Onechip thermal management and cross-domain coordination method and system

CN122802526APending Publication Date: 2026-09-22CHINA FAW CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610828200.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-09
Publication Date
2026-09-22

AI Technical Summary

Technical Problem

[0003]1、热功耗过高,全局降频影响安全与体验:OneChip单芯片高负载叠加,结温快速触墙,现有全局统一降频策略,会先降低智驾核心算力,导致智驾性能降级,同时座舱卡顿,无法兼顾安全与体验;

Benefits of technology

[0034]本申请提供分区差异化热管理降频方案,避免全局降频,优先保障智驾核心算力,同时兼顾座舱体验,控制芯片结温在安全范围;

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122802526A_ABST
    Figure CN122802526A_ABST
Patent Text Reader

Abstract

This application discloses a thermal management and cross-domain collaboration method and system for the OneChip single-chip in the vehicle cockpit field. The method includes: setting a domain partitioning strategy for the OneChip single-chip: dividing the device into three independent hardware domains—an intelligent driving safety domain, a cockpit entertainment domain, and a common computing power domain—and ensuring physical isolation between these domains; based on the domain partitioning strategy, ensuring collaborative management across domains, including prioritizing the functionality and performance of the intelligent driving safety domain, including a partitioned differentiated thermal management unit, a layered independent OTA security upgrade unit, a cross-domain zero-copy timing synchronization unit, and a collaborative control center; the partitioned differentiated thermal management unit is used to partition the thermal areas corresponding to the three independent hardware domains and perform differentiated frequency reduction; the layered independent OTA security upgrade unit adopts a dual-partition, dual-channel architecture for independent upgrades of intelligent driving and the cockpit; the cross-domain zero-copy timing synchronization unit uses a shared memory + high-precision timestamp mechanism for zero-copy data transmission and timing alignment across domains.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of vehicle cockpits, and more particularly to the thermal management and cross-domain collaboration method of the OneChip single chip for cockpit-to-vehicle systems, the thermal management and cross-domain collaboration system of the OneChip single chip for cockpit-to-vehicle systems, electronic devices, storage media, and vehicle cockpits. Background Technology

[0002] The OneChip single chip for cockpit-based autonomous driving needs to simultaneously handle multiple tasks such as intelligent driving, cockpit operation, AI large-scale modeling, and high-definition rendering. This high load leads to a surge in chip power consumption and rapid junction temperature spikes. Existing technologies employ a "global unified frequency reduction" strategy, resulting in degraded intelligent driving performance and sluggish cockpit experience. Furthermore, the OneChip solution uses "full-domain integrated OTA upgrades," meaning any upgrade will affect the entire system; upgrade failures can cause a complete system crash, rendering the entire cockpit and intelligent driving system unusable. In addition, cross-domain data (intelligent driving perception data and cockpit human-machine data) share the bus and memory pool, leading to timing asynchrony, high data copying overhead, instruction mismatches, and takeover delays. The existing technological shortcomings and industry pain points can be summarized in the following four points:

[0003] 1. Excessive thermal power consumption and global frequency reduction affect safety and experience: The OneChip single chip is under high load and the junction temperature reaches the wall quickly. The existing global unified frequency reduction strategy will first reduce the computing power of the intelligent driving core, resulting in the degradation of intelligent driving performance. At the same time, the cockpit will lag, and safety and experience cannot be taken into account.

[0004] 2. OTA upgrades are extremely risky: The entire domain integrated OTA upgrade, upgrade deadlock, version conflict will directly cause the OneChip single chip to crash, and the cockpit and intelligent driving will fail at the same time, making it impossible to achieve "free cockpit upgrades, intelligent driving safety unchanged";

[0005] 3. Cross-domain data timing is not synchronized, and copying overhead is large: Intelligent driving perception data (radar, vision) and cockpit human-machine data (DMS, voice commands) share the bus and memory pool. The timestamps are disordered and alignment is difficult. The data copying overhead is large, and the inter-domain latency is >5ms, which leads to command mismatch and takeover delay.

[0006] 4. Insufficient compliance: OTA upgrades lack security protection and cannot meet UN R155 network security requirements; cross-domain data timing is out of sync and cannot meet the real-time requirements of intelligent driving. Summary of the Invention

[0007] The purpose of this invention is to provide a method for thermal management and cross-domain collaboration of a OneChip single chip in a vehicle cabin, a system for thermal management and cross-domain collaboration of a OneChip single chip in a vehicle cabin, an electronic device, a storage medium, and a vehicle cabin, thereby solving at least one of a number of technical problems.

[0008] Key technical challenges include: providing a zone-specific differentiated thermal management frequency reduction solution to avoid global frequency reduction, prioritizing the core computing power of intelligent driving while also considering the cockpit experience, and controlling the chip junction temperature within a safe range; designing a layered independent OTA security upgrade architecture to achieve independent upgrades and fault isolation between the intelligent driving domain and the cockpit domain, preventing full-domain downtime caused by upgrade failures, and meeting UN R155 network security requirements; constructing a cross-domain zero-copy timing synchronization mechanism to eliminate data copy overhead, achieve timing alignment of intelligent driving and cockpit data, with inter-domain latency ≤1ms, meeting the hard real-time requirements of intelligent driving; and achieving coordinated management and control of thermal management, OTA upgrades, and cross-domain synchronization, adapting to the existing OneChip single-chip architecture without significant hardware modifications, reducing mass production and deployment costs, and meeting ISO 26262 compliance requirements.

[0009] This invention provides the following solution:

[0010] According to a first aspect of the present invention, a thermal management and cross-domain collaborative system for a cockpit-based OneChip single chip is provided. For the cockpit-based OneChip single chip, a domain partitioning strategy is set: dividing the chip into three independent hardware domains—an intelligent driving safety domain, a cockpit entertainment domain, and a common computing power domain—and ensuring physical isolation between each domain; based on the domain partitioning strategy, ensuring collaborative management and control across domains, including prioritizing the functionality and performance of the intelligent driving safety domain, including:

[0011] Partition-based differentiated thermal management unit, hierarchical independent OTA security upgrade unit, cross-domain zero-copy timing synchronization unit, and collaborative control center;

[0012] The partitioned differentiated thermal management unit is used to divide the thermal partitions corresponding to three independent hardware domains and to differentiate the frequency reduction.

