REMOTE RESET
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- INFINEON TECHNOLOGIES AG
- Filing Date
- 2024-12-19
- Publication Date
- 2026-06-25
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
TECHNICAL AREA The present disclosure relates to an electronic control unit, a method for triggering a reset, a control system and a use thereof. BACKGROUND Control systems, such as those used in automotive applications, typically comprise a multitude of distributed controllers. For example, in an automotive application, numerous different controllers may be distributed throughout a vehicle. These controllers may, at least partially, control different applications, such as different engines within the vehicle. Furthermore, the controllers may exhibit different hierarchies. For instance, a vehicle may be controlled by a higher-level controller, such as a central controller, or by multiple zone controllers, which in turn may control different application controllers for different applications within the vehicle. For safety-critical applications, the application controllers may each have local monitoring functions to meet a corresponding safety integrity level. This typically increases complexity and, consequently, cost. SUMMARY The first aspect introduces an electronic control unit. This unit comprises an electronic device, an application controller, and a safety node. The application controller is configured to control the electronic device. The safety node monitors input signals sent to the electronic control unit from a higher-level controller. Furthermore, the safety node identifies fault signals from these input signals and triggers a reset of the application controller upon detection of such fault signals. In another aspect, a method for triggering a reset is presented. The method comprises: a) receiving input signals from a higher-level controller at an electronic control unit; b) monitoring the input signals using a safety node of the electronic control unit; and c) triggering a reset of an application control of the electronic control unit upon identifying an error signal from the input signals. In another aspect, a control system is presented. The control system comprises a higher-level controller. The higher-level controller is configured to control an electronic control unit. The control system further comprises an electronic control unit. The electronic control unit comprises an electronic device, an application controller, and a safety node. The application controller is configured to control the electronic device. The safety node is configured to monitor input signals sent from the higher-level controller to the electronic control unit. The safety node is further configured to identify a fault signal from the input signals. The safety node is also configured to trigger a reset of the application controller upon identification of the fault signal. In another aspect, a use for an automotive application of the electronic control unit, the method for triggering a reset and / or the control system is presented. The expert will recognize additional features and advantages upon reading the following detailed description and upon examining the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS The present disclosure is illustrated by way of example and without limitation in the figures of the accompanying drawings, in which the same reference numerals refer to similar or identical elements. The elements of the drawings are not necessarily to scale relative to one another. The features of the various illustrated examples may be combined, provided they are not mutually exclusive. Figures 1, 2, 3 to 4 illustrate examples of a control system according to the present disclosure; and Figure 5 illustrates a flowchart of an example of a method for triggering a reset according to the present disclosure. DETAILED DESCRIPTION The examples described herein offer considerable advantages. The control system according to this disclosure can facilitate the centralization and harmonization of safety monitoring and fault event handling, e.g., within a vehicle. In particular, the operation of various application controllers can be monitored by a higher-level controller. The higher-level controller can then achieve a higher level of safety integrity. Conversely, the application controllers can only achieve a lower level of safety integrity, which is reflected in reduced complexity and ultimately lower costs. Nevertheless, overall safety can still be ensured by using a designated safety node. Fig. 1 schematically illustrates an example of a control system 110. The control system 110 comprises a higher-level controller 112. The higher-level controller 112 is configured to control an electronic control unit 114. The electronic control unit 114 can be an embedded system, particularly in an automotive application, e.g., for engine control. The higher-level controller 112 can be configured to control other electronic control units not shown and can itself be an electronic control unit or at least part thereof. Thus, the higher-level controller 112 can be a higher-level electronic control unit or at least part thereof. In particular, the higher-level controller 112 can be a zone controller or a central controller. The control system 110 can, in particular, be a vehicle control system.In this context, a central control unit can be established to control the entire vehicle, at least indirectly, for example, by using subordinate control units. A zone control unit can be established to control spatial or functional zones of the vehicle. The higher-level control unit 112 can be or comprise a microcontroller, in particular a main microcontroller of the control system 110. The higher-level control unit 112 can, in particular, comprise a central processing unit. The higher-level control unit 112 can be configured to monitor other components of the control system 110, such as the electronic control unit 114 