SYSTEM, METHOD, AND APPARATUS FOR PERFORMING VEHICLE COMMUNICATIONS USING A ZONE ARCHITECTURE - Patent application
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- SONATUS INC
- Filing Date
- 2023-09-08
- Publication Date
- 2026-05-22
AI Technical Summary
Vehicles face a patchwork of networks with varying security capabilities and numerous overlapping communication paths, leading to design complexity, security risks, and difficulties in updating or monitoring these networks due to the diverse range of electronic devices and communication protocols.
A vehicle network system with a multi-zone architecture, including network zones managed by zone managers, a network management controller, and a zoned architecture communication scheme to control and secure communications across zones, integrating hardware redundancy and emergency response mechanisms.
The system simplifies network design, enhances security, and improves the ability to manage and update vehicle networks efficiently, reducing hardware costs and mitigating security breaches.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical Field]
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS This application claims priority to and is a continuation-in-part of U.S. patent application Ser. No. 17 / 570,738, filed January 7, 2022, entitled SYSTEM, METHOD, AND APPARATUS TO EXTRA VEHICLE COMMUNICATIONS CONTROL (SONA-0007-U01-C01), filed January 7, 2022.
[0002] U.S. Patent Application No. 17 / 570,738 (SONA-0007-U01-C01) is a continuation of and claims priority to U.S. Patent Application No. 17 / 027,187, filed September 21, 2020, entitled SYSTEM, METHOD, AND APPARATUS TO EXTRA VEHICLE COMMUNICATIONS CONTROL (SONA-0007-U01), which now issues as U.S. Patent No. 11,228,496.
[0003] Application No. 17 / 027,187 (SONA-0007-U01) is a subsidiary of U.S. Application No. 62 / 903,462, filed September 20, 2019, entitled SYSTEM, METHOD AND APPARATUS FOR A MIXED VEHICLE NETWORK (SONA-0001-P01), and U.S. Application No. 62 / 911,249, filed October 5, 2019, entitled SYSTEM, METHOD AND APPARATUS FOR A MIXED VEHICLE NETWORK (SONA-0002-P01), entitled SYSTEM, METHOD AND APPARATUS FOR CLOUD-BASED INTERACTIONS WITH A MIXED VEHICLE This application claims benefit of priority to U.S. application Ser. No. 62 / 911,248, filed October 5, 2019, entitled SYSTEM, METHOD AND APPARATUS FOR IMPLEMENTING Configurable Data Collection for a Vehicle (SONA-0004-P01), and U.S. application Ser. No. 62 / 986,444, filed March 6, 2020, entitled SYSTEM, METHOD AND APPARATUS TO TEST AND VERIFY A VEHICLE NETWORK (SONA-0005-P01).
[0004] This application claims the benefit of priority to Provisional U.S. Application No. 63 / 404,918, filed September 8, 2022, entitled ZONAL ARCHITECTURE FOR A VEHICLE (SONA-0015-P01).
[0005] Each of the foregoing applications is incorporated herein by reference in its entirety for all purposes. [Background technology]
[0006] Vehicles and mobile applications are increasingly relying on computing devices distributed around the vehicle to perform electronic control functions. Modern passenger cars, by way of example, routinely have over 100 separate electronic control devices distributed around the vehicle. These devices collaborate and communicate with each other to perform various vehicle functions. Previously known systems globally connect devices on networks organized around specific vehicle functions. As a result, various networks are widely distributed around the vehicle, and numerous connection paths result in significantly more hardware (e.g., cables and routing devices) than is necessary simply to connect the devices. Vehicles increasingly face high design costs for integrating all of the connections and security risks from the numerous networks of various types in the vehicle that provide potential access points. The expected increase in reliance on electronic devices and the growing ability of vehicles to function autonomously and provide enhanced capabilities to electronic devices increases the severity of security breaches or other security issues related to the vehicle. Furthermore, there are a variety of devices and capabilities, ranging from modern electronic devices that can communicate over high speed networks using modern communications, to simpler electronic devices that utilize older networks that may be based on very simple protocols or industry standards. Summary of the Invention [Problem to be solved by the invention]
[0007] Thus, vehicles have a patchwork of networks with different security capabilities, many overlapping communication paths based on vehicle functions, and the inevitable difficulties in designing, monitoring, or updating the various networks or devices on the networks. [Means for solving the problem]
[0008] In some aspects, the techniques described herein relate to a system including: a vehicle having a multi-zone network including a plurality of network zones, each of the network zones including at least one zone manager, the plurality of network zones being configured according to a network topology description of a selected zone architecture; and a network management controller, wherein the network management controller includes zone enforcement circuitry structured to interpret the zoned architecture communication scheme, zone manager command circuitry structured to interpret zone manager command descriptions for each of the at least one zone manager in accordance with the zoned architecture communication scheme, and zone execution circuitry structured to provide corresponding zone manager command descriptions to each of the at least one zone manager, wherein each of the at least one zone manager is responsive to the corresponding zone manager command description to control communications between an endpoint in the corresponding network zone and an endpoint in at least one other zone of the plurality of network zones.
[0009] In some aspects, the techniques described herein relate to a system in which a network topology description includes a communication connectivity configuration of multiple network zones.
[0010] In some aspects, the techniques described herein relate to a system in which a network topology description includes a logically connected configuration of multiple network zones.
[0011] In some aspects, the techniques described herein relate to systems in which the zone enforcement circuitry is further structured to interpret a zoned architecture communication scheme according to policies provided by an external device.
[0012] In some aspects, the techniques described herein relate to a system in which policies include configuration files for network communications in a vehicle.
[0013] In some aspects, the techniques described herein relate to a system in which a network management controller is at least partially located in a central gateway zone controller, the central gateway zone controller including one of the zone managers.
[0014] In some aspects, the techniques described herein relate to a system in which the zone manager command circuitry is further structured to interpret zone manager command descriptions for each of the at least one zone manager by parsing a policy comprising a configuration file.
[0015] In some aspects, the techniques described herein relate to a system in which the zone execution circuitry is further structured to provide each of the Zone Managers with corresponding Zone Manager command descriptions by updating a local configuration file for each of the Zone Managers.
[0016] In some aspects, the techniques described herein relate to a system in which each corresponding zone manager command description includes at least one value selected from a communication tolerance value, a communication sampling rate value, a communication configuration value, or a communication destination value.
[0017] In some aspects, the techniques described herein relate to a system in which the network management controller further includes hardware redundancy enforcement circuitry structured to determine that a hardware off-nominal event has occurred and adjust at least one of the zone manager command descriptions in response to the hardware off-nominal event.
[0018] In some aspects, the techniques described herein relate to a system where the network management controller further includes control redundancy implementation circuitry configured to determine that a control emergency event has occurred and adjust at least one of the zone manager command descriptions in response to the control emergency event.
[0019] In some aspects, the techniques described herein relate to a method that includes interpreting a vehicle network performance description, determining a zonal architecture value as a function of the vehicle network performance description and the vehicle performance network impact description, and integrating a multi-zone network in a vehicle as a function of the zonal architecture value.
[0020] In some aspects, the techniques described herein relate to a method, wherein the vehicle network performance description includes at least one of a latency value between at least two endpoints of the multi-zone network, a bandwidth value between at least two endpoints of the multi-zone network, a hardware redundancy description for the multi-zone network, or a control redundancy description for the multi-zone network.
[0021] In some aspects, the techniques described herein relate to a method, wherein the vehicle performance network impact description includes at least one of an installed hardware cost value of the multi-zone network, a mission capability description of the multi-zone network, a redundancy capability description of the multi-zone network, or a reliability description of the multi-zone network.
[0022] In some aspects, the techniques described herein relate to methods in which the zone architecture values include a network topology description.
[0023] In some aspects, the techniques described herein relate to a method, wherein the zone architecture value further includes a Zone Manager distribution description.
[0024] In some aspects, the techniques described herein relate to a method in which the zone architecture value further includes a network type value for each zone of a multi-zone network.
[0025] In some aspects, the techniques described herein relate to a method in which the zone architecture values further include network protocol values for each zone of a multi-zone network.
[0026] In some aspects, the techniques described herein relate to methods in which the zone architecture values further include specification values for at least one hardware component of the multi-zone network.
[0027] In some aspects, the techniques described herein relate to a method in which integrating a multi-zone network in a vehicle includes installing a multi-zone network configured according to zone architecture values.
[0028] In some aspects, the techniques described herein relate to a method in which integrating a multi-zone network in a vehicle includes installing a multi-zone network configured according to a network topology description of a zone architecture value.
[0029] In some aspects, the techniques described herein relate to a method in which integrating a multi-zone network in a vehicle includes installing a multi-zone network configured according to a Zone Manager distribution description of a zone architecture value.
[0030] In some aspects, techniques described herein relate to a method that includes interpreting a plurality of vehicle network performance descriptions, each of the vehicle network performance descriptions corresponding to one of a plurality of selected vehicle classes; determining a zonal architecture value as a function of the plurality of vehicle network performance descriptions and the vehicle performance network impact description for each of the plurality of selected vehicle classes; and integrating a multi-zone network in each of a first vehicle and a second vehicle as a function of the zonal architecture value, wherein the first vehicle includes a first member of the plurality of selected vehicle classes and the second vehicle includes a second member of the plurality of selected vehicle classes.
[0031] In some aspects, the techniques described herein relate to a method, wherein each of the plurality of vehicle network performance descriptions includes at least one of a latency value between at least two endpoints of the multi-zone network corresponding to one of the plurality of selected vehicle classes, a bandwidth value between at least two endpoints of the multi-zone network corresponding to one of the plurality of selected vehicle classes, a hardware redundancy description for the multi-zone network corresponding to one of the plurality of selected vehicle classes, or a control redundancy description for the multi-zone network corresponding to one of the plurality of selected vehicle classes.
[0032] In some aspects, the techniques described herein relate to a method, wherein the vehicle performance network impact description corresponding to each of a plurality of selected vehicle classes includes at least one of an installed hardware cost value of the multi-zone network corresponding to one of the plurality of selected vehicle classes, a mission capability description of the multi-zone network corresponding to one of the plurality of selected vehicle classes, a redundancy capability description of the multi-zone network corresponding to one of the plurality of selected vehicle classes, or a reliability description of the multi-zone network corresponding to one of the plurality of selected vehicle classes.
[0033] In some aspects, the techniques described herein relate to methods in which the zone architecture values include a network topology description.
[0034] In some aspects, the techniques described herein relate to a method, wherein the zone architecture value further includes a Zone Manager distribution description.
[0035] In some aspects, techniques described herein relate to a method in which integrating a multi-zone network in each of a first vehicle and a second vehicle includes installing a multi-zone network in each of the first vehicle and the second vehicle configured according to zone architecture values.
[0036] In some aspects, techniques described herein relate to a method in which integrating a multi-zone network in each of a first vehicle and a second vehicle includes installing a multi-zone network in each of the first vehicle and the second vehicle configured according to a network topology description of a zone architecture value.
[0037] In some aspects, techniques described herein relate to a method in which integrating a multi-zone network in each of a first vehicle and a second vehicle includes installing a multi-zone network in each of the first vehicle and the second vehicle configured according to a zone manager distribution description of a zone architecture value.
[0038] In some aspects, the techniques described herein relate to a system including: a vehicle having a multi-zone network including a plurality of network zones, each of the network zones including at least one zone manager, the plurality of network zones configured according to a network topology description of a selected zonal architecture, the selected zonal architecture being determined in response to a vehicle-network risk description and a vehicle-performance-network-impact description; and a network management controller, the network management controller including zone enforcement circuitry structured to interpret the zonal architecture communication scheme, zone manager command circuitry structured to interpret zone manager command descriptions for each of the at least one zone manager in accordance with the zonal architecture communication scheme, and zone execution circuitry structured to provide corresponding zone manager command descriptions to each of the at least one zone manager, each of the at least one zone manager responsive to the corresponding zone manager command description to control communications between an endpoint in the corresponding network zone and an endpoint in at least one other zone of the plurality of network zones.
[0039] In some aspects, the techniques described herein relate to a system in which the selected zone architecture includes a star configuration and one of the multiple network zones includes a central zone having a central zone manager.
[0040] In some aspects, the techniques described herein relate to a system in which the plurality of network zones further includes two front zones each communicatively coupled to the central zone and one rear zone communicatively coupled to the central zone.
[0041] In some aspects, the techniques described herein relate to a system in which the selected zone architecture includes a mesh zone configuration.
[0042] In some aspects, the techniques described herein relate to a system in which the plurality of network zones further includes two front zones, one center zone, and one rear zone, and each of the plurality of network zones is communicatively coupled to all of the other network zones of the plurality of network zones.
[0043] In some aspects, the techniques described herein relate to a system in which the selected zone architecture includes a ring zone configuration.
[0044] In some aspects, the techniques described herein relate to a system in which the plurality of network zones further include, in order, a central zone having a central zone manager and communicatively coupled to a first forward zone, the first forward zone communicatively coupled to a second forward zone, the second forward zone communicatively coupled to a rear zone, and a rear zone communicatively coupled to the central zone.
[0045] In some aspects, the techniques described herein relate to a system in which the selected zone architecture includes a two-node topology, each node of the two-node topology corresponding to one of a plurality of network zones.
[0046] In some aspects, the techniques described herein relate to a system in which the selected zone architecture includes a three-node topology, each node of the three-node topology corresponding to one of a plurality of network zones.
[0047] In some aspects, the techniques described herein relate to a system in which the selected zone architecture includes a four node topology, each node of the four node topology corresponding to one of a plurality of network zones.
[0048] In some aspects, the techniques described herein relate to a system in which at least one zone of the plurality of zones includes a virtual network zone.
[0049] In some aspects, the techniques described herein relate to a method that includes interpreting a vehicle network risk description, determining a zone architecture value as a function of the vehicle network risk description and the vehicle performance network impact description, and integrating a multi-zone network in a vehicle as a function of the zone architecture value.
[0050] In some aspects, the techniques described herein relate to a method in which the vehicle network risk description includes a hardware redundancy value.
[0051] In some aspects, the techniques described herein relate to a method in which the vehicle network risk description includes a control redundancy value.
[0052] In some aspects, the techniques described herein relate to a method in which the vehicular network risk description includes a critical flow description.
[0053] In some aspects, the techniques described herein relate to a method in which the vehicle network risk description includes a critical application description.
[0054] In some aspects, the techniques described herein relate to a method in which the vehicle network risk description includes a critical communication connection description.
[0055] In some aspects, the techniques described herein relate to a method in which the vehicle network risk description includes a failure mode description.
[0056] In some aspects, the techniques described herein relate to a method in which the vehicle performance network impact description includes a performance estimate of a multi-zone network relative to the vehicle network risk description.
[0057] In some aspects, the techniques described herein relate to a system including: a vehicle having a multi-zone network including a plurality of network zones, each of the network zones including at least one zone manager, one of the at least one zone managers including a central zone manager, the plurality of network zones configured according to a network topology description of a selected zone architecture, the central zone manager being communicatively coupled directly to each of the other zone managers; and a network management controller, the network management controller including zone enforcement circuitry structured to interpret the zoned architecture communication scheme, zone manager command circuitry structured to interpret zone manager command descriptions for each of the at least one zone manager in accordance with the zoned architecture communication scheme, and zone execution circuitry structured to provide corresponding zone manager command descriptions to each of the at least one zone manager, wherein each of the at least one zone manager responds to the corresponding zone manager command description to control communications between an endpoint of the corresponding network zone and an endpoint of at least one other zone of the plurality of network zones.
