Event data acquisition system
Patent Information
- Application Number
- DE102023213336
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-28
- Publication Date
- 2025-07-03
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The present invention relates to an event data acquisition system. The event data acquisition system comprises a ring buffer-type memory. State of the art
[0002] Modern vehicle control units are complex, interconnected systems. While considerable effort is put into developing such systems to high quality standards, failures are inevitable. This requires data collection in the event of something going wrong, so that all necessary information is available for analysis and product improvement. In some cases, such event data acquisition systems are required by law or automotive standards.
[0003] Event data acquisition systems in the automotive sector are typically characterized by the following features: These systems are typically developed with low per-unit hardware costs as the dominant design driver. As a result, the physical storage medium used to store the data is chosen primarily for its low price point, which implies limited hardware characteristics of the storage medium, particularly in terms of robustness and resiliency. The required robustness must then be built into the software.
[0004] Event data acquisition systems typically append new event data to the end, store a series of older records, and eventually overwrite or even delete older, outdated data. This results in a circular buffer-like write pattern. Updates to previously written data, however, are not a typical data change scenario.
[0005] Depending on the application, several of these “ring buffers” can be kept in parallel for different types of data, different storage intervals, etc.
[0006] A challenge associated with event data acquisition systems is to provide other software layers in a software system in which such an event data acquisition system is implemented with a storage model that allows keeping multiple ring buffers robust and fail-safe despite the intrinsically unreliable physical storage medium.
[0007] The following requirements are placed on an event data acquisition system according to the present invention: 1. The system automatically allocates storage space for new records that are appended to a ring buffer. 2. The system automatically frees up the storage space occupied by outdated, no longer needed (also called invisible) records. 3. The system never returns corrupted data. If the data stored on the physical storage device is actually corrupted, the system will detect and report the data corruption. 4. The system never writes data to the physical storage medium without first erasing the block to which the data is to be written (i.e., no overwriting occurs). This includes the case of failed erase operations due to a power failure, which must be repeated. Disclosure of the invention
[0008] Against this background, the present invention proposes an event data acquisition system to which a memory area of a physical storage medium is assigned, which is addressed in the memory model of a ring buffer.
[0009] The ring buffer consists of adjacent blocks of the memory area of the physical storage medium and the ring buffer is assigned a logical start and a logical end in the blocks of the memory area.
[0010] New records are appended to the logical end of the ring buffer.
[0011] A data record is stored in exactly one block of the physical storage medium. Multiple data records can be stored in the same block of a circular buffer.
[0012] A block of a circular buffer is divided into a number of "slots." All slots in a circular buffer are the same size.
[0013] The size is preferably the maximum permissible size of a data record in this ring buffer. If more than one ring buffer is used in the event data acquisition system, the slots in each ring buffer can have different sizes. There may be unused memory at the end of a block if the block size is not a multiple of the slot size.
[0014] Each data record contains a header. The header contains a CRC value that the system uses to detect a corrupted data record.
[0015] The system maintains a log of state changes for each ring buffer. This log ensures that the logical beginning and end of each ring buffer can be restored even in the event of a power failure.
[0016] Another aspect of the present invention is an electronic control unit comprising an event data acquisition system according to the present invention.
[0017] Embodiments of the invention are explained in more detail below with reference to the accompanying drawings. In the drawings: Fig. 1 a block diagram of a vehicle control unit; Fig. 2 a schematic representation of a memory model of a ring buffer; Fig. 3 schematic representations of data sets; Fig. 4 a schematic representation of a physical memory model; Fig. 5 a schematic representation of a part of the data set.
[0018] Fig. 1 shows a block diagram of a vehicle control unit 10.
[0019] The block diagram shows only a part of the typical components of a vehicle control unit 10.
[0020] The diagram shows a physical storage medium 11 on which the data structure according to the present invention can be stored. The physical storage medium 11 can be a storage medium 11 using flash memory technology, e.g., a NOR flash storage medium.
