Vehicle-mounted multi-screen display system

CN122733221APending Publication Date: 2026-09-11AUTOLINK INFORMATION TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611016591.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-09
Publication Date
2026-09-11

AI Technical Summary

Technical Problem

[0005]本申请实施例的目的在于提供一种车载多屏显示系统,用以解决现有的车载多屏显示系统在屏显故障时,无法快速切换恢复的技术问题

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122733221A_ABST
    Figure CN122733221A_ABST
Patent Text Reader

Abstract

This application provides an in-vehicle multi-screen display system, which includes a system-on-a-chip (SoC) end and a display screen end. When the main link fails, the first status monitoring unit and the screen-side microcontroller independently determine whether the main link has failed based on the status information they read and a preset timeout threshold. The display port multi-stream transmission hub is used to switch the display signal from the first output end to the second output end and activate the backup serializer after determining that the main link has failed. The screen-side microcontroller is used to activate the backup deserializer and switch the signal receiving source from the main deserializer to the backup deserializer after independently determining that the link has failed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of vehicle technology, and more specifically, to an in-vehicle multi-screen display system. Background Technology

[0002] With the rapid development of intelligent vehicles and smart cockpit technologies, in-vehicle multi-screen display systems have become an important feature of modern vehicles. Current technologies typically include multiple display units such as an instrument panel screen, a central control screen, a passenger-side screen, and a rear-seat entertainment screen, used to present diverse functions such as vehicle status information, navigation, and entertainment content. To improve user experience, existing technologies largely focus on optimizing display effects, such as improving visual performance indicators like resolution, refresh rate, and color reproduction.

[0003] In terms of system architecture, existing in-vehicle multi-screen display systems mainly adopt centralized or distributed processing solutions. Centralized architectures drive multiple displays through a single main control chip, while distributed architectures configure an independent controller for each display. Both architectures have shortcomings in functional safety design: centralized architectures are susceptible to single points of failure, while distributed architectures lack collaborative fault-tolerance mechanisms. Currently, some systems employ simple signal path backup schemes, such as dual-channel video signal transmission, but a complete closed-loop fault handling mechanism has not been established.

[0004] In addition, existing redundancy solutions mostly use hardware replication methods, such as dual GPU configurations, which significantly increases system costs and is not conducive to widespread application in mass-produced vehicles. Summary of the Invention

[0005] The purpose of this application is to provide an in-vehicle multi-screen display system to solve the technical problem that existing in-vehicle multi-screen display systems cannot quickly switch and recover when the screen fails.

[0006] In a first aspect, the present invention provides an in-vehicle multi-screen display system, which includes a system-on-a-chip (SoC) and a display screen. The system-on-a-chip includes a video processing unit, a display port multi-stream transmission hub, a main serializer, a backup serializer, and a first status monitoring unit. The input terminal of the display port multi-stream transmission hub is connected to the video processing unit, the first output terminal of the display port multi-stream transmission hub is connected to the main serializer, and the second output terminal of the display port multi-stream transmission hub is connected to the backup serializer. The display screen includes a main deserializer, a backup deserializer, a screen-side microcontroller unit, and a display panel. The main deserializer is connected to the main serializer through a first transmission medium to form a main link. The backup deserializer is connected to the backup serializer through a second transmission medium to form a backup link. The outputs of the main deserializer and the backup deserializer are respectively connected to the screen-side microcontroller unit. The output of the screen-side microcontroller unit is connected to the display panel. The first status monitoring unit is used to read the status register of the main serializer to obtain the health status of the main link; the screen-side microcontroller unit is connected to the main deserializer and is used to read the status register of the main deserializer to obtain the health status of the main link. When the main link fails, the first status monitoring unit and the screen-side microcontroller unit independently determine whether the main link has failed based on the status information they read and the same preset timeout threshold. The DisplayPort Multi-Stream Hub is used to switch the display signal from the first output to the second output and activate the backup serializer after determining that the main link has failed. The screen-side microcontroller unit is used to activate the backup deserializer after independently determining that the link has failed, and to switch the signal receiving source from the main deserializer to the backup deserializer.

[0007] In an optional implementation, the master serializer and master deserializer have built-in bidirectional control channels, through which status information is periodically exchanged to form a heartbeat signal; The status register stores the reception status of the heartbeat signal; When the number of consecutive cycles without receiving a heartbeat signal reaches the same preset timeout threshold, the first state monitoring unit and the screen-side microcontroller unit independently determine the main link fault.

