In-vehicle system based on multi-operating system and control method thereof

The in-vehicle system employs a multi-operating system architecture with separate cores for application and safety monitoring operating systems, addressing safety issues in existing Android-based systems by ensuring independent and effective safety monitoring.

JP2025516320AActive Publication Date: 2025-05-27AUTOCHIPS
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2024564974
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-07-11
Filing Date
2023-08-24
Publication Date
2025-05-27
Estimated Expiration
2043-08-24

AI Technical Summary

Technical Problem

Existing in-vehicle systems based on the Android operating system face safety issues due to the complexity of the system, where a malfunctioning application can cause the entire system to crash, affecting the effectiveness of safety monitoring.

Method used

An in-vehicle system utilizing a multi-operating system architecture, which includes an application operating system and a safety monitoring operating system, both running on different cores of the same processor. The safety monitoring operating system is communicatively connected to the application operating system to provide independent safety monitoring.

Benefits of technology

This solution enhances the safety performance of the in-vehicle system by isolating the safety monitoring operating system from the application operating system, preventing crashes from affecting safety monitoring and improving the overall effectiveness of safety monitoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025516320000001_ABST
    Figure 2025516320000001_ABST
Patent Text Reader

Abstract

The present application provides an in-vehicle system based on a multi-operating system and a control method thereof. The in-vehicle system based on the multi-operating system includes at least one application operating system and a safety monitoring operating system. The application operating system and the safety monitoring operating system use different cores of the same processor. The application operating system is used to execute non-secure applications, and the safety monitoring operating system is communicatively connected to the application operating system in order to execute a safety monitoring service for safely monitoring the application operating system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of in-vehicle technologies, and particularly to an in-vehicle system based on a multi-operating system and a control method thereof.

Background Art

[0002] Currently, the center control system of automobiles, that is, the in-vehicle system, is becoming increasingly popular. The in-vehicle system includes not only functions such as Android (Registered Trademark) entertainment functions, car navigation, and rear view, but also functions such as safety monitoring for monitoring the safety of the system.

[0003] However, existing in-vehicle systems are usually based on the core of the Android operating system, and it is to implement an application for realizing the safety monitoring function. The Android operating system is a huge system with a large number of applications being executed. There are many safety problems in the complex and huge system. If one of the applications malfunctions, the entire system may crash. Therefore, the safety monitoring function is affected by the abnormal operation of other applications in the Android operating system and cannot provide effective safety monitoring, and the safety performance of the system is low.

Summary of the Invention

Problems to be Solved by the Invention

[0004] The present Wish , in order to improve the effectiveness of safety monitoring and enhance the safety performance of the in-vehicle system, an in-vehicle system based on a multi-operating system and a control method thereof are provided For the purpose of .

Means for Solving the Problems

[0005] To solve the above technical problems, the present application provides an in-vehicle system based on a multi-operating system. The in-vehicle system based on this multi-operating system is including at least one application operating system and a safety monitoring operating system, wherein the application operating system and the safety monitoring operating system use different cores of the same processor, the application operating system is used to execute non-secure applications, and the safety monitoring operating system is communicatively connected to the application operating system to execute a safety monitoring service for safely monitoring the application operating system.

[0006] To solve the above technical problems, the present application provides a control method for an in-vehicle system based on a multi-operating system. The in-vehicle system includes at least one application operating system and a safety monitoring operating system. The application operating system includes a second operating system that uses a different core of the same processor as the safety monitoring operating system. The second operating system is used to execute quick-start applications, and the control method includes configuring cores for the second operating system and the safety monitoring operating system, obtaining a power-on startup command, loading a mirror file of the safety monitoring operating system into the running memory of the in-vehicle system, and starting the execution of the core corresponding to the safety monitoring operating system to complete the startup of the safety monitoring operating system and its safety monitoring service, Load the kernel of the second operating system into the running memory, start the execution of the core corresponding to the second operating system, and sequentially complete the loading of the driver of the second operating system, the startup of the services on which the quick start application depends, and the startup of the quick start application.

