Control system for a motor vehicle

The central control unit in the control system addresses redundancy and cost issues by detecting faults and switching to a second system software, maintaining stability and functionality in motor vehicles.

DE102019201607B4Active Publication Date: 2026-01-29VOLKSWAGEN AG
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
DE102019201607
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2019-02-07
Publication Date
2026-01-29
Estimated Expiration
2039-02-07

AI Technical Summary

Technical Problem

Existing control systems for motor vehicles require redundant hardware and software to handle ECU failures, increasing complexity and cost, and may introduce instability due to master control units taking over local controllers.

Method used

A control system with a central control unit that monitors and coordinates multiple functional units, detects faults, and executes a second system software to replace the faulty units, minimizing redundancy and avoiding incompatibility errors.

Benefits of technology

Enables stable operation with reduced redundancy, avoiding system instability and cost increases by dynamically switching to a second system software tailored to the fault, ensuring continued functionality of essential vehicle systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Control system (100) for a motor vehicle (200), comprising: a plurality of functional units (90) of the motor vehicle (200), each with at least one electronically controllable vehicle component (80); and a central control unit (50) connected to the functional units (90) via a vehicle bus (60), which is designed to coordinate the operation of the majority of functional units (90) by executing a first system software (21), the central control unit (50) is further equipped for: to identify at least one faulty functional unit (91), to perform a restart with a second system software (22) determined depending on the at least one faulty functional unit (91), whereby the first system software (21) is replaced by the second system software (22) and to coordinate the operation of the remaining functional units (92) by executing the second system software (22).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a control system for a motor vehicle, in particular a fault-tolerant control system for an autonomously operable motor vehicle.

[0002] Modern vehicles typically feature a multitude of electronic control units (ECUs) used for a variety of different applications. While some of these applications are merely for the driver's entertainment, such as playing multimedia content, others are essential for the vehicle's proper and safe operation. The consequences of an ECU failure therefore vary drastically. While a multimedia control unit failure is usually just an inconvenience, a malfunctioning engine control unit often renders the vehicle unusable. The failure of a control unit used to manage or regulate a safety-relevant process, such as an ABS control unit or a steering system control unit, can, in some cases, even endanger the health of the vehicle's occupants.Therefore, appropriate precautions must be taken in the event of a malfunction of a control unit.

[0003] In the field of autonomous driving, the aforementioned problems are even more significant. In highly to fully automated driving, as in other safety-relevant processes, safety-critical ECUs must be protected by an emergency protocol. This protocol ensures that the vehicle is brought to a safe state in the event of a fault. This transition to a safe state typically involves providing a reduced number of emergency functionalities.

[0004] EP 3 323 687 A1 describes an emergency system for providing emergency control of an autonomous vehicle in the event of a hardware or software defect. This emergency system typically includes redundant hardware or software components that are used when primary hardware or software fails. A disadvantage of this solution is the need to maintain redundant hardware and / or software, thus requiring additional installation space and / or storage capacity. This redundancy increases the complexity of the vehicle system and, consequently, also the vehicle's cost.

[0005] German patent DE 697 37 308 T2 describes an alternative system for the fault-tolerant operation of a motor vehicle with multiple electronic vehicle components, each controlled by a local controller. A master control unit is connected to the local controllers and takes over the functions of a local controller in the event of a fault or failure. For this purpose, the local controllers are connected to the master control unit and can selectively transmit the data from the vehicle components either to the respective local controller or to the master control unit. Furthermore, the master control unit monitors the local controllers to detect any faults or failures. A disadvantage is that the master control unit must have the driver software for all local controllers and therefore require additional memory, which in turn increases costs.Similarly, the master control unit taking over the functions of the local controllers can lead to errors and thus impair the stability of the system.

[0006] DE 602 19 705 T2 relates to a fail-safe system that uses an integrated control system of a vehicle, such as an automobile or motor vehicle. Furthermore, the invention relates to a method for fail-safe operation.

[0007] DE 10 2015 003 194 A1 concerns automotive applications, in particular safety applications, e.g. for power transmission control, warning indicator control, electronic power steering or electronic brake control.

[0008] The invention is based on the objective of providing an economically advantageous control system for a motor vehicle that can be operated stably in the event of malfunctions of system components and has as little redundancy as possible than the known solutions.

