Vehicle control method and vehicle
The vehicle control method addresses the reliability issues of in-vehicle software by dynamically transferring application software execution from failing control chips to healthy ones, ensuring continuous operation and improved reliability.
Patent Information
- Application Number
- JP2024572489
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-06-24
- Filing Date
- 2023-02-22
- Publication Date
- 2025-06-19
Smart Images

Figure 2025518932000001_ABST
Abstract
Description
Technical Field
[0001] Cross - reference to Related Applications This disclosure claims priority to Chinese Patent Application No. 202210730848.4, titled "VEHICLE CONTROL METHOD, VEHICLE, AND COMPUTER - READABLE STORAGE MEDIUM", filed on June 24, 2022, the entire content of which is incorporated herein by reference.
[0002] This disclosure relates to the field of electric vehicles, and more specifically, to a vehicle control method and a vehicle.
Background Art
[0003] With the continuous development of automotive intelligence, automotive software has become more complex, and higher requirements are also presented for the scalability and reliability of in - vehicle software that supports autonomous driving.
[0004] Regarding existing in - vehicle software architectures, in - vehicle software is generally bound to the underlying hardware. However, when the processor resources in the underlying layer are limited, the functions of some in - vehicle software are disabled. Or, when there is a fault in the processor in the underlying layer, the in - vehicle software executed by that processor completely fails to function, affecting the reliability of that in - vehicle software.
Summary of the Invention
Problems to be Solved by the Invention
[0005] Currently, in - vehicle software is bound to the underlying hardware, and when there is a fault in the processor, it causes the problem that the in - vehicle software executed by that processor fails to function.
[0006] The first object of the present disclosure is to provide a new technical solution for a vehicle control method applied to a processor.
[0007] The second object of the present disclosure is to provide a new technical solution for a vehicle control method applied to a control chip.
[0008] The third object of the present disclosure is to provide a new technical solution for a vehicle.
Means for Solving the Problems
[0009] The first aspect of the present disclosure provides a vehicle control method. This method includes the following.
[0010] The execution states of a plurality of control chips are acquired.
[0011] When the execution state of the first control chip among the plurality of control chips indicates that any of the set events has occurred in the first control chip, configuration instructions for executing the first application software are transmitted to the second control chip among the plurality of control chips. The first application software is the application software currently executed by the first control chip.
[0012] According to an embodiment of the present disclosure, the set event includes at least one of an execution failure and a resource usage amount exceeding a first threshold value.
[0013] According to an embodiment of the present disclosure, the set event includes an execution failure, and when the execution state of the first control chip among the plurality of control chips indicates that any of the set events has occurred in the first control chip, the fact that the configuration instructions for executing the first application software are transmitted to the second control chip among the plurality of control chips includes the following.
[0014] When the execution state of the first control chip indicates that an execution failure has occurred in the first control chip, the first configuration instructions for executing all the first application softwares are sent to the second control chip.
[0015] According to one embodiment of the present disclosure, the set event includes that the resource usage exceeds the first threshold value. When the execution state of the first control chip among the plurality of control chips indicates that any one of the set events has occurred in the first control chip, the configuration instructions for executing the first application software are sent to the second control chip among the plurality of control chips, including the following.
[0016] When the execution state of the first control chip indicates that the resource usage of the first control chip exceeds the first threshold value, the second configuration instructions for executing some of the first application softwares are sent to the second control chip.
[0017] According to one embodiment of the present disclosure, the second configuration instructions for executing some of the first application softwares being sent to the second control chip include the following.
[0018] Based on the first parameters of all the first application softwares currently executed by the first control chip, some of the first application softwares are selected from all the first application softwares, and the second configuration instructions for executing some of the first application softwares are sent to the second control chip.
[0019] The first parameter includes at least one of a load value and a priority.
[0020] According to an embodiment of the present disclosure, the first parameter is a load value, and some first application software is the first application software having the maximum load value among all the first application software.
[0021] According to an embodiment of the present disclosure, the first parameter is a priority, and some first application software is the first application software having the lowest priority among all the first application software.
[0022] According to an embodiment of the present disclosure, the second control chip is any one of the control chips in which the set event has not occurred among a plurality of control chips.
[0023] Alternatively, the second control chip is the control chip having the minimum load value in which the set event has not occurred among a plurality of control chips.
[0024] According to an embodiment of the present disclosure, after the configuration instruction for executing the first application software is transmitted to the second control chip among a plurality of control chips, this method further includes the following.
[0025] A first message is transmitted to the second application software to cause the second application software to communicate with the first application software being executed by the second control chip.
[0026] The second application software is application software that interacts with the first application software.
[0027] The second aspect of the present disclosure provides a vehicle control method. This method includes the following.
[0028] The configuration instruction transmitted by the processor is received.
[0029] The first application software is executed according to a configuration command.