[0007] Compared with the prior art, the beneficial effects of the present application are as follows. The vehicle-mounted system based on the multi-operating system of the present application includes at least one application operating system and a safety monitoring operating system. The application operating system and the safety monitoring operating system use different cores of the same processor. The application operating system is used to execute non-secure applications, and the safety monitoring operating system is communicatively connected to the application operating system to safely monitor the application operating system. The vehicle-mounted system of the present application realizes the safety monitoring of the application operating system by using the safety monitoring operating system, and realizes the safety monitoring operating system and the application operating system respectively by using different cores of the same processor, realizes the isolation between the two, and avoids the problem that the safety monitoring application cannot run normally due to the abnormal execution of the application in the application operating system. Therefore, the effectiveness of safety monitoring can be improved, and the safety performance of the vehicle-mounted system can be enhanced.

Brief Description of the Drawings

[0008]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Embodiments for Carrying Out the Invention

[0009] Hereinafter, with reference to the drawings of the embodiments of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described. Obviously, the described embodiments are only a part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, those skilled in the art can obtain all other embodiments without creative work, which belong to the protection scope of the present application.

[0010] First, as shown in FIG. 1, the present application provides an in-vehicle system based on a multi-operating system. FIG. 1 is a configuration diagram of one embodiment of the in-vehicle system based on the multi-operating system of the present application. The in-vehicle system of this embodiment includes at least one application operating system and a safety monitoring operating system 12. The application operating system and the safety monitoring operating system 12 use different cores of the same processor, that is, both use core 1 and core 2 (and core 3) respectively. Here, the application operating system is used to execute non-secure applications, and the safety monitoring operating system 12 is communicatively connected to the application operating system to execute a safety monitoring service for monitoring the application operating system.

[0011] The in-vehicle system of this embodiment realizes the safety monitoring of the application operating system by using the safety monitoring operating system 12, and realizes the safety monitoring operating system 12 and the application operating system respectively by using different cores of the same processor, realizes the isolation between the two, and can avoid the problem that the safety monitoring application cannot run normally due to the abnormal execution of the application in the application operating system. Therefore, the effectiveness of safety monitoring can be improved, and the safety performance of the in-vehicle system can be enhanced.

[0012] Here, core 2 used to execute the safety monitoring operating system 12, that is, core 2 used by the safety monitoring operating system 12, may be one or more (two or more) cores of the same processor. The safety monitoring operating system 12 is mainly used to execute a safety monitoring application, that is, a safety monitoring service, for monitoring the execution state of the application operating system and the like.

[0013] Here, core 1 (and core 3) used to execute the application operating system, that is, core 1 (and core 3) used by the application operating system may be one or more (two or more) other cores of the same processor.

[0014] Here, the application operating system of this embodiment includes a first operating system 11 and a second operating system 13. Here, the first operating system 11 may be an Android operating system. The Android operating system mainly includes the following: (a) It includes a Kernel layer, and its driver modules include all device drivers other than the video ( VIDEO ) device driver in the system-on-a-chip (SOC), such as a graphics processing unit (GPU), a data processing unit (DPU), and other module drivers (including modules such as EMMC, I2C, WIFI, and USB). (b) A Service layer, that is, a service layer, and its services include all running services, such as OpenGLES, CarmeraSource, Surfaceflinger, and other running services (such as Storage Service, WIFI Service, and Audio Service). (c) An application layer, and its applications include VIDEO Player, Music Play, 3rd Party APP, etc.

[0015] For a specific introduction to the Android operating system, reference can be made to the prior art, and the text does not make specific limitations. In other embodiments, the application operating system may further be other non-secure multi-application systems, etc.

[0016] Note that the plurality (two or more) of cores of the present application may be of the same form or different forms, and are not particularly limited.

[0017] Optionally, the second operating system 13 of this embodiment may be Linux (Registered Trademark) operating system, and different cores of the same processor as the first operating system and the security monitoring operating system 12 are used. The Linux operating system uses core 3, and the Android operating system uses core 1. That is, the Linux operating system, the Android operating system, and the security monitoring operating system 12 each use independent cores in the same process.

[0018] Here, the Linux operating system is used to execute the quick start application. Here, the Linux operating system simplifies the Linux operating system 13 and sets only the resource items on which the quick start application depends in order to shorten the startup time of the quick start application.

[0019] The security monitoring operating system 12 is communicatively connected to the Android operating system and the Linux operating system respectively, and is used for the security monitoring of the Android operating system and the Linux operating system respectively.

[0020] Here, the core for executing the Linux operating system may be one or more (two or more) other cores of the same processor.

[0021] A quick-start application is an application that needs to start quickly. For example, it includes the Around View Monitor (AVM) application, the background application in a smart cabin, the in-vehicle instrument application, the Dealer Management System (DMS) application in a vehicle, etc.