[0013] The layered independent OTA security upgrade unit adopts a dual-partition, dual-channel architecture for independent upgrades of intelligent driving and the cockpit.

[0014] The cross-domain zero-copy timing synchronization unit adopts a shared memory + high-precision timestamp mechanism for cross-domain data zero-copy transmission and timing alignment;

[0015] The collaborative control center is used for the collaborative management and control of thermal management, OTA upgrades, and timing synchronization.

[0016] Furthermore, it includes: a zone-differentiated thermal management unit comprising multiple sets of independent temperature sensors;

[0017] The sampling frequency of the temperature sensor is ≥1kHz, the junction temperature threshold of the core thermal zone of the intelligent driving system is ≤95℃, and the corresponding frequency reduction is ≤10%.

[0018] Furthermore, the layered independent OTA security upgrade unit adopts AES-256 encrypted transmission and CRC32+ digital signature dual verification for upgrade failure rollback mechanism, ensuring that the failure of a single domain upgrade does not affect the functional operation of another domain.

[0019] Furthermore, it includes: a cross-domain zero-copy timing synchronization unit comprising a shared memory pool, a nanosecond-level timestamp module, and a GPS+BeiDou dual-mode timing module;

[0020] Cross-domain data transmission delay ≤ 1ms, timing deviation ≤ 100ns.

[0021] According to a second aspect of the present invention, a thermal management and cross-domain collaboration method for the OneChip single chip is provided. Based on the three independent hardware domains of the OneChip single chip—the intelligent driving safety domain, the cockpit entertainment domain, and the common computing power domain—the method prioritizes the protection of the functions and performance of the intelligent driving safety domain by implementing domain-based collaborative management.

[0022] It also includes the following steps: system initialization and status calibration, partitioned differentiated thermal management frequency reduction control, layered independent OTA security upgrade control, cross-domain zero-copy timing synchronization control, collaborative management and anomaly handling;

[0023] Among these features, collaborative optimization is achieved through thermal management, OTA upgrades, and cross-domain synchronization, prioritizing the safety and performance of intelligent driving.

[0024] Furthermore, in differentiated thermal management frequency reduction control, if the junction temperature of the cabin entertainment thermal zone is ≥90℃, the frequency reduction will be 15%-30%, high-load tasks will be suspended, and basic navigation and voice functions will be retained.

[0025] Furthermore, in collaborative management, when a high-load state of intelligent driving is detected, unnecessary OTA upgrades and high-load tasks in the cockpit are suspended to prioritize the protection of intelligent driving computing power and thermal safety.

[0026] According to a third aspect of the present invention, an electronic device is provided, comprising: a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other via the communication bus;

[0027] The memory stores a computer program, which, when executed by the processor, causes the processor to perform steps such as the thermal management and cross-domain collaboration method of the OneChip single chip.

[0028] According to a fourth aspect of the present invention, a computer-readable storage medium is provided, comprising: storing a computer program executable by an electronic device, wherein when the computer program is run on the electronic device, the electronic device performs steps such as the OneChip single-chip thermal management and cross-domain collaboration method.

[0029] According to a fifth aspect of the present invention, a vehicle cabin is provided, comprising:

[0030] Electronic devices, including steps for implementing thermal management and cross-domain collaboration methods such as OneChip single-chip in cabin environments;

[0031] The processor runs programs, and when the programs are running, they execute steps such as the thermal management and cross-domain collaboration methods of the OneChip single-chip system based on data output from electronic devices.

[0032] Storage medium used to store programs that, when running, execute steps such as the OneChip single-chip thermal management and cross-domain collaboration method on data output from electronic devices.

[0033] The above solution achieves the following beneficial technical effects:

[0034] This application provides a zone-differentiated thermal management frequency reduction solution to avoid global frequency reduction, prioritize the protection of the core computing power of intelligent driving, and at the same time take into account the cockpit experience, and control the chip junction temperature within a safe range.

[0035] This application designs a layered independent OTA security upgrade architecture to achieve independent upgrades and fault isolation between the intelligent driving domain and the cockpit domain, preventing system crashes caused by upgrade failures and meeting UN R155 network security requirements.

[0036] This application constructs a cross-domain zero-copy timing synchronization mechanism to eliminate data copy overhead, achieve timing alignment of intelligent driving and cockpit data, with inter-domain latency ≤1ms, and meet the hard real-time requirements of intelligent driving.

[0037] This application enables collaborative management of thermal management, OTA upgrades, and cross-domain synchronization. It is compatible with the existing OneChip single-chip architecture, requires no major hardware modifications, reduces mass production deployment costs, and meets ISO 26262 compliance requirements. Attached Figure Description

[0038] Figure 1 This is a structural diagram of a cabin-mounted OneChip single-chip thermal management and cross-domain collaborative system provided by one or more embodiments of the present invention.

[0039] Figure 2 This is a flowchart of a thermal management and cross-domain collaboration method for a OneChip single chip provided by one or more embodiments of the present invention.

[0040] Figure 3 This is a block diagram of an electronic device structure for the thermal management and cross-domain collaboration method of the OneChip single chip provided in one or more embodiments of the present invention. Detailed Implementation

[0041] The technical solution of the present invention will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0042] Figure 1 This is a structural diagram of a cabin-mounted OneChip single-chip thermal management and cross-domain collaborative system provided by one or more embodiments of the present invention.

[0043] like Figure 1 The thermal management and cross-domain collaboration system of the OneChip single chip shown in the diagram sets up a domain division strategy for the OneChip single chip: dividing it into three independent hardware domains: intelligent driving safety domain, cockpit entertainment domain, and common computing power domain, and making each domain physically isolated;

[0044] Based on the domain-based strategy, we ensure collaborative management and control across domains, including prioritizing the functionality and performance of the intelligent driving safety domain.

