Domain controller, electronic device and vehicle
By controlling the drive voltage output and delayed power-on mechanism of the domain controller at the hard reset level, the problem of incomplete reset of the intelligent driving domain controller is solved, and the complete elimination of system safety faults and functional safety reliability are achieved.
Patent Information
- Application Number
- CN202520608807.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2026-02-10
- Estimated Expiration
- 2035-03-31
AI Technical Summary
In the existing technology, the reset operation of the intelligent driving domain controller is only at the soft reset level, which cannot completely clear the fault and there is a risk of incomplete fault clearing.
By implementing the domain controller reset at the hard reset level, the system base chip and processing module control the drive voltage output of the power distribution terminal based on the trigger signal of the monitoring input terminal. Combined with the delayed power-on mechanism, the system safety fault is ensured to be associated with power-on, and the drive voltage is disconnected to achieve power-off reset.
It achieves complete fault clearing of domain controllers, ensuring the accuracy, stability and reliability of functional safety requirements, and avoiding the impact of faults under unstable conditions.
Smart Images

Figure CN223890981U_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of electric vehicle technology, and more particularly to a domain controller, electronic device, and vehicle. Background Technology
[0002] With the advancement of information technology, autonomous driving technology has made groundbreaking progress in both feasibility and practicality. The core of autonomous driving technology lies in the configuration of the intelligent driving domain controller. The intelligent driving domain controller is crucial for the intelligent upgrade of automobiles. By integrating advanced driver assistance systems and intelligent perception modules, it enables innovative functions such as autonomous driving and vehicle-to-everything (V2X) connectivity, allowing drivers to experience the technological charm of future travel.
[0003] The intelligent driving domain controller is based on a watchdog circuit. If the microcontroller unit (MCU) in the intelligent driving domain controller successfully feeds the watchdog, the intelligent driving domain controller will work normally. If the MCU fails to feed the watchdog, the watchdog circuit will output a reset signal to reset the MCU.
[0004] Resetting the MCU via a reset signal is still a soft reset and cannot achieve a power-off restart of the MCU, which carries the risk of incomplete fault clearing. Utility Model Content
[0005] This application provides a domain controller, electronic device, and vehicle that achieves domain controller reset at the hard reset level, thoroughly clearing system safety faults and accurately, stably, and reliably meeting functional safety requirements.
[0006] This application provides a domain controller for intelligent driving, including: a system base chip (101), a processing module (102), and a control module (103); the system base chip (101) includes a monitoring input terminal (110) and a power distribution terminal (120); the system base chip (101) is configured to, in response to the monitoring input terminal (110) not receiving a first trigger signal for a period of time greater than a first preset time, stop the power distribution terminal (120) from outputting a first driving voltage (VCC1), and after the period of stopping the output of the first driving voltage (VCC1) is greater than a second preset time, the power distribution terminal (120) resumes outputting the first driving voltage (VCC1), the first trigger signal indicating that the processing module (102) has not experienced a safety fault; the processing module (102) is configured to power on based on the first driving voltage (VCC1), and the control module (103) is configured to power on with a delay based on the first driving voltage (VCC1).
[0007] In some embodiments, the system base chip (101) is configured to output a first drive voltage (VCC1) through the power distribution terminal (120) in response to the first trigger signal received by the monitoring input terminal (110).
[0008] In some embodiments, the control module (103) includes: an adjustment unit (201) connected to the power distribution terminal (120) and configured to receive and delay the first driving voltage to generate a second driving voltage; and a control unit (202) connected to the adjustment unit (201) and configured to power on based on the second driving voltage.
[0009] In some embodiments, the adjustment unit (201) includes a switching transistor (301), the first end of which is connected to the power distribution terminal (120), the second end of which is connected to the adjustment unit (201), and the control terminal receives a start signal.
[0010] In some embodiments, the processing module (102) further includes a signal terminal (160) connected to the control terminal of the switching transistor (301), wherein the start signal is provided by the processing module (102) after power-on.