[0030] The first application software is the application software currently executed by the first control chip, and the first control chip is a control chip among a plurality of control chips of the vehicle in which any one of the set events has occurred.
[0031] According to an embodiment of the present disclosure, the software architecture of a vehicle includes middleware, the middleware includes a plurality of atomization services, and the execution of the first application software includes the following.
[0032] An atomization service corresponding to the first application software is selected from the plurality of atomization services.
[0033] The atomization service corresponding to the first application software is called, service data of the atomization service corresponding to the first application software is acquired, and a control command is generated based on the service data.
[0034] The corresponding processor is controlled to execute the function corresponding to the first application software according to the control command.
[0035] A third aspect of the present disclosure provides a vehicle. This vehicle a memory configured to store computer-executable instructions, a processor configured to execute a vehicle control method according to the first aspect of the present disclosure based on the control of the computer-executable instructions.
[0036] Other features and advantages of the present disclosure will become apparent from the following detailed description of exemplary embodiments of the present disclosure with reference to the drawings.
[0037] The accompanying drawings, which are incorporated herein and constitute a part of this specification, illustrate embodiments in accordance with the present disclosure and, together with the specification, are used to describe the principles of the present disclosure.
Brief Description of the Drawings
[0038]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Modes for Carrying Out the Invention
[0039] Here, various exemplary embodiments of the present disclosure will be described in detail with reference to the accompanying drawings. It should be noted that, unless otherwise specified, the opposing arrangements, mathematical formulas, and numerical values of the components and steps described in these embodiments do not limit the scope of the present disclosure.
[0040] The following description of at least one exemplary embodiment is merely illustrative and in no way constitutes a limitation on the present disclosure or on the application or use of the present disclosure.
[0041] Technologies, methods, and devices known to those of ordinary skill in the relevant technical fields may not be discussed in detail, but where appropriate, those technologies, methods, and devices should be regarded as part of this specification.
[0042] In all examples shown and discussed in this specification, any specific values should be construed merely as examples and not as limitations. Therefore, other examples of exemplary embodiments may have different values.
[0043] It should be noted that in the subsequent accompanying drawings, the same numbers and letters represent the same items. Therefore, once an item is defined in a particular accompanying drawing, that item does not need to be further discussed in subsequent accompanying drawings.
[0044] Hereinafter, the vehicle control method provided in the embodiments of the present disclosure will be described in detail with reference to the accompanying drawings.
[0045] As shown in FIG. 1, the software architecture of a vehicle implementing the vehicle control method continuously includes a hardware layer, a virtual technology layer, middleware, and an application layer from bottom to top.
[0046] The hardware layer includes a processor and a plurality of control chips. The processor is configured to constitute application software executed by the plurality of control chips. The control chips are configured to execute the application software in the application layer. The processor can be, for example, a microcontroller unit (MCU). The control chip can be, for example, a system on chip (SOC).
[0047] The virtual technology layer can provide a virtual machine environment for various operating systems. The virtual machine environment is a complete computer system, which is simulated by software, has complete hardware system functions, and operates in a completely isolated environment.
[0048] The middleware includes a system function interface layer, communication services, and multiple atomization services. For example, as shown in FIG. 1, the middleware includes atomization service A, atomization service B, and atomization service C. The system function interface layer is configured to access the communication services and each atomization service. Application softwares executed by separate control chips can communicate by using the communication services. The atomization service is an indivisible basic service unit that constitutes an application and is also the smallest unit that can be managed and assigned permissions by the operating system. The atomization service can be shared by multiple application softwares. It can be understood here that the atomization service can be designed based on the application software to be executed. For example, the atomization service can include video services, millimeter wave radar services, lidar services, location services, camera services, etc.
[0049] The application layer includes multiple application softwares. In the scenario of autonomous driving, the application layer can include, but is not limited to, Navigate on Autopilot (NOA) application software, Autonomous Valet Parking (AVP) application software, Driver Monitoring System (DMS) application software, etc. The NOA application software can enable the automatic assisted navigation driving function and automatically control the vehicle to enter or exit the highway ramp based on the destination input by the user. The AVP application software can enable the autonomous valet parking function. When the autonomous valet parking function is enabled, the vehicle can be controlled to automatically search for a parking space and park, or the vehicle can be automatically called out to wait at a designated location. The DMS application software can enable the fatigue monitoring function. The DMS application software can use features of the driver's face, eye signs, head movements, etc. to infer the driver's fatigue state, give a warning prompt, and take corresponding measures.
[0050] In the execution process, in response to a trigger operation performed by a user on application software, the application layer 11 can call the atomization service corresponding to the application software in the middleware to obtain the function corresponding to the application software. As an example, the NOA application software is used. The video service, millimeter wave radar service, lidar service, and location service can be called to perform obstacle recognition and obtain the recognition result. Based on the recognition result, a control command is generated, and the control command is sent to the corresponding processor to cause the processor to execute the control command, thereby implementing the corresponding function of the NOA application software.