[0045] It also includes a zone-differentiated thermal management unit, a layered independent OTA security upgrade unit, a cross-domain zero-copy timing synchronization unit, and a collaborative control center;

[0046] The partitioned differentiated thermal management unit is used to divide the thermal partitions corresponding to three independent hardware domains and to differentiate the frequency reduction.

[0047] The layered independent OTA security upgrade unit adopts a dual-partition, dual-channel architecture for independent upgrades of intelligent driving and the cockpit.

[0048] The cross-domain zero-copy timing synchronization unit adopts a shared memory + high-precision timestamp mechanism for cross-domain data zero-copy transmission and timing alignment;

[0049] The collaborative control center is used for the collaborative management and control of thermal management, OTA upgrades, and timing synchronization.

[0050] In this embodiment, it includes:

[0051] The zone-differentiated thermal management unit includes multiple sets of independent temperature sensors;

[0052] The sampling frequency of the temperature sensor is ≥1kHz, the junction temperature threshold of the core thermal zone of the intelligent driving system is ≤95℃, and the corresponding frequency reduction is ≤10%.

[0053] In this embodiment, it includes:

[0054] The layered independent OTA security upgrade unit uses AES-256 encrypted transmission and CRC32+ digital signature dual verification for upgrade failure rollback mechanism, ensuring that a single domain upgrade failure does not affect the operation of another domain.

[0055] In this embodiment, it includes:

[0056] The cross-domain zero-copy timing synchronization unit includes a shared memory pool, a nanosecond-level timestamp module, and a GPS+BeiDou dual-mode timing module;

[0057] Cross-domain data transmission delay ≤ 1ms, timing deviation ≤ 100ns.

[0058] Specifically, in another embodiment, at least a computing power-thermal linkage calibration module is further added as a bridge module to construct a dual-dimensional system of computing power and temperature (e.g., the full-domain collaborative optimization system of the OneChip single chip in the cabin), so as to realize the floating negative feedback adjustment of the two, solve the problem of the interaction between temperature affecting computing power and computing power accumulation affecting temperature, and ensure the safety of the intelligent driving domain.

[0059] This embodiment includes a hardware-level three-domain hard isolation unit, a global computing power pooling unit, a partitioned differentiated thermal management unit, a layered independent OTA security upgrade unit, a cross-domain zero-copy timing synchronization unit, a security protection unit, a computing power-thermal linkage calibration module, and a global control center;

[0060] The hardware-level three-domain hard isolation unit divides the OneChip single chip into three independent hardware domains: intelligent driving safety domain, cockpit entertainment domain, and common computing power domain. Each domain is equipped with an independent MMU and interrupt controller.

[0061] The global computing power pooling unit encapsulates the CPU, NPU, and GPU resources within the chip into standard computing power slices, forming a globally unified computing power pool.

[0062] The zoned differentiated thermal management unit is divided into thermal zones corresponding to the three domains, and differentiated frequency reduction is implemented;

[0063] The layered independent OTA security upgrade unit adopts a dual-partition, dual-channel architecture to achieve independent upgrades for intelligent driving and the cockpit;

[0064] The cross-domain zero-copy timing synchronization unit adopts a shared memory + high-precision timestamp mechanism to achieve cross-domain data zero-copy transmission and timing alignment;

[0065] The security protection unit enables cross-domain unauthorized access interception and OTA security protection;

[0066] The computing power-thermal linkage calibration module serves as a collaborative bridge between computing power scheduling and thermal management, used for:

[0067] Real-time monitoring of the overall chip temperature and dynamic calibration of the upper limit threshold of global computing power: when the temperature rises, the upper limit of global computing power is lowered and the duration of the highest computing power is shortened; when the temperature drops, the upper limit of global computing power and the duration of the highest computing power are restored, realizing floating negative feedback adjustment of computing power and temperature;

[0068] The heat dissipation efficiency parameters of each domain are pre-stored, and the computing power fluctuation range of each domain is adjusted according to the heat dissipation efficiency: for domains with high heat dissipation efficiency, their computing power fluctuation range is expanded to allow higher instantaneous computing power; for domains with low heat dissipation efficiency, their computing power peak and high computing power duration are limited to avoid heat accumulation.

[0069] Based on the above calibration results, when the intelligent driving safety domain requires high computing power, the resource allocation of other domains will be squeezed to prioritize the computing power and thermal safety of the intelligent driving safety domain.

[0070] Based on calibration results, the global control center enables multi-dimensional collaborative control, including scene recognition, dynamic allocation of computing power, emergency computing power circuit breaker, thermal management control, OTA upgrade control, and time synchronization control.

[0071] This embodiment also includes an ASIL-D level intelligent driving safety domain and an ASIL-B level cockpit entertainment domain, with each domain physically isolated and free from cross-domain interference.

[0072] This embodiment also includes establishing a computing power tagging system in the global computing power pooling unit, and dividing computing power slices according to security level, computing power type, and real-time performance.

[0073] This embodiment also includes a zoned differentiated thermal management unit comprising 3 independent temperature sensors. The sampling frequency of the temperature sensors is ≥1kHz, the junction temperature threshold of the intelligent driving core thermal zone is ≤95℃, and the corresponding frequency reduction amplitude is ≤10%.

[0074] This embodiment also includes a layered independent OTA security upgrade unit that uses AES-256 encrypted transmission and CRC32+ digital signature dual verification, and has an upgrade failure rollback mechanism, so that a single domain upgrade failure does not affect the operation of another domain.

[0075] This embodiment also includes a cross-domain zero-copy timing synchronization unit comprising a shared memory pool, a nanosecond-level timestamp module, and a GPS+BeiDou dual-mode timing module, with cross-domain data transmission latency ≤1ms and timing deviation ≤100ns.

[0076] This embodiment also includes a security protection unit comprising a cross-domain access firewall, a dynamic whitelist management module, and an OTA upgrade permission management module, which intercepts abnormal cross-domain access and illegal upgrade packages.

[0077] This embodiment also includes the following: in the computing power-thermal linkage calibration module, the floating negative feedback adjustment is as follows: for every 5°C increase in chip temperature, the global computing power limit is reduced by 3%, and the duration of the highest computing power is shortened by 15%; for every 5°C decrease in temperature, the global computing power limit and the duration of the maximum computing power are restored.

