions.

[0111] In some embodiments, such as Figure 4 As shown, Figure 4 A schematic diagram of a fault management system for another type of redundant circuit is shown. The fault management system for redundant circuits includes a first redundant circuit and a second redundant circuit. The first redundant circuit includes a first power supply device, a first DC-DC converter, a first power management module, a first controller, a first signal conditioning circuit, a first drive circuit, and a first load; the second redundant circuit includes a second power supply device, a second DC-DC converter, a second power management module, a second controller, a second signal conditioning circuit, a second drive circuit, and a second load. Multiple isolation devices are provided between the two redundant circuits, including a first digital isolator, a second digital isolator, a third digital isolator, a fourth digital isolator, a fifth digital isolator, a sixth digital isolator, a seventh digital isolator, a first analog isolator, and a second analog isolator.

[0112] The first power supply device provides a rated voltage of 48V as the input voltage to the first DC-DC converter. After being stepped down by the first DC-DC converter, it generates a rated voltage of 12V to power the first power management module. The first power management module generates the operating power required by the first controller. Simultaneously, the first power supply device directly provides a rated voltage of 48V to the first drive circuit, and the first controller controls the first drive circuit to drive the first load. Similarly, the second power supply device supplies power to the second DC-DC converter and the second drive circuit, and the second controller controls the second drive circuit to drive the second load.

[0113] Regarding cross-monitoring connections: the second controller controls the reset and power-on of the first DC-DC converter through the first digital isolator; the input voltage of the first power supply device is processed by the first signal conditioning circuit and transmitted to the second controller for sampling and monitoring through the first analog isolator; the status output signal of the first DC-DC converter is input to the second controller through the second digital isolator; the second controller directly participates in the control of the first drive circuit through the third digital isolator, forming an OR logic relationship with the first controller; the first controller and the second controller communicate with each other and perform watchdog monitoring through the fourth digital isolator.

[0114] The first redundant circuit and the second redundant circuit are completely symmetrical in structure and function. The power supply path, load path, and monitoring and control strategy for the second DC-DC converter in the second branch are the same as those in the first branch. The isolation devices used (the first to seventh digital isolators and the first and second analog isolators) can be any combination of multi-channel integrated isolation chips, single-channel isolation chips, or discrete isolation circuits, and this application does not impose any restrictions on them.

[0115] In some embodiments, combined with Figure 4 ,like Figure 5 As shown, Figure 5 The fault management process for redundant circuits includes the following steps: The vehicle is powered on and initialization is complete. The first controller monitors the status signal of the second DC-DC converter and determines whether the second DC-DC converter status signal is low. If the second DC-DC converter status signal is low and the watchdog timer of the second controller is functioning normally, the first controller notifies the second controller of a DC-DC converter malfunction, saves the data, and enters safe mode. The second controller controls the second drive circuit to make the second load operate in safe mode. If the second DC-DC converter status signal is not low, it is determined that the second DC-DC converter is working normally, and the first controller monitors the status signal of the second DC-DC converter.

[0116] If the status signal of the second DC-DC converter is low and the watchdog timer of the second controller malfunctions, the first controller controls the second drive circuit to put the second load into a safe mode. Then, the first controller monitors the supply voltage of the second power supply device and determines whether the supply voltage is normal. If the supply voltage is normal, the first controller attempts to reset the second DC-DC converter, starts a restart count, and determines whether the second DC-DC converter is still malfunctioning after restarting. If the second DC-DC converter is still malfunctioning, it determines whether the number of resets and restarts of the first DC-DC converter exceeds a preset threshold. If the number of resets and restarts of the first DC-DC converter exceeds the preset threshold, the first DC-DC converter is faulty. If the number of resets and restarts of the first DC-DC converter does not exceed the preset threshold, the first controller attempts to reset the second DC-DC converter, starts a restart count, and determines whether the second DC-DC converter is still malfunctioning after restarting. If the second DC-DC converter is normal, the first controller monitors the status signal of the second DC-DC converter.

[0117] If the power supply voltage is abnormal, the second power supply equipment is faulty.

