Vehicle-level dual-link redundant time synchronization method, system, device and storage medium
Patent Information
- Application Number
- CN202611026745.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-10
- Publication Date
- 2026-09-29
AI Technical Summary
[0003]然而,相关方案普遍依赖单一的gPTP以太网链路作为授时通道
[0016]本申请提出的一种整车级双链路冗余时间同步方法,通过车载第一物理链路获取第一时间信息,以及通过车载第二物理链路获取第二时间信息,使得时间同步方法同时具备两条独立物理介质的时间信息来源;在此基础上,基于预设仲裁规则从第一时间信息和第二时间信息中确定基准时间信息,并通过车载第二物理链路广播至下游节点,使得当第一物理链路因故障无法继续提供授时时,系统能够自动切换至第二物理链路继续维持整车时间基准的供给,同时所有下游节点接收到的始终是经过统一决策后的单一基准时间,无需各下游节点自行判断或切换时间源,避免了多个节点独立决策可能产生的状态不一致问题;继而获取下游节点的第一本地时间信息并基于基准时间信息与第一本地时间信息确定时间偏差信息,并将该时间偏差信息传输至下游节点内部的子模块,以使子模块基于自身的第二本地时间信息和该时间偏差信息得到与基准时间信息一致的本地同步时间,使得下游节点内部的各个子模块通过共享同一偏差量进行校准,保证子模块之间的时间修正基准一致,从而最终实现当单一授时链路发生故障时整车仍能维持统一的时间基准。
Smart Images

Figure CN122845010A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of vehicle network communication technology, and in particular to a vehicle-level dual-link redundant time synchronization method, system, device and storage medium. Background Technology
[0002] With the development of automotive intelligence and connectivity, complex functions such as smart cockpits and autonomous driving place stringent requirements on the time synchronization accuracy between onboard electronic control units. Currently, the generalized precision time protocol (gPTP) based on automotive Ethernet has become the mainstream high-precision time synchronization solution for intelligent vehicles due to its ability to achieve microsecond-level synchronization accuracy.
[0003] However, most solutions rely on a single gPTP Ethernet link as the timing channel. If the master clock module, Ethernet bridge, or transmission line in this link fails, all domain controllers in the vehicle will simultaneously lose a unified time reference. Each node will then be able to operate freely using only its own local crystal oscillator, leading to a rapid increase in time deviation between nodes and even causing the failure of collaborative tasks. Summary of the Invention
[0004] The embodiments of this application provide a vehicle-level dual-link redundant time synchronization method, system, device, and storage medium. By constructing dual physical link redundant time synchronization between the vehicle Ethernet gPTP and the Controller Area Network (CAN) bus, the system can effectively avoid the loss of the vehicle time reference due to a single link failure, and significantly improve the reliability of the vehicle time synchronization system.
[0005] The summary section introduces a series of simplified concepts, which will be further explained in detail in the detailed description section. This summary section is not intended to limit the key and essential technical features of the claimed technical solution, nor is it intended to determine the scope of protection of the claimed technical solution.
[0006] This application specifically includes the following aspects: Firstly, this application proposes a vehicle-level dual-link redundant time synchronization method, including: First time information is obtained based on the first physical link in the vehicle, and second time information is obtained based on the second physical link in the vehicle; wherein, the first physical link in the vehicle is a vehicle Ethernet General Precision Time Protocol (gPTP) link, and the second physical link in the vehicle is a vehicle controller local area network (CAN bus) link. Based on preset arbitration rules, a reference time information is determined from the first time information and the second time information, and the reference time information is broadcast to downstream nodes through the vehicle-mounted second physical link; Obtain the first local time information of the downstream node, and determine the time deviation information based on the reference time information and the first local time information; The time deviation information is transmitted to at least one sub-module within the downstream node, so that the sub-module obtains a local synchronization time consistent with the reference time information based on its own second local time information and the time deviation information.