[0078] This embodiment also includes a computing power-thermal linkage calibration module, which limits the maximum computing power of a domain with a heat dissipation efficiency lower than the threshold to no more than 70% of the rated computing power, and the duration of the high computing power state to no more than 30 seconds, in order to avoid heat accumulation.

[0079] Figure 2 This is a flowchart of a thermal management and cross-domain collaboration method for a OneChip single chip provided by one or more embodiments of the present invention.

[0080] like Figure 2 The thermal management and cross-domain collaboration method of the OneChip single-chip for cockpit driving, as shown, is based on three independent hardware domains of the OneChip single-chip: intelligent driving safety domain, cockpit entertainment domain, and public computing power domain. It prioritizes the functionality and performance of the intelligent driving safety domain, based on domain-based collaborative management, including:

[0081] Step S1: System initialization and status calibration, partitioned differentiated thermal management frequency reduction control, layered independent OTA security upgrade control, cross-domain zero-copy timing synchronization control, collaborative management and anomaly handling;

[0082] Step S2 involves collaborative optimization of thermal management, OTA upgrades, and cross-domain synchronization to prioritize intelligent driving safety and performance.

[0083] In this embodiment, the differential thermal management frequency reduction control includes the following: if the junction temperature of the cabin entertainment thermal zone is ≥90℃, the frequency reduction range is 15%-30%, high-load tasks are suspended, and basic navigation and voice functions are retained.

[0084] In this embodiment, the following is included: In the collaborative management and control, when a high load state of intelligent driving is detected, unnecessary OTA upgrades and high load tasks in the cockpit are suspended to prioritize the protection of intelligent driving computing power and thermal safety.

[0085] Specifically, in another specific embodiment, at least a bridge between computing power and thermal linkage calibration is further added to construct a dual-dimensional solution of computing power and temperature (such as the full-domain collaborative optimization method of the OneChip single chip in the cabin driving system), so as to realize the floating negative feedback adjustment of the two, solve the problem of the interaction between temperature affecting computing power and computing power accumulation affecting temperature, and ensure the safety of the intelligent driving domain.

[0086] The steps include: system initialization and status calibration, completing three-domain isolated startup, hot partition threshold calibration, OTA upgrade partition initialization, shared memory and time synchronization calibration, and loading the heat dissipation efficiency parameters of each domain;

[0087] Computing power-thermal linkage calibration monitors the overall chip temperature in real time, dynamically calibrates the upper limit threshold of global computing power and the duration of maximum computing power maintenance, and adjusts the computing power fluctuation range of each domain according to the heat dissipation efficiency of each domain to achieve floating negative feedback regulation of computing power and temperature.

[0088] Scene recognition and full-dimensional status monitoring, real-time monitoring of computing load, junction temperature of each thermal partition, OTA upgrade status, and cross-domain data time sequence status;

[0089] The system enables collaborative management across all domains. Based on the calibrated global computing power limit and the fluctuation range of each domain, it achieves collaborative optimization of dynamic computing power allocation, differentiated thermal management frequency reduction, independent OTA upgrade management, and cross-domain data timing synchronization. When the intelligent driving safety domain requires high computing power, it squeezes resources from other domains to prioritize intelligent driving safety and performance.

[0090] Emergency scenario coordinated response triggers emergency computing power circuit breaker, simultaneously suspending unnecessary high-load tasks and unnecessary OTA upgrades in the cockpit, prioritizing the protection of intelligent driving computing power and thermal safety;

[0091] Security monitoring and anomaly handling, intercepting unauthorized cross-domain access, handling OTA upgrade failure rollbacks, and calibrating cross-domain timing deviations.

[0092] This embodiment also includes a response time of ≤10μs for emergency computing power circuit breaking, freezing of unnecessary high-load tasks in the cockpit, and prioritizing the allocation of recovered computing power to the intelligent driving safety domain.

[0093] This embodiment also includes dynamic allocation of computing power, specifically including: dynamically allocating the computing power ratio between intelligent driving and the cockpit according to four scenarios: high-speed NOA, urban congestion, parking, and in-car entertainment.

[0094] This embodiment also includes differentiated thermal management frequency reduction control. When the junction temperature of the cabin entertainment thermal zone is ≥90℃, the frequency reduction is 15%-30%, high-load tasks are suspended, and basic navigation and voice functions are retained.

[0095] This embodiment also includes, in the whole-domain collaborative management, when a high load state of intelligent driving is detected, suspending unnecessary OTA upgrades and high-load tasks in the cockpit, and prioritizing the protection of intelligent driving computing power and thermal safety.

[0096] It is worth noting that although this system / device only discloses the above-mentioned modules / units, it does not mean that this system / device is limited to the above-mentioned basic functional modules. On the contrary, what this invention intends to express is that, based on the above-mentioned basic functional modules, those skilled in the art can add one or more functional modules in combination with the prior art to form an infinite number of embodiments or technical solutions. That is to say, this system is open rather than closed. It cannot be assumed that the scope of protection of the claims of this invention is limited to the above-disclosed basic functional modules just because this embodiment only discloses a few basic functional modules.

[0097] In one specific embodiment, a thermal management and cross-domain collaborative system architecture for the OneChip single-chip in the cockpit is disclosed. Its core concept is to construct a "three-in-one" collaborative management system to address the three major pain points of the OneChip single-chip: thermal power consumption, OTA risks, and cross-domain timing. This system involves dividing the chip hardware into thermal management zones and implementing differentiated frequency reduction based on task safety priorities to prioritize the core computing power of intelligent driving. At the software level, a layered independent OTA architecture is constructed to decouple the intelligent driving safety domain from the cockpit entertainment domain upgrades, enabling independent upgrades and fault rollback. At the data communication level, a shared memory + timestamp synchronization mechanism is adopted to achieve zero-copy cross-domain data transmission and timing alignment. These three elements work together to solve individual pain points while optimizing overall performance, balancing safety, user experience, and compliance.