[0118] In some embodiments, combined with Figure 4 ,like Figure 6 As shown, Figure 6 The fault management process for redundant circuits includes the following steps: The vehicle is powered on and initialization is complete. The first controller monitors the status signal of the second DC-DC converter to determine if the status signal is low. If the status signal is low, the first controller monitors the output voltage of the second DC-DC converter and determines if it exceeds a first voltage range. If the output voltage exceeds the first voltage range, the first controller continuously samples the output voltage of the second DC-DC converter to obtain an output voltage sequence. Then, based on the output voltage sequence, it determines whether the second DC-DC converter shows a deterioration trend. If the second DC-DC converter shows a deterioration trend, the first controller notifies the second controller of a DC-DC anomaly, saves the data, and enters a safe mode. The second controller controls the second drive circuit to make the second load operate in safe mode. If the status signal of the second DC-DC converter is not low, it is determined that the second DC-DC converter is working normally, and the first controller monitors the status signal. If the second DC-DC converter does not show a deterioration trend, it is working normally, and the first controller monitors the status signal.

[0119] If the output voltage does not exceed the first voltage range, the first controller controls the second drive circuit to make the second load operate in a safe mode. Then, the first controller monitors the supply voltage of the second power supply device and determines whether the supply voltage is normal. If the supply voltage is normal, the first controller attempts to control the second DC-DC converter to reset, starts a restart count, and determines whether the second DC-DC converter is still abnormal after restarting. If the second DC-DC converter is still abnormal, it determines whether the number of resets and restarts of the first DC-DC converter exceeds a preset threshold. If the number of resets and restarts of the first DC-DC converter exceeds the preset threshold, the first DC-DC converter is faulty. If the number of resets and restarts of the first DC-DC converter does not exceed the preset threshold, the first controller attempts to control the second DC-DC converter to reset, starts a restart count, and determines whether the second DC-DC converter is still abnormal after restarting. If the second DC-DC converter is normal, the first controller monitors the status signal of the second DC-DC converter.

[0120] If the power supply voltage is abnormal, the second power supply equipment is faulty.

[0121] It should be understood that the application of this application is not limited to the examples above. Those skilled in the art can make improvements or modifications based on the above description, and all such improvements and modifications should fall within the protection scope of the appended claims. Those skilled in the art can understand that implementing all or part of the processes of the above embodiments and making equivalent changes according to the claims of this application still fall within the scope of this application.

[0122] This application embodiment can, according to the above method, exemplarily divide a control system or electronic device into functional modules. For example, the control system or electronic device may include functional modules corresponding to each functional division, or two or more functions may be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. It should be noted that the module division in this application embodiment is illustrative and only represents one logical functional division; in actual implementation, there may be other division methods.

[0123] This application also provides a fault management system for redundant circuits. It includes: a first redundant circuit and a second redundant circuit; the first redundant circuit includes a first DC-DC converter and a first controller, the first DC-DC converter being electrically connected to the first controller; the second redundant circuit includes a second DC-DC converter and a second controller, the second DC-DC converter being electrically connected to the second controller; the first redundant circuit and the second redundant circuit are electrically isolated; the first controller and the second DC-DC converter are connected via an isolation device; the second controller and the first DC-DC converter are connected via an isolation device. The first controller is configured as follows: Obtain the status signal of the second DC-DC converter; If the status signal indicates that the second DC-DC converter is malfunctioning, the operating status of the second redundant circuit is determined; wherein, the operating status is used to indicate whether there is an electrical safety abnormality in the second redundant circuit. Implement the safety control strategy corresponding to the working state to ensure the electrical safety of the second redundant circuit.

[0124] In one possible implementation, the first controller is equipped with a watchdog timer, which is used to receive a watchdog signal from the second controller. Specifically, the first controller is configured to: determine the watchdog state of the second controller based on the watchdog signal received by the watchdog timer if a status signal indicates that the second DC-DC converter is malfunctioning, and / or acquire the output voltage of the second DC-DC converter; and determine the watchdog state and / or output voltage as the operating state of the second redundant circuit.

[0125] In one possible implementation, the first redundant circuit further includes a first drive circuit and a first load, the first drive circuit being electrically connected to a first controller, and the first load being electrically connected to the first drive circuit; the second redundant circuit further includes a second drive circuit and a second load, the second drive circuit being electrically connected to a second controller, and the second load being electrically connected to the second drive circuit; the first controller is specifically configured as follows: If the dog feeding status indicates that the second controller is feeding the dog normally, then a first instruction message is sent to the second controller; wherein, the first instruction message instructs the second controller to save the data and control the second drive circuit to make the second load work in a safe mode.

[0126] In one possible implementation, the first controller is connected to the second drive circuit via an isolation device; the second controller is connected to the first drive circuit via an isolation device; the first controller is specifically configured to: if the dog feeding status indicates that the second controller's dog feeding is abnormal, and / or the output voltage is not in the first voltage range, control the second drive circuit to make the second load operate in a safe mode.