[0021] The storage medium 11 is connected to a computing unit 12 which is suitable, for example, for carrying out the methods according to the present invention.
[0022] The physical storage medium 11 can be organized into fixed-size blocks. The block size can be, for example, 4 KB.
[0023] The physical storage medium 11 can be configured such that it can only be erased block by block. Erasing block by block can result in all bytes of the block being assigned a value that represents the "erased" state. Such a value can be 255 or 0xFF.
[0024] The physical storage medium 11 can be written to byte by byte. A write operation only sets the desired bits from 1 to 0. The 1 bits in the data to be written are already 1 from the last erasure. Resetting a bit from 0 to 1 is only possible by erasing the entire block.
[0025] The order of changes to a given byte must be strictly delete -> write -> delete. Adding additional 0 bits to a byte, i.e., first writing 0xFE and then writing 0xFC to the same location, is not allowed without first erasing the entire block.
[0026] The physical storage medium 11 can be read byte by byte.
[0027] A write or delete operation may fail. It cannot be assumed that the state of the affected bytes or block will actually be as expected after such an operation.
[0028] In particular, the power supply may fail, and a write or erase operation may only be partially completed. Furthermore, it is unpredictable whether a particular operation will fail or succeed (even under certain conditions). Therefore, every write or erase operation must be considered potentially failing.
[0029] Failed write or delete operations can leave the bytes that were the subject of the operation in an undefined and unstable state. Bytes that were not the subject of the operation are unaffected.
[0030] The only way to determine whether a write or erase operation to the physical storage medium was successful or not is to check the return status of the physical storage medium after the operation is complete. Write or erase operations with an unknown return status must be considered failed. In particular, there is no reliable way to determine whether a write operation was successful or not by reading back the written bytes and comparing them to the original source. Likewise, there is no reliable way to determine whether a block was successfully erased or not by comparing its contents to 0xFF.
[0031] With a storage medium 11 as shown above, erasure operations are slow. For example, an erasure operation may take 0.2 seconds. This means that the erasure of a block is likely to be interrupted by a power failure.
[0032] The computing unit 12 also has access to a working memory 13 in which process-specific data is stored. In the illustration, the computing unit 11 and the working memory 13 are shown as separate blocks. It is conceivable that the working memory 13 is integrated into the computing unit 12. Not all data stored in the working memory is also stored in the data structure 11 and would initially be lost in the event of a power failure of the control unit 10. All relevant data for resuming the process according to the present invention can be restored from the data stored in the storage medium 11.
[0033] Fig. Figure 2 shows a schematic representation of a memory model of a ring buffer for use in an event data acquisition system according to the present invention.
[0034] The Fig. 2 shows three ring buffers, each containing 3, 4, and 9 data records. Fig. 2 represents a point in time at which a data record 10 is appended to ring buffer 0. As soon as data record 10 has been appended to ring buffer 00, data record 7 is hidden, i.e. a request to read data record 7 will not return the contents of data record 7.
[0035] Fig. Figure 3 shows two schematic representations of two data records, Data Record 0 and Data Record 1, from the same circular buffer. Since they belong to the same circular buffer, the two data records have the same maximum size. However, in the illustrated state, their actual size differs because the currently contained data records are of different sizes.