[0098] The system architecture of this embodiment is based on the OneChip single chip in the cockpit and adopts a four-layer architecture of "partitioned thermal management unit + hierarchical OTA upgrade unit + cross-domain zero-copy timing synchronization unit + collaborative control center". Each unit works independently and works in coordination, as detailed below:

[0099] 1. Differentiated Thermal Management Unit: Based on the internal module layout of the OneChip single chip, it is divided into three thermal management zones, equipped with independent temperature sensors and frequency reduction control modules to achieve differentiated thermal management: Intelligent Driving Core Thermal Zone: Covers the intelligent driving safety domain (safety core, NPU), sets the highest safe junction temperature threshold (≤95℃), and only slightly reduces the frequency (frequency reduction magnitude ≤10%) when the junction temperature is close to the threshold, prioritizing the protection of the intelligent driving core computing power;

[0100] 2. Cockpit Entertainment Hot Zone: Covers the cockpit entertainment domain (GPU, A55 core), sets a normal junction temperature threshold (≤90℃), and appropriately reduces the frequency (15%-30%) when the junction temperature exceeds the standard, prioritizing basic cockpit functions (navigation, voice) and suspending high-load tasks (4K rendering, in-vehicle games).

[0101] 3. Common Hot Zone: Covers common modules such as computing power domain and bus interface, and sets a general junction temperature threshold (≤88℃). When the junction temperature exceeds the standard, the frequency is dynamically reduced according to the load priority, without affecting the core functions of intelligent driving and cockpit.

[0102] 4. Layered Independent OTA Security Upgrade Unit: Adopting a "dual-partition, dual-channel, dual-verification" architecture, it enables independent upgrades for intelligent driving and the cockpit without interference: Intelligent Driving OTA Partition: Independently stores intelligent driving security domain upgrade packages, using encrypted transmission (AES-256) and dual verification (CRC32 + digital signature), only accepting ASIL-D level authorized upgrade commands, and automatically rolling back to a stable version when the upgrade fails, without affecting cockpit functions;

[0103] 5. Cockpit OTA partition: Independent storage for cockpit entertainment domain upgrade packages, supports OTA incremental upgrades, does not consume intelligent driving computing power and memory during the upgrade process, and only restarts the cockpit module when the upgrade fails, while the core functions of intelligent driving continue to operate normally;

[0104] 6. OTA security protection module: Built-in upgrade permission management, anomaly monitoring, and fault rollback mechanism to intercept illegal upgrade packages and record upgrade logs, meeting UN R155 network security requirements.

[0105] 7. Cross-domain zero-copy timing synchronization unit: Adopting a "shared memory pool + high-precision timestamp + synchronization calibration" mechanism, it realizes zero-copy transmission and timing alignment of intelligent driving and cockpit data: Shared memory pool: It divides an independent shared memory area, and intelligent driving perception data (radar, vision) and cockpit human-machine data (DMS, voice commands) are directly written to the shared memory without secondary copying, reducing transmission overhead;

[0106] 8. High-precision timestamp module: Adds nanosecond-level timestamps to all cross-domain data, and achieves time synchronization calibration based on vehicle GPS + Beidou dual-mode time synchronization, with a synchronization error ≤100ns;

[0107] 9. Timing Alignment Module: Real-time comparison of timestamps between intelligent driving and cockpit data, millisecond-level compensation for deviation data, ensuring that the command mismatch rate is 0 and the inter-domain data transmission delay is ≤1ms.

[0108] 10. Collaborative Control Center: Independent of the three main units, it collects real-time thermal management status, OTA upgrade status, and cross-domain data timing status to achieve collaborative management and control. During OTA upgrades, it temporarily increases the cockpit thermal partition frequency reduction threshold to ensure smooth upgrades. When the intelligent driving system is under high load, it suspends unnecessary OTA upgrades and high-load tasks in the cockpit to prioritize the intelligent driving computing power and thermal safety. When cross-domain data timing is abnormal, it triggers synchronous calibration to avoid command mismatch.

[0109] Based on the thermal management and cross-domain collaborative system architecture of the OneChip single chip in this embodiment, the corresponding control method and closed-loop controllable process are uniformly managed by the collaborative control center throughout the entire process. The steps are clear, reproducible, and verifiable, as detailed below:

[0110] Step 1: System Initialization and Status Calibration

[0111] After power-on, the OneChip single chip completes the initialization of each unit: the partitioned thermal management unit starts the temperature sensor (sampling frequency ≥1kHz) and calibrates the junction temperature threshold of each thermal partition; the hierarchical OTA upgrade unit initializes the dual upgrade partition and encrypted channel and completes permission verification; the cross-domain zero-copy timing synchronization unit initializes the shared memory pool and timestamp module, and achieves time synchronization based on GPS + Beidou, with a calibration error ≤100ns; the collaborative control center completes the status self-check of each unit and enters the normal operation state.

[0112] Step 2: Differentiated thermal management and frequency reduction control for different zones

[0113] The zoned thermal management unit collects junction temperature data for each thermal zone in real time and transmits it to the collaborative control center, where differentiated frequency reduction is implemented according to the following logic:

[0114] Intelligent driving core thermal partition: Junction temperature ≤ 90℃, maintain full frequency operation; 90℃ < junction temperature < 95℃, frequency reduction by 10%; Junction temperature ≥ 95℃, trigger emergency frequency reduction (frequency reduction by 20%), and notify the collaborative control center to suspend high-load tasks in the cockpit.

[0115] In-cabin entertainment thermal zoning: Junction temperature ≤ 85℃, maintain full frequency operation; 85℃ < junction temperature < 90℃, reduce frequency by 15% and pause 4K rendering; Junction temperature ≥ 90℃, reduce frequency by 30% and retain only basic navigation and voice functions;

[0116] Common thermal zone: If the junction temperature is ≤88℃, maintain normal operation; if the junction temperature is >88℃, reduce the frequency according to load priority, prioritize power supply to intelligent driving and cockpit core modules, and reduce the power consumption of common modules.