[0008] In an optional implementation, after the backup serializer is activated, the backup serializer and the backup deserializer perform link synchronization. While activating the backup deserializer, the screen-side microcontroller synchronizes the operating parameters of the backup deserializer to be consistent with those of the main deserializer, so that the backup link is in a ready state. After the backup deserializer completes link synchronization and outputs a lock signal, the screen-side microcontroller instantly switches the signal receiving source from the main deserializer to the backup deserializer, and the display signal interruption duration of the display panel is no more than 50 milliseconds.

[0009] In an optional implementation, both the first and second transmission media are shielded twisted-pair cables, and high-speed differential signal transmission is achieved between the main serializer and the main deserializer, and between the backup serializer and the backup deserializer, through shielded twisted-pair cables.

[0010] In an optional implementation, the display panel is a vehicle instrument panel used to display vehicle speed, fault warnings, and driving prompts.

[0011] In an optional implementation, the video transmission format for both the primary and backup links is a serial / deserialized transmission format.

[0012] In an optional implementation, the display port multi-stream transmission hub integrates a signal switching module, which is configured via a local control bus to independently control the signal on / off and selection of the first and second output terminals.

[0013] In an optional implementation, the first status monitoring unit is integrated inside the system-on-a-chip and connected to the main serializer via a local integrated circuit bus; The screen-side microcontroller unit is connected to the main deserializer and the backup deserializer respectively via a local integrated circuit bus.

[0014] In an optional implementation, the display screen also includes a trusted execution environment unit, which is used to encrypt and verify the control commands between the system-on-a-chip and the display screen. If the verification is valid, the link switching operation is allowed.

[0015] In an optional implementation, the vehicle-mounted multi-screen display system also includes a regular safety screen, which is configured with a main virtual channel and a redundant virtual channel. The main virtual channel and the redundant virtual channel share the same serializer, the same deserializer, and the same transmission medium. When the main virtual channel fails, the system-on-a-chip will switch the display signal to the redundant virtual channel through the dynamic bandwidth allocation function of the display port multi-stream transmission hub.

[0016] This application provides an in-vehicle multi-screen display system, which includes a system-on-a-chip (SoC) end and a display screen end. The SoC end includes a video processing unit, a display port multi-stream transmission hub, a main serializer, a backup serializer, and a first status monitoring unit. The input terminal of the display port multi-stream transmission hub is connected to the video processing unit, the first output terminal of the display port multi-stream transmission hub is connected to the main serializer, and the second output terminal of the display port multi-stream transmission hub is connected to the backup serializer. The display screen end includes a main deserializer, a backup deserializer, a screen-side microcontroller unit, and a display panel. The main deserializer is connected to the main serializer via a first transmission medium to form a main link, and the backup deserializer is connected to the backup serializer via a second transmission medium to form a backup link. The output terminals of the main deserializer and the backup deserializer are respectively connected to the screen-side microcontroller unit. The microcontroller unit is connected, with its output connected to the display panel. A first status monitoring unit reads the status register of the main serializer to obtain the health status of the main link. The screen-side microcontroller unit is connected to the main deserializer and reads its status register to obtain the health status of the main link. When the main link fails, the first status monitoring unit and the screen-side microcontroller unit independently determine whether the main link has failed based on their respective read status information and a preset timeout threshold. The display port multi-stream hub, upon determining the main link failure, switches the display signal from the first output to the second output and activates the backup serializer. The screen-side microcontroller unit, upon independently determining the link failure, activates the backup deserializer and switches the signal receiving source from the main deserializer to the backup deserializer. This hierarchical redundancy architecture enables seamless video stream switching, improving vehicle safety. Attached Figure Description

[0017] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0018] Figure 1 This is a schematic diagram of the structure of an in-vehicle multi-screen display system provided in an embodiment of this application. Detailed Implementation

[0019] Existing in-vehicle multi-screen display systems primarily focus on optimizing display effects, lacking comprehensive functional safety redundancy designs. Only some systems employ simple single-path backups, failing to form a complete redundancy closed loop of "monitoring-diagnosis-switching-recovery." Monitoring for anomalies means that when a screen display malfunctions, rapid switching and recovery are impossible, leading to multi-screen blackouts and freezes. In particular, instrument panel malfunctions directly affect the driver's judgment of the vehicle's status, creating safety hazards.

[0020] Meanwhile, the lack of layered redundancy based on the different security levels of multiple screens in the vehicle (such as the instrument panel screen being the core security node and the passenger screen being a regular node) leads to a waste of redundant resources or insufficient security protection for core nodes.