[0011] In some embodiments, the adjustment unit (201) includes a delay device (302), the input terminal of which is connected to the power distribution terminal (120), and the output terminal of which is connected to the adjustment unit (201).
[0012] In some embodiments, the processing module (102) includes a monitoring output terminal (130), and the control module (103) includes a control input terminal (140) and a control output terminal (150). The monitoring output terminal (130) is connected to the control input terminal (140), and the control output terminal (150) is connected to the monitoring input terminal (110). The processing module (102) is configured to generate a second trigger signal in response to a security failure of the domain controller (100). The control module (103) is configured to generate a first trigger signal in response to the second trigger signal.
[0013] In some embodiments, the monitoring output terminal (130) includes multiple output pins, and the control module (103) includes at least a logic gate, the input terminal of which is connected to the control input terminal (140), and the output terminal is connected to the control output terminal (150).
[0014] In some embodiments, the plurality of output pins include at least a first pin (401) and a second pin (402); when an undervoltage fault and / or an overvoltage fault occurs, the domain controller (100) outputs the second trigger signal through the first pin (401); when a control error fault occurs, the domain controller (100) outputs the second trigger signal through the second pin (402).
[0015] In some embodiments, the logic gate includes an AND gate, the first input of which is connected to the first pin (401), the second input of which is connected to the second pin (402), and the output of which is connected to the control output (150).
[0016] In some embodiments, the processing module (102) is connected to the power distribution terminal (120), and the control module (103) is connected to the monitoring input terminal (110), the power distribution terminal (120), and the processing module (102).
[0017] This application also provides an electronic device, including the domain controller (100) provided in the above embodiments.
[0018] This application also provides a means of transportation, including the domain controller (100) provided in the above embodiments, or the electronic device provided in the above embodiments.
[0019] For the domain controller provided in this embodiment, a first trigger signal determines whether to output a first drive voltage to drive the domain controller to work, so as to associate the system's safety fault with the system power-on; when the system has a safety fault, the domain controller is powered off by disconnecting the drive voltage, and the domain controller is reset from the hard reset level, so that the system safety fault can be completely cleared and the functional safety requirements can be accurately, stably and reliably achieved. Attached Figure Description
[0020] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0021] Figure 1 This is a schematic diagram of the domain controller provided in an embodiment of this application;
[0022] Figure 2 This is a schematic diagram of the domain controller structure under the specific control module structure provided in the embodiments of this application;
[0023] Figure 3The adjustment unit provided in this embodiment is a schematic diagram of a switching transistor time domain controller;
[0024] Figure 4 The adjustment unit provided in this application embodiment is a schematic diagram of the structure of a delay device time domain controller;
[0025] Figure 5 The monitoring output terminal provided in this application includes a time domain controller with multiple output pins.
[0026] Explanation of reference numerals in the attached figures:
[0027] Domain controller 100, system base chip 101, processing module 102, control module 103, adjustment unit 201, control unit 202, switching transistor 301, delay device 302, monitoring input terminal 110, power distribution terminal 120, monitoring output terminal 130, control input terminal 140, control output terminal 150, first pin 401, second pin 402, first driving voltage VCC1, second driving voltage VCC2. Detailed Implementation
[0028] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the protection scope of this application.
[0029] In the description of this application, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Therefore, features defined with "first" and "second" may explicitly or implicitly include one or more described features. In the description of this application, "multiple" means two or more, unless otherwise explicitly specified.
[0030] In this application, the term "exemplary" is used to mean "used as an example, illustration, or description." Any embodiment described as "exemplary" in this application is not necessarily to be construed as being more preferred or advantageous than other embodiments. The following description is provided to enable any person skilled in the art to make and use this application. Details are set forth in the following description for purposes of explanation. It should be understood that those skilled in the art will recognize that this application can be made without using these specific details. In other instances, well-known structures and processes are not described in detail to avoid obscuring the description of this application with unnecessary detail. Therefore, this application is not intended to be limited to the embodiments shown, but is consistent with the broadest scope of the principles and features disclosed in this application.