or at least a part thereof. Thus, the higher-level control unit 112 can be configured to identify a fault event within the control system 110. The electronic control unit 114 can be configured to control a load 116. The load 116 can be, for example, a motor or an actuator. However, other applications are also possible. The load 116 can define the application of the electronic control unit 114. The electronic control unit 114 includes an electronic device 118. The electronic device 118 can be configured to control, and in particular to switch, the load 116. Thus, the electronic device 118 can, in particular, be or include a switch 120. The switch 120 can be configured to switch the load 116 on and off. The switch 120 can, in particular, be or include a transistor, such as a field-effect transistor. The electronic device 118 can further include a driver 122. The driver 122 can be configured to control the switch 120.For example, switch 120 can be a field-effect transistor, and driver 122 can be a gate driver configured to control a gate of the field-effect transistor. In an ON state, the field-effect transistor can then, for example, supply current to load 116 from a power supply 124. The electronic control unit 114 can further include a power adapter 126. The power adapter 126 can be configured to manage a power supply, including conversion and monitoring. For example, the power supply 124 can be or include a battery. Thus, the power adapter 126 can be configured, for example, to monitor the battery, e.g., with respect to battery life, and / or to convert a battery voltage into a voltage that can be applied to the electronic control unit 114 and / or to the load 116.In particular, the power adapter 126 can be an integrated power management circuit. The electronic control unit 114 further comprises an application controller 128. The application controller 128 is configured to control the electronic device 118. Thus, the application controller 128 can be configured, at least indirectly, to control the load 116. The application controller 128 can be or comprise a microcontroller. The application controller 128 can be configured to execute the main processing functions of the electronic control unit 114. In particular, the application controller 128 can be configured to receive and process input signals from the higher-level controller 112, such as for controlling the electronic device 118 and thus, at least indirectly, the load 116. Furthermore, the application controller 128 can be configured to send output signals to the higher-level controller 112, such as output signals indicating an operating status of the application controller 128.The signals, whether input or output signals, can be analog or digital. The digital signals can also be referred to as messages. For example, a signal can comprise a data frame. The electronic control unit 114 can also include a transceiver 130, for example, for communication between the application controller 128 and the higher-level controller 112. Thus, the signals can be transmitted via the transceiver 130. In summary, the higher-level controller 112 can be updated regularly during operation of the application controller 128. The higher-level controller 112 can therefore be configured to detect errors in the application controller 128. Furthermore, the higher-level controller 112 can receive additional signals from other components. For example, the higher-level controller 112 can receive sensor signals. Thus, the control system 110 can include a sensor 132. The sensor 132 can be configured to monitor the control system 110 or at least a part of it. In particular, the sensor 132 can be configured to monitor the electronic control unit 114 and / or the load 116. The higher-level controller 112 can be configured to evaluate the signals received from other components.Based on this, the higher-level control unit 112 can be configured to identify a fault, such as a fault in the electronic control unit 114 or at least a part thereof, or a fault in the load 116. In the event of such a fault, the higher-level control unit 112 can be configured to send a fault signal to the electronic control unit 114. In particular, the higher-level control unit 112 can be configured to identify a fault in the application control unit 128 and send a fault signal to the electronic control unit 114. Thus, the fault signal can relate to a fault in the application control unit 128. However, other options are also possible, such as a fault in another component of the electronic control unit 114 or a fault in the load 116, which is detected, for example, using the sensor 132. The electronic control unit 114 further comprises a safety node 134. The safety node 134 is configured to monitor input signals sent from the higher-level controller 112 to the electronic control unit 114. Thus, the safety node 134 can be configured to monitor input signals from the higher-level controller 112. The safety node 134 can be configured to monitor signal traffic between the higher-level controller 112 and the electronic control unit 114, in particular between the higher-level controller 112 and the application controller 128. The safety node 134 is further configured to identify an error signal from the input signals. For this purpose, the safety node can include a signal filter 136. The signal filter 136 can, for example, be a digital filter.The signal filter 136 can be configured to compare the input signals with a predetermined fixed signal to identify the fault signal. The fixed signal can, for example, be predefined in a communication protocol used within the control system 110. The safety node 134 is further configured to trigger a reset of the application controller 128 upon identification of the fault signal. Thus, the safety node 134 can be configured, in particular, to trigger a reset of the application controller 128 when an input signal matches the predetermined fixed signal. Furthermore, the