[0058] In some aspects, the techniques described herein relate to a system in which a network management controller is at least partially located in a central zone manager.
[0059] In some aspects, the techniques described herein relate to a system in which the zonal architecture communication scheme further includes a central zone manager succession scheme, and in which the zone execution circuitry is further structured to determine an off-nominal condition of the central zone manager and to transition duties of the central zone manager to another of the at least one zone manager in response to the central zone manager succession scheme.
[0060] In some aspects, the techniques described herein relate to systems in which the emergency situation includes a loss of communication.
[0061] In some aspects, the techniques described herein relate to a system in which the emergency situation includes at least one of the loss or degradation of a network zone associated with a central zone manager.
[0062] In some aspects, the techniques described herein relate to a system in which a network topology description includes a communication connectivity configuration of multiple network zones.
[0063] In some aspects, the techniques described herein relate to a system in which the communication coupling configuration comprises a star configuration.
[0064] In some aspects, the techniques described herein relate to a system in which a central zone manager comprises a central node in a star configuration.
[0065] In some aspects, the techniques described herein relate to a system in which the communication coupling configuration comprises a mesh configuration.
[0066] In some aspects, the techniques described herein relate to a system in which the communication coupling configuration comprises a ring configuration.
[0067] In some aspects, techniques described herein relate to a method including interpreting a zonal architecture communication scheme for a vehicle having a multi-zone network including a plurality of network zones, each of the network zones including at least one zone manager, one of the at least one zone managers including a central zone manager; interpreting zone manager command descriptions for each of the at least one zone manager in accordance with the zonal architecture communication scheme; providing a corresponding zone manager command description to each of the at least one zone manager; and operating each of the at least one zone manager in accordance with the corresponding zone manager command description to control communications between an endpoint of the corresponding network zone and an endpoint of at least one other zone of the plurality of network zones.
[0068] In some aspects, the techniques described herein relate to a method, wherein interpreting a zone manager command description further includes interpreting a central zone manager command description for a central zone manager.
[0069] In some aspects, the techniques described herein relate to a method further including interpreting a central zone manager succession scheme, determining a central zone manager emergency, and transferring duties of the central zone manager to another of the at least one zone manager in response to the central zone manager succession scheme.
[0070] In some aspects, the techniques described herein relate to a system including a vehicle having a multi-zone network including a plurality of network zones, each of the network zones including at least one zone manager, one of the at least one zone managers including a central zone manager, the plurality of network zones configured according to a network topology description of a selected zone architecture, the central zone manager including: a network management controller including: zone enforcement circuitry structured to interpret a zoned architecture communication scheme, the zoned architecture communication scheme including a network security description and a network connectivity description; a zone manager command circuit structured to interpret zone manager command descriptions for each of the at least one zone manager in accordance with the zoned architecture communication scheme; and a zone execution circuit structured to provide corresponding zone manager command descriptions to each of the at least one zone manager, wherein each of the at least one zone manager responds to the corresponding zone manager command description to control communications between endpoints in the corresponding network zone and endpoints in at least one other zone of the plurality of network zones.
[0071] In some aspects, the techniques described herein relate to systems in which a central zone manager is communicatively coupled directly to each of the other zone managers.
[0072] In some aspects, the techniques described herein relate to a system in which the zone enforcement circuitry is further structured to interpret a zoned architecture communication scheme update, the zone manager command circuitry is further structured to interpret zone manager command descriptions for each of the at least one zone manager according to the updated zoned architecture communication scheme, and the zone execution circuitry is further structured to provide a corresponding updated zone manager command description to each of the at least one zone manager.
[0073] In some aspects, the techniques described herein relate to a system in which the zone enforcement circuitry is further structured to interpret zoned architecture communication scheme updates by receiving policy from an external device.
[0074] In some aspects, the techniques described herein relate to a system in which a network security description includes permission values associated with at least one of a network zone of a plurality of network zones, a vehicular flow, a vehicular application, a vehicular function, or an endpoint of one of a plurality of network zones.
[0075] In some aspects, the techniques described herein relate to a system in which the permission value includes at least one permission selected from a communication bandwidth permission, a data provider permission, a data receiver permission, a service subscription permission, a service provider permission, a service visibility permission, a service publishing permission, or an endpoint communication permission.
[0076] In some aspects, the techniques described herein relate to a system in which a network connectivity description includes a connectivity scheme between at least two of a plurality of network zones.
[0077] In some aspects, the techniques described herein relate to a system in which the connection scheme defines at least one of a communication rate value, a communication protocol value, a communication encapsulation description, a sampling rate value, a communication header value, a communication metadata value, a communication unit value, or a communication timestamp description.
[0078] In some aspects, the techniques described herein relate to a system in which the network connectivity description further includes a connectivity scheme based on at least one of a source endpoint value or a destination endpoint value.
[0079] In some aspects, the techniques described herein relate to a system in which the network connectivity description further includes a connectivity scheme based on at least one of a source network type or a destination network type.
[0080] In some aspects, techniques described herein relate to a method including interpreting a zonal architecture communication scheme for a multi-zone network of vehicles including a plurality of network zones, each of the network zones including at least one zone manager, one of the at least one zone managers including a central zone manager, and the zonal architecture communication scheme including a network security description and a network connectivity description; interpreting zone manager command descriptions for each of the at least one zone manager in accordance with the zonal architecture communication scheme; providing a corresponding zone manager command description to each of the at least one zone manager; and controlling communications between endpoints of each of the plurality of network zones in accordance with the zone manager command descriptions.
[0081] In some aspects, the techniques described herein relate to a method in which interpreting a zoned architecture communication scheme includes receiving a policy from an external device at a central zone manager.
[0082] In some aspects, the techniques described herein relate to a method in which interpreting a Zone Manager command description includes parsing a policy and determining an associated Zone Manager command description for each of a plurality of Zone Managers according to the policy.
[0083] In some aspects, the techniques described herein relate to a method wherein providing a corresponding zone manager command description includes communicating the corresponding zone manager command description from a central zone manager to each individual zone manager of a plurality of zone managers.
[0084] In some aspects, the techniques described herein relate to a method further including interpreting a zoned architecture communication scheme update, interpreting zone manager command descriptions for each of at least one zone manager according to the updated zoned architecture communication scheme, and providing the corresponding updated zone manager command descriptions to each of the at least one zone manager.
[0085] In some aspects, the techniques described herein relate to a method further including controlling communications between respective endpoints of a plurality of network zones in response to updated zone manager command descriptions.
[0086] In some aspects, the techniques described herein relate to a method further including, immediately after the update, controlling communications in response to the updated Zone Manager command description.
[0087] In some aspects, the techniques described herein relate to a method that further includes controlling communications in response to an updated zone manager command description in response to a subsequent vehicle start event.
[0088] In some aspects, the techniques described herein relate to a method further including determining an implementation scheme as a function of the updated zone manager command descriptions, and controlling communications as a function of the updated zone manager command descriptions as a function of the implementation scheme.
[0089] In some aspects, the techniques described herein relate to methods in which the implementation scheme includes at least one of a runtime scheme, a startup scheme, or a mixed scheme.
[0090] In some aspects, the techniques described herein relate to a system including: a vehicle having a multi-zone network including a plurality of network zones, each of the network zones including at least one zone manager, the plurality of network zones being configured according to a network topology description of a selected zone architecture; and a network management controller, the network management controller including: zone enforcement circuitry structured to interpret a zoned architecture communication scheme, the zoned architecture communication scheme including a network security description and a network connectivity description; a zone manager command circuitry structured to interpret zone manager command descriptions for each of the at least one zone manager in accordance with the zoned architecture communication scheme; and a zone execution circuitry structured to provide a corresponding zone manager command description to each of the at least one zone manager, each of the at least one zone manager responsive to the corresponding zone manager command description to control cross-zone communications, the cross-zone communications comprising a communication zone of the multi-zone network.
[0091] In some aspects, the techniques described herein relate to a system in which a network connectivity description includes a bandwidth description between two of a plurality of network zones.
[0092] In some aspects, the techniques described herein relate to a system in which the bandwidth description is further defined as a function of at least one element involved in the cross-zone communication, the at least one element including at least one of an endpoint, a flow, a function, or an application.
[0093] In some aspects, the techniques described herein relate to systems in which network connectivity descriptions include network routing values for cross-zone communications.
[0094] In some aspects, the techniques described herein relate to a system in which the network routing value is further defined as a function of at least one element involved in the cross-zone communication, the at least one element including at least one of an endpoint, a flow, a function, or an application.
[0095] In some aspects, the techniques described herein relate to a system in which the network connectivity description further includes a priority value for cross-zone communication.
[0096] In some aspects, the techniques described herein relate to a system in which the priority value is further defined as a function of at least one element involved in the cross-zone communication, the at least one element including at least one of an endpoint, a flow, a function, or an application.
[0097] In some aspects, the techniques described herein relate to systems in which the priority values are further defined as a function of the vehicle's operating state.
[0098] In some aspects, the techniques described herein relate to a system in which a network security description includes a permission value for cross-zone communication.
[0099] In some aspects, the techniques described herein relate to a system in which the permission values are further defined as a function of at least one element involved in the cross-zone communication, the at least one element including at least one of an endpoint, a flow, a function, or an application.
[0100] In some aspects, the techniques described herein relate to a system in which the permission value includes at least one of a sampling rate description, a data resolution description, or a data latency description.
[0101] In some aspects, the techniques described herein relate to a system in which the permission values are further defined as a function of at least one element involved in the cross-zone communication, the at least one element including at least one of an endpoint, a flow, a function, or an application.
[0102] In some aspects, the techniques described herein relate to systems in which the permission values are further defined as a function of the operating state of the vehicle.
[0103] In some aspects, techniques described herein relate to a method including interpreting a zonal architecture communication scheme for a multi-zone network of vehicles including a plurality of network zones, each of the network zones including at least one zone manager, the zonal architecture communication scheme including a network security description and a network connectivity description; interpreting zone manager command descriptions for each of the at least one zone manager in accordance with the zonal architecture communication scheme; providing a corresponding zone manager command description to each of the at least one zone manager; and controlling cross-zone communications between network zones of the plurality of network zones in accordance with the zone manager command descriptions.
[0104] In some aspects, the techniques described herein relate to a method in which the network connectivity description includes a bandwidth description between two zones of a plurality of network zones, the method further including determining the bandwidth description as a function of at least one element involved in the cross-zone communication, the at least one element including at least one of an endpoint, a flow, a function, or an application.
[0105] In some aspects, the techniques described herein relate to a method in which the network connectivity description includes a network routing value for the cross-zone communication, the method further including determining the network routing value as a function of at least one element involved in the cross-zone communication, the at least one element including at least one of an endpoint, a flow, a function, or an application.
[0106] In some aspects, the techniques described herein relate to a method in which a network connectivity description includes a priority value for cross-zone communication, the method further including determining the priority value as a function of at least one element involved in the cross-zone communication, the at least one element including at least one of an endpoint, a flow, a function, or an application.
[0107] In some aspects, the techniques described herein relate to a method in which the network connectivity description includes a priority value for cross-zone communication, the method further including determining the priority value as a function of an operating state of the vehicle.
[0108] In some aspects, the techniques described herein relate to a method in which the network connectivity description includes a permission value for cross-zone communication, the method further including determining the permission value as a function of at least one element involved in the cross-zone communication, the at least one element including at least one of an endpoint, a flow, a function, or an application.
[0109] In some aspects, the techniques described herein relate to a method in which the network connectivity description includes a permission value for cross-zone communication, the method further including determining the permission value as a function of an operating state of the vehicle.
[0110] In some aspects, the techniques described herein involve a vehicle having a multi-zone network including a plurality of network zones, each of the network zones including at least one zone manager, the plurality of network zones being configured according to a network topology description of a selected zone architecture; and a service publishing circuit configured to: maintain a service register including a plurality of services and a service description for each of the plurality of services; a service publishing circuit configured to expose at least one service from the plurality of services to a requesting source in response to a service publication request; and a service subscription circuit configured to register the requesting source with the at least one service in response to a service subscription request and update the service register in response to the registration. and a network management controller, wherein the network management controller includes a zone enforcement circuit structured to interpret a zoned architecture communication scheme, a zone manager command circuit structured to interpret zone manager command descriptions for each of at least one zone manager in accordance with the zoned architecture communication scheme, and a zone execution circuit structured to provide corresponding zone manager command descriptions to each of the at least one zone manager, wherein each of the at least one zone manager is responsive to the corresponding zone manager command description and service register to control communications between endpoints in the corresponding network zone and endpoints in at least one other zone of the plurality of network zones.
[0111] In some aspects, the techniques described herein relate to a system in which a service management controller is at least partially located in a central zone manager of a plurality of zone managers.
[0112] In some aspects, the techniques described herein relate to systems in which a central zone manager is communicatively coupled directly to each of the other zone managers.
[0113] In some aspects, the techniques described herein relate to a system in which a network management controller is at least partially located in a central zone manager of a plurality of zone managers.
[0114] In some aspects, the techniques described herein relate to systems in which a central zone manager is communicatively coupled directly to each of the other zone managers.
[0115] In some aspects, the techniques described herein relate to a system in which each service of a plurality of services includes at least one of a data value, a mathematical function, a processing function, a communication function, or a data storage function.
[0116] In some aspects, the techniques described herein relate to a system in which each service of a plurality of services includes at least one of an actuator function, a command function, or a control function.
[0117] In some aspects, the techniques described herein relate to a system in which the service publishing circuitry is further structured to expose at least one service by listing the service in a data structure provided to a requesting source.
[0118] In some aspects, the techniques described herein relate to a system in which the service publishing circuitry is further structured to expose at least one service by listing the service in a data structure available to a requesting source.
[0119] In some aspects, the techniques described herein relate to systems in which the requesting source includes an external device.
[0120] In some aspects, the techniques described herein relate to a system in which the service publication circuitry is further structured to interpret a service publication request for a new service from a new service provider, determine a new service description in response to the service publication request and the new service provider, and maintain a service register by adding the new service as one of a plurality of services.
[0121] In some aspects, the techniques described herein relate to systems in which the service publishing circuitry is further structured to add new services depending on permission values associated with the new service providers.
[0122] In some aspects, the techniques described herein relate to a system in which the service publication circuitry is further structured to maintain a service register by removing a service from the plurality of services in response to a service publication request.
[0123] In some aspects, the techniques described herein relate to a system in which the service publishing circuitry is further structured to remove a service from the plurality of services by deleting an associated entry from a service register.
[0124] In some aspects, the techniques described herein relate to a system in which the service publishing circuitry is further structured to remove a service from the plurality of services by setting an inactive flag in an associated entry from a service register.
[0125] In some aspects, the techniques described herein relate to a system in which the service publication circuitry is further structured to maintain a service register by deprecating services from a plurality of services in response to service publication requests.
[0126] In some aspects, the techniques described herein relate to systems in which the service subscription circuitry is further structured to block new registrations for deprecated services.
[0127] In some aspects, the techniques described herein relate to a system in which the service publishing circuitry is further structured to maintain a service register by removing a service from the plurality of services in response to determining that at least one aspect of the service is no longer available.
[0128] In some aspects, the techniques described herein relate to a system in which the service publishing circuitry is further structured to remove a service from the plurality of services by setting an inactive flag in an associated entry from a service register.