[0031] Furthermore, this application uses specific terms to describe embodiments of the application. For example, "an embodiment," "one embodiment," and / or "some embodiments" refer to a particular feature, structure, or characteristic associated with at least one embodiment of the application. Therefore, it should be emphasized and noted that "an embodiment," "one embodiment," or "an alternative embodiment" mentioned twice or more in different locations in this specification do not necessarily refer to the same embodiment. In addition, certain features, structures, or characteristics in one or more embodiments of the application can be appropriately combined.
[0032] Similarly, it should be noted that, in order to simplify the description of the present application and thus aid in the understanding of one or more embodiments, the foregoing description of the embodiments of the present application sometimes combines multiple features into a single embodiment, drawing, or description thereof. However, this disclosure method does not imply that the subject matter of the present application requires more features than those mentioned in the claims. In fact, the embodiments contain fewer features than all the features of the single embodiments disclosed above.
[0033] In some embodiments, numbers describing the quantity of components and attributes are used. It should be understood that such numbers used in the description of embodiments are modified in some examples with the terms "approximately," "approximately," or "generally." Unless otherwise stated, "approximately," "approximately," or "generally" indicates that the numbers are allowed to vary by ±20%. Accordingly, in some embodiments, the numerical parameters used in the specification and claims are approximate values, which may be changed depending on the characteristics required by individual embodiments. In some embodiments, numerical parameters should be considered for specifying significant digits and employing a general method of digit reservation. Although the numerical ranges and parameters used to confirm their breadth of range in some embodiments of this application are approximate values, in specific embodiments, such numerical values are set as precisely as feasible.
[0034] For each patent, patent application, patent application publication, and other material such as articles, books, specifications, publications, and documents referenced in this application, the entire contents of that application are incorporated herein by reference, except for historical application documents that are inconsistent with or conflict with the content of this application, and documents that limit the broadest scope of the claims of this application (currently or subsequently appended to this application). It should be noted that if there are any inconsistencies or conflicts between the descriptions, definitions, and / or terminology used in the supplementary materials of this application and the examples in this application, the descriptions, definitions, and / or terminology used in this application shall prevail.
[0035] As is known from the background technology, resetting the MCU via a reset signal is still a soft reset operation, which cannot achieve a power-off restart of the MCU, and there is a risk of incomplete fault clearing.
[0036] To address this issue, this application provides a domain controller for intelligent driving. The domain controller includes a system base chip, a processing module, and a control module. The system base chip includes a monitoring input terminal and a power distribution terminal. The processing module is connected to the power distribution terminal, and the control module is connected to the monitoring input terminal, the power distribution terminal, and the processing module. The system base chip is configured to stop the power distribution terminal from outputting a first driving voltage when the monitoring input terminal does not receive a first trigger signal for a period longer than a first preset time. After the period of stopping the output of the first driving voltage is longer than a second preset time, the power distribution terminal resumes outputting the first driving voltage. The first trigger signal indicates that the processing module has not experienced a safety fault. The processing module is configured to power on based on the first driving voltage, and the control module is configured to power on with a delay based on the first driving voltage.
[0037] The domain controller provided in this embodiment determines whether to output a first drive voltage to drive the domain controller to work through a first trigger signal, so as to associate the system's safety fault with the system power-on; when the system has a safety fault, the domain controller is powered off by disconnecting the drive voltage, and the domain controller is reset from the hard reset level, so that the system safety fault can be completely cleared and the functional safety requirements can be accurately, stably and reliably achieved.
[0038] The domain controller provided in this embodiment will be described in detail below with reference to the accompanying drawings. Figure 1 , Figure 1 This is a schematic diagram of the domain controller provided in this embodiment.