safety node 134 can be configured to trigger the reset of the application controller 128 by sending a reset signal to the application controller 128 upon identification of the fault signal. The safety node 134 can meet a sufficiently high Safety Integrity Level (SIL), or in particular a sufficiently high Automotive Integrity Level (ASIL), for the specific application of the electronic control unit 114. In other words, the safety node 134 can meet a SIL of an overall safety requirement of the electronic control unit 114, or in particular an ASIL of an overall safety requirement of the electronic control unit 114. The IEC 61508 standard defines four SILs for functional safety, with SIL4 being the most reliable, followed by SIL3, then SIL2, and finally SIL1 being the least reliable. Similarly, the ISO 26262 standard defines four ASILs for the automotive field, with ASIL D having the highest safety requirements, followed by ASIL C, then ASIL B, and finally ASIL A having the lowest safety requirements.As an example, ASIL D refers to a likely potential for serious life-threatening or fatal injuries in the event of a failure, such as a loss of braking power on all wheels of a car, and therefore requires the highest level of safety. The safety node 134 can, in particular, meet SIL3 or even SIL4. Specifically, in an automotive application, the safety node 134 can meet ASIL D. Accordingly, the signal filter 136 can meet a SIL of an overall safety requirement of the electronic control unit, in particular SIL3 or SIL4, or more specifically ASIL D. On the other hand, the application controller 128 can then only meet a lower SIL or ASIL. Thus, a less complex and more cost-effective application controller 128 can be used within the electronic control unit 114. Accordingly, the application controller 128 can meet a SIL that is lower than a SIL of an overall safety requirement of the electronic control unit 114, or an ASIL that is lower than an ASIL of an overall safety requirement of the electronic control unit 114.In particular, the application controller can only meet a SIL lower than SIL4 or even SIL3, or an ASIL lower than ASIL D. It should be noted that, in principle, the safety node 134 can still be contained within the application controller 128. In other words, the safety node 134 can also be part of the application controller 128. In such a case, the safety node 134 can be a separate unit within the application controller 128. Thus, the safety node 134 can be separate from other components of the application controller 134 that can only meet a lower SIL or ASIL. As already indicated, with this approach, safety monitoring and fault event handling can be less focused on the application controller 128 and instead more focused on the higher-level controller 112. As mentioned, the higher-level controller 112 can be configured to monitor the operation of the application controller 128 and, in particular, to identify a fault in the application controller 128. The higher-level controller 112 can be configured to act as a remote monitoring device for the electronic control unit 114 and, in particular, for the application controller 128. Thus, the higher-level controller 112 can be configured to remotely control the reset of the application controller 128, especially by using the safety node 134.Consequently, the higher-level controller 112 can also meet a SIL of an overall safety requirement of the control system 110, or in particular an ASIL of an overall safety requirement of the control system 110. The higher-level controller 112 can, in particular, meet SIL3 or SIL4. Specifically, the application controller 112 can meet ASIL D in an automotive application. Fig. 2 schematically illustrates another example of the control system 110. Fig. 2 corresponds at least largely to Fig. 1. Thus, the description of Fig. 2 can also refer, at least largely, to the description of Fig. 1. As indicated in particular in Fig. 2, the safety node 134 can further be configured to trigger a safe state when a fault signal is identified, such as by sending a safe state signal to the electronic device 118. The safe state can, in particular, be a safe state of the load 116. As an example, the safe state can be an OFF state of a motor. Additionally or alternatively, the safe state can be a safe state of the electronic control unit 114, or at least a part of it, or even the entire control system 110. In general, the safe state can comprise at least one OFF state and one ON state.In principle, the safe state can also include a dynamic change between the OFF state and the ON state, as for example in a traction converter. Thus, particularly in the event of a fault in the application controller 128, the application controller 128 can not only be reset remotely, but the application controller 128 can also be bypassed by using the safety node 136, for example to put the load 116 into a safe state. Figure 3 schematically illustrates another example of the control system 110. Figure 3 corresponds, at least in large part, to the previous figures. Therefore, the description of Figure 3 can also refer, at least in large part, to the description of the previous figures. As mentioned, the control system 110 can, in particular, include the transceiver 130, for example, for communication between the higher-level controller 112 and the application controller 128. As further mentioned, the safety node 134 can be configured to monitor the communication between the higher-level controller 112 and the application controller 128. Thus, as shown in particular in Figure 3, the safety node 134 can also be incorporated into the transceiver 130. In other words, the safety node 134 can be part of the transceiver 130, or the transceiver 130 can include the safety node 134.As a result, the safety node 134 can be set up to directly monitor the input signals from the higher-level controller 112 to identify a fault signal. Fig. 4 schematically