[0021] Therefore, there is an urgent need for a functional safety redundancy method for in-vehicle multi-screen display systems that is adaptable to in-vehicle scenarios, has complete redundancy logic, fast switching response, controllable cost, and meets functional safety standards. This method aims to address the shortcomings of existing technologies, balance the safety, stability, and cost of multi-screen displays, and meet the functional safety requirements of in-vehicle intelligent cockpits.

[0022] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.

[0023] Example 1 Figure 1 This is a schematic diagram of the structure of an in-vehicle multi-screen display system provided in an embodiment of this application. Figure 1 As shown, the in-vehicle multi-screen display system includes a system-on-a-chip (SoC) and a display screen.

[0024] The system-on-a-chip includes a video processing unit, a display port multi-stream transmission hub, a main serializer, a backup serializer, and a first status monitoring unit. The input terminal of the display port multi-stream transmission hub is connected to the video processing unit, the first output terminal of the display port multi-stream transmission hub is connected to the main serializer, and the second output terminal of the display port multi-stream transmission hub is connected to the backup serializer.

[0025] The display screen includes a main deserializer, a backup deserializer, a screen-side microcontroller unit, and a display panel. The main deserializer is connected to the main serializer through a first transmission medium to form a main link, and the backup deserializer is connected to the backup serializer through a second transmission medium to form a backup link. The outputs of the main deserializer and the backup deserializer are respectively connected to the screen-side microcontroller unit, and the output of the screen-side microcontroller unit is connected to the display panel.

[0026] In one feasible embodiment, the system-on-a-chip (SoC) side may include a SoC, an eDP (Embedded DisplayPort), a built-in DP (DisplayPort) MST (Multi-Stream Transport) hub, and a serializer. The basic link is that the SoC generates a single native automotive-grade eDP1.2a video bus signal, outputs it to the built-in DPMSTHUB through the eDP port, the built-in DPMSTHUB splits the eDP signal through MST multi-stream transmission and transmits it to the corresponding serializer, and the serializer further serializes it into a high-speed serial signal.

[0027] The SOC can feature an A / B partition redundancy design, with partition A being the primary system and partition B being the redundant system. The two operate independently and are synchronized in real time, ensuring rapid redundancy switching in the event of a global system failure.

[0028] The SoC can be equipped with a built-in DPMSHUB to support the MST multi-stream transmission protocol, splitting the single eDP1.2a signal output by the SoC into multiple independent virtual channel video signals. Each virtual channel corresponds to a display terminal, which can flexibly adapt to in-vehicle screens with different resolutions and refresh rates. It also supports virtual channel redundancy switching, providing hardware support for the software redundancy of ordinary safety screens. It has a fault self-diagnosis function, which can monitor its own bandwidth allocation status and signal splitting status in real time, and promptly report fault information to the SoC and the screen-side MCU (Microcontroller Unit) when a fault occurs.

[0029] The serializer has a built-in CDR clock data recovery circuit and a PLL phase-locked loop, which can ensure the timing stability of serial signal transmission. It also supports heartbeat signal generation function, and realizes real-time monitoring of link faults through heartbeat interaction between SerDes (Serializer / Deserializer).

[0030] In one feasible implementation, the display screen may include a deserializer, a screen MCU, an instrument cluster display, a standard safety screen, and other displays. The standard safety screen here can be a central control screen, a passenger-side entertainment screen, etc.

[0031] Each deserializer corresponds one-to-one with the serializer on the SoC (System on Chip). The core security screen (instrument screen) is equipped with two deserializers (main instrument deserializer and backup instrument deserializer), while the ordinary security screen is equipped with one deserializer.

[0032] The deserializer uses the same automotive-grade SerDes chip as the serializer, and has high-speed serial signal deserialization and clock data recovery functions. It can convert the high-speed serial signal transmitted by the serializer into a parallel video signal and transmit it to the MCU on the screen side.

[0033] With a built-in signal integrity detection module, the signal strength and bit error rate of the transmission medium can be monitored in real time, and the abnormal signal can be reported to the MCU on the screen side in a timely manner. It supports I2C communication interface and can receive switching commands from the MCU on the screen side to realize the switching between the main and backup links.

[0034] The screen-side MCU uses an automotive-grade low-power MCU chip, which has core capabilities such as fault monitoring, instruction parsing, link control, and data interaction, and is the control core of the display screen.