[0009] The problem according to the invention is solved by a control system with the features of the main claim. Preferred embodiments are the subject of the dependent claims.

[0010] A first aspect of the invention relates to a control system for a motor vehicle, in particular an electronic control system for a motor vehicle. The control system comprises a plurality of functional units of the motor vehicle, each functional unit comprising at least one electronically controllable vehicle component. These vehicle components can implement a wide variety of functionalities in the vehicle, such as engine control, infotainment, or ABS. In a preferred embodiment, at least one vehicle component comprises at least one sensor and / or at least one electrical or electromechanical actuator. Also preferably, at least one functional unit comprises a control unit configured for operating the vehicle component. Also preferably, at least one functional unit comprises a network interface configured for communication via a vehicle bus.The functional units thus comprise various local subsystems of the control system, in particular intelligent subsystems with their own control unit or non-intelligent subsystems without a control unit.

[0011] The vehicle control system further comprises a central control unit connected to the functional units via a vehicle bus. The central control unit has at least one processor and also a network interface. Preferably, the central control unit has memory or at least memory access. The central control unit is configured to coordinate the operation of the majority of functional units by executing a first system software. System software is understood to mean the entirety of the software present on the central control unit at a given time. The system software preferably comprises an operating system and furthermore, specific software elements designed for the operation of the functional units present in the vehicle. The software elements are preferably designed for the operation of one or more functional units.Preferably, the central control unit monitors the operation of all functional units present in the control system. This monitoring is carried out directly by controlling or regulating the functional unit, or at least by communicating with a functioning control unit of the respective functional unit.

[0012] In the control system of the present invention, each of the functional units is thus designed to provide its respective functionality more or less autonomously. For example, a climate control functional unit comprises an air conditioning system and a climate control unit designed to operate the air conditioning system. The operation of the climate control functional unit is therefore largely autonomous from the central control unit, which merely monitors the correct operation of the climate control unit continuously or intermittently. In another example, a wiper functional unit comprises a plurality of sensors, for example, rain sensors, an actuator, for example, a windshield wiper motor, and a network interface. This functional unit is therefore not very autonomous from the central control unit, which receives the measurement signals from the rain sensors via the network interface.Based on these signals, the central control unit determines control instructions for the actuator and transmits them to the actuator via the network interface. In this example, the first system software includes at least software elements whose execution monitors the climate control unit, and software elements whose execution determines control instructions for the actuator based on the sensor signals.

[0013] According to the present invention, the central control unit is further configured to detect at least one faulty functional unit. In other words, the central control unit is configured to detect a malfunction in at least one functional unit. This is therefore a possible result of monitoring the operation of the functional units. In the aforementioned examples, the central control unit could thus independently detect a malfunction of the climate control unit or be informed by the climate control unit of a malfunction of the air conditioning system. Likewise, the central control unit can detect a malfunction of at least one of the multiple rain sensors, for example by verifying the plausibility of their signals, or of the windshield wiper motor.

[0014] The central control unit is further configured to perform a restart with a second system software, which is determined depending on the at least one faulty functional unit. In other words, the central control unit according to the invention is first configured to perform a restart in response to the detection of a faulty functional unit. Furthermore, the central control unit according to the invention is configured to execute a second system software after the restart, which explicitly depends on the detected faulty functional unit. In other words, after the restart, the central control unit is operated with the second system software, which takes into account which functional unit was identified as faulty. Thus, the central control unit is designed to be operated with different system software depending on the number and type of fault-free functional units.In other words, the control system according to the invention has access to a plurality of system software, each system software being adapted to a specific error pattern.

[0015] According to the invention, the central control unit is further configured to coordinate the operation of the remaining functional units by executing the second system software. The remaining functional units do not include at least the faulty functional unit. Thus, in the event of a significant malfunction of a functional unit, the control system according to the invention advantageously replaces the entire system software, with the second system software circumventing the malfunction by no longer operating the faulty functional unit during its execution. Replacing the entire system software has the advantage that a first, self-contained and stable system software is exchanged for a second, self-contained and stable system software.This advantageously avoids incompatibility errors that can occur when replacing or adapting only individual segments of a system software. Furthermore, the second system software can preferably be developed largely independently of the first. For example, the first system software may have been developed using an ASIL A-certified process, and the second system software may have been developed using an ASIL D-certified process. The second system software is therefore also suitable for implementing emergency running capabilities.