[0129] In some aspects, the techniques described herein relate to a system in which a service register includes, for each service of a plurality of services, at least one of a service identifier, a service provider description, a service permission description, or a service capability description.
[0130] In some aspects, the techniques described herein relate to a system in which the service register further includes, for each service of the plurality of services, at least one of a service input description, a service active or inactive flag, a service deprecated flag, a service registrant description, or a service participant description.
[0131] In some aspects, the techniques described herein relate to a system in which the service permission description includes at least one of a service publication permission, a service subscription permission, or a service visibility permission.
[0132] In some aspects, the techniques described herein relate to a system further including storing the service register in an external device.
[0133] In some aspects, techniques described herein relate to a method including maintaining a service register in a vehicle having a multi-zone network including a plurality of network zones, the service register including a plurality of services and a service description for each of the plurality of services, the plurality of network zones being configured according to a network topology description of a selected zonal architecture, exposing at least one service from the plurality of services to a requesting source in response to a service publication request, registering the requesting source with the at least one service in response to a service subscription request and updating the service register in response to the registration, interpreting a zonal architecture communication scheme, interpreting a zone manager command description for each of the at least one zone manager in accordance with the zonal architecture communication scheme, providing a corresponding zone manager command description to each of the at least one zone manager, and controlling communications between an endpoint of the corresponding network zone and an endpoint of at least one other zone of the plurality of network zones in response to the corresponding zone manager command description and the service register.
[0134] In some aspects, the techniques described herein relate to a method that further includes exposing at least one service by listing the service in a data structure that is provided to a requesting source.
[0135] In some aspects, the techniques described herein relate to a method further including exposing at least one service by listing the service in a data structure available to the requesting source.
[0136] In some aspects, the techniques described herein relate to a method that further includes interpreting a service publication request for a new service from a new service provider, determining a new service description in response to the service publication request and the new service provider, and maintaining a service register by adding the new service as one of a plurality of services.
[0137] In some aspects, the techniques described herein relate to a method further including adding the new service as a function of a permission value associated with the new service provider.
[0138] In some aspects, the techniques described herein relate to a method that further includes maintaining a service register by removing a service from the plurality of services in response to a service publication request.
[0139] In some aspects, the techniques described herein relate to a method that further includes removing a service from the plurality of services by deleting an associated entry from a service register.
[0140] In some aspects, the techniques described herein relate to a method that further includes removing a service from the plurality of services by setting an inactive flag in an associated entry from a service register.
[0141] In some aspects, the techniques described herein relate to a method that further includes maintaining a service register by deprecating a service from a plurality of services in response to a service publication request.
[0142] In some aspects, the techniques described herein relate to a method that further includes blocking new registrations for the deprecated service.
[0143] In some aspects, the techniques described herein relate to a method that further includes maintaining a service register by removing a service from a plurality of services in response to determining that at least one aspect of the service is no longer available.
[0144] In some aspects, the techniques described herein relate to a method that further includes removing a service from the plurality of services by setting an inactive flag in an associated entry from a service register.
[0145] In some aspects, the techniques described herein relate to a system including: a vehicle having a multi-zone network including a plurality of network zones, each of the network zones including at least one zone manager; and a network management controller, wherein the network management controller includes: a zone enforcement circuit structured to interpret a zoned architecture communication scheme, the zoned architecture communication scheme including a time management scheme; a zone manager command circuit structured to interpret zone manager command descriptions for each of the at least one zone manager in accordance with the zoned architecture communication scheme, the zone manager command descriptions further including a time management implementation; and a zone execution circuit structured to provide a corresponding zone manager command description to each of the at least one zone manager, wherein each of the at least one zone manager responds to the corresponding zone manager command description to control communications between an endpoint in the corresponding network zone and an endpoint in at least one other zone of the plurality of network zones.
[0146] In some aspects, the techniques described herein relate to a system in which the time management scheme further includes a designated one of the at least one zone manager to act as a Precision Time Protocol (PTP) grandmaster for the multi-zone network.
[0147] In some aspects, the techniques described herein relate to systems in which other Zone Managers are designated as Boundary Clocks for corresponding network zones.
[0148] In some aspects, the techniques described herein relate to a system in which the zone enforcement circuitry is further configured to operate a best master clock algorithm to determine a designated one of the at least one zone manager to operate as a PTP grandmaster.
[0149] In some aspects, the techniques described herein relate to a system in which the zone enforcement circuitry is further configured to determine a PTP grandmaster time loss event, the zone enforcement circuitry is further configured to operate a best master clock algorithm to determine an alternative one of the at least one zone manager for operation as the PTP grandmaster, and the zone enforcement circuitry is further configured to nominate the alternative one of the at least one zone manager for operation as the PTP grandmaster.
[0150] In some aspects, the techniques described herein relate to a system in which one of the zone managers includes a central zone manager, and the central zone manager is designated as the PTP grandmaster.
[0151] In some aspects, the techniques described herein relate to a system further including: the zone enforcement circuitry is further configured to determine a PTP grandmaster time loss event; and, in response to the PTP grandmaster time loss event, designate an alternative one of the zone managers as the PTP grandmaster.
[0152] In some aspects, the techniques described herein relate to a system in which the time management scheme further includes a designated controller, including an endpoint in one of a plurality of network zones, to act as a Precision Time Protocol (PTP) grandmaster for the multi-zone network.
[0153] In some aspects, the techniques described herein relate to a system in which one of the plurality of network zones includes a central network zone.
[0154] In some aspects, the techniques described herein relate to a system in which the time management scheme further includes a designated boundary controller for each of the other network zones of the plurality of network zones, each designated boundary controller including an endpoint in the corresponding network zone and operating as a boundary clock for the corresponding network zone.
[0155] In some aspects, the techniques described herein relate to a system in which the time management scheme further includes a master network zone and a designated controller that includes a zone controller for the master network zone or one of the endpoints in the master network zone, and the designated controller acts as a Precision Time Protocol (PTP) grandmaster for the multi-zone network.
[0156] In some aspects, the techniques described herein relate to a system in which a master network zone is selected based on the criticality of functionality of at least one endpoint in the master network zone.
[0157] In some aspects, the techniques described herein relate to a system in which a master network zone is selected based on the time sensitivity of a function of at least one endpoint in the master network zone.
[0158] In some aspects, the techniques described herein relate to a system in which the zone controller is further structured to apply a common PTP timestamp to at least a portion of communications provided in a corresponding one of a plurality of network zones.
[0159] In some aspects, the techniques described herein relate to a system in which the zone controller is further structured to remove local timestamps from at least a portion of communications provided in a corresponding one of a plurality of network zones.
[0160] In some aspects, the techniques described herein relate to a system in which the zone controller is further structured to facilitate application of a common PTP timestamp to at least a portion of communications provided in a corresponding one of a plurality of network zones.
[0161] In some aspects, the techniques described herein relate to a system in which the zone controller is further structured to facilitate removal of local timestamps from at least a portion of communications provided in a corresponding one of a plurality of network zones.
[0162] In some aspects, the techniques described herein relate to a system in which the zoned architecture communication scheme further includes a communication priority scheme.
[0163] In some aspects, the techniques described herein relate to a system in which each of at least one zone manager is responsive to a communication priority value and a communication priority scheme to control communications between endpoints in a corresponding network zone and endpoints in at least one other zone of a plurality of network zones.
[0164] In some aspects, the techniques described herein relate to a system in which a communication priority scheme includes network routing values.
[0165] In some aspects, the techniques described herein relate to a system in which a communications priority scheme includes a communications scheduling value.
[0166] In some aspects, the techniques described herein relate to a system in which each of the at least one zone manager is further responsive to vehicle operating conditions to control communications between endpoints in the corresponding network zone and endpoints in at least one other zone of the plurality of network zones.
[0167] In some aspects, techniques described herein relate to a method including interpreting a zonal architecture communication scheme for a multi-zone network of vehicles including a plurality of network zones, each of the network zones including at least one zone manager, the zonal architecture communication scheme including a time management scheme; interpreting zone manager command descriptions for each of the at least one zone manager in accordance with the zonal architecture communication scheme, the zone manager command descriptions further including a time management implementation; providing a corresponding zone manager command description to each of the at least one zone manager; and controlling communications between an endpoint of the corresponding network zone and an endpoint of at least one other zone of the plurality of network zones in accordance with the zone manager command description.
[0168] In some aspects, the techniques described herein relate to a method further including designating one of the at least one zone manager to act as a Precision Time Protocol (PTP) grandmaster for the multi-zone network.
[0169] In some aspects, the techniques described herein relate to a method further including nominating another Zone Manager as a Boundary Clock for a corresponding network zone.
[0170] In some aspects, the techniques described herein relate to a method in which designating one of the at least one zone manager to operate as a PTP grandmaster includes operating a best master clock algorithm.
[0171] In some aspects, the techniques described herein relate to a method that further includes determining a PTP grandmaster time loss event and operating a best master clock algorithm to nominate an alternate one of the at least one zone manager to act as the PTP grandmaster.
[0172] In some aspects, the techniques described herein relate to a method in which one of the zone managers includes a central zone manager, and further includes designating the central zone manager as the PTP grandmaster.
[0173] In some aspects, the techniques described herein relate to a method that further includes determining a PTP grandmaster time loss event and, in response to the PTP grandmaster time loss event, designating an alternative one of the zone managers as the PTP grandmaster.
[0174] In some aspects, the techniques described herein relate to a method in which the time management scheme further includes a master network zone, the method further including selecting a designated controller, including one of the zone controllers for the master network zone, or an endpoint in the master network zone, and operating the designated controller as a Precision Time Protocol (PTP) grandmaster for the multi-zone network.
[0175] In some aspects, the techniques described herein relate to a method that further includes selecting a master network zone based on a criticality of functionality of at least one endpoint in the master network zone.
[0176] In some aspects, the techniques described herein relate to a method that further includes selecting a master network zone based on time sensitivity of a function of at least one endpoint in the master network zone.
[0177] In some aspects, the techniques described herein relate to a method that further includes applying a common PTP timestamp to at least a portion of communications provided in a multi-zone network.
[0178] In some aspects, the techniques described herein relate to a method further including removing local timestamps from at least a portion of communications provided in a multi-zone network.
[0179] In some aspects, the techniques described herein relate to a method in which the zoned architecture communication scheme further includes a communication priority scheme, and further includes determining communication priority values for communications in the multi-zone network, and controlling communications in the multi-zone network according to the communication priority scheme and the communication priority values.
[0180] In some aspects, the techniques described herein relate to a method in which controlling a communication includes adjusting a network routing value as a function of the communication priority value.
[0181] In some aspects, the techniques described herein relate to a method in which controlling a communication includes adjusting a communication scheduling value as a function of a communication priority value.
[0182] In some aspects, the techniques described herein relate to a method in which controlling communications includes adjusting at least one of a communications priority scheme or a communications priority value depending on vehicle operating conditions.
[0183] In some aspects, the techniques described herein relate to a system including a vehicle multi-zone architecture configuration platform including: a build environment circuit structured to provide a virtual network build environment in a user interface; a network modeling circuit structured to build a virtual multi-zone network model of the vehicle in response to user input on the user interface, the virtual multi-zone network model including a zone controller disposed for each zone of the virtual multi-zone network model, the network modeling circuit being further structured to build the virtual multi-zone network model by applying a zoned architecture communication scheme; an endpoint modeling circuit structured to populate the virtual multi-zone network model with endpoints based on a vehicle control model; a network execution circuit structured to simulate runtime operation of the multi-zone network of the vehicle in response to the virtual multi-zone network model, the vehicle control model, and the zoned architecture communication scheme; and a zonal architecture evaluation circuit structured to provide a network operation report in response to the simulation.
[0184] In some aspects, the techniques described herein relate to a system in which the zoned architecture communication scheme includes at least one of a network security description, a network connection description, a time management scheme, or a communication priority scheme.
[0185] In some aspects, the techniques described herein relate to a system in which a vehicle control model includes a model of an endpoint of a multi-zone network that simulates vehicle control behavior.
[0186] In some aspects, the techniques described herein relate to a system in which a vehicle control model includes a model of endpoints of a multi-zone network that actuate actual vehicle control commands.
[0187] In some aspects, the techniques described herein relate to a system in which the network execution circuitry is further structured to simulate runtime operation of a multi-zone network by simulating emergency conditions.
[0188] In some aspects, the techniques described herein relate to a system in which the network execution circuitry is further configured to simulate an emergency situation by simulating at least one condition selected from a loss of an endpoint, a loss of a network component, a selected vehicle operating state, or a selected operator action.
[0189] In some aspects, the techniques described herein relate to a system in which the network modeling circuitry is further structured to build a virtual multi-zone network model of the vehicle by applying the network topology description.
[0190] In some aspects, the techniques described herein relate to a system in which applying a network topology description includes applying a selected network topology for a zone of the multi-zone network and assigning a zone controller to the zone of the multi-zone network.
[0191] In some aspects, the techniques described herein relate to a system in which applying the network topology description includes applying the network topology description in response to user input at a user interface.
[0192] In some aspects, the techniques described herein relate to a system in which network operation reports include an operation capability value.
[0193] In some aspects, the techniques described herein relate to a system in which the network operation report includes a vehicle network performance description.
[0194] In some aspects, the techniques described herein relate to a system in which the vehicle network performance description includes at least one of a latency value between at least two endpoints of the multi-zone network, a bandwidth value between at least two endpoints of the multi-zone network, a hardware redundancy description for the multi-zone network, or a control redundancy description for the multi-zone network.
[0195] In some aspects, the techniques described herein relate to a system in which network operation reports include vehicle performance network impact descriptions.
[0196] In some aspects, the techniques described herein relate to a system in which the vehicle performance network impact description includes at least one of an installed hardware cost value of the multi-zone network, a mission capability description of the multi-zone network, an integration cost description of the multi-zone network, an operational cost description of the multi-zone network, a redundancy capability description of the multi-zone network, or a reliability description of the multi-zone network.
[0197] In some aspects, the techniques described herein relate to a system in which the network modeling circuitry is further configured to build a virtual multi-zone network model of the vehicle by pre-populating the virtual multi-zone network model.
[0198] In some aspects, the techniques described herein relate to a system in which pre-populating includes prompting a user for at least one basic network selection value and building an initial model responsive to user responses to the at least one basic network selection value.
[0199] In some aspects, the techniques described herein relate to a system in which each of the at least one basic network selection value includes at least one of a network topology selection, a network zone distribution selection, a network type selection, a communication protocol selection, a cross-network sampling scheme, a cross-network encapsulation scheme, a zone manager distribution scheme, a central zone manager selection, or a cross-network routing scheme.
[0200] In some aspects, the techniques described herein relate to a system in which the network modeling circuitry is further structured to construct a virtual multi-zone network model of the vehicle by interpreting a redundancy description for at least one component of the multi-zone network.
[0201] In some aspects, the techniques described herein relate to a system in which the network modeling circuitry is further structured to construct a vehicle environment model, and the network execution circuitry is further structured to simulate runtime behavior of the multi-zone network responsive to the vehicle environment model.
[0202] In some aspects, the techniques described herein relate to a system in which the vehicle environment model includes at least one of a temperature environment model, a vibration environment model, an electromagnetic interference model, or a water intrusion model.
[0203] In some aspects, the techniques described herein relate to a system in which the network modeling circuitry is further structured to construct a network hardware model, and the network execution circuitry is further structured to simulate runtime behavior of the multi-zone network according to the network hardware model.