[0007] In one feasible implementation, the step of obtaining first time information based on a first onboard physical link and obtaining second time information based on a second onboard physical link includes: The vehicle-mounted Ethernet gPTP link receives gPTP grant messages from Ethernet and extracts the first time information from the gPTP grant messages. The system receives time messages from the GPS or BeiDou navigation system via the CAN bus link and extracts the second time information from the GPS or BeiDou navigation system time messages.
[0008] In one feasible implementation, determining the reference time information from the first time information and the second time information based on preset arbitration rules includes: The first time information is used as the base time information; If the vehicle-mounted first physical link is detected to have not received the gPTP authorization message within a series of preset periods, or if the received gPTP authorization message fails the preset integrity check, then after a preset detection delay time, the second time information will be switched as the reference time information.
[0009] In one feasible implementation, after switching to the second time information as the reference time information, the method further includes: If it is detected that the vehicle-mounted first physical link has resumed receiving the gPTP grant message and the gPTP grant message passes the preset integrity check, then after a preset back-switch delay time, the system will switch back to the first time information as the reference time information.
[0010] In one feasible implementation, broadcasting the reference time information to downstream nodes via the vehicle-mounted second physical link includes: According to the preset broadcast period, the reference time information is encapsulated into an AUTOSAR synchronization message for the Automotive Open System Architecture; Control the vehicle-mounted second physical link to send the AUTOSAR synchronization message to all downstream nodes.
[0011] In one feasible implementation, the downstream node is a microcontroller unit (MCU) in a vehicle domain controller; the step of acquiring the first local time information of the downstream node and determining the time deviation information based on the reference time information and the first local time information includes: The current count value of the real-time clock (RTC) inside the MCU is read as the first local time information; The difference between the reference time information and the first local time information is used as the time deviation information.
[0012] In one feasible implementation, the submodule is a system-on-a-chip (SoC) computing unit in the vehicle domain controller. The step of transmitting the time deviation information to at least one submodule within the downstream node, so that the submodule obtains a local synchronization time consistent with the reference time information based on its own second local time information and the time deviation information, includes: The MCU is controlled to broadcast the time deviation information to each SoC computing unit, so that each SoC computing unit reads the current count value of its internal real-time clock (RTC) as the second local time information, and obtains a local synchronization time consistent with the reference time information based on the algebraic sum of the second local time information and the time deviation information.
[0013] Secondly, this application also proposes a vehicle-level dual-link redundant time synchronization system, comprising: The information acquisition unit is used to acquire first time information based on the first physical link of the vehicle and to acquire second time information based on the second physical link of the vehicle; wherein, the first physical link of the vehicle is a vehicle Ethernet General Precision Time Protocol (gPTP) link and the second physical link of the vehicle is a vehicle controller local area network (CAN bus) link. The information broadcasting unit is used to determine reference time information from the first time information and the second time information based on a preset arbitration rule, and broadcast the reference time information to downstream nodes through the vehicle-mounted second physical link; The deviation calculation unit is used to obtain the first local time information of the downstream node and determine the time deviation information based on the reference time information and the first local time information. An information synchronization unit is used to transmit the time deviation information to at least one sub-module within the downstream node, so that the sub-module obtains a local synchronization time consistent with the reference time information based on its own second local time information and the time deviation information.
[0014] Thirdly, this application also proposes an electronic device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program stored in the memory to implement the steps of the vehicle-level dual-link redundant time synchronization method as described in any of the first aspects above.
[0015] Fourthly, this application also proposes a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the vehicle-level dual-link redundant time synchronization method as described in any of the first aspects above.