[0022] In the following, the case where the Linux operating system runs the AVM application will be taken as an example for explanation.

[0023] The AVM application depends on three important hardware modules: GPU, DPU, VIDEO IN. Here, the GPU can accelerate image processing and is compatible with the GPU driver of the Android Kernel and the OpenGLES interface of the Android Service. The DPU is a display module and is compatible with the DPU driver of the Android Kernel and the Surfacefinger interface of the Android Service. VIDEO IN is a camera image collection module and is compatible with the VIDEO IN driver of the Android Kernel and the Camer a Source interface of the Android Service.

[0024] The AVM application is an APP application written in java in the Android application layer. It obtains the camera image data collected by the IN module through the Camera Source interface, completes the distortion correction and splicing of the image data using the GPU hardware module through an algorithm, and finally displays it on the screen through Surfaceflinger. VIDEO IN module, completes the distortion correction and splicing of the image data using the GPU hardware module through an algorithm, and finally displays it on the screen through Surfaceflinger. Camera image Display on the screen.

[0025] In a conventional in-vehicle system, the AVM system as described above has the following problems.

[0026] (1) Camera S Components such as the source interface, SurfaceFlinger service, and OpenGLES library must all be loaded into the Android master file system before they can operate. The AVM APP can only be started after the entire Android system has completed startup and entered the master interface. Therefore, in a traditional in-vehicle system, when the vehicle undergoes a cold start and obtains the AVM image, the process is very slow, generally taking 20s Above .

[0027] (2) The Android system is an application-rich system with many services running. There are many security issues in a complex and large system. For example, if one of the services malfunctions, the entire system may crash, and this AVM application will also be affected. Therefore, the AVM function is affected by the Android system and has low security.

[0028] On the other hand, the in-vehicle system of this embodiment can achieve the effects of quick start and execution safety of AVM by making the AVM function independent and running it alone on the Linux operating system.

[0029] Also, the Linux operating system of this embodiment is a custom crop and includes only (a) the Linux Kernel layer mainly including the GPU, DPU, VIDEO device drivers on which AVM depends, (b) the Linux Service layer mainly including OpenGLES, CarmeraSource, SurfaceFlinger, and Safety Service on which AVM depends, and (c) the Linux application layer that runs only one AVM application. The simplified Linux operating system can further speed up the startup of AVM.

[0030] The SOC integrates multiple cores, such as 4 cores or 8 cores. This embodiment fully utilizes the resource advantages of the multi-core system to execute three operating systems on the SOC. The first operating system 11 runs on some cores, the security monitoring operating system 12 runs on some cores, and the second operating system 13 runs on the remaining cores.

[0031] Furthermore, both the first operating system 11 and the second operating system 13 of this embodiment require two resource modules, namely the GPU and the DPU. The software virtualization (Hypervisor) technology is used for these two resource modules so that the first operating system 11 and the second operating system 13 can access them commonly.

[0032] As can be seen from the above analysis, the in-vehicle system further includes an SOC. The SOC is provided with a plurality of physical cores, and at least one physical core is allocated to each of the first operating system 11, the security monitoring operating system 12, and the second operating system 13.

[0033] Specifically, as shown in Figure 2, when the SOC is running, physical cores are allocated to the first operating system 11, the security monitoring operating system 12, and the second operating system 13. For example, the SOC is provided with four physical cores Core[0] - Core[3]. 12 Core[0] is allocated to the 13 security monitoring operating system, Core[1] is allocated to the second operating system,

[0034] As an option, as shown in FIG. 3, when the in-vehicle system is powered on, it executes the bootloader, that is, the bootloader, initializes the hardware devices, and the SOC assigns different physical cores to the first operating system 11, the security monitoring operating system 12, and the second operating system 13 respectively. The bootloader loads the mirror file of the security monitoring operating system 12 into the running memory, starts the execution of the core corresponding to the security monitoring operating system 12, and completes the startup of the security monitoring operating system 12 and its security monitoring services.

[0035] The bootloader loads the Min Kernel into the running memory and starts the execution of the core corresponding to the Linux operating system. Linux K After the Linux kernel completes the driver loading, the AVM starts the CarmeraSource, surfaceflinger, and Opengles services it depends on, and finally starts the AVM application.