[0204] In some aspects, the techniques described herein relate to a system in which the network hardware model includes a model of at least one of a connector of at least one component of the multi-zone network, a cable description of at least one component of the multi-zone network, a cooling description of at least one component of the multi-zone network, or a shielding description of at least one component of the multi-zone network.
[0205] In some aspects, the techniques described herein relate to a system in which the network modeling circuitry is further structured to construct a virtual multi-zone network model of the vehicle by interpreting a time management scheme for the multi-zone network.
[0206] In some aspects, the techniques described herein relate to a system in which the network modeling circuitry is further structured to build a virtual multi-zone network model of the vehicle by interpreting a communication priority scheme.
[0207] In some aspects, the techniques described herein relate to a system in which the network modeling circuitry is further structured to construct a virtual multi-zone network model of the vehicle by interpreting the network security description.
[0208] In some aspects, the techniques described herein relate to a system in which the network modeling circuitry is further structured to construct a virtual multi-zone network model of the vehicle by interpreting the network connectivity description.
[0209] In some aspects, the techniques described herein relate to a system in which the vehicle multi-zone architecture configuration platform further includes a zonal architecture rollout circuit structured to establish a zonal architecture communication scheme in response to user manipulation at an interface.
[0210] In some aspects, the techniques described herein relate to a system in which the zonal architecture rollout circuitry is further structured to communicate the zonal architecture communication scheme to a network management controller of a target vehicle.
[0211] In some aspects, techniques described herein relate to a method that includes providing a virtual network construction environment to a user interface; constructing a virtual multi-zone network model of a vehicle in response to user input in the user interface, the virtual multi-zone network model including a zone controller disposed for each zone of the virtual multi-zone network model; populating the virtual multi-zone network model with endpoints based on a vehicle control model, the constructing the virtual multi-zone network model further including applying a zoned architecture communication scheme; simulating runtime operation of the multi-zone network of the vehicle in response to the virtual multi-zone network model, the vehicle control model, and the zoned architecture communication scheme; and providing a network operation report in response to the simulation.
[0212] In some aspects, the techniques described herein relate to a method in which the zoned architecture communication scheme includes at least one of a network security description, a network connection description, a time management scheme, or a communication priority scheme.
[0213] In some aspects, the techniques described herein relate to a method in which the vehicle control model includes a model of an endpoint of a multi-zone network that simulates vehicle control behavior.
[0214] In some aspects, the techniques described herein relate to a method in which a vehicle control model includes a model of endpoints of a multi-zone network that actuate actual vehicle control commands.
[0215] In some aspects, the techniques described herein relate to a method in which simulating runtime operation of a multi-zone network further includes simulating an emergency situation.
[0216] In some aspects, the techniques described herein relate to a method in which simulating an emergency situation includes simulating at least one condition selected from a loss of an endpoint, a loss of a network component, a selected vehicle operating state, or a selected operator action.
[0217] In some aspects, the techniques described herein relate to a method in which building a virtual multi-zone network model for a vehicle includes applying a network topology description.
[0218] In some aspects, the techniques described herein relate to a method in which applying a network topology description includes applying a selected network topology for a zone of the multi-zone network and assigning a zone controller to the zone of the multi-zone network.
[0219] In some aspects, the techniques described herein relate to a method in which applying the network topology description includes applying the network topology description in response to user input at a user interface.
[0220] In some aspects, the techniques described herein relate to a method in which the network operation report includes an operation capability value.
[0221] In some aspects, the techniques described herein relate to a method in which the network operation report includes a vehicle network performance description.
[0222] In some aspects, the techniques described herein relate to a method, wherein the vehicle network performance description includes at least one of a latency value between at least two endpoints of the multi-zone network, a bandwidth value between at least two endpoints of the multi-zone network, a hardware redundancy description for the multi-zone network, or a control redundancy description for the multi-zone network.
[0223] In some aspects, the techniques described herein relate to a method in which the network operation report includes a vehicle performance network impact description.
[0224] In some aspects, the techniques described herein relate to a method, wherein the vehicle performance network impact description includes at least one of an installed hardware cost value of the multi-zone network, a mission capability description of the multi-zone network, an integration cost description of the multi-zone network, an operational cost description of the multi-zone network, a redundancy capability description of the multi-zone network, or a reliability description of the multi-zone network.
[0225] In some aspects, the techniques described herein relate to a method in which building a virtual multi-zone network model for a vehicle further includes pre-populating the virtual multi-zone network model.
[0226] In some aspects, the techniques described herein relate to a method in which pre-populating includes prompting a user for at least one basic network selection value and building an initial model as a function of user responses to the at least one basic network selection value.
[0227] In some aspects, the techniques described herein relate to a method, wherein each of the at least one basic network selection value includes at least one of a network topology selection, a network zone distribution selection, a network type selection, a communication protocol selection, a cross-network sampling scheme, a cross-network encapsulation scheme, a zone manager distribution scheme, a central zone manager selection, or a cross-network routing scheme.
[0228] In some aspects, the techniques described herein relate to a method in which constructing a virtual multi-zone network model for a vehicle further includes interpreting a redundancy description for at least one component of the multi-zone network.
[0229] In some aspects, the techniques described herein relate to a method further including constructing a vehicle-environment model, wherein simulating runtime operation of the multi-zone network is further responsive to the vehicle-environment model.
[0230] In some aspects, the techniques described herein relate to a method in which the vehicle environment model includes at least one of a temperature environment model, a vibration environment model, an electromagnetic interference model, or a water intrusion model.
[0231] In some aspects, the techniques described herein relate to a method further comprising constructing a network hardware model, wherein simulating runtime behavior of the multi-zone network is further responsive to the network hardware model.
[0232] In some aspects, the techniques described herein relate to a method in which the network hardware model includes a model of at least one of a connector of at least one component of the multi-zone network, a cable description of at least one component of the multi-zone network, a cooling description of at least one component of the multi-zone network, or a shielding description of at least one component of the multi-zone network.
[0233] In some aspects, the techniques described herein relate to a method in which constructing a virtual multi-zone network model for a vehicle further includes interpreting a time management scheme for the multi-zone network.
[0234] In some aspects, the techniques described herein relate to a method in which building a virtual multi-zone network model for a vehicle further includes interpreting a communication priority scheme.
[0235] In some aspects, the techniques described herein relate to a method in which constructing a virtual multi-zone network model for a vehicle further includes interpreting a network security description.
[0236] In some aspects, the techniques described herein relate to a method in which building a virtual multi-zone network model for a vehicle further includes interpreting a network connectivity description.
[0237] In some aspects, the techniques described herein relate to a method further including constructing a zoned architecture communication scheme in response to user interaction in the interface.
[0238] In some aspects, the techniques described herein relate to a method further including communicating the zoned architecture communication scheme to a network management controller of a target vehicle.
[0239] In some aspects, the techniques described herein relate to a system including a vehicular multi-zone monitoring platform including a network layout circuit structured to interpret a virtual network layout for a vehicle having a multi-zone network; a network characterization circuit structured to interpret network activity for the vehicle; and a network analysis circuit structured to determine a virtual network map as a function of the virtual network layout and the network activity, and to provide the virtual network map to a user interface.
[0240] In some aspects, the techniques described herein relate to a system in which a virtual network map includes a bidirectional network activity depiction.
[0241] In some aspects, the techniques described herein relate to systems in which the network analysis circuitry is further structured to provide network detail values in response to user selections in a user interface.
[0242] In some aspects, the techniques described herein relate to a system in which the network detail values include at least one of a network traffic description, a zoned architecture communication scheme, a network statistic, or a network event notification.
[0243] In some aspects, the techniques described herein relate to a system in which the vehicular multi-zone monitoring platform further includes network configuration circuitry structured to interpret network conditions and update the virtual network map in response to the network conditions.
[0244] In some aspects, the techniques described herein relate to a system in which the network analysis circuitry is further configured to determine a network impact value as a function of the network adjustment value and to provide the network impact value to a user interface.
[0245] In some aspects, the techniques described herein relate to a system in which the vehicular multi-zone monitoring platform further includes a zonal architecture rollout circuit configured to establish a zonal architecture communication scheme in response to a network adjustment value.
[0246] In some aspects, the techniques described herein relate to a system in which the zonal architecture rollout circuitry is further structured to communicate the zonal architecture communication scheme to a network management controller of at least one of the vehicle or an offset vehicle.
[0247] In some aspects, techniques described herein relate to a method that includes interpreting a virtual network layout for a vehicle having a multi-zone network, interpreting network activity for the vehicle, determining a virtual network map as a function of the virtual network layout and the network activity, and providing the virtual network map to a user interface.
[0248] In some aspects, the techniques described herein relate to a method that further includes providing a virtual network map as the interactive network activity depiction.
[0249] In some aspects, the techniques described herein relate to a method further including providing network detail values in response to a user selection in a user interface.
[0250] In some aspects, the techniques described herein relate to a method in which the network detail values include at least one of a network traffic description, a zoned architecture communication scheme, a network statistic, or a network event notification.
[0251] In some aspects, the techniques described herein relate to a method further including interpreting the network conditioning values and updating the virtual network map in response to the network conditioning values.
[0252] In some aspects, the techniques described herein relate to a method further including determining a network impact value as a function of the network adjustment value and providing the network impact value to a user interface.
[0253] In some aspects, the techniques described herein relate to a method further including establishing a zoned architecture communication scheme in response to the network conditioning value.
[0254] In some aspects, the techniques described herein relate to a method further including communicating the zoned architecture communication scheme to a network management controller of at least one of the vehicle or an offset vehicle.
[0255] In some aspects, the techniques described herein relate to a system including: a vehicle having a multi-zone network including a plurality of network zones, each of the network zones including at least one zone manager; and a network monitoring controller, the network monitoring controller including: network layout circuitry structured to interpret a zonal architecture communication scheme and a network layout for the vehicle; network characterization circuitry structured to interpret network activity for the vehicle and to determine network performance events in response to the network activity; and network reaction circuitry structured to perform network event actions in response to the network performance events.
[0256] In some aspects, the techniques described herein relate to a system in which a network event action includes collecting event information in response to a network performance event and communicating the event information to an external device.
[0257] In some aspects, the techniques described herein relate to systems in which the network reaction circuitry is further structured to collect event information as post-event activity.
[0258] In some aspects, the techniques described herein relate to a system in which the network reaction circuitry is further structured to collect event information by capturing network activity that is utilized to determine network performance events.
[0259] In some aspects, the techniques described herein relate to a system in which a network event action includes performing a network test.
[0260] In some aspects, the techniques described herein relate to a system in which a network event action includes performing a diagnostic.
[0261] In some aspects, the techniques described herein relate to a system in which a network event action includes adjusting a zoned architecture communication scheme.
[0262] In some aspects, the techniques described herein relate to a system in which a network event action includes implementing a redundancy plan.
[0263] In some aspects, the techniques described herein relate to a system in which a network event action includes adjusting control responsibility of at least one endpoint in a multi-zone network.
[0264] In some aspects, techniques described herein relate to a method that includes interpreting a zonal architecture communication scheme and network layout for a vehicle having a multi-zone network including multiple network zones, each of the network zones including at least one zone manager; interpreting network activity for the vehicle; determining network performance events in response to the network activity; and implementing network event actions in response to the network performance events.
[0265] In some aspects, the techniques described herein relate to a method in which a network event action includes collecting event information in response to a network performance event and communicating the event information to an external device.
[0266] In some aspects, the techniques described herein relate to a method in which collecting event information includes collecting the event information as post-event activity.
[0267] In some aspects, the techniques described herein relate to a method in which collecting event information includes collecting event information by capturing network activity that is utilized to determine network performance events.
[0268] In some aspects, the techniques described herein relate to a method in which performing a network event action includes performing a network test.
[0269] In some aspects, the techniques described herein relate to a method in which performing a network event action includes performing a diagnostic.
[0270] In some aspects, the techniques described herein relate to a method in which performing a network event action includes adjusting a zoned architecture communication scheme.
[0271] In some aspects, the techniques described herein relate to a method in which implementing a network event action includes implementing a redundancy plan.
[0272] In some aspects, the techniques described herein relate to a method in which performing a network event action includes adjusting control responsibility of at least one endpoint in a multi-zone network.
[0273] These and other systems, methods, objects, features, and advantages of the present disclosure will become apparent to those skilled in the art from the following detailed description of the preferred embodiments and drawings.
[0274] All documents cited herein are hereby incorporated by reference in their entirety. Reference to a singular item should be understood to include the plural item, and vice versa, unless expressly stated otherwise or clear from the text. Grammatical conjunctions are intended to express any and all separate and conjunctive combinations of coordinated clauses, sentences, words, and the like, unless stated otherwise or clear from the context.