[0039] The domain controller 100 includes at least a system base chip 101, which includes a monitoring input terminal 110 and a power distribution terminal 120. The system base chip 101 is configured to output a first drive voltage VCC1 through the power distribution terminal 120 in response to a first trigger signal received at the monitoring input terminal 110. The first trigger signal indicates that no safety fault has occurred in the domain controller, and the first drive voltage is the power supply voltage of the domain controller. The processing module 102 is connected to the power distribution terminal 120 and is configured to power on based on the first drive voltage VCC1. The control module 103 is connected to the monitoring input terminal 110, the power distribution terminal 120, and the processing module 102 and is configured to power on with a delay based on the first drive voltage VCC1.
[0040] The first trigger signal is used to determine whether a safety fault has occurred in the system, and the first drive voltage is used to drive the domain controller at least.
[0041] The System Basis Chip (SBC) 101 is a standalone chip that integrates power, communication, monitoring and diagnostics, and security monitoring. It is one of the most fundamental and important chips in a domain controller.
[0042] The processing module 102 is the microcontroller unit (MCU) in the domain controller. Typically, the functional safety of the domain controller 100 is achieved through the cooperation of the system base chip 101 and the processing module 102. The system base chip 101 primarily handles power supply and functional safety monitoring, while the processing module 102 primarily handles functional safety monitoring and fault output. The system base chip 101 has a functional safety monitoring input pin (i.e., monitoring input terminal 110), and the processing module 102 has a functional safety fault output pin (i.e., monitoring output terminal 130).
[0043] In some embodiments, the system base chip 101 may be an MPQ70331 manufactured by MPS; the processing module 102 may be a U2A16 manufactured by RENESAS.
[0044] In one example, the system base chip 101 can continuously output a first drive voltage VCC1 based on a first trigger signal. Specifically, when the first trigger signal is "1", it indicates that no safety fault has occurred in the system; when the first trigger signal is "0", it indicates that a safety fault has occurred in the system. The system base chip 101 is configured to output the first drive voltage VCC1 through the power distribution terminal 120 in response to the first trigger signal received at the monitoring input terminal 110 being "1"; and to stop outputting the first drive voltage VCC1 in response to the first trigger signal received at the monitoring input terminal 110 being "0".
[0045] In one example, the system base chip 101 can stop outputting the first drive voltage based on a first trigger signal. Specifically, when the first trigger signal is "1", it indicates that a safety fault has occurred in the system; when the first trigger signal is "0", it indicates that no safety fault has occurred in the system. The system base chip 101 is configured to stop outputting the first drive voltage VCC1 in response to the first trigger signal received at the monitoring input terminal 110 being "1"; and to output the first drive voltage VCC1 through the power distribution terminal 120 in response to the first trigger signal received at the monitoring input terminal 110 being "0".
[0046] It should be noted that if the time during which the monitoring input terminal 110 does not receive the first trigger signal is greater than the first preset time, the first preset time is used to ensure that the monitoring input terminal 110 does not receive the first trigger signal. The specific value of the first preset time can be set based on the specific application scenario.
[0047] It should be noted that the second preset time from power failure to power restoration of the system base chip 101 is set based on the requirements of the application scenario and is not limited in this embodiment. The specific setting value of the second preset time depends on the detection time interval of the system safety fault.
[0048] In some embodiments, the system base chip 101 is configured to output a first drive voltage VCC1 through the power distribution terminal 120 in response to a first trigger signal received at the monitoring input terminal 110.
[0049] The domain controller provided in this embodiment determines whether to output a first drive voltage to drive the domain controller to work through a first trigger signal, so as to associate the system's safety fault with the system power-on; when the system has a safety fault, the domain controller is powered off by disconnecting the drive voltage, and the domain controller is reset from the hard reset level, so that the system safety fault can be completely cleared and the functional safety requirements can be accurately, stably and reliably achieved.
[0050] In addition, this embodiment avoids the influence of fault signal status from processing module 102 on domain controller 100 during unstable phase by delaying power-on. Thus, no matter what state the functional safety fault output pin of processing module 102 is in before processing module 102 is powered on and stabilized, it will not affect the normal output of power supply to system base chip 101, and thus will not affect the normal startup of domain controller 100.