illustrates another example of the control system 110. Fig. 4 corresponds, at least in large part, to the previous figures. Thus, the description of Fig. 4 can also refer, at least in large part, to the description of the previous figures. As mentioned, the control system 110 can, in particular, also include the power adapter 126. As Fig. 4 specifically indicates, the safety node 134 can also be part of the power adapter 126, or, in other words, the power adapter 126 can include the safety node 134. Apart from the example illustrated in Fig. 3, which shows the safety node 134 as part of the transceiver 130, and the example illustrated in Fig. 4, which shows the safety node 134 as part of the power adapter 126, other options are, of course, possible.As already stated, the safety node 134 can be a single component within the electronic control unit 114 or a separate unit within the application control 128, or the safety node 134 can of course also be part of another component of the electronic control unit 114. Figure 5 illustrates a flowchart of an example procedure for triggering a reset. The procedure comprises the following steps. The presented steps can be executed in the specified order. However, it should be noted that a different order is also possible. The procedure may include additional steps not listed. Furthermore, one or more of the steps can be executed once or repeatedly. Additionally, two or more steps can be executed simultaneously or overlapping in time.a) Receiving input signals from a higher-level controller 112 at an electronic controller 114 (designated by reference numeral 138); b) Monitoring the input signals using a safety node 134 of the electronic control unit 114 (designated by reference numeral 140); and c) Triggering a reset of an application controller 128 of the electronic control unit 114 upon identifying a fault signal from the input signals (designated by reference numeral 142); and optionally d) Triggering a safe state upon identifying a fault signal from the input signals (designated by reference numeral 144). In particular, step b) can include comparing the input signals with a predetermined fixed signal. Step c) can then include triggering the reset of the application controller 128 when an input signal matches the predetermined fixed signal. Step c) can further include sending a reset signal to the application controller 128. Accordingly, step d) can include sending a safe status signal to the electronic device 118. The control system 110, the electronic control unit 114 and / or the method for triggering a reset can be used in particular in an automotive application, such as for controlling a load 116 in a vehicle, e.g., an engine. Of course, other uses are also conceivable. In addition to the examples described above, the following examples are disclosed here: Example 1: An electronic control unit comprising: • an electronic device; • an application controller configured to control the electronic device; and • a safety node configured to: ◯ monitor input signals sent to the electronic control unit from a higher-level controller; ◯ identify a fault signal from the input signals; and ◯ trigger a reset of the application controller upon identification of the fault signal. Example 2: The electronic control unit according to the preceding example, wherein the fault signal relates to a fault in the application controller.Example 3: The electronic control unit according to any of the preceding examples, wherein the application control meets a Safety Integrity Level (SIL) lower than a SIL of an overall safety requirement of the electronic control unit, in particular a SIL lower than SIL4, or more specifically an Automotive Safety Integrity Level (ASIL) lower than ASIL D. Example 4: The electronic control unit according to any of the preceding examples, wherein the safety node meets a SIL of an overall safety requirement of the electronic control unit, in particular SIL4, or more specifically ASIL D. Example 5: The electronic control unit according to any of the preceding examples, wherein the safety node comprises a signal filter configured to compare the input signals with a predetermined fixed signal to identify the fault signal.Example 6: The electronic control unit according to the preceding example, wherein the safety node is configured to trigger a reset of the application controller when an input signal matches the predetermined fixed signal. Example 7: The electronic control unit according to any one of the two preceding examples, wherein the signal filter meets a SIL of an overall safety requirement of the electronic control unit, in particular SIL4, or more specifically ASIL D. Example 8: The electronic control unit according to any one of the three preceding examples, wherein the signal filter is a digital signal filter. Example 9: The electronic control unit according to any one of the preceding examples, wherein the safety node is configured to trigger the reset of the application controller by sending a reset signal to the application controller when the fault signal is identified.Example 10: The electronic control unit according to any of the preceding examples, wherein the safety node is further configured to trigger a safe state when the fault signal is identified. Example 11: The electronic control unit according to the preceding example, wherein the safety node is configured to trigger the safe state by sending a safe state signal to the electronic device when the fault signal is identified. Example 12: The electronic control unit according to any of the two preceding examples, wherein the safe state is a safe state of a load controlled by the electronic control unit, in particular by the electronic device. Example 13: The electronic control unit according to any of the preceding examples, wherein the electronic device comprises a switch and / or a driver.Example 14: The electronic control unit according to any of the preceding examples, wherein