Fail-silent vehicle ECU with maintenance of Ethernet on-board communication
The control unit design maintains Ethernet network integrity by stopping synchronization signals to the safety microcontroller and Ethernet switch upon fault detection, ensuring continuous communication with other microcontrollers, addressing the disruption caused by safety microcontroller failures.
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- BAYERISCHE MOTOREN WERKE AG
- Filing Date
- 2024-11-12
- Publication Date
- 2026-05-13
AI Technical Summary
Existing vehicle Ethernet networks fail to maintain communication functionality when a fault is detected in a safety microcontroller, leading to disruption of the entire network and loss of communication between control units, even if other microcontrollers are functioning.
A control unit design that includes a switching module to stop synchronization signals to the safety microcontroller and Ethernet switch upon fault detection, while maintaining power supply to the Ethernet switch, ensuring communication continuity with other microcontrollers.
Preserves Ethernet network functionality and communication between control units, even when a safety microcontroller fails, by preventing power disconnection of the Ethernet switch, thus achieving a 'fail-silent' state.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The invention relates to a control unit for a vehicle, a vehicle with at least one such control unit, and a method for operating a control unit of a vehicle.
[0002] Motor vehicles, such as passenger cars, typically incorporate a large number of sensors and actuators. The latter are often intended for numerous subsystems within such a vehicle, and the sensors are also conveniently distributed throughout the vehicle. Therefore, sensors, actuators, and their associated control units must be connected via a network within the vehicle. It is known from the prior art to use an Ethernet network to connect a large number of control units. One possibility is that each control unit includes one or more microcontrollers and its own Ethernet switch as a communication interface to the Ethernet network.
[0003] In this context, WO 2021 / 068067 A1, for example, shows a redundant Ethernet network system for a vehicle, comprising a first node connected to a first sensor and a second node connected to a second sensor. A first Ethernet cable is connected between the first and second nodes, a second Ethernet cable is connected between the first node and an electronic control unit (ECU), and a third Ethernet cable is connected between the second node and the ECU. Data from the first and second sensors are transmitted over the Ethernet network to reach the ECU. The data from these sensors is also compared and processed locally at the first and second nodes to improve reliability and reduce the processing load on the ECU.
[0004] Furthermore, CN 115042729 A discloses a vehicle control unit (“Electronic Control Unit”, abbreviated ‘ECU’) sleep system based on a vehicle Ethernet and a shutdown method thereof, wherein the system comprises a central gateway module, a vehicle body control unit, a vehicle entertainment module and an automatic driving module, wherein a 1000BASE-T1 interface between the modules is assumed to perform a signal connection of a PHY sleep signal (physical layer) and an optical module.Furthermore, the lower power consumption of the equipment in the vehicle control unit's sleep system is limited; firstly, an Ethernet link partner sends a power saving command LPS (Low Power Protocol) to the device, and after the command data has been confirmed, a sleep handshake is initiated, thus realizing the comprehensive and integral automatic shutdown process to reduce power consumption and extend the device's lifespan.
[0005] Furthermore, EP 3 385 728 A1 discloses an electronic control system for vehicle safety with regard to safety and fault detection. It describes the importance of detecting deviations in the performance of processors within an electronic control system for vehicle safety. The electronic control system for vehicle safety consists of a processor with a processor clock and a reference clock source. It also includes a test device configured to calculate the difference between a test count and a reference count. The values for the reference count and the test count depend on the processor clock source and the processor clock source, respectively.
[0006] CN 118300813 A also relates to a vehicle-mounted Ethernet communication method, a control unit, an electronic device and a storage medium belonging to the technical field of communication security, wherein the method comprises the following steps: receiving the message content from a communication control unit; assessing the security level of the message content to obtain a security level result for the message content; if the security level result is the first or second security level, retrieving a destination authentication key and a destination encryption key and performing security authentication for the message content based on the destination authentication key;If the security authentication of the message content is successful, the communication ciphertext within the message content is decrypted based on the target encryption key to obtain the communication data transmitted by the communication control unit. The vehicle-mounted Ethernet communication method ensures the authenticity of the message content, prevents the message content from being transmitted in plaintext only, and can effectively prevent malicious attackers from stealing the message content to be encrypted, thereby improving the security of vehicle-mounted Ethernet communication.