[0051] In some embodiments, a voltage stabilizing and filtering circuit is provided on the path through which the processing module 102 and the control module 103 receive the first driving voltage VCC1. The voltage stabilizing and filtering circuit is used to stabilize and filter the first driving voltage VCC1 to increase the reliability of the circuit.
[0052] In some embodiments, the processing module 102 includes a monitoring output terminal 130, and the control module 103 includes a control input terminal 140 and a control output terminal 150. The monitoring output terminal 130 is connected to the control input terminal 140, and the control output terminal is connected to the monitoring input terminal 110. The processing module 102 is configured to generate a second trigger signal in response to a security failure of the domain controller 100; the control module 103 is configured to generate a first trigger signal in response to the second trigger signal.
[0053] The second trigger signal is used to detect whether a safety fault has occurred in the system. In one example, when a safety fault is detected, the second trigger signal output by the processing module 102 is "0"; when no safety fault is detected, the second trigger signal output by the processing module 102 is "1".
[0054] There may be a difference in the state of the monitoring input terminal 110 and the monitoring output terminal 130 before the system is powered on. If the monitoring input terminal 110 and the monitoring output terminal 130 are directly connected, the domain controller 100 may report an error or repeatedly restart due to the different states of the monitoring input terminal 110 and the monitoring output terminal 130.
[0055] In this embodiment, the monitoring input terminal 110 and the monitoring output terminal 130 are connected via the control module 103 to avoid circuit failures that may be caused by direct connection between the monitoring input terminal 110 and the monitoring output terminal 130.
[0056] for Figure 1 When the domain controller 100 encountered a security fault, the processing module 102 detected the fault and generated a second trigger signal. The control module 103 generated a first trigger signal based on the second trigger signal, and the system base chip 101 stopped outputting the first drive voltage VCC1 based on the first trigger signal. At this time, the processing module 102 was powered off. After a preset time interval, the system base chip 101 resumed providing the first drive voltage VCC1, the processing module 102 restarted, and the control module 103 started after a delay based on the first drive voltage VCC1, thereby re-establishing the security fault signal transmission path.
[0057] refer to Figure 2 , Figure 2 This is a schematic diagram of the domain controller under the specific control module structure provided in this embodiment. In some embodiments, the control module 103 includes an adjustment unit 201 and a control unit 202. The adjustment unit 201 is connected to the power distribution terminal 120 and is configured to receive and delay a first driving voltage VCC1 to generate a second driving voltage VCC2. The control unit 202 is connected to the adjustment unit 201 and is configured to power on based on the second driving voltage VCC2.
[0058] Specifically, the control unit 202 is used to realize the relay of the safety fault signal transmission path in the control module 103, and the adjustment unit 201 is used to realize the delayed power-on of the control module 103 compared with the processing module 102.
[0059] refer to Figure 3 , Figure 3 The adjustment unit provided in this embodiment is a schematic diagram of a switching transistor time domain controller. In some embodiments, the adjustment unit 201 includes a switching transistor 301, the first end of which is connected to the power distribution terminal 120, the second end of which is connected to the adjustment unit 201, and the control terminal receives a start signal.
[0060] By activating the switching transistor 301 with the start signal, the first driving voltage VCC1 is delayed, thereby generating the second driving voltage VCC2 to complete the delayed power-on of the control module 103.
[0061] In some embodiments, the processing module 102 further includes a signal terminal 160, which is connected to the control terminal of the switching transistor 301, wherein the start signal is provided by the processing module after it is powered on.
[0062] The power-on of the control module 103 is achieved by the start signal provided by the processing module 102 after it is powered on, so as to ensure that the control module 103 starts to power on after the processing module 102 is powered on, thereby achieving a delayed power-on of the control module 103 compared to the processing module 102.