[0036] The bootloader loads the Android Kernel into the running memory and starts the execution of the core corresponding to the Android operating system. After the Android Kernel completes the driver loading, it starts all Android services. After the startup of the Android services is completed, finally, it starts the Android application.

[0037] Furthermore, for the quick start of the AVM application, more physical cores can be allocated to the second operating system 13 at the startup stage of the AVM application, and after the startup of the AVM application is completed, the physical cores can be released to the first operating system 11. In this embodiment, at the startup stage of the AVM application, more physical cores can be arranged by the second operating system 13 to ensure the quick start of the AVM application. After the startup of the AVM application is completed, in order to ensure the execution speed of other application operating systems and the reasonable utilization of resources, a part of the physical cores allocated to the second operating system 13 Divide can be released to other application operating systems of the in-vehicle system, such as the first application operating system 11.

[0038] In other embodiments, cores can also be allocated to the first operating system 11, the security monitoring operating system 12, and the second operating system 13 by software virtualization (Hypervisor) technology. The in-vehicle system of this embodiment further includes a core virtualization system 14 (as shown in FIG. 4), and its general implementation is to design one layer of software at the EL2 (Exception Level) of the processor. The core virtualization system 14 virtualizes physical cores into multiple virtual cores using Hypervisor technology, and the SOC allocates at least one virtual core to the first operating system 11, the security monitoring operating system 12, and the second operating system 13 respectively.

[0039] Specifically, as shown in FIG. 4, the core virtualization system 14 virtualizes the physical cores Core[0]-Core[3] into a plurality of virtual cores VCore[0]-VCore[5] using Hypervisor technology, allocates VCore[0] to the security monitoring operating system 12, allocates VCore[0] and VCore[2] to the second operating system 13, and allocates VCore[3], VCore[4], and VCore[5] to the first operating system 11.

[0040] Optionally, as shown in FIG. 5, the system is powered on, the bootloader is executed, the hardware devices are initialized, the bootloader loads the mirror file of the Hypervisor into the running memory, after successfully starting the Hypervisor, virtualizes a plurality of virtual cores, the Hypervisor loads the mirror file of the security monitoring operating system 12 into the running memory, starts the execution of the core corresponding to the security monitoring operating system 12, and completes the startup of the security monitoring operating system 12 and its security monitoring services.

[0041] The Hypervisor loads the Min Kernel into the running memory and starts the execution of the core corresponding to the Linux operating system. After the Linux K kernel completes the driver load, the AVM-dependent CarmeraSource, surfaceflinger, and Opengles services are started, and finally the AVM application is started.

[0042] The Hypervisor loads the Android Kernel into the running memory and starts the execution of the core corresponding to the Android operating system. After the Android Kernel completes the driver load, all Android services are started, and after the startup of the Android services is completed, finally the Android application is started.

[0043] In other embodiments, for the first operating system, the security monitoring operating system, and the second operating system, cores can also be allocated with reference to the physical partitioning method of the embodiment of FIG. 2 and the virtual partitioning method of the embodiment of FIG. 4.

[0044] Specifically, the SOC is provided with a plurality of physical cores. The core virtualization system virtualizes a part of the physical cores into a plurality of virtual cores. The SOC allocates at least one virtual core to each of the first operating system and the second operating system, and allocates at least one physical core to the security monitoring operating system.

[0045] In other embodiments, physical cores can also be allocated to the first operating system and / or the second operating system, and virtual cores can be allocated to the security monitoring operating system.

[0046] A memory is also installed in the vehicle-mounted system of this embodiment.

[0047] Optionally, the vehicle-mounted system of this embodiment can also implement communication between different cores. Specifically, as shown in FIG. 6, this embodiment realizes communication between different cores based on interrupts and shared memory. Assuming that there are n cores in the SOC, taking the example of sending a message from Core[0] to Core[n - 1], Core[0] writes the message to a predetermined shared memory data_A[], Core[0] writes an interrupt, the controller triggers Core[n - 1] to receive the interrupt, Core[n - 1] receives the interrupt, enters the interrupt handler, and reads the message from the shared memory data_A[].

[0048] Optionally, as shown in FIG. 7, this embodiment uses the following method for the first operating system 11 and the second operating system 13 ExecuteRealize the monitoring of the state, and the Safety Service running on the second operating system 13 and the first operating system 11 sends messages at regular frequency intervals via inter-process communication, that is, the IPC method, and notifies the Safety Monitor running on the safety monitoring operating system 12. The message type can be defined independently, and two messages, "alive" and "fatal", can be defined.