[0035] The first status monitoring unit is used to read the status register of the master serializer to obtain the health status of the main link. The screen-side microcontroller unit is connected to the master deserializer and is used to read the status register of the master deserializer to obtain the health status of the main link.

[0036] Here, a built-in status monitoring unit can be configured with fault monitoring parameters (such as signal delay threshold and bit error rate threshold), and collect the operating status of the deserializer and display screen in real time. Simultaneously, it interacts with the SoC through the AUX (Auxiliary Channel) and I2C communication channels to synchronize link operating status and fault information. It features link parameter synchronization, enabling the synchronization of parameters (resolution, refresh rate, signal gain, timing parameters) between the core security screen's main link and backup link, ensuring the backup link is ready and achieving seamless switching in case of failure. It also supports command parsing and execution, receiving commands from the SoC and its own fault monitoring unit to perform operations such as link switching and fault recovery.

[0037] When the main link fails, the first status monitoring unit and the screen-side microcontroller unit independently determine whether the main link has failed based on the status information they read and the same preset timeout threshold.

[0038] The DisplayPort Multi-Stream Hub is used to switch the display signal from the first output to the second output and activate the backup serializer after determining that the main link has failed.

[0039] The screen-side microcontroller unit is used to activate the backup deserializer after independently determining that the link has failed, and to switch the signal receiving source from the main deserializer to the backup deserializer.

[0040] The master serializer and master deserializer have built-in bidirectional control channels, which periodically exchange status information to form a heartbeat signal. The status register stores the reception status of the heartbeat signal.

[0041] When the number of consecutive cycles without receiving a heartbeat signal reaches the same preset timeout threshold, the first state monitoring unit and the screen-side microcontroller unit independently determine the main link fault.

[0042] After the backup serializer is activated, it synchronizes with the backup deserializer. Simultaneously, the screen-side microcontroller synchronizes the backup deserializer's operating parameters to match those of the primary deserializer, ensuring the backup link is ready. Once the backup deserializer completes link synchronization and outputs a lock signal, the screen-side microcontroller instantly switches the signal receiving source from the primary deserializer to the backup deserializer, with the display panel's signal interruption duration not exceeding 50 milliseconds.

[0043] In one feasible embodiment, a hardware redundancy scheme is adopted for the core safety screen, which has a complete main SerDes link and a backup SerDes link. The two links are independently laid out and run in parallel to ensure that the normal display of the instrument screen is not affected when a single link fails.

[0044] The SoC is equipped with a master serializer and a backup serializer for the instrument panel, while the display screen is equipped with a master deserializer and a backup deserializer. The two SerDes links use independent STP (Shielded Twisted Pair) transmission media and are independently connected to two different virtual channels of the built-in DPMSTHUB. The master link is responsible for signal transmission to the instrument panel under normal operating conditions, while the backup link synchronizes the display data and operating parameters of the master link in real time and is in a ready state. If the master link fails, it immediately switches to the backup link with a switching delay of less than or equal to 50ms, ensuring uninterrupted critical information on the instrument panel.

[0045] For ordinary security screens, a software redundancy solution can be adopted, without the need for additional backup hardware. Redundancy is achieved solely through the built-in DPMSTHUB virtual channel, which has a primary virtual channel and a redundant virtual channel, sharing the same SerDes serializer, deserializer, and transmission medium, thus reducing redundancy costs.

[0046] The display screen here also includes a standard security screen, which is configured with a primary virtual channel and a redundant virtual channel. The primary and redundant virtual channels share the same serializer, deserializer, and transmission medium. When the primary virtual channel fails, the system-on-a-chip (SoC) switches the display signal to the redundant virtual channel through the dynamic bandwidth allocation function of the display port multi-stream transmission hub.

[0047] Specifically, each standard safety panel can correspond to one primary virtual channel and one redundant virtual channel via the built-in DPMSHUB. The two virtual channels share the same SerDes serializer, deserializer, and STP transmission medium. The primary virtual channel is responsible for signal transmission under normal operating conditions, while the redundant virtual channel is in standby mode. When the primary virtual channel fails, the bandwidth of the redundant virtual channel is adjusted through the dynamic bandwidth allocation function of the built-in DPMSHUB, switching the display signal to the redundant virtual channel without needing to activate backup hardware, thus achieving low-cost software redundancy.

[0048] In one feasible embodiment, both the first and second transmission media are shielded twisted-pair cables, and high-speed differential signal transmission is achieved between the main serializer and the main deserializer, and between the backup serializer and the backup deserializer, through shielded twisted-pair cables.