[0063] In one example, the switching transistor 301 can be based on a PMOS, in which case the start signal is a low-level signal. Specifically, when the start signal is high, the PMOS is off, and the first and second terminals of the PMOS are considered disconnected. The first driving voltage VCC1 cannot be transmitted to the control unit 202 through the PMOS, and the control unit 202 cannot be powered on, that is, the control module 103 cannot be powered on. When the start signal is low, the PMOS is on, and the first and second terminals of the PMOS are considered connected. The first driving voltage VCC1 is transmitted to the control unit 202 through the PMOS, and the control unit 202 is powered on, that is, the control module 103 is powered on.
[0064] In another example, the switch 301 can be based on an NMOS transistor, in which case the startup signal is a high-level signal. Specifically, when the startup signal is low, the NMOS transistor is off, and the first and second terminals of the NMOS transistor are considered disconnected. The first driving voltage VCC1 cannot be transmitted to the control unit 202 through the NMOS transistor, and the control unit 202 cannot be powered on, meaning the control module 103 cannot be powered on. When the startup signal is high, the NMOS transistor is on, and the first and second terminals of the NMOS transistor are considered connected. The first driving voltage VCC1 is transmitted to the control unit 202 through the NMOS transistor, and the control unit 202 is powered on, meaning the control module 103 is powered on.
[0065] It should be noted that this embodiment does not limit the type of the switching transistor 301. If the purpose of setting the switching transistor 301 is to realize the power-on time difference between the control module 103 and the processing module 102, it should fall within the protection scope of this application.
[0066] refer to Figure 4 , Figure 4 This is a schematic diagram of the structure of the adjustment unit provided in this embodiment, which is a time-domain controller for a delay device. In some embodiments, the adjustment unit 201 includes a delay device 302, the input terminal of which is connected to the power distribution terminal 120, and the output terminal of which is connected to the adjustment unit 201.
[0067] The delay device 302 delays the first driving voltage VCC1 to generate the second driving voltage VCC2 to complete the delayed power-on of the control module 103.
[0068] In some embodiments, the specific delay time of the delay device 302 can be set to the time interval between the processing module 102 receiving the first driving voltage VCC1 and the processing module 102 completing power-on.
[0069] In some embodiments, the specific delay time of the delay device 302 can also be set based on a preset time; wherein, the preset time can be manually controlled by the operator to adapt to the domain controller 100 with different aging levels.
[0070] refer to Figure 5 , Figure 5 This embodiment provides a schematic diagram of a time-domain controller with multiple output pins as the monitoring output terminal. In some embodiments, the monitoring output terminal 130 includes multiple output pins, and the control module 103 includes at least a logic gate. The output terminal of the logic gate is connected to the control input terminal 140, and the output terminal is connected to the control output terminal 150.
[0071] Specifically, the processing module 102 may not be limited to one type of safety fault monitoring, such as system overvoltage or undervoltage safety faults, or system safety policy faults; through the control of multiple output pins and logic gates, the domain controller 100 can be powered off and reset based on different types of safety faults.
[0072] In some embodiments, the plurality of output pins include at least a first pin 401 and a second pin 402; wherein, when an overcurrent fault and / or overvoltage fault occurs, the domain controller 100 outputs a second trigger signal through the first pin 401; and when a control error fault occurs, the domain controller 100 outputs a second trigger signal through the second pin 402.
[0073] In one example, the first pin 401 is the VMONOUT pin on the processing module 102. The VMONOUT pin is used to monitor whether there is overvoltage or undervoltage in each power supply of the processing module 102. Once overvoltage or undervoltage occurs, the pin outputs a low-level signal.
[0074] It should be noted that, for the VMONOUT pin, in order to avoid the unexpected working situation caused by the unstable power supply at the beginning of power-on, this pin is set to a low level during the Power On Reset (POR) phase; therefore, the pin state before the processing module 102 has finished starting needs to be specially handled, otherwise it will conflict with the functional safety monitoring of the system base chip 101.