[0049] When Safety Monitor receives "alive", it determines that the operating system that sent the message is running normally, continues to monitor the message without processing the message. When Safety Monitor receives "fatal", it determines that a fatal error has occurred in the execution of the operating system that sent the message, and it is necessary to restart the operating system to resume normal execution. When Safety Monitor does not receive a message sent from the operating system within a predetermined time, it determines that a fatal error has occurred in the execution of the operating system that did not send the message, and it is necessary to restart the operating system to resume normal execution.

[0050] Furthermore, Safety Monitor can also monitor its own execution status via the watchdog Watchdog. For example, it sends a notification signal to the Register of Watchdog at regular frequency intervals. If Safety Monitor executes abnormally and the notification is not made in a timely manner, the safety monitoring operating system 12 restarts to resume normal execution.

[0051] The present application further provides a control method for an in-vehicle system based on a multi-operating system, as shown in FIG. 8, which is a flowchart of an embodiment of the control method for the in-vehicle system based on the multi-operating system of the present application. The control method of this embodiment can be used in the in-vehicle system based on the multi-operating system described above. Specifically, the control method of this embodiment includes the following steps.

[0052] Step S81, configure cores for the second operating system and the safety monitoring operating system.

[0053] The in-vehicle system further includes at least one application operating system and a safety monitoring operating system. The application operating system includes the second operating system. The SOC configures cores for the second operating system and the safety monitoring operating system. The SOC configures cores for the second operating system. The second operating system and the safety monitoring operating system are located on different cores of the processor. The second operating system is used to execute quick start applications. Here, the second operating system simplifies the Linux operating system and only sets the resource items on which the quick start application depends in order to shorten the startup time of the quick start application.

[0054] The quick start application is an application that needs to be started quickly, such as an AVM application, a background application in a smart cabin, an in-vehicle instrument application, an in-vehicle DMS application, etc.

[0055] Furthermore, the application operating system can also include the first operating system. The SOC constitutes the core for the first operating system, the second operating system, and the security monitoring operating system respectively.

[0056] When the SOC is running, at least one physical core is allocated to the first operating system, the security monitoring operating system, and the second operating system respectively. Or, when the SOC is running, the physical cores of the SOC are virtualized into multiple virtual cores using Hypervisor technology via the core virtualization system, and the SOC allocates at least one virtual core to the first operating system, the security monitoring operating system, and the second operating system respectively. Or, a part of the physical cores of the SOC is virtualized into multiple virtual cores using Hypervisor technology via the core virtualization system, the SOC allocates at least one virtual core to the first operating system and the second operating system respectively, and allocates at least one non-virtualized physical core to the security monitoring operating system.

[0057] In other embodiments, the SOC can also allocate physical cores to the first operating system and / or the second operating system, and allocate virtual cores to the security monitoring operating system.

[0058] Here, the second operating system of this embodiment may be a Linux operating system, the first operating system may be an Android operating system, and in other embodiments, the first operating system may be other non-secure multi-application systems, etc.

[0059] Step S82, obtain a power-on command and the mirror file of the security monitoring operating system In-vehicleLoad it into the running memory of the system and start the execution of the core corresponding to the security monitoring operating system to complete the startup of the security monitoring operating system and its security monitoring service.

[0060] Step S83: Load the Kernel of the second operating system into the running memory, start the execution of the core corresponding to the second operating system, and sequentially complete the driver loading of the second operating system, the startup of the services on which the quick start application depends, and the startup of the quick start application.

[0061] Furthermore, the control method of this embodiment further includes step S84.

[0062] Step S84: Load the Kernel of the first operating system into the running memory, start the execution of the core corresponding to the first operating system, and sequentially complete the driver loading of the first operating system, the service startup, and the application startup.

[0063] The vehicle-mounted system of this embodiment realizes the security monitoring of the application operating system by using the security monitoring operating system, and realizes the security monitoring operating system and the application operating system respectively by using different cores of the same processor, realizes the isolation between the two, and can avoid the problem that the security monitoring application cannot run normally due to the abnormal execution of the application in the application operating system. Therefore, the effectiveness of security monitoring can be improved, and the security performance of the vehicle-mounted system can be enhanced.