[0049] The display panel is the vehicle's instrument panel, used to display vehicle speed, fault warnings, and driving prompts. The video transmission format for both the main and backup links is serial / deserialized transmission.

[0050] The DisplayPort Multi-Stream Hub integrates a signal switching module, which is configured via a local control bus to independently control the signal on / off and selection of the first and second output terminals.

[0051] The first status monitoring unit is integrated within the system-on-a-chip (SoC) and connected to the main serializer via a local integrated circuit bus. The screen-side microcontroller unit is connected to both the main deserializer and the backup deserializer via the local integrated circuit bus.

[0052] In one feasible embodiment, the display screen also includes a trusted execution environment unit, which is used to encrypt and verify the control commands between the system-on-a-chip and the display screen. If the verification is valid, the link switching operation is allowed.

[0053] Specifically, the TEE (Trusted Execution Environment) adopts an automotive-grade TEE (such as ARM TrustZone), independent of the ordinary execution environment of the on-screen MCU. It features security isolation, identity verification, and command encryption, conforming to the ISO26262 functional safety standard. It is used to complete system signature verification and control command signature verification, preventing component tampering and command forgery, and ensuring the security of redundancy switching and fault recovery processes. A built-in security key management module stores the identity keys of each component (SoC, SerDes chip, DPMSHUB), and verifies the legitimacy of components through key signature verification, ensuring that only legitimate components can access the system.

[0054] Specifically, after the system is powered on, the SoC and the on-screen MCU synchronously complete the initialization of each module, the configuration of the hierarchical redundancy strategy, and the system security verification to ensure that the system components are legitimate and the parameters are consistent.

[0055] For example, the SoC initializes the SoC chip's A / B partitions, eDP interface, built-in DPMSHUB, and all serializers, configuring the transmission rate (e.g., 6Gbps), signal gain, and heartbeat cycle (10ms) for each serializer. The screen-side MCU initializes the corresponding deserializer and its own fault monitoring unit, configuring fault monitoring parameters (signal delay threshold less than or equal to 100μs, bit error rate threshold less than or equal to 0.1%). Simultaneously, the SoC sends initialization commands to each screen-side MCU via the I2C communication channel, synchronizing the resolution and refresh rate parameters of each screen.

[0056] The SoC can issue redundancy policy commands to the built-in DPMSHUB and the screen-side MCU based on the screen type (core / normal). The core security screen (instrument screen) is configured in hardware redundancy mode, enabling primary and backup SerDes links and setting link switching priorities (backup links have higher priority than the emergency mode in case of primary link failure). The normal security screen is configured in software redundancy mode, enabling primary and redundant virtual channels and setting the virtual channel bandwidth allocation ratio (primary virtual channel 70%, redundant virtual channel 30%, dynamically adjustable).

[0057] The on-screen MCU can read the operating parameters (signal gain, timing parameters, EDID information) of the main link deserializer through the I2C communication channel and synchronize them to the backup link deserializer to ensure that the parameters of the backup link are consistent with those of the main link, the backup link is in a ready state, and the synchronization error is less than or equal to 10μs. The synchronization error formula is as follows: ΔP = |P_main - P_standby|; ΔP represents the parameter deviation between the primary and standby links, P_main represents the parameter value of the primary link, and P_standby represents the parameter value of the standby link. The parameters include signal gain, timing offset, etc.

[0058] The TEE trusted environment can be used to verify the legitimacy of all core components of the system, preventing the components from being tampered with. The verification process uses an asymmetric encryption algorithm (RSA-2048).

[0059] In a specific embodiment, the SoC, the built-in DPMSTHUB, the SerDes chip (serializer / deserializer), and the screen-side MCU all have built-in unique identifiers (IDs). The TEE trusted environment collects the identity IDs and digital certificates of each component through the I2C communication channel.

[0060] The TEE trusted environment uses a preset root key (private key) to decrypt the digital certificates of each component, extract the component identity ID, and compare it with the collected component identity ID.

[0061] If all component verifications are valid, the system starts normally and enters normal operating mode. If an illegal component is found, the TEE trusted environment immediately reports the fault information to the SoC and the screen-side MCU, preventing the system from starting. At the same time, a message "Illegal component, requires inspection" is displayed on the vehicle's central control screen to ensure system security.