[0117] Step 3: Layered Independent OTA Security Upgrade Control

[0118] The collaborative control center receives OTA upgrade commands from the cloud, allocates them to the corresponding OTA partition according to the upgrade type (Intelligent Driving / Cockpit), and executes the following process:

[0119] Intelligent Driving OTA Upgrade: The upgrade package is received in encrypted form and double-verified (CRC32 + digital signature). After successful verification, the upgrade is performed in the background. During the upgrade process, the core functions of Intelligent Driving remain stable. If the upgrade fails, it will automatically roll back to the previous stable version, record the upgrade failure log and upload it to the cloud.

[0120] Cockpit OTA upgrade: Receives incremental upgrade packages, independently occupies cockpit computing power, and does not affect intelligent driving functions; if high intelligent driving load is detected during the upgrade process, the upgrade is paused and resumed after the intelligent driving load decreases; if the upgrade fails, only the cockpit module is restarted, and intelligent driving functions are not affected;

[0121] After the upgrade is completed, the OTA security protection module performs a self-check. Once it confirms that there are no abnormalities, it synchronizes the upgrade log to the cloud, completing the upgrade loop.

[0122] Step 4: Cross-domain zero-copy timing synchronization control

[0123] The cross-domain zero-copy timing synchronization unit achieves data transmission and timing alignment according to the following process:

[0124] The intelligent driving perception module directly writes radar and vision data into a shared memory pool and adds nanosecond-level timestamps; the cockpit human-machine module synchronously writes DMS and voice command data into a shared memory pool and adds timestamps of the same reference.

[0125] The timing alignment module compares the timestamps of the two types of data in real time. If the deviation is greater than 1ms, it immediately performs millisecond-level compensation to adjust the data reading timing. If the deviation is less than or equal to 1ms, it directly transmits the data synchronously to the corresponding task unit.

[0126] The collaborative control center monitors the timing synchronization status in real time. If a timestamp anomaly occurs (synchronization error > 100ns), it triggers time synchronization calibration, recalibrates the time reference based on GPS + BeiDou, and ensures the stability of timing synchronization.

[0127] Step 5: Collaborative Management and Anomaly Handling

[0128] The central control unit coordinates the three main units in real time to handle various abnormal scenarios:

[0129] High load on intelligent driving + chip junction temperature exceeds the standard: Suspend cockpit OTA upgrades and high-load tasks, increase the frequency reduction threshold of the core hot zone of intelligent driving, and prioritize the computing power of intelligent driving.

[0130] If an anomaly occurs during the OTA upgrade process: immediately trigger a fault rollback, roll back the intelligent driving OTA to a stable version, suspend the cockpit OTA upgrade, and ensure that the core functions of intelligent driving are not interrupted;

[0131] Excessive cross-domain timing deviation: Suspend unnecessary cross-domain data transmission, prioritize the transmission of intelligent driving control commands, and perform time calibration to eliminate timing deviation;

[0132] After all anomalies have been handled, the anomaly data is recorded and uploaded to the cloud for system optimization and iteration.

[0133] The core innovation of this embodiment lies in:

[0134] 1. The first OneChip single-chip partitioned differentiated thermal management frequency reduction solution divides the thermal partitions according to the task safety priority to avoid global frequency reduction. It controls the chip junction temperature and prioritizes the core computing power of intelligent driving, taking into account both safety and cockpit experience.

[0135] 2. Design a layered independent OTA security upgrade architecture to achieve independent upgrades for intelligent driving and cockpit in two partitions and two channels. Equipped with encryption verification and fault rollback mechanisms, it prevents system-wide downtime caused by upgrade failures and meets UN R155 network security requirements.

[0136] 3. Construct a cross-domain zero-copy timing synchronization mechanism, using shared memory + high-precision timestamp calibration to eliminate data copy overhead, achieve inter-domain latency ≤1ms and timing deviation ≤100ns, and solve the pain points of cross-domain data timing asynchrony and instruction mismatch.

[0137] 4. It achieves integrated collaborative management of thermal management, OTA upgrades, and cross-domain synchronization. The three functions work together to adapt to different scenarios without requiring significant modifications to OneChip hardware, making it highly adaptable to mass production and meeting ISO 26262 compliance requirements.

[0138] In another specific embodiment, a hardware configuration of one embodiment is disclosed;

[0139] Test vehicle: L3-level mass-produced passenger vehicle; OneChip single chip: Qualcomm Thor SoC; Partitioned thermal management unit: 3 sets of independent temperature sensors (sampling frequency 1kHz), frequency reduction control module; Layered OTA upgrade unit: dual upgrade partitions (16GB each), AES-256 encryption module, CRC32 verification module; Cross-domain zero-copy timing synchronization unit: shared memory pool (8GB), nanosecond-level timestamp module, GPS+BeiDou dual-mode timing module; Collaborative control center: independent control chip (ARM Cortex-R52).

[0140] In another specific embodiment, a test scenario embodiment and its operation process are further disclosed, including:

[0141] Test Scenario 1: High-speed NOA activation (vehicle speed 110km / h, intelligent driving NPU at full load), the cabin is running 4K video and navigation simultaneously, and the chip junction temperature rises rapidly to 92℃; the zone thermal management unit detects that the junction temperature of the intelligent driving core thermal zone is 89℃ (not exceeding the standard) and maintains full frequency operation; the junction temperature of the cabin entertainment thermal zone is 91℃ (exceeding the standard), automatically reduces the frequency by 25%, pauses 4K video and audio, and retains the navigation function; the chip junction temperature stabilizes at 88℃, the intelligent driving decision has no delay, and the basic cabin functions are normal.

[0142] Test Scenario 2: Cockpit OTA upgrade (2GB incremental upgrade package), while the intelligent driving system is in a congested urban area (medium load); the layered OTA upgrade unit starts the independent upgrade channel for the cockpit, occupying 15% of the cockpit's computing power, without affecting the intelligent driving system's computing power allocation; during the upgrade process, a network interruption is simulated (upgrade failure), and the system automatically pauses the cockpit upgrade without triggering any abnormalities in the intelligent driving system's functions; after the network is restored, the upgrade continues, and after the upgrade is completed, the cockpit functions normally, and the intelligent driving system operates without interruption throughout the entire process.