[0127] In one possible implementation, the first controller is specifically configured to: if the output voltage is within a first voltage range, continuously acquire the output voltage of the second DC-DC converter within a preset time to obtain an output voltage sequence; determine the changing trend of the output voltage of the second DC-DC converter based on the output voltage sequence; if the changing trend indicates that the output voltage of the second DC-DC converter is deteriorating, send a first indication message to the second controller; wherein the first indication message instructs the second controller to save the data and control the second drive circuit to make the second load work in a safe mode.

[0128] In one possible implementation, the first redundant circuit further includes a first power supply device, and the second redundant circuit further includes a second power supply device; the first controller is connected to the second power supply device via an isolation device; the second controller is connected to the first power supply device via an isolation device. The first controller is specifically configured to: determine the supply voltage of the second power supply device after controlling the second drive circuit to make the second load work in a safe mode; wherein the second power supply device is a power supply device located on the same branch as the second DC-DC converter; If the supply voltage is in the second voltage range, the second DC-DC converter will be reset and restarted, and the number of restarts will be incremented. If the status signal of the second DC-DC converter still indicates that the second DC-DC converter is malfunctioning after restarting, and the number of restarts is less than or equal to the preset threshold, then the second DC-DC converter will be reset and restarted repeatedly. If the status signal of the second DC-DC converter still indicates that the target DC-DC converter is malfunctioning after restarting, and the number of restarts exceeds the preset threshold, then the second DC-DC converter is determined to be faulty.

[0129] In one possible implementation, the execution of the security control policy corresponding to the working state also includes: If the power supply voltage is not within the second voltage range, a second indication message is sent to the second controller to cause the second controller to shut down the second power supply equipment; wherein, the second indication message indicates a fault in the second power supply equipment.

[0130] If the power supply voltage is not within the second voltage range, a second indication message is sent to the second controller to cause the second controller to shut down the second power supply equipment; wherein, the second indication message indicates a fault in the second power supply equipment.

[0131] In one possible implementation, the first controller is specifically configured to: execute the safety control policy corresponding to the working state, and further includes: If the power supply voltage is not within the second voltage range, a second indication message is sent to the second controller to cause the second controller to shut down the second power supply equipment; wherein, the second indication message indicates a fault in the second power supply equipment.

[0132] In one possible implementation, the first controller is specifically configured to determine that the output voltage of the second DC-DC converter is deteriorating if the trend indicates that the output voltage of the second DC-DC converter is continuously decreasing and the decrease is greater than a preset threshold.

[0133] In one possible implementation, the first controller is specifically configured to determine that the second controller's dog feeding is abnormal if it does not receive a dog feeding signal from the second controller within a preset time.

[0134] In one possible implementation, the isolation devices include digital isolators and / or analog isolators; The first controller is connected to the second DC-DC converter via a digital isolator and / or an analog isolator; the second controller is connected to the first DC-DC converter via a digital isolator and / or an analog isolator. The first controller and the second controller are connected via a digital isolator.

[0135] Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 7 As shown, the electronic device includes, but is not limited to, a processor 701 and a memory 702.

[0136] The aforementioned memory 702 is used to store the executable instructions of the aforementioned processor 701. It is understood that the processor 701 is configured to execute instructions to implement the vehicle control method or the active suspension system control method in the above embodiments. That is, the electronic device 70 can be a display device or a vehicle; this application embodiment does not impose any limitations on this.

[0137] Processor 701 is the control center of the electronic device. It connects various parts of the electronic device via various interfaces and lines. By running or executing software programs and / or modules stored in memory 702, and by calling data stored in memory 702, it performs various functions and processes data, thereby controlling the electronic device as a whole. Processor 701 may include one or more processing modules. Optionally, processor 701 may integrate an application processor and a modem processor. The application processor mainly handles the operating system, user interface, and applications, while the modem processor mainly handles wireless communication. It is understood that the modem processor may not be integrated into processor 701.

[0138] The memory 702 can be used to store software programs and various data. The memory 702 may primarily include a program storage area and a data storage area. The program storage area may store the operating system and application programs required by at least one functional module (such as an acquisition unit, a determination module, a processing unit, etc.). Furthermore, the memory 702 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device.

[0139] This application also provides a vehicle including a fault management system for the aforementioned electronic equipment or redundant circuits.