[0016] This application proposes a vehicle-level dual-link redundant time synchronization method. It acquires first time information via a first onboard physical link and second time information via a second onboard physical link, providing two independent physical sources of time information simultaneously. Based on this, a reference time is determined from the first and second time information according to a preset arbitration rule and broadcast to downstream nodes via the second onboard physical link. This ensures that when the first physical link fails and cannot continue providing time synchronization, the system automatically switches to the second physical link to maintain the vehicle's time reference. Simultaneously, all downstream nodes always receive a single reference time determined through unified decision-making. Each downstream node needs to independently determine or switch its time source, avoiding inconsistencies that may arise from multiple nodes making independent decisions. Then, it acquires the first local time information from the downstream node and determines the time deviation information based on the reference time information and the first local time information. This time deviation information is then transmitted to the sub-modules within the downstream node, enabling the sub-modules to obtain a local synchronization time consistent with the reference time information based on their own second local time information and the time deviation information. This allows each sub-module within the downstream node to perform calibration by sharing the same deviation, ensuring consistent time correction references between sub-modules. Ultimately, this ensures that the entire vehicle can maintain a unified time reference even when a single timing link fails.
[0017] The vehicle-level dual-link redundant time synchronization method, system, device, and storage medium proposed in this application, along with other advantages, objectives, and features of this application, will be partly apparent from the following description and partly understood by those skilled in the art through study and practice of this application. Attached Figure Description
[0018] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit this specification. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings: Figure 1A flowchart illustrating a vehicle-level dual-link redundant time synchronization method provided in this application embodiment; Figure 2 A detailed architecture diagram of master-slave time synchronization between an internal MCU and a SoC of a downstream domain controller is provided for embodiments of this application; Figure 3 This application provides an overall architecture diagram of a vehicle-level dual-link redundant time synchronization method. Figure 4 A functional module diagram of a vehicle-level dual-link redundant time synchronization system provided in this application embodiment; Figure 5 This is a schematic diagram of a vehicle-level dual-link redundant time synchronization device provided in an embodiment of this application. Detailed Implementation
[0019] To better understand the technical solutions provided in the embodiments of this specification, the technical solutions of the embodiments of this specification will be described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the embodiments of this specification and the specific features in the embodiments are detailed descriptions of the technical solutions of the embodiments of this specification, rather than limitations on the technical solutions of this specification. In the absence of conflict, the embodiments of this specification and the technical features in the embodiments can be combined with each other.
[0020] In this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, without necessarily requiring or implying any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element. The term "two or more" includes two or more cases.
[0021] Please see Figure 1 This is a flowchart illustrating a vehicle-level dual-link redundant time synchronization method provided in an embodiment of this application, which may specifically include: S110. Obtain first time information based on the first physical link of the vehicle and obtain second time information based on the second physical link of the vehicle; wherein, the first physical link of the vehicle is the vehicle Ethernet General Precision Time Protocol (gPTP) link, and the second physical link of the vehicle is the vehicle controller local area network (CAN bus) link.
[0022] For example, after the vehicle is powered on and started, the time gateway node simultaneously acquires time information through two independent physical links. On the first physical link, the time gateway node receives gPTP time messages from the gPTP master clock via the vehicle's Ethernet interface and extracts high-precision Coordinated Universal Time (UTC) from these messages as the first time information, with synchronization accuracy down to the microsecond level. On the second physical link, the time gateway node receives time messages from the Global Positioning System (GPS) or BeiDou receiver via the CAN bus interface and extracts satellite navigation system time information from these messages as the second time information, with accuracy typically in the millisecond range.
[0023] S120. Based on the preset arbitration rules, determine the reference time information from the first time information and the second time information, and broadcast the reference time information to the downstream node through the vehicle-mounted second physical link.
[0024] For example, the arbitration module inside the time gateway node determines the reference time information for the entire vehicle from the first time information and the second time information according to preset arbitration rules. By default, the arbitration module prioritizes the first time information from the vehicle's first physical link as the reference time information because the gPTP protocol on which this link is based can provide higher synchronization accuracy. The arbitration module broadcasts the determined reference time information to all downstream nodes through the vehicle's second physical link at a period of 10ms. Specifically, the arbitration module encapsulates the reference time information into a synchronization message conforming to the Automotive Open System Architecture (AUTOSAR) standard format, and then calls the send interface of the Controller Area Network (CAN) driver layer to send the message to the vehicle's CAN bus.
[0025] S130. Obtain the first local time information of the downstream node, and determine the time deviation information based on the reference time information and the first local time information.