[0275] The present disclosure and the following detailed description of certain embodiments thereof can be understood by reference to the following figures. [Brief explanation of the drawings]
[0276] [Figure 1] 1 is a schematic diagram illustrating a previously known network configuration; [Figure 2] 1 is a schematic diagram illustrating an embodiment of the present disclosure. [Figure 3] FIG. 1 is a block diagram depicting particular considerations for a star topology, in accordance with certain embodiments of the present disclosure. [Figure 4] FIG. 2 is a block diagram depicting particular considerations for a ring topology, in accordance with certain embodiments of the present disclosure. [Figure 5]FIG. 2 is a block diagram depicting particular considerations for mesh topology, in accordance with certain embodiments of the present disclosure. [Figure 6A] FIG. 2 is a block diagram depicting an example two-zone network, in accordance with certain embodiments of the present disclosure. [Figure 6B] FIG. 2 is a block diagram depicting an example two-zone network, in accordance with certain embodiments of the present disclosure. [Figure 7] FIG. 1 is a block diagram depicting an example conceptual layering configuration, in accordance with certain embodiments of the present disclosure. [Figure 8] FIG. 2 is a block diagram depicting an example physical packaging configuration in accordance with certain embodiments of the present disclosure. [Figure 9] FIG. 1 is a block diagram depicting example zoning with three zones, in accordance with certain embodiments of the present disclosure. [Figure 10] FIG. 2 is a block diagram depicting example data traffic types, in accordance with certain embodiments of the present disclosure. [Figure 11] FIG. 2 is a block diagram depicting an example central network controller, in accordance with certain embodiments of the present disclosure. [Figure 12] FIG. 1 is a block diagram depicting an example time synchronization operation in accordance with certain embodiments of the present disclosure. [Figure 13] FIG. 2 is a block diagram depicting an example embodiment of controlling a zonal architecture with mixed criticality of messages, in accordance with certain embodiments of the present disclosure. [Figure 14] FIG. 2 is a block diagram depicting an example embodiment of controlling a zonal architecture with mixed criticality of messages, in accordance with certain embodiments of the present disclosure. [Figure 15] FIG. 2 is a schematic representation of example hardware layers for implementing an SOA communication embodiment in a vehicle, in accordance with certain embodiments of the present disclosure. [Figure 16] FIG. 2 is a schematic representation of example hardware layers for implementing an SOA communication embodiment in a vehicle, in accordance with certain embodiments of the present disclosure. [Figure 17]FIG. 2 is a schematic representation of example hardware layers for implementing an SOA communication embodiment in a vehicle, in accordance with certain embodiments of the present disclosure. [Figure 18] FIG. 10 is a diagram that schematically depicts another embodiment for implementing SOA in a vehicle, in accordance with certain embodiments of the present disclosure. [Figure 19] FIG. 1 is a diagram that schematically depicts an embodiment for implementing SOA in a vehicle, in accordance with certain embodiments of the present disclosure. [Figure 20] FIG. 1 is a diagram that schematically depicts some capabilities of embodiments herein, including embodiments that utilize containerized applications, in accordance with certain embodiments of the present disclosure. [Figure 21] FIG. 1 is a block diagram depicting an example implementation of a zone architecture, according to certain embodiments of the present disclosure. [Figure 22] FIG. 10 is a block diagram depicting another example implementation of a zone architecture, according to certain embodiments of the present disclosure. [Figure 23] FIG. 2 is a block diagram depicting an example software stack for a zone architecture in a vehicle, in accordance with certain embodiments of the present disclosure. [Figure 23A] FIG. 2 is a block diagram depicting an example software stack for a zone architecture in a vehicle, in accordance with certain embodiments of the present disclosure. [Figure 23B] FIG. 2 is a block diagram depicting an example software stack for a zone architecture in a vehicle, in accordance with certain embodiments of the present disclosure. [Figure 24] FIG. 1 is a block diagram depicting an example implementation of a zone architecture, along with certain features and considerations related to certain features, in accordance with certain embodiments of the present disclosure. [Figure 25] FIG. 1 is a block diagram depicting an example implementation of a zone architecture, according to certain embodiments of the present disclosure. [Figure 25A] FIG. 1 is a block diagram depicting an example implementation of a zone architecture, according to certain embodiments of the present disclosure. [Figure 25B] FIG. 1 is a block diagram depicting an example implementation of a zone architecture, according to certain embodiments of the present disclosure. [Figure 26] FIG. 1 is a block diagram depicting an example implementation of a zone architecture with an SOA implementation, according to certain embodiments of the present disclosure. [Figure 27] FIG. 10 is a block diagram depicting another example software stack and / or logical layers for a zone architecture in a vehicle, in accordance with certain embodiments of the present disclosure. [Figure 28] FIG. 2 is a block diagram depicting a zone controller according to certain embodiments of the present disclosure. [Figure 29] FIG. 2 is a block diagram depicting a network manager controller in accordance with certain embodiments of the present disclosure. [Figure 30] FIG. 10 is a block diagram depicting a Zone Manager command description in accordance with certain embodiments of the present disclosure. [Figure 31] FIG. 2 is a block diagram depicting a network topology description in accordance with certain embodiments of the present disclosure. [Figure 32] FIG. 1 is a diagram of a procedure for integrating a multi-zone network in a vehicle, according to certain embodiments of the present disclosure. [Figure 33] 33 is a diagram of an alternative procedure to FIG. 32 in which a multi-zone network is installed, according to certain embodiments of the present disclosure. [Figure 34] 33 is a diagram of an alternative procedure to FIG. 32 in which a multi-zone network is installed, according to certain embodiments of the present disclosure. [Figure 35] 33 is a diagram of an alternative procedure to FIG. 32 in which a multi-zone network is installed, according to certain embodiments of the present disclosure. [Figure 36] FIG. 2 is a block diagram depicting a vehicle network performance description according to certain embodiments of the present disclosure. [Figure 37] FIG. 2 is a block diagram depicting a vehicle performance network impact description according to certain embodiments of the present disclosure. [Figure 38]FIG. 1 is a block diagram depicting zone architecture values according to certain embodiments of the present disclosure. [Figure 39] FIG. 10 is a diagram of a process for integrating multi-zone networks in each of a first and a second vehicle according to certain embodiments of the present disclosure. [Figure 40] FIG. 40 is a diagram of another process as in FIG. 39 for integrating multi-zone networks in each of the first and second vehicles according to certain embodiments of the present disclosure. [Figure 41] FIG. 40 is a diagram of another process as in FIG. 39 for integrating multi-zone networks in each of the first and second vehicles according to certain embodiments of the present disclosure. [Figure 42] FIG. 40 is a diagram of another process as in FIG. 39 for integrating multi-zone networks in each of the first and second vehicles according to certain embodiments of the present disclosure. [Figure 43] FIG. 1 is a diagram of a process for utilizing the zone architecture values of the current proposal, in accordance with certain embodiments of the present disclosure. [Figure 44] FIG. 1 is a block diagram depicting a vehicle network risk description, according to certain embodiments of the present disclosure. [Figure 45] FIG. 1 is a diagram of a process for integrating a multi-zone network in a vehicle, according to certain embodiments of the present disclosure. [Figure 46] FIG. 2 is a block diagram depicting a network management controller in accordance with certain embodiments of the present disclosure. [Figure 47] FIG. 1 is a block diagram depicting a zoned architecture communication scheme in accordance with certain embodiments of the present disclosure. [Figure 48] FIG. 10 is a diagram of a process for operating a Zone Manager in accordance with certain embodiments of the present disclosure. [Figure 49] FIG. 10 is a diagram of another process step in operating a Zone Manager, in accordance with certain embodiments of the present disclosure. [Figure 50]FIG. 10 is a diagram of a process for transferring the duties of a central zone manager in accordance with certain embodiments of the present disclosure. [Figure 51] FIG. 2 is a block diagram depicting a network security description in accordance with certain embodiments of the present disclosure. [Figure 52] FIG. 2 is a block diagram depicting permission values according to certain embodiments of the present disclosure. [Figure 53] FIG. 1 is a block diagram depicting a connection scheme in accordance with certain embodiments of the present disclosure. [Figure 54] FIG. 2 is a diagram of a process for control communication between endpoints in a multi-zone network in accordance with certain embodiments of the present disclosure. [Figure 55] FIG. 55 is a diagram of another process portion as in FIG. 54 for control communications between endpoints in a multi-zone network, in accordance with certain embodiments of the present disclosure. [Figure 56] FIG. 55 is a diagram of another process portion as in FIG. 54 for control communications between endpoints in a multi-zone network, in accordance with certain embodiments of the present disclosure. [Figure 57] FIG. 10 is a diagram of a process for providing updated Zone Manager command descriptions in accordance with certain embodiments of the present disclosure. [Figure 58] FIG. 2 is a diagram of a process for controlling communications between endpoints in a multi-zone network in accordance with certain embodiments of the present disclosure. [Figure 59] FIG. 2 is a diagram of another process for controlling communications between endpoints in a multi-zone network in accordance with certain embodiments of the present disclosure. [Figure 60] FIG. 2 is a diagram of another process for controlling communications between endpoints in a multi-zone network in accordance with certain embodiments of the present disclosure. [Figure 61] FIG. 2 is a diagram of another process for controlling communications between endpoints in a multi-zone network in accordance with certain embodiments of the present disclosure. [Figure 62]FIG. 2 is a block diagram depicting a network connectivity description in accordance with certain embodiments of the present disclosure. [Figure 63] FIG. 2 is a diagram of a process for controlling communications between endpoints in a multi-zone network in accordance with certain embodiments of the present disclosure. [Figure 64] FIG. 10 is a diagram of another process for controlling communications between endpoints in a multi-zone network in accordance with certain embodiments of the present disclosure. [Figure 65] FIG. 10 is a diagram of another process for controlling communications between endpoints in a multi-zone network in accordance with certain embodiments of the present disclosure. [Figure 66] FIG. 10 is a diagram of another process for controlling communications between endpoints in a multi-zone network in accordance with certain embodiments of the present disclosure. [Figure 67] FIG. 2 is a block diagram depicting a service manager controller in accordance with certain embodiments of the present disclosure. [Figure 68] FIG. 1 is a system diagram depicting a process for a service management controller in accordance with certain embodiments of the present disclosure. [Figure 69] FIG. 1 is a block diagram depicting aspects of a zone architecture in accordance with certain embodiments of the present disclosure. [Figure 70] FIG. 1 is a diagram of a sample service register, according to certain embodiments of the present disclosure. [Figure 71] FIG. 2 is a diagram of a process for controlling communications between endpoints in a multi-zone network in accordance with certain embodiments of the present disclosure. [Figure 72] FIG. 1 is a diagram of a process for maintaining a service register, according to certain embodiments of the present disclosure. [Figure 73] FIG. 2 is a block diagram depicting a network management controller in accordance with certain embodiments of the present disclosure. [Figure 74] FIG. 1 is a block diagram depicting a zoned architecture communication scheme in accordance with certain embodiments of the present disclosure. [Figure 75]FIG. 2 is a diagram of a process for controlling communications between endpoints in a multi-zone network in accordance with certain embodiments of the present disclosure. [Figure 76] FIG. 2 is a diagram of a process for controlling communications between endpoints in a multi-zone network in accordance with certain embodiments of the present disclosure. [Figure 77] FIG. 1 is a block diagram depicting a vehicle multi-zone architecture configuration platform, in accordance with certain embodiments of the present disclosure. [Figure 78] FIG. 2 is a block diagram process depiction of a vehicle multi-zone architecture configuration platform in accordance with certain embodiments of the present disclosure. [Figure 79] FIG. 1 is a block diagram depicting a vehicle multi-zone architecture configuration platform, in accordance with certain embodiments of the present disclosure. [Figure 80] FIG. 1 is a block diagram depicting a zoned architecture communication scheme in accordance with certain embodiments of the present disclosure. [Figure 81] FIG. 2 is a block diagram depicting a network operation report in accordance with certain embodiments of the present disclosure. [Figure 82] FIG. 2 is a block diagram depicting a vehicle network performance description according to certain embodiments of the present disclosure. [Figure 83] FIG. 2 is a block diagram depicting a vehicle performance network impact description according to certain embodiments of the present disclosure. [Figure 84] FIG. 2 is a block diagram depicting basic network selection values, in accordance with certain embodiments of the present disclosure. [Figure 85] FIG. 2 is a block diagram depicting a vehicle-environment model, according to certain embodiments of the present disclosure. [Figure 86] FIG. 2 is a block diagram depicting a network hardware model in accordance with certain embodiments of the present disclosure. [Figure 87] FIG. 1 is a diagram of a process for providing network operation reports in accordance with certain embodiments of the present disclosure. [Figure 88]FIG. 1 is a diagram of a process for communicating a zoned architecture communication scheme in accordance with certain embodiments of the present disclosure. [Figure 89] FIG. 1 is a block diagram depicting a vehicle multi-zone monitoring platform, according to certain embodiments of the present disclosure. [Figure 90] FIG. 2 is a block diagram depicting network detail values, in accordance with certain embodiments of the present disclosure. [Figure 91] FIG. 1 is a diagram of a process for providing a virtual network map to a user interface in accordance with certain embodiments of the present disclosure. [Figure 92] FIG. 1 is a diagram of a process for establishing a zoned architecture communication scheme in accordance with certain embodiments of the present disclosure. [Figure 93] FIG. 2 is a block diagram depicting a network monitoring controller in accordance with certain embodiments of the present disclosure. [Figure 94] FIG. 2 is a block diagram depicting network event actions according to certain embodiments of the present disclosure. [Figure 95] FIG. 1 is a diagram of a process for implementing a network event action in accordance with certain embodiments of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0277] Without being limited to any other aspects of the disclosure, aspects of the disclosure herein provide implementations of a zonal network architecture in a vehicle, where each zone includes a portion of endpoints in the vehicle, and where each zone can include multiple network types, with some endpoints communicating over a CAN network architecture and other endpoints communicating over an Ethernet architecture, a LIN architecture, or the like. Utilizing a zonal architecture provides several benefits over previously known systems, such as allowing endpoints to communicatively couple to networks and other devices based on their physical location rather than their function, reducing path lengths for electrical connections, allowing redundancy of connectivity options for endpoints (e.g., to accommodate loss of connectivity infrastructure due to wear and tear, failure, vehicle damage, or the like), improving network control and security, allowing greater options for controller distribution (e.g., reducing the number of controllers required, allowing redundancy between controllers), and dynamic configuration of vehicle applications, connectivity between endpoints, data collection operations, and / or data provisioning options (e.g., making data available from an endpoint to any other endpoint).
[0278] Example embodiments utilize policies to enforce security, permissions, and / or configuration options. For example, policies may include data structures that define which endpoints are allowed to request data, which endpoints are allowed to provide data, priorities for the endpoints, configurations of the data for the endpoints (e.g., units, sampling rate, latency, priority, resolution, etc.), or the like. In particular embodiments, policies are files or other data structures that can be dynamically updated, allowing changes to configuration without requiring firmware changes, software changes, or the like, and allowing dynamic updates without requiring shutdowns, increasing the risk of incomplete updates that could disable the controller, or the like.
[0279] Certain aspects of the present disclosure include various operations for controlling communications in a vehicular network environment, including providing communications between devices or endpoints in different network zones and / or different network types, providing control without requiring the communicator's specific knowledge of the actual addresses or locations of other devices on the network, utilizing policies or configuration files to update network control parameters, and the like. Additionally, certain aspects of the present disclosure include controlling communications between vehicular devices and external devices in either direction. Additionally, certain aspects of the present disclosure include adjusting the routing of communications on the network, whether between separate devices on the network or between devices on the network and external devices.Without being limited to any aspect of the present disclosure, descriptions that may enhance understanding of some of the tools that may be utilized in conjunction with the present disclosure to tactically implement certain operations herein, as well as some of the terminology used herein (e.g., policy, endpoint, external device, network protocol, network type, etc.), may be found in U.S. application Ser. No. 17 / 027,167, filed September 21, 2020, and entitled SYSTEM, METHOD, AND APPARATUS TO SUPPORT MIXED NETWORK COMMUNICATIONS ON A VEHICLE (SONA-0006-U01); U.S. application Ser. No. 17 / 027,187, filed September 21, 2020, and entitled SYSTEM, METHOD, AND APPARATUS TO EXTRA VEHICLE COMMUNICATIONS CONTROL (SONA-0007-U01); and U.S. application Ser. No. 17 / 027,187, filed March 8, 2021, and entitled SYSTEM, METHOD, AND APPARATUS FOR MANAGING VEHICLE DATA No. 17 / 195,589, filed June 6, 2022, and entitled SYSTEM, METHOD, AND APPARATUS FOR MANAGING VEHICLE DATA COLLECTION (SONA-0010-U01), and U.S. application Ser. No. 17 / 833,614, filed June 6, 2022, and entitled SYSTEM, METHOD, AND APPARATUS FOR MANAGING VEHICLE DATA COLLECTION (SONA-0012-U01), each of which is incorporated herein by reference in its entirety for all purposes. Embodiments throughout this disclosure may be embodied at least in part utilizing controllers, circuits, components, processors, and / or operations such as those described in one or more of the aforementioned patents or patent applications.For example, operations for managing intra-network and / or inter-network communications in a vehicle, including adjusting management based on changes to policy or the like, can utilize embodiments such as those described in the '167 application; operations for managing communications between any endpoint and an external device, including adjusting management based on changes to policy or the like, can utilize embodiments such as those described in the '187 application; operations for managing data collection operations, including adjusting data collection, formatting, and / or configuring data, data lifecycle management, and communication of collected data, can utilize embodiments such as those described in the '589 application; and / or operations for implementing, executing, and otherwise managing automated vehicle operations, including operations that can be performed without software or firmware updates being required, can utilize embodiments such as those described in the '614 application.