[0016] In a preferred embodiment, the central control unit only performs a restart if it is determined that restoring the faulty functional unit to a functional state during the central control unit's operation is not possible or not to be expected. In other words, the central control unit preferably only restarts itself and thus the control system in response to a serious (irreparable) fault. Particularly preferably, the central control unit first attempts to restore the functionality of the faulty functional unit, for example, by restarting the functional unit, by restarting a control unit of the functional unit, or by restarting a software element in the central control unit used for control or regulation. If restoring functionality fails, the central control unit then performs a restart of itself.

[0017] In a particularly preferred embodiment, the central control unit is configured to prevent the operation of at least one faulty functional unit during the execution of the second system software. In other words, at least the faulty functional unit is inactive when the central control unit is operating with the second system software. Advantageously, the faulty functional unit cannot adversely affect the operation of the control system, particularly the remaining functional units, after the central control unit has restarted. Particularly preferably, the faulty functional unit is not detected or addressed by the second system software. Preferably, the control system is operated with the second system software as if the faulty functional unit did not exist.

[0018] In a further preferred embodiment, the central control unit is also configured to define new functional units by or during the execution of the second system software. Preferably, if a first control unit of a first functional unit of the first system software fails, a remaining functional vehicle component of this first functional unit is combined with a functional control unit of a second functional unit of the first system software to form a new functional unit of the second system software. Thus, when the second system software is executed, the intact vehicle component is advantageously operated by an intact control unit without the defective first control unit impairing its operation.

[0019] In a further preferred embodiment for redefining functional units during the execution of the second system software, a first functional unit of the first system software comprises several sensors, at least one actuator, and a control unit. The control unit is configured to operate the at least one actuator based on the sensor signals from the several sensors. One of the sensors has a defect, which is detected by the central control unit. After the central control unit restarts, it is operated with a second system software that combines the remaining functional sensors, the control unit, and the actuator into a new functional unit of the second system software. Thus, the control unit now operates the actuator based on the sensor signals from the remaining functional sensors.According to this embodiment, the redefinition of the functional units thus includes the definition of the sensors to be considered by the control unit for controlling the actuator. Alternatively, preferably, the central control unit is part of this functional unit instead of the control unit itself.

[0020] In a particularly preferred embodiment of the control system according to the invention, the second system software is determined by the central control unit as a system image. A system image describes, in particular, a bootable system, thus comprising a bootable operating system and all software elements necessary for the operation of the control system, especially for the operation of the functional units of the control system. In other words, the second system software is loaded directly into a memory of the control system during the boot process, for which the central control unit has access rights. Particularly preferred is the second system software, like the first system software and independent of the first system software, a self-contained system image.

[0021] In a further preferred embodiment of the control system according to the invention, the central control unit is also configured to receive functional data and / or status information from the functional units. Functional data includes all data that can be used to control or regulate the functional unit, preferably to control or regulate actuators or sensors of the functional unit. In the aforementioned example of the wiper functional unit, the functional data received by the central control unit thus preferably includes the sensor signals from the rain sensors. In the aforementioned example of the climate control functional unit, the received functional data preferably includes the outside and inside temperatures of the vehicle. Furthermore, status information is preferably received from the functional units that have a control unit.In the aforementioned example of the climate control unit, status information includes, for example, information on the functionality of the air conditioning system or the climate control unit. This status information can be determined, for example, using the control unit's respective test algorithms, such as checksums.

[0022] According to the aforementioned embodiment, the central control unit is further configured to evaluate the received functional data and / or status information and, depending on this received data and / or information, to transmit command signals to the functional units to coordinate their operation. Preferably, data and information received from at least a second functional unit are also taken into account for controlling or regulating a first functional unit. For example, a second functional unit can transmit to the central control unit that it is receiving implausible signals from a first functional unit, allowing the central control unit to conclude that the first functional unit is faulty. Thus, the central control unit is preferably configured to detect a fault in a functional unit based on received functional data or status information.