[0007] Given the current state of the art, it is logical to cut off the power supply to the Ethernet switch of a vehicle's control unit (ECU) when a fault is detected in its safety microcontroller, as a failsafe measure. This prevents the ECU from transmitting data to the rest of the Ethernet network. However, if the ECU contains other microcontrollers besides the safety microcontroller, these will also be unable to access the Ethernet network and communicate with other control units in the vehicle due to the lack of power to the ECU's Ethernet switch, even if they are otherwise unaffected by the detected fault in the safety microcontroller and are still functioning. This also applies to temporary deactivations of the Ethernet switch, for example, for a restart or reset.The functionality of the entire Ethernet network in the vehicle is disabled by such a shutdown, and all other control units on the Ethernet network lose the ability to communicate with each other due to the single deactivated Ethernet switch. If, for example, another control unit is connected to the Ethernet network, which controls a screen based on data from one or more other control units, then the interference with the Ethernet network caused by switching off the Ethernet switch of the affected control unit will result in this screen displaying no image or a standardized emergency image. This is undesirable for the vehicle's occupants.
[0008] The object of the invention is to prevent this undesirable behavior and to find an alternative method for shutting down the power supply of the Ethernet switch of a control unit in whose safety microcontroller a fault has been detected.
[0009] The invention is defined by the features of the independent claims. Advantageous further developments and embodiments are the subject of the dependent claims.
[0010] A first aspect of the invention relates to a control unit for a vehicle, comprising a switching module, a safety microcontroller, an Ethernet switch, and an oscillator connected to the safety microcontroller and the Ethernet switch, the oscillator being configured to transmit a synchronization signal to the safety microcontroller and the Ethernet switch for communication between the safety microcontroller and the Ethernet switch, characterized in that the switching module is configured to switch off the synchronization signal or stop its transmission to the safety microcontroller and / or the Ethernet switch upon detection of a fault in the safety microcontroller, in each case without interrupting the power supply to the Ethernet switch.
[0011] The malfunction is specifically a safety-critical fault. The safety microcontroller can be a microcontroller or microprocessor. Alternatively, another microcontroller within the control unit can be implemented as a microprocessor. The safety microcontroller is a microcontroller or microprocessor that is safety-critical; that is, in particular, it is configured to perform at least one safety-critical function.
[0012] It is therefore advantageously planned that, upon detection of a fault in the safety microcontroller, the oscillator should be switched off, or at least the synchronization signal still generated by the oscillator should no longer be transmitted to the Ethernet switch or the safety microcontroller, preferably not to both the Ethernet switch and the safety microcontroller, rather than cutting off the power supply to the control unit's Ethernet switch. The technical effect of this is to prevent regular communication between the safety microcontroller and the Ethernet switch, regardless of whether the oscillator is completely switched off or the signal still generated by the oscillator is no longer transmitted to the Ethernet switch and the safety microcontroller, or at least to one of them.The oscillator essentially serves as a serial interface, specifically RGMII, SGMII, or HSGMII, to generate a synchronization signal, also known as a "clock," enabling synchronization of data communication between the safety microcontroller and the Ethernet switch. By manipulating the synchronization signal as described above, a fail-silent safety functionality of the safety microcontroller is achieved if it is affected by a safety-related fault. Therefore, it is advantageous not to design the entire control unit to be fail-safe.
[0013] By maintaining the power supply to the ECU's Ethernet switch, even when a fault is detected in the ECU's safety microcontroller, the Ethernet switch remains functional and the ECU remains part of the vehicle's Ethernet network. Maintaining the Ethernet switch's functionality allows the ECU with the faulty safety microcontroller to communicate with at least one other ECU module in the vehicle's Ethernet network, preferably all other ECU modules in the network, thus preserving the Ethernet network's functionality. The safety microcontroller still fulfills its fail-silent safety functionality.