[0036] In Fig. 2 and Fig. 3 shows a memory model for a set of ring buffers that exhibit the following behavior: 1. A circular buffer contains a fixed number of records. The maximum number of records in a circular buffer is called the history length. 2. A record contains one or more record parts. A record part is assigned a record part type and a number of content sizes. 3. Within each ring buffer, each record has the same maximum size. This size is called the record size. Furthermore, each record in the same ring buffer has the same maximum number of record parts. 4. Registered records are never modified. However, the record parts of a record can arrive at different times. New record parts can be appended to a record as long as the maximum number of record parts is not exceeded. New record parts may only be appended to the most recent record in the ring buffer. This means that new record parts can be appended to multiple records simultaneously, as long as the records are assigned to different ring buffers. 5. Read requests to a particular circular buffer only return records up to the record length, even if more records are actually stored on the physical storage device. The records that can be returned by a read request to a circular buffer are called the "visible" records of the circular buffer. 6. When a new record is appended to a ring buffer, the record becomes "visible" in that ring buffer. If the ring buffer contained visible records equal to the record length before the new record was written, the oldest visible record in the ring buffer (in the order of writing) becomes invisible. If the ring buffer contained fewer records than the record length before the new record was written, the previously visible records remain, and the new record also becomes visible. 7. The event data acquisition system guarantees, even during power outages, that if a record part has been appended to a record in a circular buffer, the record part can either be read at a later time (before it becomes invisible) or the system detects that the record part is corrupted. In other words, the system guarantees that no invalid data will be read or output. Data loss is permitted in an error situation as long as the system detects the data loss. 8. Individual records cannot be explicitly deleted. They only become invisible when new records are appended to the same ring buffer. However, the system allows you to delete all records in all ring buffers.
[0037] In order to obtain the behavior of the event data acquisition system and the ring buffers used therein described above, a detailed description of the structure and function is given below.
[0038] The invention is therefore based on the following principles to address the challenges described above: 1. Each ring buffer is assigned a dedicated set of adjacent blocks of the physical storage medium used in the ring buffer model. Thus, each ring buffer of the logical storage model is assigned to a physically contiguous storage area with a logical beginning and a logical end. New records are appended to the logical end. The logical beginning and the logical end are mapped to a physical storage location within the ring buffer blocks. 2. A data record is stored in exactly one block of the physical storage medium. Multiple data records can be stored in the same block of a circular buffer. A data record is never stored across multiple physical blocks. 3. A block of a circular buffer is divided into a number of "slots." All slots in a circular buffer have the same size, which is the maximum allowable size of a record in that circular buffer. There may be unused memory at the end of a block if the block size is not a multiple of the slot size. 4. Each data record section is preceded by a header. The header contains a CRC that the system uses to detect a corrupted data record section. 5. The system maintains a log of state changes for all ring buffers. This log ensures that the logical beginning and end of each ring buffer can be restored in the event of a power failure.
[0039] Fig. Figure 4 shows a schematic representation of the physical memory model used to store the data records of the logical memory model described above. As described above, the data records of a circular buffer are stored in the blocks of the circular buffer in the order in which they arrive. This results in an array-like structure at the data record level. The most recent data record marks the logical end, while the oldest data record that has not yet been deleted or hidden marks the logical beginning.
[0040] The data record parts of a data record are stored in the slots of the respective block in the order in which they are stored.
[0041] In Fig. 3, it has already been shown that the data set parts can vary in size, and not every data set can have the same number of data set parts, even within the same circular buffer. Therefore, it is very likely that there will be unused space after the last written slot in the block occupied by a data set.
[0042] The following describes in detail methods that can be performed in an event data acquisition system according to the present invention.
[0043] To save a new data record or part of a data record into the ring buffer of the event data acquisition system, proceed as follows:
[0044] First, the logical end of the ring buffer intended for the data record or data record part is shifted one slot forward. If the block with the current logical end no longer has any free slots, the logical end is shifted to the first slot of the next block. If the current logical end already pointed to the last slot of the last block of the ring buffer, the logical end is shifted to the first slot of the first block of the ring buffer. Once the new logical end of the ring buffer is determined, the first data record part of the new data record is written to the just assigned slot.
[0045] Each time a new data record or part of a data record is to be written to the ring buffer, the maximum possible amount of memory that a data record can have for the respective ring buffer is reserved (allocated). This is ensured by the size of the ring buffer slot.