the security node is configured to monitor communication between the higher-level controller and the application controller. Example 15: The electronic control unit according to any of the preceding examples, further comprising a transceiver for communication with the higher-level controller, wherein the security node is part of the transceiver. Example 16: The electronic control unit according to any of the preceding examples, further comprising a power adapter, wherein the security node is part of the power adapter. Example 17: The electronic control unit according to the preceding example, wherein the power adapter is an integrated power management circuit. Example 18: The electronic control unit according to any of the preceding examples, wherein the security node is part of the application controller.Example 19: The electronic control unit according to the preceding example, wherein the safety node is a separate unit within the application control. Example 20: A method for triggering a reset, wherein the method comprises: a) receiving input signals from a higher-level controller at an electronic control unit; b) monitoring the input signals using a safety node of the electronic control unit; and c) triggering a reset of an application control of the electronic control unit upon identifying a fault signal from the input signals. Example 21: The method according to the preceding example, wherein the electronic control unit is an electronic control unit according to any of the preceding examples relating to an electronic control unit.Example 22: The method according to any of the preceding method examples, wherein step b) comprises comparing the input signals with a predetermined fixed signal. Example 23: The method according to the preceding example, wherein step c) comprises triggering the reset of the application controller when an input signal matches the predetermined fixed signal. Example 24: The method according to any of the preceding method examples, wherein step c) comprises sending a reset signal to the application controller. Example 25: The method according to any of the preceding method examples, further comprising: d) triggering a safe state upon identifying an error signal from the input signals. Example 26: The method according to the preceding example, wherein step d) comprises sending a safe state signal to the electronic device.Example 27: A control system comprising: • a higher-level controller configured to control an electronic control unit; and • an electronic control unit comprising: ◯ an electronic device; ◯ an application controller configured to control the electronic device; and ◯ a safety node configured to: ▪ monitor input signals sent from the higher-level controller to the electronic control unit; ▪ identify a fault signal from the input signals; and ▪ trigger a reset of the application controller upon identification of the fault signal. Example 28: The control system of the preceding example, wherein the electronic control unit is an electronic control unit according to any of the preceding examples relating to an electronic control unit.Example 29: The control system according to any of the preceding examples relating to a control system, wherein the higher-level controller is configured to monitor the operation of the application controller, in particular to identify an error in the application controller. Example 30: The control system according to any of the preceding examples relating to a control system, wherein the higher-level controller meets a SIL of a safety requirement of the control system, in particular SIL4, or more specifically ASIL D. Example 31: The control system according to any of the preceding examples relating to a control system, wherein the higher-level controller is a central controller or at least a zone controller.Example 32: A use for an automotive application of at least one of the electronic control unit according to one of the preceding examples relating to an electronic control unit, a method for triggering a reset according to one of the preceding method examples, and a control system according to one of the preceding examples relating to a control system. Although specific examples have been illustrated and described here, the person skilled in the art will recognize that a multitude of alternative and / or equivalent implementations can replace the specific examples shown and described without deviating from the scope of this disclosure. This application is intended to cover any adaptations or variations of the specific examples discussed herein. Therefore, it is intended that this disclosure is limited only by the claims and their equivalents. It should be noted that the methods and devices, including their preferred embodiments, as set forth in this document, can be used alone or in combination with the other methods and devices disclosed herein. Furthermore, the features described in connection with a device are also applicable to a corresponding method, and vice versa. Moreover, all aspects of the methods and devices described in this document can be combined as desired. In particular, the features of the claims can be combined with one another in any way desired. It should be noted that the description and drawings merely illustrate the principles of the proposed methods and systems. The person skilled in the art will be able to implement various arrangements which, although not expressly described or shown here, embody the principles of the disclosure and are contained within its meaning and scope. Furthermore, all examples and embodiments set forth in this document are expressly intended primarily for illustrative purposes only, to assist the reader in understanding the principles of the proposed methods and systems. Moreover, all statements herein that provide principles, aspects, and embodiments of the disclosure, as well as specific examples thereof, are intended to include equivalents thereof.