[0023] In a further preferred embodiment of the control system according to the invention, the central control unit is further configured to receive at least one error message from at least one functional unit. In other words, the functional unit itself is configured to detect an internal fault condition, i.e., a fault in the vehicle component and / or the control unit, and to output an error message to the central control unit in response. Preferably, the central control unit is further configured to store at least one corresponding error code in a fault memory in response to receiving such an error message. Alternatively or additionally, the central control unit is configured to store an error code in the fault memory in response to the detection of a fault condition of a functional unit based on received functional data or status information.Furthermore, the central control unit is preferably configured to determine a second system software corresponding to at least one fault code. Equally preferably, a memory address corresponding to the determined system software is stored in the fault memory, or the fault code is equal to the memory address of the corresponding second system software.

[0024] Determining the second system software corresponding to at least one error code preferably occurs during the restart of the central control unit. Particularly preferably, during the boot process of the central control unit, the error memory is first accessed and the at least one error code stored therein is read. Based on the error code, the central control unit, especially by means of a bootable software element stored therein, further preferably determines which memory location of internal memory or network memory should be accessed to load or boot the second system software. Alternatively, the error memory directly contains the memory location of the second system software, so that it is loaded or booted during the boot process. When the second system software is loaded, it is completely copied to internal memory before execution.During booting, for example from network storage, the second system software stored in the network storage is executed immediately. Preferably, the second system software corresponding to at least one error code is determined during the shutdown of the central control unit. In this case, the second system software is preferably loaded and stored in internal memory, which is accessed when the central control unit starts up. Alternatively, a memory location of the determined second system software is stored in memory that is accessed during booting. Thus, the second system software can be loaded immediately during boot.

[0025] In a further preferred embodiment of the control system according to the invention, the central control unit is also configured to load the second system software from an internal memory of the control system, in particular of the central control unit. Preferably, the second system software is already stored at the factory in an internal memory of the central control unit. Thus, the first system software and at least one second system software are stored in the internal memory. In an alternatively preferred embodiment, the central control unit is configured to retrieve the second system software from a network storage device. The network address of the network storage device is preferably stored as a result of determining the second system software in a memory location that is accessed during the boot process.

[0026] In a particularly preferred embodiment of the control system according to the invention, the central control unit is further configured to update or determine the second system software depending on context-dependent information. In other words, in this embodiment, the second system software is determined not only depending on the faulty functional unit but also depending on context-dependent information. For example, the second system software is determined depending on the current driving situation. For example, if the faulty functional unit relates to an autonomous driving function of the motor vehicle, different second system software versions are determined for driving on a highway or on a rural road. For example, software elements of the second system software relating to traffic sign recognition may exhibit country-specific differences.Preferably, the second system software is determined as context-dependent information, depending on the faulty functional unit and a country code. These software elements could, for example, relate to the weighting factors of a neural network trained for traffic sign recognition. In this case, the context-dependent information can also be independent of the faulty functional unit.

[0027] According to an alternatively preferred embodiment, the second system software is determined as context-dependent information based on the current season. This is advantageous, for example, if the faulty functional unit is a climate control unit of the vehicle. Alternatively preferred, at least one second system software stored in a memory of the control system, in particular the central control unit, or in a network memory is updated based on context-dependent information. For example, in the event of a fault in a climate control unit, a second system software can exist in two different versions, one for summer and one for winter.Depending on the season, one of the two versions is then stored in the internal memory or the network storage, with the version switching occurring, for example, during a service appointment or the semi-annual tire change. Determining the second system software can therefore be carried out independently of, or decoupled from, context-dependent information.

[0028] The functionalities of the system according to the invention can be implemented by electrical or electronic components (hardware), by firmware (ASIC) and / or by executing a suitable program (software).

[0029] Preferably, the functionalities of the system according to the invention are realized or implemented by a combination of hardware, firmware and / or software. For example, individual components of the system according to the invention are designed as a separately integrated circuit for performing individual functionalities or are arranged on a common integrated circuit.

[0030] Furthermore, components designed to perform individual system functionalities are preferably arranged on a printed (flexible) circuit board (PCB), a tape carrier package (TCP), or another suitable substrate.

[0031] The individual functionalities of the control system according to the invention are further preferably designed as one or more processes that run on one or more processors in one or more electronic computing devices and are generated when one or more computer programs are executed.