[0062] The screen-side MCU monitors the operating status of all components in the entire link in real time through the AUX auxiliary channel, I2C communication channel, and heartbeat signals between SerDes. Combined with EDID information and fault monitoring parameters, it can achieve accurate diagnosis of link faults and generate fault reports.

[0063] The AUX auxiliary channel is responsible for monitoring the transmission status of eDP signals (signal strength, timing offset), with a sampling frequency of 1kHz (the specific frequency can be set according to the actual project). The I2C communication channel is responsible for monitoring the SoC operating status, DPMSTUB bandwidth allocation status, and SerDes chip operating status, with a sampling frequency of 500Hz (the specific frequency can be set according to the actual project). The SerDes heartbeat signal (period 10ms) is responsible for monitoring the connection status between the serializer and the deserializer.

[0064] The parameters acquired in real time include the amplitude of the SoC output eDP signal (standard amplitude 1.2V±0.1V), the bandwidth allocation value of each virtual channel of DPMSTHUB, the bit error rate (BER) of the SerDes chip, the signal delay of the transmission medium, the EDID information of the display screen (resolution, refresh rate), and the display status (brightness, contrast, whether the screen is black).

[0065] The MCU on the screen side receives the heartbeat signal sent by the SerDes chip (serializer / deserializer) in real time. If no heartbeat signal is received for three consecutive heartbeat cycles (30ms), it is determined that the SerDes chip has failed or the link is interrupted.

[0066] Based on monitoring parameters and preset thresholds, a threshold-based judgment method is used to determine faults. Simultaneously, the display screen's resolution and refresh rate parameters are read using EDID information and compared with preset parameters; if the deviation exceeds 5%, the display screen is deemed abnormal. Combining bit error rate and signal delay indicators, when the bit error rate is greater than 0.1% or the signal delay is greater than 100μs, a link signal abnormality is determined, triggering an early fault warning.

[0067] When a link failure is detected, the screen-side MCU immediately records the fault point (e.g., instrument main link, central control screen main virtual channel), fault type (e.g., link interruption, SerDes failure), and fault occurrence time (accurate to milliseconds). A fault diagnosis report is generated in JSON format and stored in the screen-side MCU's non-volatile memory. Simultaneously, it is reported to the SoC via the I2C communication channel for later fault investigation and repair. The fault report format is as follows: {"Fault Point": "Instrument Main Link", "Fault Type": "Link Interruption", "Fault Time": "2026-04-2014:30:00.123", "Bit Error Rate": "100%", "Signal Delay": "--"}. The specific fault report format can be defined according to project needs.

[0068] In one feasible implementation, based on the fault diagnosis results, a corresponding redundancy switching operation can be performed according to the hierarchical redundancy strategy to ensure that multi-screen display is not interrupted.

[0069] Specifically, when the main link of the core safety panel (instrument panel) fails (such as main serializer failure, main link interruption, or main deserializer malfunction), the MCU immediately switches to the backup deserializer. The MCU sends a switching command via I2C, and the SoC controls the DPMSHUB to switch the corresponding display signal of the instrument panel to the backup serializer and backup transmission medium (STP shielded twisted pair cable). The switching delay is less than 50ms, ensuring that critical information (vehicle speed, fault, warning, etc.) on the instrument panel is displayed without interruption. If the I2C channel is also malfunctioning, the MCU cannot send a switching command. The MCU and SoC on the panel side determine the link failure based on the SerDes heartbeat timeout, and both parties automatically switch to the backup link according to the agreed time.

[0070] When the link of the ordinary safety screen (central control screen, passenger entertainment screen) fails, software redundancy switching can be performed. Through the dynamic bandwidth allocation function of DPMSTHUB, the bandwidth of the redundant virtual channel can be adjusted, and the SerDes chip and transmission medium can be reused to switch the display signal of the ordinary safety screen to the redundant virtual channel. There is no need to start the backup hardware, thus reducing costs.

[0071] When a global link (such as SoC or DPMSTUB) fails, the SoC's built-in fault monitoring unit monitors the operating status of partition A (the main system) in real time. When it detects a CPU crash, video signal output interruption, or DPMSTUB failure in partition A, it immediately determines it as a global link failure and triggers partition A / B switching. The SoC initiates system redundancy for partition A / B. When partition A (the main system) fails, it starts through partition B (the redundant system). The SoC system reinitializes the main and backup links of the core security screen and the links of the ordinary security screens to ensure rapid recovery of multi-screen display.