[0051] According to this embodiment of the present disclosure, by designing the atomization service of the middleware, it is possible to isolate the application software in the application layer from the lower-layer software and hardware, and it is possible to flexibly deploy the application software on separate control chips in the hardware layer. In addition, redundant protection for failures of the control chips is implemented, thereby ensuring the normal execution of all application software and improving the reliability of the execution of the vehicle software architecture.
[0052] Figure 2 is a schematic flowchart of a vehicle control method according to an embodiment of the present disclosure. This vehicle control method is implemented by a processor. The processor is communicatively connected to a plurality of control chips. As shown in Figure 2, this vehicle control method can include step S2100 and step S2200.
[0053] Step S2100: The execution states of a plurality of control chips are obtained.
[0054] Step S2200: When the execution state of the first control chip among the plurality of control chips indicates that any of the set events has occurred in the first control chip, the configuration instruction to execute the first application software is transmitted to the second control chip among the plurality of control chips. The first application software is the application software currently executed by the first control chip.
[0055] In this embodiment, when an execution failure occurs in the control chip, the application software executed by that control chip becomes inoperative. In addition, when the resources of that control chip reach a bottleneck, the application software executed by that control chip is also affected. Considering this, the set events include at least one of an execution failure and the resource usage exceeding a first threshold.
[0056] The execution state can be used to determine whether any of the set events has occurred in the control chip. For example, the execution state can be the communication state of the control chip, and based on the communication state of the control chip, it is possible to determine whether an execution failure has occurred in the control chip. Specifically, the heartbeat signal transmitted by the control chip can be monitored to determine whether the communication state of the control chip is normal. When the communication state of the control chip is abnormal, it is determined that an execution failure has occurred in the control chip.
[0057] For example, the execution state can include the resource usage of the control chip. Specifically, it is possible to obtain the resource usage of the control chip. The resource usage of the control chip is compared with a first threshold value, and based on the resource usage of the control chip, it is possible to determine whether the resource usage of the control chip exceeds the first threshold value, that is, it is possible to determine whether the resources of the control chip have reached the upper limit. It can be understood here that the resource usage can be the CPU usage or the memory usage.
[0058] In one embodiment, the second control chip is configured to execute the first application software currently being executed by the first control chip in which a set event has occurred. The second control chip can be any one of the control chips in which the set event has not occurred among the plurality of control chips.
[0059] For example, the second control chip can be a specified control chip among the plurality of control chips. In other words, the plurality of control chips includes an alternative second control chip, and the second control chip is in an idle state when the set event does not occur in the plurality of control chips. In this way, since the resources of the alternative second control chip are sufficient, it is possible to ensure the normal execution of the first application software, and it is possible to prevent the normal execution of the application software on another control chip from being affected.
[0060] For example, the second control chip can be the control chip with the minimum load value among the plurality of control chips where the set event has not occurred. In this way, when the set event occurs in the first control chip among the plurality of control chips, the first application software being executed by the first control chip can be transferred to the control chip with the minimum load value among the other control chips, thereby ensuring the normal execution of the first application software currently being executed by the first control chip. In addition, it is possible to prevent the normal execution of the application software on the second control chip from being affected due to the resources of the second control chip reaching the upper limit.
[0061] The process of configuring the control chip when various set events occur in the control chip is described hereinafter by using specific embodiments.
[0062] In one embodiment, the set event includes an execution failure, and when the execution state of the first control chip among the plurality of control chips indicates that any of the set events has occurred in the first control chip, the configuration instructions for executing the first application software are transmitted to the second control chip among the plurality of control chips, which includes that when the execution state of the first control chip indicates that an execution failure has occurred in the first control chip, all the first configuration instructions for executing the first application software are transmitted to the second control chip.
[0063] The configuration process shown in FIG. 3 is used as an example. The hardware layer of the software architecture includes control chip A, control chip B, and control chip C. Control chip A executes the NOA application software, control chip B executes the AVP application software, and control chip C executes the DMS application software. The execution states of control chip A, control chip B, and control chip C are obtained separately. If an execution failure occurs in control chip C, if the load value of control chip B is the minimum, the first configuration instruction is sent to control chip B to cause the DMS application software to be executed on control chip B, that is, after the application software is redeployed, control chip B executes the AVP application software and the DMS application software.
[0064] In this embodiment, when an execution failure occurs in a certain control chip among multiple control chips, the application software currently executed by that control chip can be dynamically deployed on another control chip, thereby implementing redundant protection against control chip failures, thereby preventing the execution failure of the control chip from affecting the execution of another application software and improving the reliability of executing the software architecture of the vehicle.