[0143] Test Scenario 3: The intelligent driving perception module transmits radar and visual data (frequency 100Hz), and the cockpit DMS module transmits driver status data (frequency 30Hz); the cross-domain zero-copy timing synchronization unit writes the two types of data into shared memory, adds nanosecond-level timestamps, and the timing alignment module calibrates in real time. The inter-domain transmission delay is 0.8ms, the timing deviation is 80ns, there is no instruction mismatch, and the intelligent driving takeover response is delayed.

[0144] The test results of this embodiment are as follows: the chip junction temperature is controlled at ≤95℃, the frequency reduction of the intelligent driving core computing power is ≤10%, and there is no lag in the basic cockpit functions; there is no global downtime due to OTA upgrade failure, and the intelligent driving function remains stable; the cross-domain data transmission latency is ≤1ms, the timing deviation is ≤100ns, and the instruction mismatch rate is 0; it meets the compliance requirements of ISO 26262 and UN R155; it is compatible with mainstream OneChip single chips such as Qualcomm Thor and Black Sesame C1300, and has strong mass production feasibility.

[0145] In another specific embodiment, the thermal management, OTA upgrade, and cross-domain synchronization system of the OneChip single-chip for cockpit driving is summarized, including a partitioned differentiated thermal management unit, a layered independent OTA security upgrade unit, a cross-domain zero-copy timing synchronization unit, and a collaborative control center. The partitioned differentiated thermal management unit divides the intelligent driving core, cockpit entertainment, and public into three thermal partitions and implements differentiated frequency reduction. The layered independent OTA security upgrade unit adopts a dual-partition, dual-channel architecture to achieve independent upgrades for intelligent driving and the cockpit. The cross-domain zero-copy timing synchronization unit adopts a shared memory + high-precision timestamp mechanism to achieve zero-copy data transmission and timing alignment across domains. The collaborative control center realizes the collaborative management and control of the three units.

[0146] The zone-differentiated thermal management unit includes three independent temperature sensors (sampling frequency ≥ 1 kHz) and a frequency reduction control module. The junction temperature threshold of the core thermal zone of the intelligent driving system is ≤ 95℃, and the frequency reduction amplitude is ≤ 10%.

[0147] The layered independent OTA security upgrade unit adopts AES-256 encrypted transmission and CRC32+ digital signature dual verification, and has an upgrade failure rollback mechanism, so that upgrade failure will not affect the function of another domain.

[0148] The cross-domain zero-copy timing synchronization unit includes a shared memory pool, a nanosecond-level timestamp module, and a GPS+BeiDou dual-mode timing module. The cross-domain data transmission latency is ≤1ms, and the timing deviation is ≤100ns.

[0149] In another specific embodiment, a method for thermal management, OTA upgrade, and cross-domain synchronization of the OneChip single chip for autonomous driving is summarized. The method is characterized by the following steps: system initialization and status calibration, partition-differentiated thermal management frequency reduction control, hierarchical independent OTA security upgrade control, cross-domain zero-copy timing synchronization control, collaborative management and anomaly handling. The method achieves collaborative optimization of thermal management, OTA upgrade, and cross-domain synchronization, prioritizing the protection of intelligent driving safety and performance.

[0150] In the zoned differentiated thermal management frequency reduction control, when the junction temperature of the cabin entertainment thermal zone is ≥90℃, the frequency reduction is 15%-30%, high-load tasks are suspended, and basic functions are retained.

[0151] In collaborative management and anomaly handling, when the intelligent driving system is under high load, unnecessary OTA upgrades and high-load tasks in the cockpit should be suspended to prioritize the protection of intelligent driving computing power and thermal safety.

[0152] Figure 3 This is a block diagram of an electronic device structure for the thermal management and cross-domain collaboration method of the OneChip single chip provided in one or more embodiments of the present invention.

[0153] like Figure 3 As shown, this application provides an electronic device, including: a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus;

[0154] The memory stores a computer program that, when executed by the processor, causes the processor to perform steps of a thermal management and cross-domain collaboration method for a OneChip single chip.

[0155] This application also provides a computer-readable storage medium storing a computer program executable by an electronic device, which, when run on the electronic device, causes the electronic device to perform the steps of the OneChip single-chip thermal management and cross-domain collaboration method.

[0156] This application also provides a vehicle cabin, including:

[0157] Electronic devices, comprising the steps for implementing a thermal management and cross-domain collaboration method for the OneChip single-chip in a cockpit;

[0158] The processor runs a program, and when the program runs, it executes the steps of the OneChip single-chip thermal management and cross-domain collaborative method based on the data output from the electronic device.

[0159] Storage medium for storing programs that, when running, execute steps of the OneChip single-chip thermal management and cross-domain collaboration method on data output from electronic devices.

[0160] The communication bus mentioned in the above electronic devices can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in the diagram, but this does not indicate that there is only one bus or one type of bus.

[0161] The electronic device comprises a hardware layer, an operating system layer running on top of the hardware layer, and an application layer running on the operating system. The hardware layer includes hardware such as a central processing unit (CPU), a memory management unit (MMU), and memory. The operating system can be any one or more computer operating systems that control the electronic device through processes, such as Linux, Unix, Android, iOS, or Windows. Furthermore, in this embodiment of the invention, the electronic device can be a smartphone, tablet computer, or other handheld device, or a desktop computer, portable computer, or other electronic device; there is no particular limitation in this embodiment.

[0162] In this embodiment of the invention, the executing entity for electronic device control can be an electronic device itself, or a functional module within an electronic device capable of calling and executing a program. The electronic device can obtain the firmware corresponding to the storage medium. This firmware is provided by the supplier, and different storage media may have the same or different firmware; no limitation is made here. After obtaining the firmware corresponding to the storage medium, the electronic device can write this firmware into the storage medium; specifically, it burns the firmware corresponding to the storage medium into the storage medium. The process of burning the firmware into the storage medium can be implemented using existing technology, and will not be elaborated upon in this embodiment of the invention.

[0163] Electronic devices can also obtain reset commands corresponding to the storage media. The reset commands corresponding to the storage media are provided by the supplier. The reset commands corresponding to different storage media can be the same or different, and no restrictions are imposed here.