[0026] For example, after receiving the UTC message broadcast by the time gateway through its CAN controller, the microcontroller unit (MCU) of each downstream node parses it to obtain the current reference time information. Simultaneously, the MCU reads the current count value of its internal real-time clock (RTC) as the first local time information for that node. The MCU's deviation calculation module subtracts the reference time information from the first local time information to calculate a time deviation, which reflects the magnitude and direction of the error between the node's local clock and the vehicle's reference time information.
[0027] S140. Transmit the time deviation information to at least one submodule within the downstream node, so that the submodule obtains a local synchronization time consistent with the reference time information based on its own second local time information and time deviation information.
[0028] For example, the MCU broadcasts this time offset information to each sub-module within the domain controller, i.e., the System-on-a-Chip (SoC) computing unit, via an on-chip interconnect bus (e.g., IPC). Each SoC computing unit reads the current count value of its internal RTC as a second local time information, and then algebraically adds this second local time information to the received time offset information to obtain a local synchronization time consistent with the reference time information. This local synchronization time is then provided to the upper-layer applications running on each SoC computing unit to ensure that all algorithm modules operate on a unified time base.
[0029] In some examples, first-time information is obtained based on the first physical link of the vehicle, and second-time information is obtained based on the second physical link of the vehicle, including: Receive gPTP grant messages from Ethernet via the vehicle-mounted Ethernet gPTP link, and extract first-time information from the gPTP grant messages; The system receives time messages from the GPS or BeiDou Navigation Satellite System via a CAN bus link and extracts second time information from these messages.
[0030] For example, the time gateway node acquires first time information based on the vehicle's first physical link. Specifically, the time gateway node is equipped with a gPTP receiving module, which receives gPTP message transmissions from Ethernet via the vehicle's Ethernet gPTP link. The gPTP message transmissions carry high-precision time information, and the time gateway node extracts this time information from the received gPTP message transmissions and uses it as the first time information. Simultaneously, the time gateway node acquires second time information based on the vehicle's second physical link. Specifically, the time gateway node is equipped with a CAN receiving module, which receives message transmissions from GPS or BeiDou navigation systems via a CAN bus link. The GPS or BeiDou navigation system message transmissions carry time information provided by the satellite navigation system, and the time gateway node extracts this time information from the received message transmissions and uses it as the second time information.
[0031] In some examples, a reference time is determined from first-time information and second-time information based on preset arbitration rules, including: Use the first time information as the base time information; If the vehicle-mounted first physical link is detected to have not received gPTP authorization messages for multiple consecutive preset periods, or if the received gPTP authorization messages fail the preset integrity check, then after a preset detection delay time, the system will switch to the second time information as the reference time information.
[0032] For example, within the time gateway node, the arbitration module continuously monitors the update status of the first time information from the vehicle's first physical link and the second time information from the vehicle's second physical link. The arbitration module internally maintains a state machine with two main states: a primary state and a backup state.
[0033] In primary mode, the arbitration module determines the first time information as the reference time information. This is the default operating mode: since the gPTP protocol can provide microsecond-level time synchronization accuracy, which is much higher than the millisecond-level accuracy of CAN bus time synchronization, the time provided by it should be used as the vehicle reference when the first physical link on the vehicle is working normally.
[0034] The arbitration module simultaneously performs link health monitoring. Specifically, it monitors whether new gPTP authorization messages are received in each preset period. If no gPTP authorization messages are received within several consecutive preset periods, or if gPTP authorization messages are received but fail the preset integrity check (e.g., CRC check failure, incorrect message format, or timestamp exceeding a reasonable range), the arbitration module determines that the vehicle's first physical link may be faulty. In this case, the arbitration module does not immediately switch the time source but starts a preset detection delay timer (e.g., 50ms) to continue observing the status of the vehicle's first physical link. If the vehicle's first physical link recovers within the detection delay time, the primary state remains unchanged; if the vehicle's first physical link still has not recovered after the detection delay time expires, the arbitration module switches the state machine to the standby state and determines the second time information as the new reference time information.