[0064] In this embodiment, by making the quick start application independent and running it alone on the Linux operating system, the effects of quick start and execution security of the quick start application can be achieved.

[0065] In other embodiments, the execution order of steps S82 - S84 is not limited.

[0066] In one application scenario, after the SOC allocates physical cores to the Android operating system, the security monitoring operating system, and the Linux operating system, the in-vehicle system is powered on, and the bootloader, that is, the bootloader, is executed to initialize the hardware device. The SOC allocates different physical cores to the Android operating system, the security monitoring operating system, and the Linux operating system respectively. The bootloader loads the mirror file of the security monitoring operating system into the running memory, starts the execution of the core corresponding to the security monitoring operating system, and completes the startup of the security monitoring operating system and its security monitoring service.

[0067] The bootloader loads the Min Kernel into the running memory and starts the execution of the core corresponding to the Linux operating system. After the Linux K kernel completes the driver load, the AVM starts the CarmeraSource, surfaceflinger, and Opengles services it depends on, and finally starts the AVM application.

[0068] The bootloader loads the Android Kernel into the running memory and starts the execution of the core corresponding to the Android operating system. After the Android Kernel completes the driver load, all Android services are started. After the startup of the Android services is completed, finally the Android application is started.

[0069] In other application scenarios, after the SOC allocates virtual cores to the Android operating system, the security monitoring operating system, and the Linux operating system, the system is powered on, the bootloader is executed, the hardware devices are initialized, and the bootloader loads the mirror file of the Hypervisor into the running memory. After successfully starting the Hypervisor, it virtualizes multiple virtual cores. The Hypervisor then loads the mirror file of the security monitoring operating system into the running memory, starts the execution of the cores corresponding to the security monitoring operating system, and completes the startup of the security monitoring operating system and its security monitoring services.

[0070] The Hypervisor loads the Min Kernel into the running memory and starts the execution of the cores corresponding to the Linux operating system. After the Linux K kernel completes the driver load, the AVM starts the CarmeraSource, surfaceflinger, and Opengles services it depends on, and finally starts the AVM application.

[0071] The Hypervisor loads the Android Kernel into the running memory and starts the execution of the cores corresponding to the Android operating system. After the Android Kernel completes the driver load, it starts all Android services. After the startup of the Android services is completed, finally, the Android application is started.

[0072] Furthermore, for the quick start of the quick start application, the SOC allocates a preset number of cores to the second operating system and releases some of the cores to the first operating system after the startup of the second operating system is completed. Here, this preset number is larger than the number of cores required for the second operating system to execute the quick start application. This embodiment can configure more physical cores for the second operating system during the startup phase of the AVM application to ensure the quick start of the AVM application. After the startup of the AVM application is completed, in order to ensure the execution speed of other application operating systems of the in-vehicle system and the reasonable utilization of resources, the second operating system Divide Some of the allocated physical cores can be released to other application operating systems of the in-vehicle system, such as the first application operating system.

[0073] Optionally, the control method of the present application can also realize communication between different cores. The processor (SOC) is provided with a first core and a second core, corresponding to the application operating system and the safety monitoring Operating system respectively. The control method of this embodiment realizes communication between different cores based on interrupts and shared memory. Here, this communication method specifically includes steps S91 - S93 shown in FIG. 9.

[0074] Step S91, the application operating system writes a message to the shared memory.

[0075] The first core writes a message to the shared memory.

[0076] Step S92, the application operating system triggers the safety monitoring Operating system to receive the interrupt by writing an interrupt.

[0077] The first core triggers the second core to receive the interrupt by writing the interrupt.

[0078] Step S93, after receiving the interrupt, the security monitoring operating system enters the interrupt handler and reads the message from the shared memory.

[0079] After receiving the interrupt, the second core enters the interrupt handler and reads the message from the shared memory.

[0080] Assuming that there are n cores in the SOC, taking the example of sending a message from Core[0] to Core[n - 1], Core[0] writes a message to a predetermined shared memory data_A[], Core[0] writes an interrupt, the controller triggers Core[n - 1] to receive the interrupt, Core[n - 1] receives the interrupt, enters the interrupt handler, and reads the message from the shared memory data_A[].

[0081] It should be noted that between the cores corresponding to the above different operating systems, communication can be carried out as described above.

[0082] Optionally, the control method of the present application can also realize the security monitoring of the security monitoring operating system for the application operating system. Specifically, it can be realized by the method shown in FIG. 10, and the method of this embodiment includes steps S101 - S103.