[0014] The ECU's ability to communicate, even when a fault is detected in the safety microcontroller, is crucial because the Ethernet architecture relies on the communication capability of all network components. In contrast, with alternative network architectures, such as CAN, disabling an ECU's communication interface would not have such negative effects; instead, the ECU would simply be removed from the network as a component. By maintaining the functionality of the ECU's Ethernet switch, the safety microcontroller, where a fault is detected, remains operational. As described above, this ensures the ECU's communication capability and the functionality of the Ethernet network are preserved. Such a fault is typically an E / E fault, meaning an electrical and / or electronic fault.
[0015] By maintaining its power supply, the Ethernet switch allows other microcontrollers integrated into the control unit to communicate with other vehicle control unit (ECU) modules via the Ethernet network. However, communication between the Ethernet switch and the safety microcontroller ceases because the absence of the oscillator synchronization signal at the safety microcontroller and / or the Ethernet switch disrupts the basic functionality of communication between them.
[0016] The Ethernet switch serves as a communication interface between the control unit and the wider Ethernet network in a vehicle. To this end, it receives communication packets from the safety microcontroller and, if applicable, one or more other integrated microcontrollers of the control unit, and forwards these packets to the wider Ethernet network. It also receives communication packets from this Ethernet network and forwards them to the safety microcontroller and, if applicable, to other integrated microcontrollers of the control unit.
[0017] The security microcontroller, and, if applicable, other integrated microcontrollers in the vehicle's control unit, are preferably implemented as system-on-a-chip (SoC) systems. The security microcontroller, optionally at least one other integrated microcontroller, as well as the oscillator and the Ethernet switch are components of the control unit. Several such control units can be provided as ECUs in a vehicle, whereby not necessarily every one of these control units, but at least one, such as the one described above and below, also includes a security microcontroller.
[0018] The oscillator enables communication between the security microcontroller and the Ethernet switch, using a synchronization signal generated by the oscillator. Therefore, the oscillator is also referred to as an "oscillator clock" and preferably functions as an RGMII clock. The RGMII interface specifically uses four-bit wide transmit and receive data paths, each with its own source-synchronous clock. However, an HSGMII or SGMII clock can also be used.
[0019] The switching module can be physically and / or software-wise separated from the safety microcontroller, the Ethernet switch, and the oscillator, forming a standalone module. In an alternative embodiment, however, the switching module is integrated into another module of the control unit and thus provided as an additional function of an existing physical module. In particular, the switching module can be a safety watchdog or a functional safety PMIC (PMIC stands for "Power Management Integrated Circuit"). Such a functional safety PMIC is connected to the safety microcontroller, specifically via a power supply rail and a communication rail.Upon detection of a fault by the safety microcontroller, the functional safety PMIC issues a command to the oscillator to stop or cease transmitting the synchronization signal, preferably via an RGMII clock shut-down signal (RGMII is an abbreviation for "Reduced Gigabit Media-Independent Interface"). This silences the RGMII Ethernet connection from the safety microcontroller to the Ethernet switch of the control unit, also known as the ECU.
[0020] A key advantage of the invention is that the functional safety objectives of a motor vehicle's Ethernet network—namely, safety and availability—are maintained to the greatest extent possible, particularly with regard to an Ethernet switch of a control unit containing a safety microcontroller, even if a fault is detected in the safety microcontroller. This is achieved primarily by not disconnecting the Ethernet switch from its power supply, thus preventing it from remaining active and maintaining the integrity of the Ethernet network. Instead, only communication with the safety microcontroller is blocked, thereby ensuring a safe state for the control unit, as a so-called "fail-silent" state is achieved.As described, however, the functionality of the control unit's Ethernet switch is retained, thus ensuring that further communication between the control unit's microcontrollers (in the sense of an ECU) and other control unit modules (also in the sense of ECUs) of the Ethernet network is not affected.
[0021] According to an advantageous embodiment, the control unit has at least one further integrated microcontroller that is connected to the control unit's Ethernet switch. In one embodiment, two further integrated microcontrollers are provided in the control unit, each of which is connected to the Ethernet switch in order to communicate via the vehicle's Ethernet network, in particular with other control unit modules, and especially preferably with further microcontrollers in the other control unit modules.
[0022] According to another advantageous embodiment, the security microcontroller is implemented as a system-on-a-chip. A system-on-a-chip configuration is also abbreviated as "SoC".