[0032] The electronic computing devices are preferably designed to work together with other components, for example one or more sensors or actuators, in order to realize the functionalities described herein.

[0033] The computer programs are preferably stored in volatile memory, such as a RAM element, or in non-volatile storage media, such as a CD-ROM, flash memory, or the like.

[0034] It is also apparent to those skilled in the art that the functionalities of several computers (data processing devices, control units, control devices) can be combined or combined in a single device, or that the functionality of a particular data processing device can be distributed across a multitude of devices in order to realize the functionalities of the control system according to the invention.

[0035] A further aspect of the present invention relates to a vehicle, in particular a passenger car with an internal combustion, hybrid, or electric motor, with a control system according to the invention, as described above. The vehicle according to the invention preferably has several control systems according to the invention, each with its own central control unit. In a preferred embodiment, the central control units can be connected to a network storage device via a common network interface. The vehicle also preferably has a vehicle bus to which all control systems are connected. The vehicle also preferably has a driving system for providing at least one autonomous driving function. Such a driving system particularly preferably forms a functional unit of a control system according to the invention.

[0036] Further preferred embodiments of the invention result from the remaining features mentioned in the dependent claims. Unless otherwise specified in a particular case, the various embodiments of the invention mentioned in this application can be advantageously combined with one another.

[0037] The invention is explained below using exemplary embodiments with reference to the accompanying drawings. These show: Fig. 1 a schematic representation of a redundantly designed control unit according to the state of the art; Fig. 2 a schematic representation of a vehicle with a control system according to an embodiment in a first configuration; Fig. 3 a schematic representation of a vehicle with a control system according to one embodiment in a second configuration; Fig. 4 a schematic representation of the function of the central control unit of a control system according to the invention in a first embodiment and Fig. 5 a schematic representation of the function of the central control unit of a control system according to a second embodiment according to the invention.

[0038] Fig. Figure 1 shows a schematic representation of a redundantly designed control unit 10 or 10' of a motor vehicle according to the prior art. The control unit 10 comprises, in particular, a processor 11 and internal memory 12. The internal memory 12 contains a first system software 20, which includes an operating system and all software elements necessary for operating the first control unit 10. The first system software 20 is provided by a network server 120, in particular a network server of a manufacturer of the motor vehicle or the control unit 10, and may be updated at regular intervals in a step S200. When the control unit 10 is switched on, both for the first time and during a reboot, the processor 11 loads the first system software 20 from the internal memory 12 in a startup process S100 and executes it.

[0039] In the event of a defect in control unit 10, for example, an integrated circuit or the like, control unit 10 shuts down. Simultaneously, a redundant control unit 10' is booted, which is identical to control unit 10. The redundant control unit 10' has a processor 11' and internal memory 12'. A copy of the first system software 11' is stored in the internal memory 12'. This software is also provided by a network server 120 and has been updated if necessary. The processor 11' boots the first system software 20' from the internal memory 12' and executes it. A disadvantage of this prior art solution is that the entire control unit 10 is redundant, which increases the system complexity and the cost of the vehicle.

[0040] Fig. Figure 2 shows a schematic representation of a vehicle 200 with a control system 100 according to an embodiment of the invention. The control system 100 comprises a central control unit 50 with at least one processor 51 and at least one internal memory 52. ​​Furthermore, the central control unit 50 has read and write access to an internal fault memory 40 and communicates bidirectionally with a communication module 30. The communication module 30 is configured to communicate with a network storage device 110, in particular to send requests to it and receive data from it. The network storage device communicates with a network server 120. The central control unit 50 is connected to a vehicle bus 60 via a network interface (not shown). Preferably, the vehicle bus 60 is a CAN bus.Preferably, the vehicle bus 60 is implemented as one of the following vehicle bus types: ABUS, VAN, J1850, K-BUS, P-BUS, I-BUS, USB, P1394, or as one of the following standard computer data bus types: PCI, USB, P1394. A system software for open platforms, stored in the internal memory 52, preferably runs on the central control unit 50. During runtime, the system software is loaded into a volatile memory (not shown) and executed on the processor 51. The central control unit is also connected to a sensor 86, which communicates exclusively with the central control unit 50 and is not assigned to any functional unit 90.