[0083] Step S101, the application operating system sends a message to the security monitoring operating system.

[0084] The Safety Service running on the application operating system sends messages at regular intervals via inter - process communication, i.e., the IPC method, and notifies the Safety Monitor, a safety monitoring service running on the safety monitoring operating system. The message type can be defined independently, and two messages, "alive" and "fatal", can be defined.

[0085] Step S102, the safety monitoring operating System determines the execution state of the application operating system based on the message or the waiting time for receiving the message.

[0086] When Safety Monitor receives "alive", it determines that the application operating system that sent the message is running normally and continues to monitor the message without processing it. When Safety Monitor receives "fatal", it determines that a fatal error has occurred in the execution of the application operating system that sent the message and that it is necessary to restart the application operating system to resume normal execution. When Safety Monitor does not receive a message sent from the application operating system within a predetermined time, it determines that a fatal error has occurred in the execution of the application operating system that did not send the message and that it is necessary to restart the application operating system to resume normal execution.

[0087] Step S103, if the execution state is an abnormal state, the safety monitoring operating system restarts the application operating system.

[0088] If the application operating system runs abnormally, the safety monitoring operating system restarts the application operating system.

[0089] The security monitoring operating system is respectively communicatively connected to the Android operating system and the Linux operating system, and the security monitoring of the Android operating system and the Linux operating system can be realized by using the above method.

[0090] Furthermore, Safety Monitor can also monitor its own execution state via the watchdog Watchdog. For example, a notification signal is sent to the Register of the Watchdog at a certain frequency interval. If Safety Monitor executes abnormally and the notification is not made in a timely manner, the security monitoring operating system restarts to resume normal execution.

[0091] The description of each of the above operating systems can refer to the above embodiments, and the description is omitted here.

[0092] Different from the prior art, the in-vehicle system based on the multi-operating system of the present application includes at least one application operating system and a safety monitoring operating system. The application operating system and the safety monitoring operating system use different cores of the same processor. The application operating system is used to execute non-secure applications, and the safety monitoring operating system is communicatively connected to the application operating system to monitor the application operating system for safety. The in-vehicle system of the present application realizes the safety monitoring of the application operating system by using the safety monitoring operating system, and realizes the safety monitoring operating system and the application operating system respectively by using different cores of the same processor, realizes the isolation between the two, and can avoid the problem that the safety monitoring application cannot run normally due to the abnormal execution of the application in the application operating system. Therefore, the effectiveness of safety monitoring can be improved, and the safety performance of the in-vehicle system can be enhanced.

[0093] The present application provides for independently executing an AVM application on one system, allocating the multi-core SOC to the cores required for the safety monitoring operating system, the cores required for the second operating system, and the cores required for the first operating system, executing the AVM application on the second operating system, executing an Android application on the first operating system, executing a Safety Monitor on the safety monitoring operating system, monitoring the execution states of the second operating system and the first operating system, handling abnormal recovery, and achieving the effects of quick start (the AVM startup display can be completed in about 3S) and execution safety.

[0094] This application places the AVM application in the second operating system. Since the second operating system only needs to support the AVM application, it can be cropped very concisely, thereby achieving the purpose of quick start. In addition, compared with the complex and huge first operating system, the simple second operating system has fewer services to execute and a single application, so it is more stable and secure. Also, since the first operating system and the second operating system are isolated, even if an abnormality occurs in the execution of the first operating system, it will not affect the second operating system.

[0095] The system architecture and method provided by this application can be applied not only to the scene of quick start and execution safety of AVM, but also to other module scenes such as quick start of background in smart cabins, quick start of in-vehicle instruments, and quick start of in-vehicle DMS systems.

[0096] The above are only embodiments of this application, and do not limit the patent scope of this application. Any equivalent structure or equivalent flow conversion made using the content of this application specification and drawings, or those directly or indirectly applied to other related technical fields, are all included in the patent protection scope of this application.

[0097] This application claims the priority of a Chinese patent application with an application number of 2022108132200 and an application title of "In-vehicle System Based on Multi-operating System and Its Control Method", which was filed with the Chinese Patent Office on July 11, 2022, and all of its content is incorporated into this application by reference.