[0280] Certain aspects of the present disclosure may be described as a controller, a circuit, a computing device, a processor, an electronic computing unit (ECU), a manager (see, e.g., FIG. 22 and related discussion), a management device (see, e.g., FIG. 8 and related discussion), an adapter (see, e.g., FIG. 19 and related discussion), a platform, or any other component having a similar language and configured to perform particular operations and / or having structure for performing particular operations. Any such device will be referred to as a "circuit or similar term" in the remainder of this paragraph. Without being limited to any other aspect of the present disclosure, a circuit or similar term as used herein may be embodied as any one or more of: a computing device having computational resources (e.g., processing, memory, communication interfaces, etc.) configured and capable of performing aspects of the operations described; any hardware interface element such as a mouse, keyboard, microphone, display device, or the like; a sensor configured to provide the described data elements and / or to provide information from which the described data elements may be determined, estimated, or inferred; an actuator configured to provide the described operations; instructions stored on a computer-readable medium such that a processor responds to the instructions and thereby performs one or more of the described operations; a hardware component configured to perform one or more of the operations in response to operating conditions (e.g., a valve, spring, switch, gear arrangement, etc. configured to perform one or more of the described operations); and / or a logic circuit configured and / or programmed to perform one or more of the described operations. A circuit or similar term is depicted as a single device in the embodiments herein for clarity of this description.A circuit or similar term may be distributed, e.g., portions of a circuit may be located on different computing devices and / or may be at least partially embodied on various hardware devices, with the distributed portions cooperating to perform the described functionality. In particular embodiments, the distribution of a circuit or similar term may vary according to a current operational state, e.g., portions of the build environment circuitry 9804 (see FIG. 77 and related description) may be located on a particular operational user interface and / or user device, e.g., to make operation more responsive to the user and / or (in this example) to enhance the security of communications between the user and the vehicle multi-zone architecture configuration platform. Furthermore, the devices embodying the circuit or similar term may vary depending on the operational state and / or the operation being performed. In a further example using the build environment circuitry 9804, a user may connect to the platform at a first device (e.g., a laptop) at a first time and at a second device (e.g., a mobile phone) at a second time, and the elements embodying the build environment circuitry 9804 may differ; for example, a portion of the build environment circuitry 9804 may be located on the user device during a particular operation. In another example, the central zone manager may be transitioned during a particular operation, such as when another zone controller is designated as the central zone manager in response to an emergency event; therefore, the particular hardware device embodying the central zone manager may differ at different times, in different operational states, and / or depending on the particular operation being performed by the system. The use of circuitry or other similar terms herein is provided for clarity of this description and contemplates any device configured to operatively perform the operations described herein. Illustrative and non-limiting specific configurations are described herein to provide clarity of explanation and context to clarify the operation and benefits of the present disclosure; however, any other configurations capable of and configured to perform the described operations are specifically contemplated herein.
[0281] Various embodiments herein are presented as descriptions of procedures, methods, or other operations for performing particular actions that embody aspects of the present disclosure. Such operations will be referred to as "procedures" in the remainder of this paragraph. Any such procedures may vary in the order of operations performed as cyclical or repeated operations (where relevant, and in whole or in part), the described operations may be divided into parts, and / or operations may be combined (in whole or in part). In particular embodiments, a procedure may be performed in whole or in part by any hardware device as described throughout this disclosure, including any circuit, controller, computing device, etc., capable of performing the operations of the illustrative procedure.
[0282] FIG. 1 illustrates an example previously known system 100 that includes various networks and endpoints distributed around a vehicle. The example of FIG. 1 is simplified to illustrate differences from the system of the present disclosure, but actual examples of the previously known system are more complex and intertwined than the depicted system. The example of FIG. 2 schematically depicts an example system 200 of the present disclosure. The network is divided into zones selected based on cost (e.g., reducing wiring, interface, and configuration costs) and risk management (e.g., reduced exposure of network paths to various vehicle risks, improved security because fewer network zone managers can monitor network zones and enforce security protocols). Other embodiments of the present disclosure maintain cost reduction and risk management but can further support capabilities such as providing redundant control and / or hardware operation, for example, to create a system robust against failures and maintain selected capabilities based on failures. Thus, the system of the present disclosure has a reduced probability of failure and improved response capabilities in the event of a failure.
[0283] 3-5 illustrate example basic topologies 300, 400, and 500 supported by embodiments herein. Example topologies are non-limiting and include a star topology (e.g., all zones communicate through a central zone), a ring topology (e.g., communications traverse through successive links of all zones in a selected order, with adjacent zones able to communicate directly and remote zones communicating using hops through intermediate zones), and / or a mesh topology (e.g., each zone is communicatively coupled to every other zone). Particular embodiments may utilize one or more combinations of these and / or partial implementations of one or more of these (e.g., a mesh topology with some connections omitted). Note that topology herein refers to network connections between network zones and the Zone Managers for each network zone, rather than connections between endpoints. In a highly distributed system of 100 or more devices with mixed overlapping networks, the terminology of mesh, star, or ring topology would indicate something entirely different from the network zone layouts of FIGS. 3-5. It should further be noted that the depicted network zone selection and locations are non-limiting examples. Zone layouts can be selected based on the cost to design, maintain, and integrate the resulting network zones, and can further be selected to support redundancy. Reducing the number of extended connections throughout a vehicle allows embodiments of the present disclosure to improve routing, such as by taking routes through lower-risk areas for the vehicle and reducing the likelihood that any one of these routes will result in an adverse event. For example, if a vehicle suffers damage in one location, the damage is much more likely to affect no network at all or to damage only a single zone connection, rather than damaging several networks and causing the loss of numerous devices distributed around the vehicle.Furthermore, by allowing the network to be organized around devices rather than functions, inherent risk management of the vehicle is likely to support risk management for the network. For example, the battery pack of an electric vehicle is typically located within a protected space. In previously known systems, multiple network links for the battery pack are distributed around the vehicle, which can result in unexpected failure conditions, such as damage to another remote area of the vehicle causing a loss of battery pack functionality (e.g., the ability to automatically disconnect the battery in the event of an accident), reducing the value of efforts to protect the battery pack.
[0284] Figure 3 illustrates certain considerations for a star topology, with four network zones in the example. A star topology is a low-cost implementation and offers other benefits, such as a significant reduction in the amount of cabling required, I / O between zones, and reduced implementation costs for implementing network management features that would otherwise be required to obtain some of the benefits of other topologies. A star topology includes certain disadvantages, such as a single point of failure in the central zone controller that would disable connections between other network zones, a lack of redundancy if communication is lost between one zone and the central zone, and a requirement for a high-capacity central zone controller. Nevertheless, embodiments such as in Figure 3 are feasible, for example, if a high-capacity central zone controller is located in the protected area.
[0285] FIG. 4 illustrates specific considerations for a ring topology 400, with four network zones in the example. A ring topology provides a significant reduction in the amount of cabling required, but less than a star topology and less than I / O between zones. A ring topology may introduce some latency, for example, between two high-demand endpoints located in remote zones. A ring topology provides some redundancy, for example, if the system has the ability to function if any single connection between zones fails or is lost. It will be understood that network management may be implemented to support redundancy, for example, rerouting if a link is lost between two zones. In certain embodiments, failure analysis may be utilized to determine ring configurations and sequencing that ensure, for example, that two critical zones are not separated by too many “hops” upon failure of a connection between any two zones in the system. In certain embodiments, a ring topology may be enhanced with, for example, additional direct connections between critical zones and / or separate connections between critical zones, with a connection between the critical zone and a “central” zone. Embodiments herein often include the central zone concept. While various design considerations may cause the central zone to often be centrally located in a geometric sense, the central zone notion as utilized herein refers to logical centrality; for example, the central zone in many embodiments comprises a single point for communication to external devices, for monitoring the network, and for receiving and distributing updates.
[0286] FIG. 5 illustrates certain considerations for a mesh topology 500. A mesh topology provides the highest redundancy and lowest latency implementation. In certain embodiments, a mesh topology may be augmented with additional connections, such as dual connections between two critical zones and / or between a critical zone and a central zone. A mesh topology still introduces significant cost savings in terms of reduced wires and connections required compared to previously known systems, such as previously known systems that may have 100 or more endpoints coupled to various network devices, where the wiring is configured according to the function of the endpoints and regardless of the physical location of those endpoints. A mesh topology requires management of communications to achieve the benefits of available redundancy, avoid duplicate communications utilizing network bandwidth, and the like.
[0287] FIG. 6A depicts an example two-zone network 600, for example, with an endpoint at the front of the vehicle connected to a first zone and an endpoint at the rear of the vehicle connected to a second zone. The example of FIG. 6A includes two separate connection paths that allow communication to continue even if one of the paths is compromised. FIG. 6B depicts an example three-zone network 601, with the zones depicted as front, rear, and center. References herein to front, rear, center, or other similar terms are not limited to physical locations on the vehicle but instead refer to logical connections, which may, but need not, correspond to physical locations. For example, the endpoint load in many vehicles is heavier at the front of the vehicle; therefore, a three-zone network may include two zones at the front (one “front” zone and one “center” zone) and a single zone at the rear. The selection of zone locations can be based on the physical locations of the endpoints, the functionality of the endpoints (including interrelationships of the functionality), inter-zone communications (e.g., number, content, communication speed, message size, latency requirements, etc.) that will be required to support the particular deployment, the capabilities of the zone controllers, and the like.
[0288] 7 depicts an example conceptual layering configuration 700 for embodiments herein. The example layering in FIG. 7 includes a hardware layer (e.g., the actual physical layout of zones, networks, connections to endpoints, etc.), a physical component layer (e.g., switches, controllers, edge gateways, memory devices, etc.) to support communications, an application layer (e.g., control modules and functions to support operations such as network management, data management, service-oriented architecture (service) management, automation management (e.g., support for automated vehicle functions, service operations, vehicle testing, etc.), and / or security management (e.g., managing encryption of messages, stored data, etc., and managing communications and / or endpoint data permissions)), and a vehicle function layer (e.g., specific vehicle functions supported by a distributed set of endpoints across zones, such as the vehicle's control software, infotainment support, automated driver assistance support, or the like).
[0289] FIG. 8 depicts an example physical packaging configuration 800 for an example embodiment with endpoint communication to a particular zone and with communication between zones implementing cross-zone communication between endpoints.
[0290] FIG. 9 depicts an example zoning embodiment 900, with three zones in the example, and considerations for implementing a zonal architecture in a vehicle. The group of endpoints 306 in the example are CAN devices coupled to one of the network zones. The present disclosure enables any type of connection of endpoints to a given network zone and seamless communication between endpoints in different zones regardless of the underlying network type specific to the endpoint. For example, a CAN device in a first network zone can easily communicate with a LIN device in another network zone. Furthermore, a user with access to the vehicle (with authorization) can browse devices in the system without requiring any knowledge by the user of the device location or possibly the network type for the device's connection. Additionally, a user can request or collect available data from devices without requiring any knowledge of the device, the device's network location or type, or possibly knowledge of whether the data was provided by a specific device or some other determination (e.g., virtual sensor). The example of FIG. 9 includes a central zone manager 302 and two zone managers 304 for the other two zones.
[0291] 10 depicts example 1000 data traffic types that may be present in an example vehicle having a zonal architecture, depicted in the context of the zone manager 304 (or zone controller). Network management control, which may be implemented in a central zone controller and / or distributed across two or more zone controllers, includes managing network bandwidth, permissions, message prioritization, or the like to ensure that critical vehicle functions are supported, as well as to support other functions in a desired manner and / or at a desired service level consistent with the required support of critical vehicle functions.
[0292] FIG. 11 depicts an example 1100 central network controller 302 along with some considerations for the central network controller and configuration of network management for vehicles.
[0293] FIG. 12 depicts example 1200 time synchronization operations for embodiments herein. Example synchronization operations include operations to ensure that time-sensitive messages are delivered within expected windows (e.g., latency, arrival time, etc.), are time-stamped according to accepted norms that enable control actions at endpoints to utilize the data in an expected manner, or the like. In particular embodiments, time synchronization may be relative (e.g., ensuring that all interested endpoints can utilize data as expected without regard for synchronization relationship to some absolute reference time), absolute (e.g., ensuring that all interested endpoints can correlate data values to an absolute reference time), or a combination thereof. FIG. 34 depicts additional or alternative time synchronization operations for embodiments herein.
[0294] 13-14 depict an example embodiment including a three-zone network with various communication routing options for different systems. Routing options may be determined based on, but not limited to, source or destination endpoints, message content, associated flow of messages, application, function, or the like, current vehicle operating conditions, and / or to support redundancy operations (e.g., replacing or mitigating loss or degradation of hardware components and / or controllers). System 1300 depicts various routing paths 1302, 1304 for different messages. System 1400 depicts various alternative routing paths 1402, 1404 for FIG. 13, which may be based on difference-based configurations depending on message scale and / or vehicle operating conditions.
[0295] FIG. 15 is a schematic illustration of a service-oriented architecture (SOA) implementation 1500 that enables endpoints to subscribe to services (e.g., collect desired data, provide actuator commands, etc.), publish services, and / or restrict service access according to permissions (e.g., as described in a policy or similar implementation). FIG. 16 is a schematic illustration of an example hardware layer 1600 for implementing an SOA communication embodiment in a vehicle. Utilizing SOA for network communications in a vehicle provides several benefits, including ease of dynamic changes to network configuration and security control for endpoints to access and / or publish data. FIGS. 17 and 18 schematically illustrate embodiments 1700, 1800 for implementing SOA in a vehicle. FIG. 19 schematically illustrates an embodiment 1900 for implementing SOA in a vehicle utilizing an SOA adapter, which may be included in a zone, e.g., on a central zone controller, and / or with the zone controller.
[0296] Figure 20 schematically depicts some capabilities for embodiments herein, including embodiments utilizing containerized applications 2006 (e.g., containerized network control, time synchronization management 2008, automation management 2004, SOA support 2010, endpoint control 2002, vehicle functionality, or the like). Figure 21 depicts example implementation considerations for containerized network management of a zone architecture.
[0297] Figure 21 depicts an example implementation 2100 for a zone architecture with support for various network type interface endpoints with the zones. Figure 22 depicts another example implementation 2200 for a zone architecture. Figure 23 depicts an example software stack 2300 for a zone architecture in a vehicle, divided into Figures 23A and 23B, traversing a hardware layer 2306 at the bottom, a control layer 2304 in the middle, and cloud communications at the top 2302.
[0298] Figure 24 depicts an example implementation 2400 for a zone architecture, along with certain features and considerations for certain features. The example in Figure 24 includes a central zone 2402 hosting several applications 2408, communications to a cloud server 2406, endpoints 306 in the central zone 2402, and a second zone 2404 with a zone controller.
[0299] FIG. 25, divided into FIGS. 25A and 25B, schematically depicts a zone controller 2500 that may be utilized as a central zone manager for various embodiments of the present disclosure.
[0300] FIG. 26 depicts an example zone configuration 2600 having two zones, with some applications supported in a first zone and some endpoints supported in a second zone.
[0301] 27 depicts a control hierarchy 2700 with a core services layer 2706, a services layer 2704, and an application layer 2702. The control hierarchy 2700 may be implemented or coordinated by a controller in the system, such as a central zone manager.
[0302] FIG. 28 depicts a zone controller 302 with example network traffic types that may be present in a vehicle having a zoned architecture that may be considered for various embodiments herein, including at least a selected zone configuration, mixed-criticality message management, SOA implementation, or the like.
[0303] Without being limited to any other aspect of the present disclosure, embodiments herein provide systems and procedures for implementing a zonal network architecture in a vehicle to improve reliability, installation costs, operating costs, operational performance, and / or the ability to avoid or mitigate risk, failure, or degradation of the network and the resulting impact on the vehicle mission.