[0035] In some examples, after switching to the second time information as the base time information, the following is also included: If the vehicle's first physical link is detected to have resumed receiving gPTP grant messages and the gPTP grant messages pass the preset integrity check, then after a preset back-off delay time, the system will switch back to the first time information as the reference time information.
[0036] For example, after the arbitration module switches to standby mode (i.e., using the second time information as the reference time information) due to a failure of the vehicle's first physical link, the arbitration module does not stop monitoring the vehicle's first physical link. Instead, the arbitration module continues to listen to the vehicle's Ethernet port to detect whether any new gPTP authorization messages arrive.
[0037] When the arbitration module detects that gPTP message arrivals have resumed and that all gPTP message reception received within several consecutive preset periods passes the preset integrity check, the arbitration module determines that the vehicle's first physical link has been restored. However, the arbitration module does not immediately perform a switchback operation, as the newly restored link may still be unstable, and an immediate switchback could lead to another switchback within a short period. Therefore, the arbitration module starts a preset switchback delay timer (e.g., 100ms) to continuously monitor the stability of the vehicle's first physical link during this delay. Specifically, the arbitration module continues to verify the integrity and continuity of each received gPTP message during the switchback delay. If no further message loss or verification failure occurs during this period, the vehicle's first physical link is determined to have been stably restored. After the switchback delay expires, the arbitration module switches the state machine from the standby state back to the primary state, re-establishing the first time information as the base time information.
[0038] In some examples, reference time information is broadcast to downstream nodes via an onboard second physical link, including: According to the preset broadcast cycle, the reference time information is encapsulated into AUTOSAR synchronization messages for automotive open system architecture; Control the vehicle-mounted second physical link to send AUTOSAR synchronization messages to all downstream nodes.
[0039] For example, the CAN broadcast module inside the time gateway node is responsible for distributing the reference time information determined by the arbitration module to all downstream nodes. Specifically, the CAN broadcast module performs broadcast tasks periodically according to a preset broadcast period (e.g., 10ms). At the arrival of each broadcast period, the CAN broadcast module obtains the reference time information (UTC time) determined by the current arbitration module, and then encapsulates the UTC time information into an AUTOSAR synchronization message according to the time synchronization message format defined in the AUTOSAR standard.
[0040] After the message is encapsulated, the time gateway node calls the CAN controller's transmit interface to send the AUTOSAR synchronization message to the CAN bus. Because the CAN bus has broadcast characteristics, all downstream nodes connected to the CAN bus can receive the message simultaneously. Each downstream node's MCU receives the message through its CAN controller and parses out the reference time information within it.
[0041] In some examples, the downstream node is a microcontroller unit (MCU) in the vehicle domain controller; the first local time information of the downstream node is obtained, and time deviation information is determined based on the reference time information and the first local time information, including: Read the current count value of the MCU's internal real-time clock (RTC) as the first local time information; The difference between the reference time information and the first local time information is used as the time deviation information.
[0042] For example, an intelligent driving domain controller is used as an example. This domain controller contains an MCU and multiple SoC computing units. After receiving the AUTOSAR synchronization message broadcast by the time gateway through its CAN controller, the MCU first parses it to obtain the current reference time information.
[0043] Subsequently, the MCU's deviation calculation module reads the current count value of the MCU's internal RTC. The MCU's internal RTC is typically driven by a local crystal oscillator and is a free-running counter whose count increases over time. Due to factors such as manufacturing errors, temperature drift, and device aging in the crystal oscillator, deviations will exist between the RTCs of different MCUs and between the RTC and the actual UTC. The deviation calculation module uses the read current RTC count value as the first local time information.
[0044] Next, the deviation calculation module performs a subtraction operation to calculate the time deviation information according to the following formula: D = UTC_gateway - RTC_MCU; Wherein, UTC_gateway represents the reference time information, RTC_MCU represents the first local time information, and D represents the calculated time deviation information.