[0140] In some embodiments, this application also provides a computer program product comprising a computer program that, when executed by a device, causes the device to perform the method as described above.

[0141] In this way, the computer program in the computer program product can be customized according to the specific needs and operating conditions of the equipment, realizing personalized control methods and improving the adaptability and flexibility of equipment control.

[0142] In addition, computer program products can be executed on different devices or systems, achieving cross-platform applicability, providing a unified control method for different types of devices, and improving system integration and interoperability.

[0143] Although this application has been described in conjunction with specific features and embodiments, it is obvious that various modifications and combinations can be made thereto without departing from the spirit and scope of this application. Accordingly, this specification and drawings are merely exemplary illustrations of this application as defined by the appended claims, and are considered to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Clearly, those skilled in the art can make various alterations and modifications to this application without departing from the spirit and scope of this application. Thus, if such modifications and modifications of this application fall within the scope of the claims of this application and their equivalents, this application is also intended to include such modifications and modifications.

[0144] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A fault management method for redundant circuits, characterized in that, A first controller is applied in a fault management system for redundant circuits; the fault management system for redundant circuits includes a first redundant circuit and a second redundant circuit; the first redundant circuit includes a first DC-DC converter and a first controller, the first DC-DC converter being electrically connected to the first controller; the second redundant circuit includes a second DC-DC converter and a second controller, the second DC-DC converter being electrically connected to the second controller; the first redundant circuit and the second redundant circuit are electrically isolated. The first controller and the second DC-DC converter are connected via an isolation device; The second controller is connected to the first DC-DC converter via an isolation device; The method includes: Obtain the status signal of the second DC-DC converter; If the status signal indicates that the second DC-DC converter is malfunctioning, then the operating status of the second redundant circuit is determined; wherein, the operating status is used to indicate whether there is an electrical safety abnormality in the second redundant circuit; The safety control strategy corresponding to the operating state is executed to ensure the electrical safety of the second redundant circuit.

2. The fault management method for redundant circuits according to claim 1, characterized in that, The first controller is equipped with a watchdog timer, and the first controller is used to receive the watchdog feed signal from the second controller through the watchdog timer; Determining the operating state of the second redundant circuit includes: If the status signal indicates that the second DC-DC converter is malfunctioning, the watchdog timer receives a watchdog timer feed signal, determines the watchdog feeding status of the second controller, and / or collects the output voltage of the second DC-DC converter. The dog-feeding state and / or output voltage are determined as the operating state of the second redundant circuit.

3. The fault management method for redundant circuits according to claim 2, characterized in that, The first redundant circuit further includes a first drive circuit and a first load, wherein the first drive circuit is electrically connected to the first controller and the first load is electrically connected to the first drive circuit; the second redundant circuit further includes a second drive circuit and a second load, wherein the second drive circuit is electrically connected to the second controller and the second load is electrically connected to the second drive circuit. The execution of the security control strategy corresponding to the working state includes: If the dog-feeding status indicates that the second controller is feeding the dog normally, then a first instruction message is sent to the second controller; wherein, the first instruction message instructs the second controller to save the data and control the second drive circuit to make the second load work in a safe mode.

4. The fault management method for redundant circuits according to claim 3, characterized in that, The first controller and the second drive circuit are connected via an isolation device; the second controller and the first drive circuit are connected via an isolation device; the execution of the safety control strategy corresponding to the working state further includes: If the dog-feeding status indicates that the second controller is malfunctioning, and / or the output voltage is not within the first voltage range, then the second drive circuit is controlled to make the second load work in a safe mode.

5. The fault management method for redundant circuits according to claim 3, characterized in that, The execution of the security control strategy corresponding to the working state also includes: If the output voltage is within the first voltage range, the output voltage of the second DC-DC converter is continuously acquired within a preset time to obtain an output voltage sequence; Based on the output voltage sequence, determine the changing trend of the output voltage of the second DCDC converter; If the trend indicates that the output voltage of the second DC-DC converter is deteriorating, a first indication message is sent to the second controller; wherein the first indication message instructs the second controller to save the data and control the second drive circuit to make the second load work in a safe mode.