[0072] Furthermore, after the redundancy switch is completed, the system enters the redundancy operation mode. The MCU on the screen side continuously monitors the operating status of the redundant links and performs real-time diagnosis of the main link fault points, attempting automatic recovery (such as restarting the faulty SerDes chip and repairing the transmission link signal).

[0073] For repairable faults (such as temporary SerDes chip failure, transmission link signal attenuation, and abnormal virtual channel bandwidth), a self-healing strategy of "reboot + parameter calibration" is adopted. The on-screen MCU collects the operating parameters of the main link fault point in real time to determine the fault type (repairable / unrepairable). Repairable faults include incomplete SerDes chip failure, link signal attenuation, excessive bit error rate, and abnormal virtual channel bandwidth. Unrepairable faults may include physical damage to the SerDes chip, transmission medium breakage, and display screen damage.

[0074] Here, for repairable faults, the screen-side MCU can send a restart command to restart the faulty SerDes chip (restart time less than or equal to 5ms). Simultaneously, a parameter calibration algorithm is initiated to adjust the link signal gain and timing parameters, calibrating the bit error rate and signal delay. The calibration algorithm uses PID closed-loop control, with standard parameters as the target values. Once the main link fault is recovered and stable operation is achieved (stable operation time greater than or equal to 10s, which can be set according to actual project needs), link back-switching is initiated. The screen-side MCU continuously monitors the main link's operating parameters. If, within 10 consecutive seconds, the bit error rate is less than or equal to 0.1%, the signal delay is less than or equal to 100μs, and the heartbeat signal is normal, the main link is considered to be operating stably. The screen-side MCU sends a back-switching command via the I2C communication channel. The SoC controls the built-in DPMSHUB to switch the display signal back to the main link (core security screen) or the main virtual channel (ordinary security screen). The screen-side MCU synchronously controls the deserializer to switch back to the main deserializer. The back-switching process is free of screen flickering and frame loss, with a back-switching delay of less than or equal to 50ms. After the failover is completed, the backup link (or redundant virtual channel) is restored to a ready state, waiting for the next fault response.

[0075] For unrepairable faults, if the main link failure cannot be automatically recovered (such as physical damage to the SerDes chip), the system continues to maintain a redundant operating mode. The MCU on the screen side reports the fault information to the SoC, and the SoC displays the fault prompt (such as "Instrument main link failure, needs maintenance") on the central control screen, which facilitates manual maintenance later.

[0076] Throughout the redundancy switching and fault recovery process, all control commands can be securely verified and signed through the TEE security environment to prevent commands from being tampered with.

[0077] For example, a module (SoC, screen-side MCU) that sends control commands (such as link switching commands, self-healing commands, and back-switch commands) can use the RSA-2048 asymmetric encryption algorithm to encrypt the commands and generate encrypted commands and digital signatures.

[0078] After receiving the encrypted command, the TEE trusted environment decrypts it using a preset public key, extracting the original command and digital signature. Simultaneously, the TEE performs a hash calculation on the original command, generating a hash value, which is then compared with the decrypted digital signature.

[0079] If the signature verification is valid, the TEE trusted environment allows instruction execution, and the on-screen MCU or SoC performs the corresponding redundancy switching and fault recovery operations. If the signature verification is invalid, the TEE trusted environment refuses to execute the instruction, reports the fault information, and prohibits link operations to prevent security risks caused by malicious instruction tampering.

[0080] This application provides an in-vehicle multi-screen display system with fast switching response and high reliability. It enables seamless switching, avoiding interruptions to multi-screen displays. The screen-side MCU provides real-time monitoring and accurate diagnosis, quickly locating fault points, reducing erroneous switching, and supporting automatic fault recovery, further improving system reliability and reducing maintenance costs.

[0081] Furthermore, the in-vehicle multi-screen display system provided in this application combines a hierarchical redundancy strategy, with key security nodes being prioritized and ordinary nodes having simplified redundancy to avoid wasting redundant resources. At the same time, it integrates TEE security verification to improve the security of the redundant system.

[0082] In the embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. Furthermore, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Additionally, the displayed or discussed mutual couplings, direct couplings, or communication connections may be through some communication interfaces; indirect couplings or communication connections between devices or units may be electrical, mechanical, or other forms.

[0083] Furthermore, the units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0084] Furthermore, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0085] It should be noted that if the function is implemented as a software module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0086] In this document, relational terms such as first and second are used only to distinguish one entity or operation from another entity or operation, without necessarily requiring or implying any such actual relationship or order between these entities or operations.