[0045] The calculation result is used as time deviation information. This time deviation information can be positive (indicating that the MCU's local clock is slow, lagging behind the reference time information) or negative (indicating that the MCU's local clock is fast, leading the reference time information). For example, if the reference time information is 10:00:00.000 and the first local time information is 10:00:00.005, then the time deviation information is -0.005 seconds, indicating that the MCU's local clock is 5 milliseconds ahead of the vehicle's reference time.
[0046] In some examples, the submodule is a system-on-a-chip (SoC) computing unit within the vehicle domain controller, transmitting time deviation information to at least one submodule within a downstream node. This allows the submodule to obtain a local synchronized time consistent with the reference time information based on its own second local time information and time deviation information, including: The control MCU broadcasts the time deviation information to each SoC computing unit, so that each SoC computing unit reads the current count value of its internal real-time clock RTC as the second local time information, and obtains the local synchronization time consistent with the reference time information based on the algebraic sum of the second local time information and the time deviation information.
[0047] For example, in an intelligent driving domain controller, after the MCU calculates the time deviation information, it broadcasts this information to each SoC computing unit within the domain controller via the on-chip interconnect bus. The MCU transmits the time deviation information to each SoC computing unit through this on-chip interconnect bus.
[0048] After receiving the time deviation information, each SoC computing unit performs a local time recovery operation. Specifically, each SoC computing unit reads the current count value of its internal RTC as the second local time information. Each SoC computing unit calculates its local synchronization time according to the following formula: UTC_local = RTC_SOC + D; Wherein, RTC_SOC represents the second local time information, D represents the time deviation information received from the MCU, and UTC_local represents the calculated local synchronization time that is consistent with the reference time information.
[0049] Each SoC computing unit algebraically adds the second local time information RTC_SOC it reads to the time deviation information D received from the MCU to calculate the local synchronization time UTC_local.
[0050] In one embodiment of the present invention, Figure 2 This illustrates the detailed architecture of master-slave time synchronization between the MCU and SoC within the downstream domain controller. (Refer to...) Figure 2 The UTC broadcast from the vehicle's CAN bus (sent as an AUTOSAR CAN synchronization message at 10ms intervals) enters the domain controller and is parsed by the CAN receiving module of the MCU main module to obtain the reference time information. The MCU main module has a local RTC (driven by a local crystal oscillator, with a drift of approximately ±1ppm). The deviation calculation module calculates the time deviation information D according to the formula D = UTC_gateway - RTC_MCU. The MCU main module broadcasts the calculated time deviation information D to each SoC computing unit (SoC1, SoC2...SoCN) within the domain controller via the deviation broadcast interface through the on-chip interconnect bus (or shared memory). Each SoC computing unit has a local RTC (driven by a local crystal oscillator, with a drift of approximately ±20~50ppm). The UTC recovery module calculates the local synchronization time consistent with the reference time information according to the formula UTC_local = RTC_SOC + D and outputs the local UTC for use by upper-layer applications.
[0051] In summary, in a complete embodiment of the present invention, Figure 3 The overall architecture of the vehicle-level dual-link redundant time synchronization method corresponding to the above-described method embodiments is shown. (Refer to...) Figure 3The system has two external time sources: a gPTP master clock and a CAN time source. The gPTP master clock provides primary time synchronization via the vehicle Ethernet, while the CAN time source provides backup time synchronization via the CAN bus. The vehicle time synchronization gateway node internally includes a gPTP receiving module, a CAN receiving module, a source arbitration and UTC generation module, and a CAN time broadcast control module. The gPTP receiving module receives time messages from the gPTP master clock via the vehicle Ethernet, while the CAN receiving module receives time messages from the CAN time source via the CAN bus. The source arbitration and UTC generation module arbitrates the two time sources, defaulting to gPTP time and switching to CAN time when the gPTP link fails, generating a unified time base for the entire vehicle. The CAN time broadcast control module encapsulates this base time into UTC messages at a preset period of 10ms and broadcasts them to downstream domain controllers via the CAN bus. Downstream domain controllers include intelligent driving domain controller, cockpit domain controller and body domain controller, etc. Each domain controller receives the UTC message through its internal MCU, performs deviation calculation and internal time synchronization, and finally enables each SoC computing unit inside the domain controller to obtain a local synchronization time consistent with the vehicle reference.