[0065] In another embodiment, the set event includes that the resource usage exceeds a first threshold, and when the execution state of the first control chip among the plurality of control chips indicates that any of the set events has occurred in the first control chip, the configuration instruction to execute the first application software is transmitted to the second control chip among the plurality of control chips. When the execution state of the first control chip indicates that the resource usage of the first control chip exceeds the first threshold, it includes that the second configuration instruction to execute some of the first application software is transmitted to the second control chip.
[0066] In this embodiment, that the second configuration instruction to execute some of the first application software is transmitted to the second control chip may further include that some of the first application software is selected from all the first application software currently executed by the first control chip based on the first parameters of all the first application software, and the second configuration instruction to execute some of the first application software is transmitted to the second control chip.
[0067] Based on the first parameters, it is possible to select some of the first application software from all the first application software currently executed by the first control chip. Optionally, the first parameters include at least one of a load value and a priority. The load value of the application software can reflect the quantity of resources required to execute the application software. The priority of the application software can reflect the importance of the service corresponding to the application software. The higher the priority of the application software, the higher the importance of the service corresponding to the application software.
[0068] Some of the first application software can be one or more of the first application software currently executed by the first control chip.
[0069] For example, when the first parameter is a load value, some of the first application software is the first application software having the maximum load value among all the first application software. In this way, when the resource usage of the first control chip exceeds the first threshold, the first application software having the maximum resource usage on the first control chip is migrated to the second control chip for execution, thereby effectively reducing the resource usage of the first control chip and ensuring the normal execution of another first application software on the first control chip.
[0070] For example, when the first parameter is a load value, based on the load values of the first application software, a preset amount of the first application software among all the first application software is executed on the second control chip. For example, two pieces of the first application software having larger load values among all the first application software currently executed by the first control chip can be used as some of the first application software and executed on the second control chip. In this way, when the resource usage of the first control chip exceeds the first threshold, a plurality of the first application software among all the first application software currently executed by the first control chip is migrated to the second control chip for execution, thereby effectively reducing the execution pressure of the first control chip and ensuring the normal execution of another first application software on the first control chip.
[0071] For example, when the first parameter is the priority, some first application software is the first application software with the lowest priority among all the first application software. In this way, when the resource usage amount of the first control chip exceeds the first threshold value, the first application software with the lowest priority among all the first application software currently executed by the first control chip is transferred to the second control chip for execution, thereby preventing the execution of important services from being affected, and thereby making it possible to ensure the reliability of the execution of the vehicle's software architecture.
[0072] For example, when the first parameter is the priority, based on the priority of the first application software, a preset amount of the first application software among all the first application software is executed on the second control chip. In this way, the execution pressure of the first control chip is effectively reduced, thereby making it possible to ensure the normal execution of another first application software on the first control chip. In addition, the execution of important services is prevented from being affected, and thereby making it possible to ensure the reliability of the execution of the vehicle's software architecture.
[0073] Hereinafter, this embodiment will be described by using the configuration process shown in FIG. 4. As shown in FIG. 4, the hardware layer of the software architecture includes a control chip A and a control chip B. The control chip A runs the NOA application software and the DMS application software, and the control chip B runs the AVP application software. The hardware layer of the software architecture further includes an alternative control chip C. The resource usage of the control chip A and the resource usage of the control chip B are obtained separately. When the resource usage of the control chip B exceeds a first threshold, a second configuration command is sent to the control chip C to cause the control chip C to execute the DMS application software with the maximum load value. In other words, after the application software is redeployed, the control chip A runs the NOA application software, the control chip B runs the AVP application software, and the control chip C runs the DMS application software.
[0074] In this embodiment, when the resource usage of a certain control chip among multiple control chips exceeds a first threshold, some of the application software currently being executed by that control chip can be relocated to another control chip, thereby effectively reducing the execution pressure on the first control chip, ensuring the normal execution of another first application software on the first control chip, and enabling the software architecture of the vehicle to have better scalability.
[0075] In one embodiment, after the configuration instructions for executing the first application software are sent to the second control chip among the plurality of control chips, the method further includes sending a first message to the second application software to cause the second application software to communicate with the first application software being executed by the second control chip. The second application software is application software that interacts with the first application software.
[0076] Specifically, the second application software can establish a communication connection to the first application software by using communication services in the middleware of the software architecture.
[0077] In this embodiment, the configuration instructions for executing the first application software are sent to the second control chip among the plurality of control chips, and the first message is sent to the second application software that interacts with the first application software, notifying the second application software to communicate with the redeployed first application software, thereby ensuring the normal execution of the second application software.
[0078] Hereinafter, a specific example will be used to describe the vehicle control method. Referring to FIG. 5, this vehicle control method includes the following steps.
[0079] Step S501: The processor obtains the execution states of the plurality of control chips.
[0080] Step S502: The processor determines whether a first control chip with an execution failure exists among the plurality of control chips. If so, step S503 is executed; otherwise, step S501 is executed.