6. The fault management method for redundant circuits according to any one of claims 3, 4, or 5, characterized in that, The first redundant circuit further includes a first power supply device, and the second redundant circuit further includes a second power supply device; the first controller and the second power supply device are connected through an isolation device; the second controller and the first power supply device are connected through an isolation device. The execution of the security control strategy corresponding to the working state also includes: After controlling the second drive circuit to make the second load work in a safe mode, the supply voltage of the second power supply device is determined; wherein, the second power supply device is the power supply device located on the same branch as the second DC-DC converter; If the power supply voltage is in the second voltage range, the second DC-DC converter is reset and restarted, and the number of restarts is incremented. If the status signal of the second DC-DC converter still indicates that the second DC-DC converter is malfunctioning after restarting, and the number of restarts is less than or equal to a preset threshold, then the second DC-DC converter will be reset and restarted repeatedly. If the status signal of the second DC-DC converter still indicates that the target DC-DC converter is malfunctioning after restarting, and the number of restarts exceeds a preset threshold, then the second DC-DC converter is determined to be faulty.

7. The fault management method for redundant circuits according to claim 6, characterized in that, The execution of the security control strategy corresponding to the working state also includes: If the power supply voltage is not within the second voltage range, a second indication message is sent to the second controller to cause the second controller to shut down the second power supply device; wherein the second indication message indicates a fault in the second power supply device.

8. The fault management method for redundant circuits according to claim 5, characterized in that, The execution of the security control strategy corresponding to the working state also includes: If the trend indicates that the output voltage of the second DC-DC converter continues to decrease and the decrease is greater than a preset threshold, then it is determined that the output voltage of the second DC-DC converter is deteriorating.

9. The fault management method for redundant circuits according to claim 2, characterized in that, The step of determining the feeding status of the second controller based on the feeding signal received by the watchdog timer further includes: If the dog-feeding signal is not received from the second controller within a preset time, it is determined that the dog-feeding function of the second controller is abnormal.

10. A fault management system for redundant circuits, characterized in that, The fault management system of the redundant circuit includes a first redundant circuit and a second redundant circuit; the first redundant circuit includes a first DC-DC converter and a first controller, the first DC-DC converter being electrically connected to the first controller; the second redundant circuit includes a second DC-DC converter and a second controller, the second DC-DC converter being electrically connected to the second controller; the first redundant circuit and the second redundant circuit are electrically isolated; the first controller and the second DC-DC converter are connected through an isolation device; the second controller and the first DC-DC converter are connected through an isolation device. The first controller is configured as follows: Obtain the status signal of the second DC-DC converter; If the status signal indicates that the second DC-DC converter is malfunctioning, then the operating status of the second redundant circuit is determined; wherein, the operating status is used to indicate whether there is an electrical safety abnormality in the second redundant circuit; The safety control strategy corresponding to the operating state is executed to ensure the electrical safety of the second redundant circuit.

11. The fault management system for redundant circuits according to claim 10, characterized in that, The first controller is equipped with a watchdog timer, and the first controller is used to receive the watchdog feed signal from the second controller through the watchdog timer; The first controller is specifically configured as follows: If the status signal indicates that the second DC-DC converter is malfunctioning, the watchdog timer receives a watchdog timer feed signal, determines the watchdog feeding status of the second controller, and / or collects the output voltage of the second DC-DC converter. The dog-feeding state and / or output voltage are determined as the operating state of the second redundant circuit.

12. The fault management system for redundant circuits according to claim 11, characterized in that, The first redundant circuit further includes a first drive circuit and a first load, wherein the first drive circuit is electrically connected to the first controller and the first load is electrically connected to the first drive circuit; the second redundant circuit further includes a second drive circuit and a second load, wherein the second drive circuit is electrically connected to the second controller and the second load is electrically connected to the second drive circuit. The first controller is specifically configured as follows: If the dog-feeding status indicates that the second controller is feeding the dog normally, then a first instruction message is sent to the second controller; wherein, the first instruction message instructs the second controller to save the data and control the second drive circuit to make the second load work in a safe mode.

13. The fault management system for redundant circuits according to claim 10 or 11, characterized in that, The isolation devices include digital isolators and / or analog isolators; Wherein, the first controller and the second DC-DC converter are connected via the digital isolator and / or the analog isolator; the second controller and the first DC-DC converter are connected via the digital isolator and / or the analog isolator. The first controller and the second controller are connected via the digital isolator.

14. A vehicle, characterized in that, The vehicle includes a fault management system for redundant circuitry as described in any one of claims 10-13.

15. An electronic device, characterized in that, It includes a processor and a memory, the processor being connected to the memory, the memory storing computer instructions that, when executed on the electronic device, cause the electronic device to perform the method as described in any one of claims 1-9.