[0304] Referring to FIG. 29 , an example system 5000 includes a vehicle having a multi-zone network including multiple network zones, each of which includes at least one zone manager. Throughout this disclosure, a zone manager may alternatively be referred to as a zone controller. While vehicles are not depicted in FIG. 29 , the system 5000 of FIG. 29 may include, in whole or in part, any of the embodiments described herein that include a vehicle having a multi-zone network. For example, in the example system 5000, the network zones are configured according to a network topology description of a selected zone architecture, the network topology description including any one or more aspects as described throughout this disclosure (e.g., see FIGS. 31 and 38 and related discussion). In certain embodiments, each network zone includes a zone manager configured to perform control operations for the zone, such as, for example, enabling communication with other zones, limiting bandwidth or other resource utilization, prioritizing messages, and / or performing any other zone manager (or zone controller) operations as described herein.
[0305] The example system 5000 further includes a network management controller 5002. The example network management controller 5002 includes a zone enforcement circuit 5004 that interprets a zoned architecture communication scheme 5014, a zone manager command circuit 5006 that interprets zone manager command descriptions 5016 for each of the zone managers in accordance with the zoned architecture communication scheme 5014, and a zone execution circuit 5008 that provides corresponding zone manager command descriptions 5016 to each of the zone managers. For example, the zoned architecture communication scheme 5014 may be embodied as part of a policy passed to the network management controller 5002, such as by an external device, that defines various aspects of managing network communications in the vehicle and between zones in the vehicle.
[0306] Some of the communication controls may apply to different endpoints in different zones, and the specific configurations may not be known to the user (e.g., an employee of the vehicle manufacturer) creating the policy. In an example, the zone manager command circuit 5006 determines the responsibilities of each zone manager that will comply with the zonal architecture communication scheme 5014 and determines zone manager command descriptions 5016 for implementing the portion of the zonal architecture communication scheme 5014 associated with this particular zone manager, for example, based on the endpoints (e.g., sensors, actuators, controllers, etc.), flows, functions, applications, or the like, served by or embodied in the zone. The zone execution circuit 5008 then distributes the zone manager command descriptions 5016 to the various zone managers. Utilization of local versions of the zone manager command descriptions 5016 by individual zone managers, such as local configuration files, allows the system to implement zone communication control updates immediately upon vehicle startup and / or allows updates during runtime operation, possibly depending on the desired behavior of the system and / or the type of change in the zone manager command descriptions 5016 updates.
[0307] Embodiments herein thereby enable users with particular expertise, for example in risk management or failure analysis, to configure the zoned architecture communication scheme 5014 according to their expertise, without requiring the users to understand the particular configuration of endpoints and control responsibilities for vehicles. Thus, embodiments of the present disclosure allow systems to be built by appropriate experts to improve outcomes, for example, optimize the risk profile of the network, and also by reducing development time and turnaround time for rolling out improvements. Furthermore, embodiments of the present disclosure reduce costs by enabling zones to seamlessly collaborate and hand off data without (and typically with) loss of security or communication capabilities.
[0308] One consequence of the zone architecture configuration herein, which allows the zone architecture to be configured for various purposes (e.g., system cost, system reliability, providing redundancy, etc.) independent of the function of the endpoints in the zone, is that for many vehicle functions, the supporting endpoints will be distributed across two or more zones. Utilizing the Zone Manager command descriptions 5016 allows these endpoints to seamlessly cooperate to perform the underlying vehicle function while having a consistent implementation for these endpoints with respect to communication latency, applicable security, data quality, and the like. Previously known systems group network zones, with distinct zones existing entirely on the vehicle's function (e.g., a network providing communication between powertrain components) to enforce security of communications with the hardware layer (e.g., providing separate public and private CANs) or based on the party responsible for a particular endpoint (e.g., an electric motor supplier). Thus, previously known systems result in expensive and redundant hardware layers, for example, with numerous parallel network cables traversing the same vast area of the vehicle, exposing numerous systems to risks all distributed around the vehicle. Embodiments of the present disclosure significantly reduce the overall cost of network support, which can be built with planned management of risk, redundancy, security applications, and the like, and with a selected combination based on the designer's priorities of enhanced capacity, reduced risk, reduced cost, and enhanced security.
[0309] In the example of Figure 29, each of the Zone Managers responds to a corresponding Zone Manager command description 5016 to control communications between endpoints in the corresponding network zone and endpoints in at least one other zone in the network zone.
[0310] 31 , example aspects of a network topology description include, without limitation, a communication coupling configuration 5204 of zones (e.g., which zones are directly coupled to a particular zone, which may be a star, mesh, ring, or other configuration) or a logical coupling configuration 5206 of zones (e.g., ordering and sequencing of communications between zones, e.g., when communications pass through another intermediate zone, priority between zones, and / or a description of zones, which may be virtual zones, e.g., where some communications share the same hardware layer but are separated in terms of which endpoints can see or understand various communications).
[0311] The example zone enforcement circuitry 5004 interprets the zoned architecture communication scheme 5014 in response to a policy provided by an external device. The example policy is, for example, a configuration file for network communications in the vehicle that allows the Zone Manager command descriptions 5016 to be updated without modifications to the base software for the vehicle, at least for certain embodiments or update operations, reducing the risk of an incomplete update (which could totally disable the vehicle), and reducing the operational impact of the update (e.g., without requiring a shutdown, operational incapacity, and / or dedicated service operation). The example Zone Manager command circuitry parses the policy that includes the configuration file to determine the Zone Manager command descriptions 5016. In certain embodiments, the Zone Manager command descriptions 5016 are embodied as local configuration files that are communicated to and utilized by the corresponding Zone Manager. In particular embodiments, the Zone Manager command descriptions 5016 are embodied as updates to local configuration files for one or more Zone Managers, and the Zone Execution Circuit 5008 provides the corresponding Zone Manager command descriptions 5016 to each of the Zone Managers by updating the local configuration files for the associated Zone Managers.
[0312] Referring to FIG. 30, an illustrative and non-limiting zone manager command description 5016 may include communication tolerance values 5102 (e.g., which endpoints, flows, applications, functions, network zones, etc. are allowed to communicate with others of these, which may be provided as inclusive and / or exclusive descriptions), communication sampling rate values 5104 (e.g., how fast an endpoint, flow, application, function, network zone is allowed to request or provide messages, and / or absolute or relative descriptions of allowed bandwidth usage, including by zone), communication configuration values 5106 (e.g., message headers, units, byte depth, metadata, encapsulation, and / or includes one or more aspects such as message information such as latency parameters to be implemented (e.g., maximum or minimum latency values), and / or communication destination values 5108 (e.g., endpoints, zones, addresses to which messages from endpoints, flows, applications, functions, network zones are allowed to send messages, etc., and / or routing descriptions such as "Zone 1 can send messages generated by Flow A directly to Zone 2, and all other messages to Zone 2 will be passed through Zone 3," for example, to maintain bandwidth in critical network zones, balance workload and utilization, etc.).
[0313] The example network management controller 5002 further includes a hardware redundancy enforcement circuit 5010 that supports the implementation of a hardware redundancy scheme. The example hardware redundancy enforcement circuit 5010 determines that a hardware emergency event 5018 has occurred (e.g., an endpoint, network zone, zone manager, etc. loses communication and / or experiences degraded performance) and adjusts at least one of the zone manager command descriptions 5016 in response to the hardware emergency event 5018. For example, the system 5000 may have a defined redundancy scheme where, if Zone Manager A fails, Zone Manager B alters operation to at least partially fulfill the responsibilities of Zone Manager A. The available hardware redundancy for a given system 5000 depends on the zone configuration and connections, as reflected in the zoned architecture communication scheme 5014, and further on the planning for such hardware failures. In a further example, Endpoint Z in Zone A may implement a particular vehicle function that is unavailable if Zone Manager A fails. The response may depend on the type of failure; for example, if Zone Manager B can communicate with Endpoint Z, Zone Manager B can simply perform the network control duties previously performed by Zone Manager A, and full system capability is likely to remain available. Nevertheless, if a failure of Zone Manager A eliminates all communications to Zone A, the response may include transferring control responsibilities from Zone A to an endpoint in another zone of the vehicle, and Zone Manager B may be configured to further notify the endpoint that it will perform substitute operations to replace the functionality of Endpoint Z. In certain embodiments, other changes may be implemented to account for, for example, different network traffic patterns and the like that may affect more than just Zone B, and thus the changes to Zone Manager command description 5016 for a manager failure in Zone A may extend further than just updates to the duties of Zone Manager B.In certain embodiments, the lost functionality may be completely replaced, e.g., another endpoint in the system is capable of completely replacing all operations of endpoint Z. In certain embodiments, the lost functionality may be partially replaced, e.g., a less capable endpoint may perform some critical functions of endpoint Z, allowing continued operation that may be degraded. In certain embodiments, the replacement of functionality may be very limited but still be important, e.g., allowing the vehicle to continue operating in a limp home mode to allow the operator to move the vehicle to a safe location, and / or allowing some functionality, such as a battery disconnect operation, to be performed separately by endpoint Z that is limited and mission-disabled, but may be important in a catastrophic failure situation (e.g., an accident with a vehicle that disables a significant portion of the entire network hardware layer). The utilization of hardware emergency events 5018 and updates to zone manager command descriptions 5016 allows for a layered response to various hardware failures while maintaining as much vehicle operation as possible with as little impact to the operator as possible.
[0314] The illustrative network management controller 5002 includes a control redundancy enforcement circuit 5012 that determines that a control emergency event 5020 has occurred and adjusts the zone manager command descriptions 5016 in response to the control emergency event 5020. For example, if an endpoint controller fails in a system, hardware connections to the zone and to other endpoints may still exist, but the functionality performed by this endpoint will otherwise be lost. In an example, the control emergency event 5020 adjusts the zone management commands 5016 to transfer responsibility for the lost control functionality to another endpoint (or multiple endpoints) in the vehicle. In certain embodiments, the control emergency event 5020 may be a control emergency event 5020 determined by performance degradation, questionable performance (e.g., stuck or slow response values), and / or a fault code or diagnostic action. Consideration of the control emergency event 5020 is otherwise similar to considerations for a hardware emergency event 5018, where various endpoints, zone managers, and network zones may be affected by response actions. It will be understood that some events may not be easily categorized as hardware events or control events. The actions described herein apply generally to emergency events, regardless of the specific reason for the event, and the specific terminology using hardware events and control events is utilized for clarity in describing specific actions. The terminology utilized is not limiting, and emergency events can be addressed even if the true cause or classification of the event may not be known.
[0315] Referring to FIG. 32 , an example procedure 5300 for implementing a zonal architecture in a vehicle is generally depicted. The example procedure 5300 includes operations for interpreting a vehicular network performance description 5702 (see FIG. 36 ). The example vehicular network performance description 5702 includes performance measures for the vehicular network, where the measures may include minimally acceptable values (e.g., for performing a vehicle mission and / or meeting specifications), target or desired values, maximum values (e.g., performance values above which commercial benefit is not achieved and / or above which benefit is expected to stop increasing), statistical descriptions (e.g., averages, time-averaged values, fluctuation descriptions, etc.), and / or any other type of performance measure description. In certain embodiments, aspects of the vehicular network performance description 5702 are utilized in an index, for example, to compare costs and / or benefits between two or more zonal architecture values.
[0316] The example vehicle network performance description 5702 includes latency values 5704, such as, for example, maximum or minimum acceptable latency, an average latency description, a latency trajectory, or a duty cycle (e.g., to represent burst behavior, etc.). In particular embodiments, the latency values 5704 may be considered for various endpoints, flows, features, applications, or the like, and / or between particular endpoints, network zones, etc. The example vehicle network performance description 5702 includes bandwidth values 5706, representing, for example, the bandwidth of one or more zones to be maintained, to be achieved, available, etc. In particular embodiments, the bandwidth values 5706 are related to a zone or an endpoint. The example vehicle network performance description 5702 includes hardware redundancy descriptions 5708, including, for example, hardware aspects of the network that should have backup operations available and / or acceptable capacity descriptions for these backup operations. The example vehicle network performance description 5702 includes a control redundancy description 5710, which includes, for example, control aspects of the network and / or network endpoints that should have available backup operations, and / or acceptable capability descriptions for these backup operations.
[0317] The example procedure 5300 further includes an operation 5304 for determining a zone architecture value in response to the vehicle network performance description 5702 and a vehicle performance network impact description 5802 (see FIG. 37 ). The example vehicle performance network impact description 5802 includes the impact on network capacity for the considered zone architecture value, taking into account the vehicle configuration and taking into account which network impacts are important to the particular system.
[0318] The example vehicle performance network impact description 5802 includes an installed hardware cost value 5804, which may include consideration of some cost type of the zone architecture value considered. Example hardware cost values 5804 include aspects such as the hardware physical cost (e.g., cost of controllers, zone managers, cables, connectors, shielding, etc. to physically implement the zone architecture value), the physical footprint of the installation (e.g., space, weight, number and type of integration interfaces such as brackets, routing, difficulty and / or sensitivity of integration, testing requirements to verify the installation, etc.), the control cost of the installation (e.g., the engineering work required to code the solution, the testing cost to ensure any code work is as planned, bandwidth utilization to implement the solution, processor utilization to implement the solution, memory utilization to implement the solution, etc. - any base control can be considered a change to the vehicle, for example, by combining endpoints and / or changing the way vehicle controls operate and / or Zone Manager operation), and / or the service cost of the installation (e.g., the impact on physical access to service procedures and / or parts of the vehicle affected by the installation, the ability to replace components, any testing or validation procedures incorporated into service procedures by the installation, the sophistication of service tools to perform service procedures that may be affected by the installation, etc.). The installed hardware cost value 5804 may generally be considered as the “cost” portion of a given zone architecture value that is utilized in an optimization routine to determine, for example, an acceptable, improved, and / or optimized zone architecture value.
[0319] Example vehicle performance network impact description 5802 includes mission capability description 5806, e.g., a description of the ability of the considered zonal architecture values to satisfy performance measures of basic vehicle operation, e.g., throughout a defined space, under all normal operating conditions, environmental conditions, and the like. Example vehicle performance network impact description 5802 includes redundancy capability description 5808, including a description of the ability of the considered zonal architecture values to satisfy hardware and / or control redundancy descriptions. Example vehicle performance network impact description 5802 includes reliability description 5810, including a description of the likely impact of the considered zonal architecture values on reliability factors, e.g., estimating maintenance schedules, failure rates and costs, downtime costs, etc. These estimates may be based on temperature, vibration, EMI, and / or water ingress factors related to the vehicle and may depend on the physical routing of the network cables, the location and environment of the network components (e.g., zone managers), and selected physical components such as cable type, shielding utilized, connector type, cooling parameters (e.g., controller fins, size, and power utilization, etc.).