[0081] Step S503: The processor sends a first configuration instruction to the second control chip in order to cause the second control chip to execute all of the first application software.
[0082] The first application software is the application software currently being executed by the first control chip.
[0083] Step S504: The processor sends a first message to the second application software in order to notify the second application software to communicate with the first application software being executed by the second control chip.
[0084] The second application software is application software that interacts with the first application software.
[0085] In this example, if an execution failure occurs in one of the multiple control chips, the application software currently being executed by that control chip can be dynamically deployed on another control chip, thereby implementing redundant protection against control chip failures, thereby preventing the execution failure of the control chip from affecting the execution of another application software and improving the reliability of executing the vehicle's software architecture.
[0086] Hereinafter, another specific example will be used to describe the vehicle control method. Referring to FIG. 6, this vehicle control method includes the following steps.
[0087] Step S601: The processor obtains the resource usage amounts of the multiple control chips.
[0088] Step S602: The processor determines whether there is a first control chip among a plurality of control chips whose resource usage exceeds a first threshold. If the answer is "yes", it executes step S603; otherwise, it executes step S601.
[0089] Step S603: The processor sends a second configuration instruction to the second control chip in order to cause the second control chip to execute some first application software.
[0090] The first application software is the application software currently being executed by the first control chip.
[0091] Step S604: The processor sends a first message to the second application software in order to notify the second application software to communicate with the first application software being executed by the second control chip.
[0092] The second application software is the application software that interacts with the first application software.
[0093] In this example, if the resource usage of a certain control chip among a plurality of control chips exceeds the first threshold, some application software currently being executed by that control chip can be relocated to another control chip, thereby effectively reducing the execution pressure on the first control chip, ensuring the normal execution of another first application software on the first control chip, and making it possible for the software architecture of the vehicle to have better scalability.
[0094] According to this embodiment of the present disclosure, in the process of executing application software in the application layer, the execution states of a plurality of control chips are acquired, and when the execution state of the first control chip among the plurality of control chips indicates that any of the set events is occurring in the first control chip, the configuration instruction for executing the first application software is transmitted to the second control chip among the plurality of control chips, and the first application software currently being executed by the first control chip is transferred to the second control chip for execution, thereby dynamically deploying the application software and enabling flexible expansion of the application software. In addition, redundant protection for control chip failures is implemented, thereby ensuring the normal execution of all application software and improving the reliability of the execution of the vehicle software architecture.
[0095] FIG. 7 is a schematic flowchart of another vehicle control method according to an embodiment of the present disclosure. This vehicle control method is implemented by a control chip. As shown in FIG. 7, this vehicle control method may include step S7100 and step S7200.
[0096] Step S7100: A configuration instruction transmitted by a processor is received.
[0097] Step S7200: The first application software is executed according to the configuration instruction, and the first application software is the application software currently being executed by the first control chip, and the first control chip is the control chip in which any of the set events is occurring among the plurality of control chips of the vehicle.
[0098] In this embodiment, the hardware layer of the vehicle's software architecture includes a plurality of control chips, and the plurality of control chips can include a first control chip and a second control chip. During a specific implementation, the second control chip receives configuration instructions sent by a processor. The second control chip executes the first application software according to the configuration instructions.
[0099] In this embodiment, the set events include at least one of an execution failure and a resource usage exceeding a first threshold. The configuration instructions include a first configuration instruction and a second configuration instruction.
[0100] When the configuration instruction is the first configuration instruction, the first configuration instruction is a configuration instruction for executing all the first application software that is sent to the second control chip when an execution failure occurs in the first control chip. The second control chip executes all the first application software according to the first configuration instruction.
[0101] When the configuration instruction is the second configuration instruction, the second configuration instruction is a configuration instruction for executing some of the first application software that is sent to the second control chip when the resource usage of the first control chip exceeds the first threshold. The second control chip executes some of the first application software according to the second configuration instruction.
[0102] According to this embodiment of the present disclosure, a configuration command transmitted by a processor is received, and in response to the configuration command, a first application software is executed to transfer the first application software currently being executed by a first control chip to a second control chip for execution, thereby dynamically deploying the application software and enabling flexible expansion of the application software. In addition, redundant protection against failures of the control chip is implemented, thereby ensuring the normal execution of all application software and improving the reliability of the execution of the vehicle's software architecture.
[0103] In one embodiment, the vehicle's software architecture includes middleware, the middleware includes a plurality of atomization services, and the execution of the first application software may further include that an atomization service corresponding to the first application software is selected from the plurality of atomization services. The atomization service corresponding to the first application software is called, the service data of the atomization service corresponding to the first application software is obtained, and a control command is generated based on the service data. A corresponding processor is controlled to execute the function corresponding to the first application software according to the control command.