[0041] The control system 100 further comprises a plurality of functional units 90a-90d of the motor vehicle 200. Functional units 90a, 90b, and 90c each have a control unit 72a, 71b, and 72c, respectively, as well as a vehicle component 82a, 81b, and 82c, and are thus designed as intelligent functional units with their own control unit. Functional unit 90d, on the other hand, only has a network interface 75d, at least one sensor 85d, and at least one actuator 86d, and is therefore designed as a non-intelligent functional unit without its own control unit. Both the at least one sensor 85d and the at least one actuator 86d are connected to the network interface 75d. The functional units are also connected to the vehicle bus 60 and, via this bus, to the central control unit.

[0042] The vehicle components 82a-c of the intelligent functional units 90a-c generally comprise a mechanical component, such as the brakes, engine, or transmission, which is controlled by an electronically controlled actuator. The control units 72a, 71b, 72c are configured to control the respective actuator and thus the respective mechanical device of the vehicle component 82a, 81b, 82c. The control units 72a, 71b, 72c are implemented as a microprocessor, digital signal processor, application-specific integrated circuit (ASIC), or the like. Furthermore, the functional units 90a-c may include sensors (not shown) for monitoring the respective mechanical devices or actuators in order to provide functional data and status information to the respective control unit 72a, 71b, 72c.This design of the motor vehicle components 82a, 81b, 82c of the intelligent functional units 90a-c is common and known in the prior art.

[0043] The non-intelligent functional unit 90d also includes a mechanical component (not shown), such as the brakes, engine, or transmission, which is controlled by the electronically controlled actuator 86d. The actuator 86d is controlled by control signals generated by the central control unit 50 and transmitted to the actuator 86d via the data bus 60 and the network interface 75d. The generation of these control signals in the central control unit depends on signals from the sensor 85d, which are transmitted to the central control unit 50 via the network interface 75d and the data bus 60. This configuration of a non-intelligent functional unit 90d is also common and known in the prior art.

[0044] Specifically, the control system has 100 of the Fig. 2 a climate function unit 90a with a climate control unit 72a and an air conditioning system 82, an infotainment function unit 90b with an infotainment control unit 71b and an audio and video playback system 81b, and an engine function unit 90c with an engine control unit 72c and an injection and ignition system 82c. The operation of this control system 100 will be described below with reference to the Fig. 2 will be briefly described.

[0045] Initially, the control system 100 operates such that the central control unit 50 coordinates the operation of the functional units 90a-d by executing initial system software. During normal operation of the control system 100, the central control unit 50 is the master of the vehicle bus 60. All other electronic components connected to the bus 60, in particular the functional units 90a-d with their subordinate control units 72a, 71, and 72c, are slaves to the central control unit 50. The central control unit 50 manages the data flow between the functional units 90a-d and enables the sharing of resources and information. For this purpose, the initial system software 21 has network management capabilities that enable the central control unit 50 to manage the data flow via the vehicle bus 60.

[0046] The central control unit 50 initializes the network communication and the functional units 90a-d. In other words, the central control unit initiates the operation of the functional units 90a-d and, in particular, transitions them from an inactive state to an active state. Furthermore, the first system software 21 can contain software elements for operating the vehicle components 82a, 81b, 82c, which are transmitted to the control units 72a, 71b, 72c after initialization. Subsequently, the data flow to the central control unit 50 with regard to the active functional units 90a-90d primarily comprises status information from the respective control units 72a, 71b, 72c, which otherwise largely autonomously control the vehicle components 82a, 81b, 82c within the framework of the first system software 21. The data flow from the functional unit 90d comprises the signals from the sensor 85d, which detects at least one physical measurement quantity important for the operation of the functional unit 90d.Based on these sensor signals, the central control unit determines 50 command signals for the actuator 86d and transmits them via vehicle bus 60 and network interface 75d.

[0047] Finally, during the operation of control system 100, the central control unit 50 detects a fault in the infotainment function unit 90b. Specifically, both the infotainment control unit 71b and the audio and video playback system 81b are defective. There is a risk that one of these defective components 71b, 81b could impair the function of other, still functional, function units 90a, 90c, 90d, for example, by outputting faulty signals to the vehicle bus 60 or similar. In response to the detection of the fault in infotainment function unit 90b, the central control unit 50 therefore writes a corresponding fault code to the fault memory 40, with the fault code indicating the defect in infotainment function unit 90b. Furthermore, the central control unit 50 queries another sensor value from sensor 86, which in this example is a GPS module.Using the GPS position, the central control unit 50 determines, in particular, a country code for the vehicle 200 and stores this in the fault memory 40 along with the already stored fault code. Finally, the central control unit 50 shuts down the control system 100 and restarts it.