[0023] According to another advantageous embodiment, the switching module is a Power Management Integrated Circuit. A Power Management Integrated Circuit is typically also abbreviated as "PMIC".
[0024] According to another advantageous embodiment, the switching module is connected to the safety microcontroller via a power supply rail and a data rail.
[0025] Another aspect of the invention relates to a vehicle with at least one control unit as described above and below.
[0026] Advantages and preferred further developments of the proposed vehicle result from an analogous and meaningful transfer of the above statements made in connection with the proposed control unit.
[0027] According to another advantageous embodiment, the vehicle has additional control unit modules that are connected to the control unit via an Ethernet network.
[0028] Another aspect of the invention relates to a method for operating a vehicle control unit, wherein an oscillator connected to an Ethernet switch and a security microcontroller of the control unit transmits a synchronization signal to the security microcontroller and the Ethernet switch for communication between the security microcontroller and the Ethernet switch, and a switching module switches off the synchronization signal and / or stops its transmission to the security microcontroller and / or to the Ethernet switch upon detection of a fault in the security microcontroller, without interrupting the power supply to the Ethernet switch.
[0029] Advantages and preferred further developments of the proposed procedure result from an analogous and substantive transfer of the above statements made in connection with the proposed control unit.
[0030] Further advantages, features and details will become apparent from the following description, in which - possibly with reference to the drawing - at least one embodiment is described in detail.
[0031] They show: Fig. 1: A control unit for a vehicle according to an embodiment of the invention. Fig. 2: A vehicle with a control unit and further control unit modules according to a further embodiment of the invention. Fig. 3: A method for operating a control unit of a vehicle according to an embodiment of the invention.
[0032] The representations in the figures are schematic and not to scale.
[0033] Fig. Figure 1 schematically shows a control unit 1 for a vehicle 2. The control unit 1 has two integrated microcontrollers 7, as well as a safety microcontroller 4. Both the two microcontrollers 7 and the safety microcontroller 4 are connected to an Ethernet switch 5 and are each implemented as a SoC, i.e., system-on-a-chip. The Ethernet switch 5 allows the microcontrollers 7 and the safety microcontroller 4 to connect to an Ethernet network of a vehicle 2 (see Figure 1). Fig. 2) To transmit data and receive data from this Ethernet network. The safety microcontroller 4 is configured as the safety master of the control unit 1. All microcontrollers, both the two integrated microcontrollers 7 and the safety microcontroller 4, can be configured as microcontrollers or microprocessors. For simplicity, a respective data bus connection to the wider Ethernet network of the vehicle 2 and the control unit 1 is shown in the Fig. 1 shown as an open interface pointing downwards; the data bus channels emanating from the Ethernet switch 5 serve in particular to communicate with other Ethernet switches of other control unit modules 8 of the vehicle 2 (see Fig. 2) to communicate. The control unit 1 is thus a network component in an Ethernet network of the vehicle 2. Furthermore, the control unit 1 has a switching module 3, which is connected to the safety microcontroller 4 via a power supply rail and a communication rail. The switching module 3 is a PMIC, i.e.A power management IC (short for "Integrated Circuit") leads via a safe-state (SS1) GPIO (short for "General-purpose input / output") to oscillator 6, a clock oscillator which, upon receiving a corresponding command from the switching module 3, causes an RGMII clock shutdown, thereby stopping the regular communication between the safety microcontroller 4 and the Ethernet switch 5, while by maintaining the power supply to the Ethernet switch 5, the two integrated microcontrollers 7 can continue to exchange data with the Ethernet network of the vehicle 2, since the Ethernet switch 5 can continue to function perfectly for the data of these two microcontrollers 7.
[0034] Fig. Figure 2 shows an example vehicle 2 with a control unit 1 (an ECU), as shown below. Fig. 1 described. Furthermore, the vehicle has 2 additional control unit modules 8 (additional ECUs) which are connected to the vehicle 2 via an Ethernet network as described below. Fig. The control unit 1 described in section 1 is connected to these additional control unit modules 8 of the vehicle 2. These additional control unit modules 8 themselves contain their own Ethernet switches and SoCs, for example, to transmit display data to a screen in the interior of the vehicle 2. If the Ethernet switch 5 of the control unit 1 were to be rendered inoperative, at least temporarily, by a reset or complete power interruption, such a screen would, in the event of a fault detection by the switching module 3 on the safety microcontroller 4, display a black screen or, if so designed, switch to an emergency signal.However, by keeping the Ethernet switch 5 of the control unit 1 functional even in such a case, the integrity of the entire Ethernet network of the vehicle 2 can be maintained and, for example, the other microcontrollers 7 of the control unit 1 can transmit data to the screen, which can therefore continue to output meaningful information to an occupant of the vehicle 2 even in the event of such a fault detection.