[0104] The atomization service is an indivisible basic service unit that constitutes an application and is also the smallest unit that can be managed and have permissions assigned by the operating system. The atomization service can be shared by multiple application softwares. It can be understood here that the atomization service can be designed based on the application software to be executed. For example, the atomization service can include video services, millimeter-wave radar services, lidar services, location services, camera services, etc.
[0105] The corresponding processor can be a processor configured to execute control instructions.
[0106] An example of executing the NOA application software is used. The video service, millimeter-wave radar service, lidar service, and location service in multiple atomization services are called. Based on the service data of the video service, millimeter-wave radar service, lidar service, and location service, an obstacle recognition result is obtained. A control instruction is generated based on the obstacle recognition result, and the control instruction is sent to the corresponding processor to cause the processor to execute the control instruction, thereby implementing the navigate-on autopilot function.
[0107] In this embodiment, by designing the middleware atomization service, the application software in the application layer can be separated from the underlying software and hardware, and the application software can be flexibly deployed on separate control chips in the hardware layer. In addition, redundant protection against control chip failures is implemented, thereby ensuring the normal execution of all application software and improving the reliability of the execution of the vehicle's software architecture.
[0108] FIG. 8 shows a vehicle control device according to an embodiment of the present disclosure. This vehicle control device is used in a processor. The processor is communicably connected to a plurality of control chips. As shown in FIG. 8, the vehicle control device 800 can include an acquirer 810 and a configurator 820.
[0109] The acquirer 810 can be configured to acquire the execution states of a plurality of control chips.
[0110] The configurator 820 is configured to send configuration instructions for executing the first application software to the second control chip among the plurality of control chips when the execution state of the first control chip among the plurality of control chips indicates that any of the set events has occurred in the first control chip. The first application software is the application software currently executed by the first control chip.
[0111] In one embodiment, the set events include at least one of an execution failure and a resource usage amount exceeding a first threshold.
[0112] In one embodiment, the set event includes an execution failure, and the configurator 820 is specifically configured to send, to the second control chip, first configuration instructions for executing all first application software when the execution state of the first control chip indicates that an execution failure has occurred in the first control chip.
[0113] In one embodiment, the set event includes that the resource usage exceeds a first threshold, and the configurator 820 is specifically configured to send, to the second control chip, second configuration instructions for executing some first application software when the execution state of the first control chip indicates that the resource usage of the first control chip exceeds the first threshold.
[0114] In one embodiment, sending, to the second control chip, second configuration instructions for executing some first application software includes selecting some first application software from all first application software based on first parameters of all first application software currently executed by the first control chip, and sending, to the second control chip, second configuration instructions for executing some first application software. The first parameters include at least one of a load value and a priority.
[0115] In one embodiment, the first parameter is a load value, and some first application software is the first application software having the maximum load value among all first application software.
[0116] In one embodiment, the first parameter is a priority, and some first application software is the first application software having the lowest priority among all first application software.
[0117] In one embodiment, the second control chip is any one of the control chips among the plurality of control chips in which the set event has not occurred. Alternatively, the second control chip is the control chip having the minimum load value among the plurality of control chips in which the set event has not occurred.
[0118] In one embodiment, the vehicle control device 800 may further include a transmission module configured to transmit a first message to a second application software in order to cause the second application software to communicate with the first application software being executed by the second control chip. The second application software is application software that interacts with the first application software.
[0119] According to this embodiment of the present disclosure, in the process of executing the application software in the application layer, the execution states of the plurality of control chips are acquired, and when the execution state of the first control chip among the plurality of control chips indicates that any one of the set events has occurred in the first control chip, the configuration instruction for executing the first application software is transmitted to the second control chip among the plurality of control chips, and the first application software currently being executed by the first control chip is transferred to the second control chip for execution, thereby dynamically deploying the application software, and thereby enabling flexible expansion of the application software. In addition, redundant protection against failures of the control chips is implemented, thereby ensuring the normal execution of all application software and improving the reliability of the execution of the vehicle software architecture.
[0120] Figure 9 shows another vehicle control device according to an embodiment of the present disclosure. This vehicle control device is used in a control chip. As shown in Figure 9, the vehicle control device 900 can include a receiver 910 and a runner 920.
[0121] The receiver 910 can be configured to receive configuration instructions transmitted by a processor.
[0122] The runner 920 can be configured to execute first application software according to the configuration instructions. The first application software is the application software currently executed by the first control chip, and the first control chip is the control chip in which any one of the set events among a plurality of control chips of the vehicle has occurred.
[0123] In one embodiment, the software architecture of the vehicle includes middleware, the middleware includes a plurality of atomization services, and the runner 920 is specifically configured to select an atomization service corresponding to the first application software from the plurality of atomization services, call the atomization service corresponding to the first application software, obtain service data of the atomization service corresponding to the first application software, generate a control command based on the service data, and control the corresponding processor to execute the function corresponding to the first application software according to the control command.