[0164] At this time, the storage medium of the electronic device is a storage medium on which the corresponding firmware has been written. The electronic device can respond to the reset command corresponding to the storage medium on which the corresponding firmware has been written, thereby resetting the storage medium on which the corresponding firmware has been written according to the reset command. The process of resetting the storage medium according to the reset command can be implemented by existing technology and will not be described in detail in this embodiment of the invention.

[0165] For ease of description, the above devices are described separately by function as various units and modules. Of course, in implementing this application, the functions of each unit and module can be implemented in one or more software and / or hardware.

[0166] It will be understood by those skilled in the art that, unless otherwise defined, all terms used herein (including technical and scientific terms) have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. It should also be understood that terms such as those defined in general dictionaries should be understood to have the meaning consistent with their meaning in the context of the prior art, and should not be interpreted in an idealized or overly formal sense unless specifically defined.

[0167] For the sake of simplicity, the method embodiments are described as a series of actions. However, those skilled in the art should understand that the embodiments of the present invention are not limited to the described order of actions, because according to the embodiments of the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions involved are not necessarily essential to the embodiments of the present invention.

[0168] As can be seen from the above description of the embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus necessary general-purpose hardware platforms. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in various embodiments or some parts of the embodiments of this application.

[0169] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A thermal management and cross-domain collaborative system for a OneChip single-chip in a cockpit, characterized in that, For the OneChip single chip for cockpit driving, a domain partitioning strategy is set up: three independent hardware domains are divided into intelligent driving safety domain, cockpit entertainment domain, and common computing power domain, and each domain is physically isolated; Based on the domain-based strategy, we ensure domain-based collaborative management and control, including prioritizing the protection of the functions and performance of the intelligent driving safety domain, including a zone-differentiated thermal management unit, a layered independent OTA security upgrade unit, a cross-domain zero-copy timing synchronization unit, and a collaborative control center. The partitioned differentiated thermal management unit is used to divide the thermal partitions corresponding to the three independent hardware domains and to perform differentiated frequency reduction. The layered independent OTA security upgrade unit adopts a dual-partition, dual-channel architecture for independent upgrades of intelligent driving and the cockpit. The cross-domain zero-copy timing synchronization unit adopts a shared memory + high-precision timestamp mechanism for cross-domain data zero-copy transmission and timing alignment. The collaborative control center is used for the collaborative management and control of thermal management, OTA upgrades, and timing synchronization.

2. The cabin-mounted OneChip single-chip thermal management and cross-domain collaborative system according to claim 1, characterized in that, include: The zone-differentiated thermal management unit includes multiple sets of independent temperature sensors; The sampling frequency of the temperature sensor is ≥1kHz, the junction temperature threshold of the intelligent driving core thermal zone is ≤95℃, and the corresponding frequency reduction is ≤10%.

3. The cabin-mounted OneChip single-chip thermal management and cross-domain collaborative system according to claim 1, characterized in that, include: The layered independent OTA security upgrade unit uses AES-256 encrypted transmission and CRC32+ digital signature dual verification for upgrade failure rollback mechanism to ensure that a single domain upgrade failure does not affect the operation of another domain.

4. The cabin-mounted OneChip single-chip thermal management and cross-domain collaborative system according to claim 1, characterized in that, include: The cross-domain zero-copy timing synchronization unit includes a shared memory pool, a nanosecond-level timestamp module, and a GPS+BeiDou dual-mode timing module. Cross-domain data transmission delay ≤ 1ms, timing deviation ≤ 100ns.

5. A method for thermal management and cross-domain collaboration of a OneChip single-chip in a cockpit, characterized in that, Based on the OneChip single chip, the system comprises three independent hardware domains: intelligent driving safety domain, cockpit entertainment domain, and public computing power domain. With domain-based collaborative management and control as the foundation, priority is given to ensuring the functionality and performance of the intelligent driving safety domain. It also includes the following steps: system initialization and status calibration, partitioned differentiated thermal management frequency reduction control, layered independent OTA security upgrade control, cross-domain zero-copy timing synchronization control, collaborative management and anomaly handling; Among these features, collaborative optimization is achieved through thermal management, OTA upgrades, and cross-domain synchronization, prioritizing the safety and performance of intelligent driving.

6. The thermal management and cross-domain collaboration method for the OneChip single chip in the cockpit according to claim 5, characterized in that, include: In the differentiated thermal management frequency reduction control, if the junction temperature of the cabin entertainment thermal zone is ≥90℃, the frequency reduction range is 15%-30%, high-load tasks are suspended, and basic navigation and voice functions are retained.

7. The thermal management and cross-domain collaboration method for the OneChip single chip in the cockpit according to claim 5, characterized in that, include: In the aforementioned collaborative management and control, when a high-load state of intelligent driving is detected, unnecessary OTA upgrades and high-load tasks in the cockpit are suspended to prioritize the protection of intelligent driving computing power and thermal safety.

8. An electronic device, characterized in that, include: The processor, communication interface, memory, and communication bus are connected, with the processor, communication interface, and memory communicating with each other via the communication bus. The memory stores a computer program that, when executed by a processor, causes the processor to perform the steps of the OneChip single-chip thermal management and cross-domain collaboration method as described in any one of claims 5 to 7.

9. A computer-readable storage medium, characterized in that, include: The device stores a computer program executable by an electronic device, which, when run on the electronic device, causes the electronic device to perform the steps of the OneChip single-chip thermal management and cross-domain collaboration method as described in any one of claims 5 to 7.

10. A vehicle cabin, characterized in that, include: An electronic device for implementing the steps of the cabin-mounted OneChip single-chip thermal management and cross-domain collaboration method as described in any one of claims 5 to 7; The processor runs a program that, when the program is running, performs the steps of the OneChip single-chip thermal management and cross-domain collaboration method as described in any one of claims 5 to 7 by executing data output from the electronic device. A storage medium for storing a program that, when running, performs the steps of the OneChip single-chip thermal management and cross-domain collaboration method as described in any one of claims 5 to 7 on data output from an electronic device.