[0035] Fig.Figure 3 shows a method for operating a control unit 1 of a vehicle 2, wherein an oscillator 6, connected to an Ethernet switch 5 and a safety microcontroller 4 of the control unit 1, transmits a synchronization signal to the safety microcontroller 4 and the Ethernet switch 5 S1 for communication between the safety microcontroller 4 and the Ethernet switch 5, and a switching module 3, upon detection S2 of a fault on the safety microcontroller 4, switches off the synchronization signal and / or stops its transmission to the safety microcontroller 4 and / or the Ethernet switch 5 S3, without interrupting the power supply of the Ethernet switch 5.
[0036] Although the invention has been further illustrated and explained in detail by means of preferred embodiments, the invention is not limited by the disclosed examples, and other variations can be derived from them by a person skilled in the art without departing from the scope of protection of the invention. It is therefore clear that a multitude of possible variations exist. It is also clear that the embodiments mentioned as examples are truly only examples and are not to be understood in any way as limiting, for example, the scope of protection, the possible applications, or the configuration of the invention. Reference symbol list 1 control unit 2 vehicles 3 Switching module 4 safety microcontrollers 5 Ethernet Switch 6 Oscillator 7 more microcontrollers 8 additional control unit modules QUOTES INCLUDED IN THE DESCRIPTION
[0000] This list of documents cited by the applicant was automatically generated and is included solely for the reader's convenience. The list is not part of the German patent or utility model application. The DPMA accepts no liability for any errors or omissions. Cited patent literature
[0000] WO 2021 / 068067 A1
[0003] CN 115042729 A
[0004] EP 3 385 728 A1
[0005] CN 118300813 A
[0006]
Claims
Control unit (1) for a vehicle (2), comprising a switching module (3), a safety microcontroller (4), an Ethernet switch (5), and an oscillator (6) connected to the safety microcontroller (4) and the Ethernet switch (5), which is configured to transmit a synchronization signal to the safety microcontroller (4) and the Ethernet switch (5) for communication between the safety microcontroller (4) and the Ethernet switch (5), characterized in that the switching module (3) is configured to switch off the synchronization signal or to stop its transmission to the safety microcontroller (4) and / or to the Ethernet switch (5) upon detection of a fault in the safety microcontroller (4), in each case without interrupting the power supply to the Ethernet switch (5). Control unit (1) according to claim 1, wherein the control unit (1) has at least one further integrated microcontroller (7) which is connected to the Ethernet switch (5) of the control unit (1). Control unit (1) according to one of the preceding claims, wherein the security microcontroller (4) is designed as a system-on-a-chip. Control unit (1) according to one of the preceding claims, wherein the switching module (3) is a Power Management Integrated Circuit. Control unit according to one of the preceding claims, wherein the switching module (3) is connected to the safety microcontroller (4) via a power supply rail and a data rail. Vehicle (2) with at least one control unit (1) according to one of the preceding claims. Vehicle (2) according to claim 6, wherein the vehicle (2) has further control unit modules (8) which are connected to the control unit (1) via an Ethernet network. Method for operating a control unit (1) of a vehicle (2), wherein an oscillator (6) connected to an Ethernet switch (5) and a security microcontroller (4) of the control unit (1) transmits a synchronization signal to the security microcontroller (4) and the Ethernet switch (5) for communication between the security microcontroller (4) and the Ethernet switch (5) (S1), and a switching module (3) switches off the synchronization signal and / or stops its transmission to the security microcontroller (4) and / or to the Ethernet switch (5) upon detection (S2) of a fault in the security microcontroller (4) (S3), without interrupting the power supply to the Ethernet switch (5).