[0048] Upon restarting the control system 100, in particular the central control unit 50, it first accesses a predetermined root partition. This partition instructs the central control unit 50 to read the internal fault memory 40. The program instructions stored in the root partition further cause the central control unit 50 to determine a second system software 22 based on the fault code and country code retrieved from the fault memory 40, specifically an identifier for this second system software. In the next step, the central control unit 50 checks whether a second system software with this identifier is present in the internal memory 52. ​​If so, the central control unit 50 loads the second system software 22 from the memory 52 and executes it.If a second system software with this identifier is not stored in memory 52, the central control unit requests a corresponding second system software from a network storage device 110 via the communication module 30. For this purpose, the central control unit 50 transmits the identifier to the network storage device 110 via the communication module 30 and receives the second system software 22 from it in return. As soon as the second system software is loaded, the central control unit 50 executes it. During or by executing the second system software, the control system 100 according to the invention is operated in a second configuration in which the infotainment function unit is essentially no longer part of the control system 100. A corresponding second configuration of the control system 100 is described in the [document / reference]. Fig. Figure 3 is shown. In this second configuration, the central control unit 50 continues to coordinate the operation of the remaining fault-free functional units 90a, 90c, and 90d as described above. Thus, stable continued operation of the vehicle 200 with the second system software 22 is possible.

[0049] The Fig. 4 and Fig. Figure 5 shows highly simplified schematic representations of the function of the central control unit 50 of a control system 100 according to the invention in accordance with various embodiments of the present invention.

[0050] According to the in Fig. In the embodiment shown in Figure 4, a first system software 21 and a second system software 22 are already present in the internal memory 52 of the central control unit 50. The system software 21 and 22 are updated at regular or irregular intervals in a step S200 from a network storage device 110, which is operated by a network server 120 of a vehicle manufacturer. The update S200 can be performed by default or depending on context-dependent information, as described above. According to this embodiment, the processor 51 of the central control unit 50 can thus perform a start operation S100 by simply accessing the memory 52 and thereby booting and executing the first system software 21. In the event that a faulty functional unit is detected, as described above with reference to the Fig. As described in section 2, the processor can also perform a restart operation S150 by simply accessing the internal memory 52 and thereby booting and executing the second system software 22. According to the Fig. In the embodiment shown in Figure 5, only a first system software 21 is present in the internal memory 52 of the central control unit 50. Thus, the processor 51 of the central control unit 50 can perform a start operation S100 by simply accessing the internal memory 52 and thereby booting and executing the first system software 21, but if a faulty functional unit is detected, as described above with reference to the Fig. As described in section 2, the central control unit 50 must boot a second system software 22 from a network storage device 110 during a restart process S150. This has the advantage of saving storage space in the central control unit 50, thus reducing installation space and costs. Reference symbol list 10 (redundant) control units (state of the art) 11 (redundant) processors (state of the art) 12 (redundant) storage units (state of the art) 20 (redundant) system software 21 first system software 22 second system software 30 Communication module 40 fault memory 50 Central control unit 51 processor 52 GB internal storage 60 vehicle buses 70 Control unit 71 faulty control unit 72 error-free control units 75 Network interface 80 vehicle components 81 faulty vehicle components 82 faultless vehicle components 85 Sensor 86 Actuator 90 functional unit 91 faulty functional unit 92 fault-free functional units 100 control system 110 network storage 120 network servers 200 vehicles S100 startup process S150 restart process S200 Update

Citation Information

Patent Citations

  • Method and device for handling safety-critical errors

    DE102015003194A1

  • fail-safe monitoring system and suitable method in an integrated vehicle control

    DE60219705T2

  • fault-tolerant AUTOMOTIVE CONTROL SYSTEM

    DE69737308T2

  • An emergency handling system for an autonomous driving vehicle (ADV)

    EP3323687A1