[0087] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A vehicle-mounted multi-screen display system, characterized in that, The in-vehicle multi-screen display system includes a system-on-a-chip (SoC) and a display screen. The system-on-a-chip includes a video processing unit, a display port multi-stream transmission hub, a main serializer, a backup serializer, and a first status monitoring unit. The input terminal of the display port multi-stream transmission hub is connected to the video processing unit, the first output terminal of the display port multi-stream transmission hub is connected to the main serializer, and the second output terminal of the display port multi-stream transmission hub is connected to the backup serializer. The display screen includes a main deserializer, a backup deserializer, a screen-side microcontroller unit, and a display panel. The main deserializer is connected to the main serializer via a first transmission medium to form a main link. The backup deserializer is connected to the backup serializer via a second transmission medium to form a backup link. The outputs of the main deserializer and the backup deserializer are respectively connected to the screen-side microcontroller unit. The output of the screen-side microcontroller unit is connected to the display panel. The first status monitoring unit is used to read the status register of the main serializer to obtain the health status of the main link; the screen-side microcontroller unit is connected to the main deserializer and is used to read the status register of the main deserializer to obtain the health status of the main link; When the main link fails, the first status monitoring unit and the screen-side microcontroller unit independently determine whether the main link has failed based on the status information they read and the same preset timeout threshold. The display port multi-stream transmission hub is used to switch the display signal from the first output terminal to the second output terminal and activate the backup serializer after determining that the main link has failed. The screen-side microcontroller unit is used to activate the backup deserializer after independently determining that the link has failed, and to switch the signal receiving source from the main deserializer to the backup deserializer.

2. The in-vehicle multi-screen display system according to claim 1, characterized in that, The main serializer and the main deserializer have built-in bidirectional control channels, which periodically exchange status information to form a heartbeat signal. The status register stores the reception status of the heartbeat signal; When the number of consecutive cycles without receiving a heartbeat signal reaches the same preset timeout threshold, the first status monitoring unit and the screen-side microcontroller unit each independently determine the main link failure.

3. The in-vehicle multi-screen display system according to claim 1, characterized in that, After the backup serializer is activated, the backup serializer and the backup deserializer perform link synchronization. While activating the backup deserializer, the screen-side microcontroller synchronizes the operating parameters of the backup deserializer to be consistent with those of the main deserializer, thus putting the backup link into a ready state. After the backup deserializer completes link synchronization and outputs a lock signal, the screen-side microcontroller instantly switches the signal receiving source from the main deserializer to the backup deserializer, and the display signal interruption duration of the display panel is no more than 50 milliseconds.

4. The in-vehicle multi-screen display system according to claim 1, characterized in that, Both the first transmission medium and the second transmission medium are shielded twisted-pair cables. High-speed differential signal transmission is achieved between the main serializer and the main deserializer, and between the backup serializer and the backup deserializer, through the shielded twisted-pair cables.

5. The in-vehicle multi-screen display system according to claim 1, characterized in that, The display panel is a vehicle instrument panel used to display vehicle speed, fault warnings, and driving prompts.

6. The in-vehicle multi-screen display system according to claim 5, characterized in that, The video transmission format of the main link and the backup link is serial / deserialized transmission format.

7. The in-vehicle multi-screen display system according to claim 1, characterized in that, The display port multi-stream transmission hub integrates a signal switching module, which is configured via a local control bus to independently control the signal on / off and selection of the first and second output terminals.

8. The in-vehicle multi-screen display system according to claim 1, characterized in that, The first status monitoring unit is integrated inside the system-on-a-chip and is connected to the main serializer via a local integrated circuit bus; The screen-side microcontroller unit is connected to the main deserializer and the backup deserializer respectively via a local integrated circuit bus.

9. The in-vehicle multi-screen display system according to claim 1, characterized in that, The display screen also includes a Trusted Execution Environment (TEX) unit, which is used to encrypt and verify the control commands between the system-on-a-chip (SoC) and the display screen. If the verification is valid, the link switching operation is allowed.

10. The in-vehicle multi-screen display system according to claim 1, characterized in that, The vehicle-mounted multi-screen display system also includes a regular safety screen, which is configured with a main virtual channel and a redundant virtual channel. The main virtual channel and the redundant virtual channel share the same serializer, the same deserializer and the same transmission medium. When the primary virtual channel fails, the system-on-a-chip (SoC) will switch the display signal to the redundant virtual channel through the dynamic bandwidth allocation function of the display port multi-stream transmission hub.