[0075] In one example, the second pin 402 is the ERROROUT_M pin on the processing module 102. The processing module 102 includes an error control module (ECM). Once the error control module diagnoses a control error fault, this pin outputs a low-level signal.
[0076] It should be noted that, for the ERROROUT_M pin, in order to avoid the unexpected working situation caused by the unstable power supply at the beginning of power-on, this pin is set to a low level during the Power On Reset (POR) phase; therefore, the pin state before the processing module 102 has finished starting needs to be specially handled, otherwise it will conflict with the functional safety monitoring of the system base chip 101.
[0077] In one example, for the monitoring input 110 pin, once the pin detects a low level that matches its width setting, it immediately enters Deep Safe mode. In this mode, the system base chip 101 does not provide power input to the processing module 102, which can achieve the purpose of powering down and restarting the processing module 102, thereby clearing the fault.
[0078] It should be noted that Deep Safe mode is a state in the state machine of the system base chip 101. After the set time is reached, it will automatically enter the power supply mode so that the processing module 102 can be powered on again. Since this pin is monitored continuously after the system base chip 101 is powered on, and the power supply of the system base chip 101 is constant, the first pin 401 and / or the second pin 402 cannot be directly connected to this pin.
[0079] In some embodiments, the logic gate includes an AND gate, with the first input of the AND gate connected to the first pin 401, the second input of the AND gate connected to the second pin 402, and the output of the AND gate connected to the control output terminal 150.
[0080] It should be noted that the multiple output pins, including the first pin 401 and the second pin 402, are only used to illustrate the multiple output pins and demonstrate that the domain controller 100 can be powered down and reset based on different types of security faults, and do not constitute a limitation on this embodiment. In other embodiments, the multiple output pins may also include pins for monitoring other types of security faults.
[0081] For the domain controller 100 provided in this embodiment, when a security fault is encountered, the processing module 102 detects the security fault and generates a second trigger signal; the control module 103 generates a first trigger signal based on the second trigger signal, and the system base chip 101 stops outputting the first drive voltage VCC1 based on the first trigger signal. At this time, the processing module 102 is powered off. After a preset time interval, the system base chip 101 resumes providing the first drive voltage VCC1, the processing module 102 restarts, and the control module 103 starts after a delay based on the first drive voltage VCC1, thereby re-establishing the security fault signal transmission path.
[0082] The domain controller provided in this embodiment determines whether to output a first drive voltage to drive the domain controller to work through a first trigger signal, so as to associate the system's safety fault with the system power-on; when the system has a safety fault, the domain controller is powered off by disconnecting the drive voltage, and the domain controller is reset from the hard reset level, so that the system safety fault can be completely cleared and the functional safety requirements can be accurately, stably and reliably achieved.
[0083] It should be noted that, without conflict, the features disclosed in the domain controller 100 provided in the above embodiments can be randomly combined to obtain new domain controller 100 embodiments.
[0084] Another embodiment of this application also provides an electronic device, which includes the domain controller 100 provided in the above embodiments.
[0085] Another embodiment of this application provides a vehicle that includes the domain controller 100 provided in the above embodiments, or the electronic device provided in the above embodiments.
[0086] The exclusive right of this means of transport possesses all the beneficial effects of the aforementioned minimally protected subject matter, which will not be elaborated upon here. This means of transport may be a gasoline-powered vehicle, a plug-in hybrid electric vehicle, or a new energy vehicle, etc., and this application does not specifically limit it in this regard.
[0087] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the detailed descriptions of other embodiments above, which will not be repeated here.
[0088] The basic concepts have been described above. Obviously, for those skilled in the art, the detailed disclosure above is merely illustrative and does not constitute a limitation of this application. Although not explicitly stated herein, those skilled in the art may make various modifications, improvements, and corrections to this application. Such modifications, improvements, and corrections are suggested in this application, and therefore remain within the spirit and scope of the exemplary embodiments of this application.