[0052] Furthermore, this application also proposes a vehicle-level dual-link redundant time synchronization system for implementing any of the above-mentioned vehicle-level dual-link redundant time synchronization methods, specifically as follows: Figure 4 The diagram shown is a functional module schematic of a vehicle-level dual-link redundant time synchronization system proposed in this application. The system includes: The information acquisition unit 21 is used to acquire first time information based on the first physical link of the vehicle and to acquire second time information based on the second physical link of the vehicle; wherein, the first physical link of the vehicle is the vehicle Ethernet General Precision Time Protocol (gPTP) link and the second physical link of the vehicle is the vehicle controller local area network (CAN bus) link. Information broadcasting unit 22 is used to determine reference time information from first time information and second time information based on preset arbitration rules, and broadcast the reference time information to downstream nodes through the vehicle-mounted second physical link; Deviation calculation unit 23 is used to obtain the first local time information of the downstream node and determine the time deviation information based on the reference time information and the first local time information; The information synchronization unit 24 is used to transmit time deviation information to at least one sub-module within the downstream node, so that the sub-module can obtain a local synchronization time consistent with the reference time information based on its own second local time information and time deviation information.
[0053] It should be noted that the above embodiments are merely best examples and are not intended to limit the implementation of this application.
[0054] Furthermore, such as Figure 5 As shown, this application embodiment also provides an electronic device 300, including a processor 310, a memory 320, and a computer program 321 stored in the memory 320 and executable on the processor. When the processor 310 executes the computer program 321, it implements the steps of any of the above-described vehicle-level dual-link redundant time synchronization methods.
[0055] Since the electronic device described in this embodiment is the device used to implement the vehicle-level dual-link redundant time synchronization method in the embodiments of this application, those skilled in the art can understand the specific implementation method and various variations of the electronic device in this embodiment based on the method described in the embodiments of this application. Therefore, how the electronic device implements the method in the embodiments of this application will not be described in detail here. Any device used by those skilled in the art to implement the method in the embodiments of this application falls within the scope of protection of this application.
[0056] In practical implementation, when the computer program 321 is executed by the processor, it can achieve the following: Figure 1 Any of the corresponding implementation methods in the embodiments.
[0057] It should be noted that the descriptions of each embodiment in the above embodiments have different focuses. For parts that are not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.
[0058] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-readable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-readable program code.
[0059] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create a machine for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0060] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0061] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0062] This application also provides a computer program product, which includes computer software instructions that, when executed on a processing device, cause the processing device to execute a process of a vehicle-level dual-link redundant time synchronization method.
[0063] A computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the flow or function according to the embodiments of this application is generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium may be any available medium that a computer can store or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk (SSD)).
[0064] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0065] In the several embodiments provided in this application, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, or indirect coupling or communication connection between devices or units, and may be electrical, mechanical, or other forms.
[0066] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0067] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0068] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0069] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.
[0070] Although preferred embodiments have been described in this specification, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this specification.
[0071] Obviously, those skilled in the art can make various modifications and variations to this specification without departing from its spirit and scope. Therefore, if such modifications and variations fall within the scope of the claims and their equivalents, this specification is also intended to include such modifications and variations.
Claims
1. A vehicle-level dual-link redundant time synchronization method, characterized in that, include: First time information is obtained based on the first physical link in the vehicle, and second time information is obtained based on the second physical link in the vehicle; wherein, the first physical link in the vehicle is a vehicle Ethernet General Precision Time Protocol (gPTP) link, and the second physical link in the vehicle is a vehicle controller local area network (CAN bus) link. Based on preset arbitration rules, a reference time information is determined from the first time information and the second time information, and the reference time information is broadcast to downstream nodes through the vehicle-mounted second physical link; Obtain the first local time information of the downstream node, and determine the time deviation information based on the reference time information and the first local time information; The time deviation information is transmitted to at least one sub-module within the downstream node, so that the sub-module obtains a local synchronization time consistent with the reference time information based on its own second local time information and the time deviation information.