[0124] According to this embodiment of the present disclosure, a configuration command transmitted by a processor is received, and in response to the configuration command, a first application software is executed to transfer the first application software currently executed by a first control chip to a second control chip for execution, thereby dynamically deploying the application software and enabling flexible expansion of the application software. In addition, redundant protection against failures of the control chip is implemented, thereby ensuring the normal execution of all application software and improving the reliability of the execution of the vehicle's software architecture.
[0125] FIG. 10 shows a vehicle according to an embodiment of the present disclosure. As shown in FIG. 10, the vehicle 100 includes a memory 101 and a processor 102. The memory 101 is configured to store computer-executable instructions. The processor 102 is configured to execute the vehicle control method according to the foregoing embodiment based on the control of the computer-executable instructions.
[0126] In this embodiment, the software architecture of the vehicle 100 is shown in FIG. 1.
[0127] An embodiment of the present disclosure further provides a computer-readable storage medium. This computer-readable storage medium stores computer instructions, and those computer instructions can be read and executed by a computer. When the computer instructions are executed by a processor, the vehicle control method according to the foregoing embodiment is executed.
[0128] The embodiments described in this specification are all described in a progressive manner. For the same or similar parts in these embodiments, cross-references can be made. The description of each embodiment focuses on the differences from other embodiments. However, those skilled in the art should clearly understand that the foregoing embodiments can be used alone or in combination with each other as necessary. In addition, the device embodiments basically correspond to the method embodiments and are therefore described briefly. For related parts, refer to the partial description in the method embodiments. The system embodiments described above are only examples, and the modules described as separate parts can be physically separate or not physically separate.
[0129] The present disclosure can be implemented as a system, a method, and / or a computer program product. The computer program product can include a computer-readable storage medium that holds computer-readable program instructions for causing a processor to implement aspects of the present disclosure.
[0130] A computer-readable storage medium can be a tangible device that can hold and store instructions for use by an instruction execution device. The computer-readable storage medium can be, for example, an electrical storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any combination thereof, but is not limited thereto. More specific examples (non-exhaustive list) of computer-readable storage media include portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), compact disk read-only memory (CD-ROM), digital versatile disk (DVD), memory stick, floppy disk, mechanical coding devices such as punch cards or raised structures in grooves that store instructions, and any suitable combination thereof. The computer-readable storage medium here is not to be construed as a transient signal such as a radio wave or another freely propagating electromagnetic wave, an electromagnetic wave propagated by a waveguide or another transmission medium (e.g., an optical pulse propagated by an optical fiber cable), or an electrical signal transmitted by an electric wire.
[0131] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to respective computing / processing devices, or can be downloaded through a network, such as the Internet, a local area network, a wide area network, and / or a wireless network, to an external computer or an external storage device. The network can include copper wire transmission cables, optical fiber transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter or network interface in each computing / processing device receives the computer-readable program instructions from the network and transfers the computer-readable program instructions, whereby the computer-readable program instructions are stored in the computer-readable storage medium in each computing / processing device.
[0132] The computer program instructions for executing the operations of the present disclosure can be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state setting data, or source code or target code written in any combination of one or more programming languages. The programming languages include object-oriented programming languages such as Smalltalk and C++, and conventional programming languages such as "C" or similar programming languages. The computer-readable program instructions can be executed entirely on a user computer, partially executed on a user computer, executed as an independent software package, partially executed on a user computer and partially executed on a remote computer, or executed entirely on a remote computer or server. In cases involving a remote computer, the remote computer can be connected to the user's computer through any type of network including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (for example, through the Internet by using an Internet service provider). In some embodiments, an electronic circuit such as a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA) can be personalized by using the state information of the computer-readable program instructions. The electronic circuit can execute the computer-readable program instructions to implement aspects of the present disclosure.
[0133] Aspects of the present disclosure are described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present disclosure. It should be understood that each block of the flowcharts and / or block diagrams, as well as combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer-readable program instructions.
[0134] These computer-readable program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or another programmable data processing device to produce a machine, such that the instructions executed by the processor of the computer or another programmable data processing device create a device for implementing the functions / acts specified in one or more blocks in the flowchart and / or block diagram. These computer-readable program instructions can alternatively be stored in a computer-readable storage medium. These instructions enable a computer, a programmable data processing device, and / or another device to operate in a particular manner. Accordingly, the computer-readable medium storing the instructions includes a manufacturer that includes instructions for implementing aspects of the functions / acts specified in one or more blocks in the flowchart and / or block diagram.
[0135] Those computer-readable program instructions may alternatively be loaded onto a computer, other programmable data processing device, or other device to cause a series of operation steps to be performed on that computer, other programmable data processing device, or other device, thereby creating computer-implemented processing, and those instructions which execute on that computer, other programmable data processing device, or other device are used to implement the functions / actions specified in one or more blocks in the flowchart and / or block diagram.