Claims
An electronic control unit (114) comprising: • an electronic device (118); • an application controller (128) configured to control the electronic device (118); and • a safety node (136) configured to: ◯ monitor input signals sent to the electronic control unit (114) from a higher-level controller (112); ◯ identify a fault signal from the input signals; and ◯ trigger a reset of the application controller (128) upon identification of the fault signal. The electronic control unit (114) according to the preceding claim, wherein the fault signal relates to a fault in the application control (128). The electronic control unit (114) according to one of the preceding claims, wherein the application control (128) meets a safety integrity level, SIL, which is lower than a SIL of an overall safety requirement of the electronic control unit (114), in particular a SIL which is lower than SIL4, or more specifically an automotive safety integrity level, ASIL, which is lower than ASIL D. The electronic control unit (114) according to one of the preceding claims, wherein the safety node (134) fulfills a SIL of an overall safety requirement of the electronic control unit (114), in particular SIL4, or more specifically ASIL D. The electronic control unit (114) according to one of the preceding claims, wherein the safety node (134) comprises a signal filter (136) configured to compare the input signals with a predetermined fixed signal to identify the fault signal. The electronic control unit (114) according to one of the preceding claims, wherein the safety node (134) is configured to trigger the reset of the application control (128) by sending a reset signal to the application control (128) upon identification of the fault signal. The electronic control unit (114) according to one of the preceding claims, wherein the safety node (134) is further configured to trigger a safe state upon identification of the fault signal. The electronic control unit (114) according to the preceding claim, wherein the safety node (114) is configured to trigger the safe state by sending a safe state signal to the electronic device (18) upon identification of the fault signal. The electronic control unit (114) according to one of the two preceding claims, wherein the safe state is a safe state of a load (116) controlled by the electronic control unit (114), in particular by the electronic device (118). The electronic control unit according to one of the preceding claims, wherein the electronic device (118) comprises a switch (120) and / or a driver (122). The electronic control unit (114) according to one of the preceding claims, wherein the safety node (134) is configured to monitor communication between the higher-level control unit (112) and the application control unit (128). The electronic control unit (114) according to one of the preceding claims, further comprising a transceiver (130) for communication with the higher-level control unit (112), wherein the safety node (134) is a part of the transceiver (130). The electronic control unit (114) according to one of the preceding claims, further comprising a power adapter (126), wherein the safety node (134) is a part of the power adapter (126). The electronic control unit (114) according to one of the preceding claims, wherein the safety node (134) is a part of the application control (128), wherein the safety node (134) is a separate unit within the application control (128). A method for triggering a reset, comprising: a) receiving input signals from a higher-level controller (112) at an electronic control unit (114); b) monitoring the input signals using a safety node (134) of the electronic control unit (114); and c) triggering a reset of an application controller (128) of the electronic control unit (114) upon identifying a fault signal from the input signals. The method according to the preceding claim, further comprising: d) triggering a safe state upon identification of an error signal from the input signals. A control system (110) comprising: • a higher-level controller (112) configured to control an electronic control unit (114); and • an electronic control unit (114) comprising: ◯ an electronic device (118); ◯ an application controller (128) configured to control the electronic device (118); and ◯ a safety node (134) configured to: ▪ monitor input signals sent from the higher-level controller (112) to the electronic control unit (114); ▪ identify a fault signal from the input signals; and ▪ trigger a reset of the application controller (128) upon identification of the fault signal. The control system (110) according to the preceding claim, wherein the superior control (112) is configured to monitor the operation of the application control (128), in particular to identify an error in the application control (128). The control system (110) according to one of the preceding claims relating to a control system (110), wherein the superior control (112) is a central control or at least a zone control. A use for an automotive application of at least one of the electronic control unit (114) according to one of the preceding claims relating to an electronic control unit (114), a method for triggering a reset according to one of the preceding method claims and a control system (110) according to one of the preceding claims relating to a control system (110).
Citation Information
Patent Citations
Automated vehicle control system architecture
US20180143650A1
Secure system that includes driving related systems
US20200039530A1