Claims

1. An in-vehicle system based on a multi-operating system, comprising: at least one application operating system and a safety monitoring operating system; wherein the application operating system and the safety monitoring operating system use different cores of the same processor; the application operating system is used to execute non-secure applications; the safety monitoring operating system is communicatively connected to the application operating system to execute a safety monitoring service for safety monitoring the application operating system; An in-vehicle system based on a multi-operating system, characterized in that.

2. The application operating system includes a second operating system that uses a different core of the safety monitoring operating system and the processor. The second operating system is used to execute quick-start applications, and the second operating system is configured to load only resource items on which the quick-start applications depend; the safety monitoring operating system is communicatively connected to the second operating system to safety monitor the second operating system; The in-vehicle system according to claim 1, characterized in that.

3. The application operating system further includes a first operating system communicatively connected to the safety monitoring operating system, and the safety monitoring operating system is further used to safety monitor the first operating system; The in-vehicle system according to claim 2, characterized in that.

4. The in-vehicle system further includes an on-chip system, and the on-chip system is provided with a plurality of physical cores, and at least one of the physical cores is assigned to each of the first operating system, the safety monitoring operating system, and the second operating system; The in-vehicle system according to claim 3, characterized in that.

5. The in-vehicle system further includes an on-chip system and a core virtualization system. The on-chip system is provided with physical cores. The core virtualization system virtualizes at least some of the physical cores into a plurality of virtual cores. The on-chip system allocates at least one of the virtual cores and / or at least one of the physical cores to the first operating system, the safety monitoring operating system, and the second operating system respectively. The in-vehicle system according to claim 3, characterized in that.

6. A control method for an in-vehicle system based on a multi-operating system, comprising: The in-vehicle system includes at least one application operating system and a safety monitoring operating system. The application operating system includes a second operating system that uses different cores of the same processor as the safety monitoring operating system. The second operating system is used to execute quick start applications. The control method includes: Configuring cores for the second operating system and the safety monitoring operating system; Obtaining a power-on startup command, loading a mirror file of the safety monitoring operating system into the running memory of the in-vehicle system, and starting the execution of the core corresponding to the safety monitoring operating system to complete the startup of the safety monitoring operating system and its safety monitoring service; Loading the Kernel of the second operating system into the running memory, starting the execution of the core corresponding to the second operating system, and sequentially completing the driver loading of the second operating system, the startup of the services on which the quick start application depends, and the startup of the quick start application. A control method for an in-vehicle system based on a multi-operating system, characterized in that.

7. The application operating system further includes a first operating system that uses different cores of the processor from the safety monitoring operating system and the second operating system. The control method further includes: configuring a core for the first operating system; loading the Kernel of the first operating system into the running memory, starting the execution of the core corresponding to the first operating system, and sequentially completing the driver loading, service startup, and application startup of the first operating system; The control method according to claim 6, characterized in that.

8. Configuring cores for the first operating system, the second operating system, and the security monitoring operating system includes: allocating at least one physical core to each of the security monitoring operating system, the second operating system, and the first operating system, or virtualizing at least a part of the physical cores into a plurality of virtual cores; allocating at least one of the virtual cores and / or at least one of the physical cores to each of the security monitoring operating system, the second operating system, and the first operating system. The control method according to claim 7, characterized in that.

9. Configuring a core for the second operating system includes: allocating a preset number of cores to the second operating system. The control method further includes: after the startup of the second operating system is completed, releasing a part of the cores to the first operating system. The control method according to claim 7, characterized in that.

10. The control method further includes: the application operating system writing a message to the shared memory; the application operating system triggering the security monitoring operating system to receive the interrupt by writing an interrupt; after receiving the interrupt, the security monitoring operating system entering an interrupt handler and reading the message from the shared memory. The control method according to claim 6, characterized in that.

11. The application operating system sending a message to the security monitoring operating system. The safety monitoring operation determines the execution state of the application operating system based on the message or the waiting time for receiving the message, and when the execution state is an abnormal state, the safety monitoring operating system further includes restarting the application operating system. The control method according to claim 6, characterized by the above.

Citation Information

Patent Citations

  • Vehicles with multiple user interface operating domains

    JP2017507401A

  • Method, apparatus, device, and medium for starting virtual machine

    JP2020194521A

  • Control unit for vehicle, display system for vehicle, and display control method for vehicle

    JP2020201761A

  • Vehicle drawing device

    JP2022033216A

  • Multi-Operating System

    US20150058611A1