[0136] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible embodiments of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a portion of an instruction. That module, that program segment, or that portion of the instruction contains one or more executable instructions for performing the specified logical function. In some alternative embodiments, functions annotated in the blocks can occur in a different order than the order annotated in the accompanying drawings. For example, in fact, two blocks shown consecutively can be executed basically in parallel, and in some cases, those two blocks can be executed in the reverse order. This is determined by the related functions. It should also be noted that each block in the block diagram and / or flowchart, as well as combinations of blocks in the block diagram and / or flowchart, can be implemented by using a dedicated hardware-based system configured to perform the specified function or action, or can be implemented by using a combination of dedicated hardware and computer instructions. It is well known to those skilled in the art that implementations in hardware form, in software form, and in combinations of software and hardware are equivalent.
[0137] Embodiments of the present disclosure have been described above. The foregoing description is exemplary, not exhaustive, and is not limited to the disclosed embodiments. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The terms used herein are intended to best explain the principles of the embodiments, practical applications, or technical improvements in the market, or to enable others of ordinary skill in the art to understand the embodiments disclosed herein. The scope of the present disclosure is limited only by the appended claims.
Claims
1. Obtaining the execution states of a plurality of control chips; When the execution state of a first control chip among the plurality of control chips indicates that any of the set events has occurred in the first control chip, transmitting a configuration instruction to execute a first application software to a second control chip among the plurality of control chips, where the first application software is the application software currently being executed by the first control chip; A vehicle control method including the above.
2. The vehicle control method according to Claim 1, wherein the set event includes at least one of an execution failure and a resource usage amount exceeding a first threshold.
3. When the set event includes the execution failure and the execution state of a first control chip among the plurality of control chips indicates that any of the set events has occurred in the first control chip, transmitting the configuration instruction to execute the first application software to a second control chip among the plurality of control chips is When the execution state of the first control chip indicates that an execution failure has occurred in the first control chip, including transmitting a first configuration instruction to execute all of the first application software to the second control chip. The vehicle control method according to Claim 1.
4. When the set event includes the resource usage amount exceeding the first threshold and the execution state of a first control chip among the plurality of control chips indicates that any of the set events has occurred in the first control chip, transmitting the configuration instruction to execute the first application software to a second control chip among the plurality of control chips is When the execution state of the first control chip indicates that the resource usage of the first control chip exceeds the first threshold, the vehicle control method according to claim 1, comprising transmitting second configuration instructions for executing some first application software to the second control chip.
5. Transmitting the second configuration instructions for executing some first application software to the second control chip is Based on the first parameters of all the first application software currently executed by the first control chip, selecting some first application software from all the first application software, and transmitting the second configuration instructions for executing the some first application software to the second control chip, The vehicle control method according to claim 4, wherein the first parameter includes at least one of a load value and a priority.
6. The vehicle control method according to claim 5, wherein the first parameter is a load value, and the some first application software is the first application software having the maximum load value among all the first application software.
7. The vehicle control method according to claim 5, wherein the first parameter is a priority, and the some first application software is the first application software having the lowest priority among all the first application software.
8. The second control chip is any one of the control chips in the plurality of control chips where the set event has not occurred, or The vehicle control method according to claim 1, wherein the second control chip is the control chip having the minimum load value among the plurality of control chips where the set event has not occurred.
9. After transmitting the configuration instructions for executing the first application software to the second control chip among the plurality of control chips, Further including transmitting a first message to the second application software in order to cause the second application software to communicate with the first application software being executed by the second control chip, The vehicle control method according to claim 1, wherein the second application software is application software that interacts with the first application software.
10. Receiving configuration instructions transmitted by a processor, Executing first application software according to the configuration instructions and including The first application software is application software currently being executed by a first control chip, and the first control chip is a control chip among a plurality of control chips of a vehicle in which any one of the set events has occurred. The vehicle control method.
11. The software architecture of the vehicle includes middleware, the middleware includes a plurality of atomization services, and executing the first application software is Selecting an atomization service corresponding to the first application software from the plurality of atomization services, Invoking the atomization service corresponding to the first application software, obtaining service data of the atomization service corresponding to the first application software, and generating a control instruction based on the service data. Controlling the corresponding processor to execute a function corresponding to the first application software according to the control instruction The vehicle control method according to claim 10, comprising the above.
12. A memory configured to store computer-executable instructions A processor configured to execute the vehicle control method according to any one of claims 1 to 9 based on the control of the computer-executable instructions A vehicle comprising the above.
Citation Information
Patent Citations
Hypervisor, and arithmetic unit
JP2019139453A
Load leveling device, load leveling method, and load leveling program
JP2020071840A
Real-time communication processing system and real-time communication processing method
JP2021060858A
Parameter configuration method, apparatus and system
WO2022110970A1