2. The method according to claim 1, characterized in that, The acquisition of first time information based on the first physical link of the vehicle and the acquisition of second time information based on the second physical link of the vehicle include: The vehicle-mounted Ethernet gPTP link receives gPTP grant messages from Ethernet and extracts the first time information from the gPTP grant messages. The system receives time messages from the GPS or BeiDou navigation system via the CAN bus link and extracts the second time information from the GPS or BeiDou navigation system time messages.
3. The method according to claim 2, characterized in that, The step of determining the reference time information from the first time information and the second time information based on preset arbitration rules includes: The first time information is used as the base time information; If the vehicle-mounted first physical link is detected to have not received the gPTP authorization message within a series of preset periods, or if the received gPTP authorization message fails the preset integrity check, then after a preset detection delay time, the second time information will be switched as the reference time information.
4. The method according to claim 3, characterized in that, After switching to the second time information as the reference time information, the following is also included: If it is detected that the vehicle-mounted first physical link has resumed receiving the gPTP grant message and the gPTP grant message passes the preset integrity check, then after a preset back-switch delay time, the system will switch back to the first time information as the reference time information.
5. The method according to claim 1, characterized in that, The step of broadcasting the reference time information to downstream nodes via the vehicle-mounted second physical link includes: According to the preset broadcast period, the reference time information is encapsulated into an AUTOSAR synchronization message for the Automotive Open System Architecture; Control the vehicle-mounted second physical link to send the AUTOSAR synchronization message to all downstream nodes.
6. The method according to claim 1, characterized in that, The downstream node is a microcontroller unit (MCU) in a vehicle domain controller; the step of acquiring the first local time information of the downstream node and determining the time deviation information based on the reference time information and the first local time information includes: The current count value of the real-time clock (RTC) inside the MCU is read as the first local time information; The difference between the reference time information and the first local time information is used as the time deviation information.
7. The method according to claim 6, characterized in that, The submodule is a system-on-a-chip (SoC) computing unit in the vehicle domain controller. The step of transmitting the time deviation information to at least one submodule within the downstream node, so that the submodule obtains a local synchronization time consistent with the reference time information based on its own second local time information and the time deviation information, includes: The MCU is controlled to broadcast the time deviation information to each SoC computing unit, so that each SoC computing unit reads the current count value of its internal real-time clock (RTC) as the second local time information, and obtains a local synchronization time consistent with the reference time information based on the algebraic sum of the second local time information and the time deviation information.
8. A vehicle-level dual-link redundant time synchronization system, characterized in that, include: The information acquisition unit is used to acquire first time information based on the first physical link of the vehicle and to acquire second time information based on the second physical link of the vehicle; wherein, the first physical link of the vehicle is a vehicle Ethernet General Precision Time Protocol (gPTP) link and the second physical link of the vehicle is a vehicle controller local area network (CAN bus) link. The information broadcasting unit is used to determine reference time information from the first time information and the second time information based on a preset arbitration rule, and broadcast the reference time information to downstream nodes through the vehicle-mounted second physical link; The deviation calculation unit is used to obtain the first local time information of the downstream node and determine the time deviation information based on the reference time information and the first local time information. An information synchronization unit is used to transmit the time deviation information to at least one sub-module within the downstream node, so that the sub-module obtains a local synchronization time consistent with the reference time information based on its own second local time information and the time deviation information.
9. An electronic device, comprising: The memory and processor are characterized in that the processor is used to implement the steps of the vehicle-level dual-link redundant time synchronization method as described in any one of claims 1 to 7 when executing a computer program stored in the memory.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the vehicle-level dual-link redundancy time synchronization method as described in any one of claims 1 to 7.