[0089] The domain controller, electronic device, and vehicle provided in the embodiments of this application have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this application. The description of the above embodiments is only for the purpose of helping to understand the method and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.
Claims
1. A domain controller (100) for use in intelligent driving, characterized in that, include: The system includes a base chip (101), a processing module (102), and a control module (103). The system base chip (101) includes a monitoring input terminal (110) and a power distribution terminal (120); The system base chip (101) is configured to, in response to the monitoring input terminal (110) not receiving the first trigger signal for a period of time longer than a first preset time, stop the power distribution terminal (120) from outputting the first driving voltage (VCC1), and after the period of stopping the output of the first driving voltage (VCC1) is longer than a second preset time, the power distribution terminal (120) resumes outputting the first driving voltage (VCC1), wherein the first trigger signal indicates that the processing module (102) has not experienced a safety fault; The processing module (102) is configured to power on based on the first driving voltage (VCC1), and the control module (103) is configured to power on with a delay based on the first driving voltage (VCC1).
2. The domain controller (100) according to claim 1, characterized in that, The system base chip (101) is configured to output a first drive voltage (VCC1) through the power distribution terminal (120) in response to the first trigger signal received by the monitoring input terminal (110).
3. The domain controller (100) according to claim 2, characterized in that, The control module (103) includes: The adjustment unit (201), connected to the power distribution terminal (120), is configured to receive and delay the first driving voltage to generate a second driving voltage; The control unit (202), connected to the adjustment unit (201), is configured to power on based on the second drive voltage.
4. The domain controller (100) according to claim 3, characterized in that, The adjustment unit (201) includes a switching transistor (301), the first end of which is connected to the power distribution terminal (120), the second end of which is connected to the adjustment unit (201), and the control terminal receives a start signal.
5. The domain controller (100) according to claim 4, characterized in that, The processing module (102) further includes a signal terminal (160), which is connected to the control terminal of the switching transistor (301). The start signal is provided by the processing module (102) after it is powered on.
6. The domain controller (100) according to claim 3, characterized in that, The adjustment unit (201) includes a delay device (302), the input terminal of which is connected to the power distribution terminal (120), and the output terminal of which is connected to the adjustment unit (201).
7. The domain controller (100) according to any one of claims 2 to 6, characterized in that, The processing module (102) includes a monitoring output terminal (130), and the control module (103) includes a control input terminal (140) and a control output terminal (150). The monitoring output terminal (130) is connected to the control input terminal (140), and the control output terminal (150) is connected to the monitoring input terminal (110). The processing module (102) is configured to generate a second trigger signal in response to a security failure of the domain controller (100); The control module (103) is configured to generate the first trigger signal in response to the second trigger signal.
8. The domain controller (100) according to claim 7, characterized in that, The monitoring output terminal (130) includes multiple output pins, and the control module (103) includes at least a logic gate. The input terminal of the logic gate is connected to the control input terminal (140), and the output terminal is connected to the control output terminal (150).
9. The domain controller (100) according to claim 8, characterized in that, The plurality of output pins includes at least a first pin (401) and a second pin (402); When an undervoltage fault and / or overvoltage fault occurs, the domain controller (100) outputs the second trigger signal through the first pin (401); When a control error occurs, the domain controller (100) outputs the second trigger signal through the second pin (402).
10. The domain controller (100) according to claim 9, characterized in that, The logic gate includes an AND gate, the first input of which is connected to the first pin (401), the second input of which is connected to the second pin (402), and the output of which is connected to the control output (150).
11. The domain controller (100) according to any one of claims 1 to 6, characterized in that, The processing module (102) is connected to the power distribution terminal (120), and the control module (103) is connected to the monitoring input terminal (110), the power distribution terminal (120), and the processing module (102).
12. An electronic device, characterized in that, Includes the domain controller (100) as described in any one of claims 1 to 11.
13. A means of transportation, characterized in that, It includes the domain controller (100) as described in any one of claims 1 to 11, or the electronic device as described in claim 12.