[0046] Therefore, no additional memory space needs to be reserved for writing the remaining data segments of a data record. The currently used number of bytes in the current slot is kept in main memory. The next data segment is appended after these bytes.
[0047] Moving the logical end to the next slot changes the state of the circular buffer. Such a state change is made persistent in the event data acquisition system log.
[0048] Whenever the logical end of a circular buffer is moved to a new block, the system must ensure that the current block and the block behind the current block (or the first block if the current block is the last block of the circular buffer) are erased.
[0049] A block can be deleted if it contains only invisible records, such as in Fig. 4. Such blocks are referred to as obsolete.
[0050] Data record sections that contain invalid data must be detectable. This can be achieved by prepending a CRC of the data record content as a data part header. Since the data content can be of variable length, the system also stores the data length in the data part header so that it is known how many data bytes are to be considered when calculating and comparing the CRC for a read request. The CRC and the length can also be corrupted. A corrupted CRC will most likely not match, but a corrupted length can cause serious problems. For this reason, a second CRC is used to cover the data content of the data part header. This is shown schematically in Fig. 5 shown.
[0051] Each record part also has a record part data type that specifies the semantics of the record part. The record part data type is also stored in the record part header.
[0052] When a record part is appended to a record, the record part data type, the data length, and the CRC of the data content of the record part header are first serialized in main memory. The header CRC is calculated in this ring buffer. Only then are the header CRC, the header content (including the record part data type, data content length, and data content CRC), and the data part content written to the physical storage medium.
[0053] When a data record part is read from the physical storage medium, the system first reads the data record part data header and checks whether the data header CRC is valid. If the CRC is invalid, the data record part is considered invalid and it is assumed that the respective data record does not contain any further data record parts. If the CRC is valid, the CRC data content is evaluated on as many bytes after the CRC data content as specified in the data record part data type. If the CRC data content does not match, the data record part is considered invalid and the next data record part of the data record is checked. If the CRC data content is valid, the data content of the data record part is processed.
[0054] Each physical storage medium used to store a logical ring buffer has a state that contains the logical beginning and end. If this information is lost or misinterpreted, data is lost, new data is written over old data without intermediate deletion, and obsolete (invisible) data is assumed to be visible and read. To prevent this, every state change of a ring buffer is logged. The following sequence is essential: 1. First record, then write 2. First delete, then log
[0055] Whenever a new slot is reserved for writing a record, the state is first updated and then logged.
[0056] If no data can be written to the new slot, it contains invalid data and its CRC doesn't match. But under no circumstances can the next record be written to the same slot (without first erasing the block).
[0057] When a block in a ring buffer is deleted, the status is only updated and logged after the deletion is successful. If the deletion is unsuccessful, the ring buffer remains in its previous state, in which the corresponding block has not yet been deleted. The system will attempt to delete the block again later.
[0058] After a system crash, the state of all records is initialized to the most recent data in the log. This means that when the system starts, it first reads the log in reverse order from the end. The last log entry found for a given circular buffer is used to initialize the state of the circular buffer.
Claims
[1] Event data acquisition system, wherein a memory area of a physical storage medium is assigned to the event data acquisition system, wherein the memory area is addressed in the memory model of a ring buffer, wherein the assigned memory area comprises a plurality of adjacent blocks of the physical storage medium, wherein a logical start of the ring buffer and a logical end of the ring buffer are each assigned a block. [2] The event data acquisition system of claim 1, wherein the event data acquisition system is configured such that a data record is associated with exactly one of the blocks. [3] An event data acquisition system according to claim 1 or 2, wherein each block is divided into a number of slots, each slot of a block having a predetermined size. [4] Event data acquisition system according to one of the preceding claims, wherein a protocol is assigned to the event data acquisition system, wherein the protocol is designed such that it records state changes of the event data acquisition system, in particular state changes concerning the logical start and the logical end of the ring buffer. [5] Electronic control unit comprising an event data acquisition system according to any one of the preceding claims.