[0320] The operation 5304 for determining zonal architecture values as a function of the vehicle network performance description 5702 and the vehicle-performance network impact description 5802 may include, for example, any decision algorithm or optimized routing as understood in the art that utilizes the vehicle network performance description 5702 parameters generally as a “benefit” function and the vehicle-performance network impact description 5802 parameters generally as a “cost” function. In particular embodiments, the vehicle network performance description 5702 is input by a user and / or determined from vehicle specifications, and the vehicle-performance network impact description 5802 is determined as a function of the network routing layout, network topology, location of network components, the zonal architecture communication scheme, and known information about the vehicle and the likely operating environment. In particular embodiments, the initial zonal architecture values are utilized as a starting point, which may be a design input by the user, a design from a previous model year of the vehicle, a design from a similar vehicle, and / or a simple baseline design used as a general starting point. In particular embodiments, the operations of procedure 5300 and / or similar design procedures described in this disclosure (e.g., and without limitation, procedures described and / or supported in the embodiments in Figures 43, 45, 77, and 93, and related description) include working through a base set of zonal architecture values (e.g., star, mesh, ring, two-node, three-node, four-node, etc.) and using the best outcome result from these base sets of zonal architecture values as the initial zonal architecture value. If the initial zonal architecture value is acceptable, operation 5304 can include using the initial zonal architecture value as the determined zonal architecture value, potentially highlighting or signaling any aspects of interest, such as sources of greatest cost, lowest performance parameters, etc.In certain embodiments, the zonal architecture values may be adjusted to increase low performance parameters and / or decrease maximum cost parameters until an acceptable zonal architecture value is determined and / or according to a convergence measure (e.g., further adjustments achieve improvement below a threshold rate). In certain embodiments, a threshold may be utilized that uses, for example, the baseline installation as a marker and ensures that the selected zonal architecture value has a cost / benefit ratio at or above the baseline (e.g., this should implement continuous improvement over time and / or between model years while minimizing the cycle time for finding a zonal architecture value solution). In certain embodiments, various aspects of the vehicle network performance description 5702 and the vehicle performance network impact description 5802 may be utilized in an index or other normalized comparison, including weighting of the various aspects. In particular embodiments, operation 5304 includes minimizing cost, minimizing certain aspects of cost (e.g., a luxury vehicle may prioritize low failure rates and high redundancy capabilities over installed hardware costs), maximizing benefits, maximizing certain aspects of benefits (e.g., biasing zonal architecture values of two different vehicle models to be similar), including offsetting vehicle similarity in the cost / benefit analysis. In particular embodiments, sensitivity to parameters may be considered in operation 5304; for example, if an estimate or uncertainty for a particular parameter (e.g., vibration profile) creates a high sensitivity to the overall performance or cost of the selected zonal architecture value, then another option for the zonal architecture value with slightly worse raw material cost / benefit characteristics may be selected, even though the other option has a lower sensitivity (e.g., a lower risk that the estimated cost / benefit will not be achieved).
[0321] The example procedure 5300 further includes an operation 5306 for integrating a multi-zone network in a vehicle according to the zone architecture value. With reference to FIG. 33, the example operation 5306 includes installing a multi-zone network configured according to the zone architecture value (e.g., according to the zone architecture value as a design for installation). With reference to FIG. 34, the example operation 5306 includes installing a multi-zone network configured according to a network topology description of the zone architecture value (e.g., according to the zone architecture value for topology determination, but potentially varying other aspects to accommodate, e.g., minor differences in supplied components, changes in available space in the vehicle, changes in the actual vehicle environment compared to estimation, etc.). With reference to FIG. 35, the example operation 5306 includes installing a multi-zone network configured according to a zone manager distribution description of the zone architecture value (e.g., according to key aspects of the zone architecture value, but potentially varying other aspects, such as selection of a central zone manager and zone managers for the zones).
[0322] Referring to FIG. 38 , example and non-limiting aspects of zone architecture values 5902 include a network topology description 5202 (e.g., number and placement of network zones), a Zone Manager distribution description 5904 (e.g., location and duties of Zone Managers, including the use of highly capable endpoints as one or more Zone Managers and / or the use of dedicated Zone Managers), a network type value 5906 (e.g., network type to be utilized, speed capabilities, industry standards for compliance, etc.), a network protocol value 5908 (e.g., specific protocol selections and / or selection of headers, metadata, communication protocols, synchronization selections, etc.), and / or hardware component specification values 5910 (e.g., processor and network communication device capabilities, cable specifications, connector specifications, etc.).
[0323] Referring to FIG. 39 , an example procedure 6000 for implementing a zonal architecture in two or more vehicle classes is generally depicted. The operations of procedure 6000 enable vehicle classes to benefit from commonality in zonal architecture design while balancing the costs and benefits of cross-vehicle decisions. Example procedure 6000 includes operation 6002 for interpreting several vehicle network performance descriptions (e.g., one per vehicle class) for several vehicle classes and operation 6004 for determining a zonal architecture value as a function of the vehicle network performance description and vehicle performance network impact description for each of the vehicle classes (e.g., based on the specific environmental and operating characteristics of each class). Operation 6004 may include any of the considerations described for operation 5304, along with separate considerations for each vehicle class where appropriate. The overall cost / benefit analysis may consider the number of vehicles per class, the economic impact of vehicles per class (e.g., vehicle cost, downtime cost, specific use of the class—e.g., an ambulance class of vehicle may specifically accept risk compared to other vehicles). The example procedure 6000 includes an operation 6006 for integrating a multi-zone network of vehicles from each of a vehicle class. As used herein, a vehicle class refers to any group of related vehicles that have common aspects among them for network planning purposes, such as, for example, vehicles from the same model and year, vehicles intended for the same use, vehicles serving a common geographic area, vehicles belonging to a particular fleet, etc. Procedure 6000 allows for leveraging the flexibility of using a zone architecture to simultaneously benefit multiple vehicle classes while preserving commonality among the vehicles.
[0324] With reference to Figure 40, example operation 6006 includes installing a multi-zone network configured according to the zone architecture value in each of the first and second vehicles. With reference to Figure 41, example operation 6006 includes installing a multi-zone network configured according to the network topology description of the zone architecture value (e.g., allowing for variability among specific vehicle classes while leveraging the benefits of a selected topology) in each of the first and second vehicles. With reference to Figure 42, example operation 6006 includes installing a multi-zone network configured according to the zone manager distribution description of the zone architecture value (again allowing for variability among vehicle classes) in each of the first and second vehicles.
[0325] Without being limited to any other aspect of the present disclosure, embodiments herein provide systems and procedures for implementing a zonal network architecture in a vehicle to avoid or mitigate physical system risks due to environmental issues such as, for example, temperature, vibration, electromagnetic interference (EMI), road spray (or water intrusion in general), or the like. Additionally or alternatively, the setup and configuration of a zonal network architecture in a vehicle can avoid negative consequences and / or improve the consequences of a system for failure modes of concern, including any failure mode of concern such as loss of a network component (e.g., endpoint failure, loss of communication, loss of cable, etc.), physical damage to the vehicle that may impact the network (e.g., damage due to an accident, improper connection of a tow vehicle, damage to a cable during a service event, electrical damage to the vehicle, etc.).
[0326] Referring again to Figure 29, example system 5000 includes a selected zone architecture (e.g., determined in any manner described throughout this disclosure, such as by the operations of Figure 32 or Figure 43) that has been determined in response to the vehicle network risk description and the vehicle performance network impact description. Referring to Figure 43, example procedure 6400 for determining a zone architecture value includes operation 6402 for determining a vehicle network risk description that defines, for example, a risk to the vehicle network to be managed and a measure for determining how well the risk is managed. Referring to FIG. 44 , example and non-limiting aspects of the vehicle network risk description 6502 include hardware redundancy values 6504 (e.g., hardware elements for which redundancy should be provided and / or acceptable performance levels during redundant hardware operation, e.g., whether total loss of a network zone should be managed with zero degradation in capacity), control redundancy values 6506 (e.g., control elements and / or specific endpoints or zone managers for which redundancy should be provided and / or acceptable performance levels during redundant control operation), critical flow descriptions 6508 (e.g., groups of related operations that represent critical flows and acceptable redundancy performance if lost - note that a given flow may involve many endpoints and that redundancy of any endpoint may be prohibitive).Redundancy management for such situations may include consolidating control from various endpoints, replacing aspects such as utilized sensor values with available substitutes, such as estimated or virtual sensors for lost sensors, replicating control capabilities at two or more endpoints, and / or providing a critical flow description 6508 (which may be a strong policy in the location and distribution of network zones), critical application descriptions 6510 (e.g., vehicle applications or features for which redundancy should be available and acceptable performance in the event of loss, an application is any related group of functions, or a set of functions that provide a particular operator experience). The flow may include any group of functions packaged for some purpose (e.g., applications for HVAC management, audiovisual system control, navigation, etc.; note that in some cases, an application may further be considered to be a flow), critical communication connection description 6512 (e.g., a backbone between two important network zones; e.g., if powertrain control is distributed between zones A and B, the communication connection in zone AB may be considered critical; the critical communication connection description 6512 may include connections between zones, endpoints, controllers, etc.), and / or failure mode description 6514. The failure mode description 6514 may include any scenario, use case, event, etc. that is considered to be a failure mode to protect against, and may be determined according to the usage history of similar vehicles, specified by regulations, provided in the vehicle specifications, analyzed in a failure mode and effects analysis (FMEA), etc. For example, the failure mode description 6514 may include a description of "18-inch destruction of the front of the vehicle during a collision" and an acceptable performance level after the failure mode.Illustrative and non-limiting failure mode descriptions 6514 include specific event descriptions, removal (loss) of a specific component, loss of any component of a single type (e.g., loss of any connector in the system should not cause loss of functionality greater than XYZ), occurrence of a specific electrical event (e.g., cable XYZ shorted to ground), and / or any type of defined event (e.g., ECU case cracked during a maintenance event, one wire cut / removed from the network, vehicle exposed to an EM field of a specific strength (e.g., proximity to high voltage power lines), etc.).
[0327] The example procedure 6400 further includes operation 6404 for applying the vehicle network risk description 6502 to the current proposed zone architecture values to determine a vehicle performance network impact description. For example, in operation 6404, metrics from the failure mode description 6514 are compared to determine a degradation of vehicle network performance in light of the failure mode, and this degraded performance is compared to an acceptable performance level.
[0328] Illustrative procedure 6400 includes operation 6406 for determining whether the performance measures of the zonal architecture values have converged. For example, operation 6406 may be determined to be yes if a selected number of adjustments to the zonal architecture values did not result in an improvement in performance relative to the vehicle network risk description and / or the percentage of improvement has fallen below a threshold. In particular embodiments, operation 6406 may still be determined to be yes, for example, if performance relative to the vehicle network risk description is acceptable, even if further improvement may be available or is likely to be available. In particular embodiments, performance relative to the vehicle network risk description may be measured as an improvement relative to a baseline (e.g., a previous model year of the vehicle), or at least not as a degradation, to ensure, for example, that continuous improvement is pursued. In particular embodiments, operation 6406 may utilize a full optimization routine and / or may include a cost analysis in which performance relative to the vehicle network risk description is used as a threshold for convergence, with cost being minimized, improved relative to the baseline, and / or kept at a threshold that must not be exceeded as part of operation 6406.
[0329] In response to operation 6406 determining yes, procedure 6400 includes operation 6408 for utilizing the current proposed zonal architecture value as the zonal architecture value. In response to operation 6406 determining no, procedure 6400 includes operation 6410 for adjusting the zonal architecture value based on performance deficiencies and / or improvement opportunities relative to the vehicle network risk description and / or cost analysis. After operation 6410 for adjusting the proposed zonal architecture value, procedure 6400 returns to operation 6404. In particular embodiments, after several iterations of operation 6410, and / or after the design space has been sufficiently explored without convergence (e.g., the main plausible network topologies have been considered), procedure 6400 may decide to terminate, for example, by providing notification of operational parameters (e.g., attempted zonal architecture values, best results, gap indications that prevented convergence, etc.) to allow a user to consider, for example, whether some constraints can be relaxed and / or whether cost limits may need to be adjusted.
[0330] Procedure 6400 includes operation 6402 for determining a vehicle network risk description and convergence operation 6406 determined according to performance on the vehicle network risk description. In particular embodiments, procedure 6400 can utilize the vehicle network performance description as the value determined in 6402 and for determining convergence operation 6406 to select zone architecture values to enhance performance measures rather than, or in addition to, the risk measures of the vehicle network risk description, for example. Similarly, procedure 6400 can utilize the vehicle performance network impact description as the value determined in 6402 and for determining convergence operation 6406 to select zone architecture values to enhance cost measures rather than, or in addition to, the risk measures of the vehicle network risk description, for example. Additionally or alternatively, procedure 6400 can be operated simultaneously for multiple vehicle classes, similar to the operations described in FIG. 39 and related description, for example, where it would be beneficial to incorporate some commonality in the zone architecture values of different vehicle classes and / or to leverage common techniques to address difficult risk management or fault management problems.
[0331] The example system 5000 includes a selected zone architecture as a star configuration (e.g., see FIG. 3 and related discussion), where one of the network zones includes a central zone having a central zone manager 302. The example system 5000 includes a selected zone architecture as a mesh configuration (e.g., see FIG. 5 and related discussion), where it can include a central zone manager 302. The example system 5000 includes a selected zone architecture as a ring configuration (e.g., see FIG. 4 and related discussion), where it can include a central zone manager 302.
[0332] The example system 5000 includes a selected zone architecture as a star configuration with a total of four zones, including a central zone, two front zones each communicatively coupled to the central zone, and a rear zone communicatively coupled to the central zone (see, e.g., FIG. 3 and related discussion).
[0333] The example system 5000 includes a selected zone architecture as a mesh configuration having a total of four zones, including a central zone (in the example, the central zone is the zone associated with the central zone manager 302 responsible for the central zone, regardless of the geometric location of the central zone), two front zones, and one rear zone, each of which is communicatively coupled to all of the other zones (see, e.g., FIG. 5 and related discussion).
[0334] The example system 5000 includes a selected zone architecture as a ring configuration having a ring configuration with a total of four zones, the zones being communicatively coupled in sequence such that a central zone (in the example, the central zone again does not have to be the geometrically central zone, but may be) having a central zone manager is coupled to a first front zone, which is coupled to a second front zone, which is coupled to a rear zone, and which is communicatively coupled to the central zone (see, e.g., FIG. 4 and related discussion).
[0335] The example system 5000 includes a selected zone architecture as a two node topology, with one of the two nodes being a central zone (see, e.g., FIG. 6A and related discussion). The example system 5000 includes a selected zone architecture as a three node topology, with one of the three nodes being a central zone (see, e.g., FIG. 6B and related discussion).
[0336] The example system 5000 includes a selected zone architecture that includes at least one of a plurality of zones provided as a virtual network zone. Without being limited to any other aspect of the present disclosure, the utilization of one or more virtual network zones provides additional degrees of freedom in the configuration space for available zone architecture values. Assuming there is a properly deployed hardware-based network zone in the vehicle capable of managing the additional communication load from messages to the virtual network zone without hardware modifications (e.g., higher-grade cables, network communication devices, shielding requirements, etc.), it will be appreciated that utilizing a virtual network zone will in most cases reduce hardware cost values. Nevertheless, there will be some trade-offs in the design space due to, for example, increased traffic and risk in a hardware-based network zone servicing two logical network zones of the vehicle, which may increase the risk associated with a failure related to this zone and may reduce the redundancy options available to address certain failure modes or risks. The availability of spare degrees of freedom by considering virtual network zones will improve the outcome of the convergence behavior and / or overall performance for risk-based, cost-based, or performance-based convergence measures, but the use of virtual network zones may not be selected for a given vehicle or vehicle class.
[0337] 45, an example methodology 6600 for integrating a multi-zone network in a vehicle is generally depicted. The example methodology 6600 includes an operation 6602 for interpreting a vehicle network risk description and an operation 6604 for determining a zone architecture value as a function of the vehicle network risk description and the vehicle performance network impact description. The example methodology 6600 further includes an operation 6606 for integrating a multi-zone network in the vehicle as a function of the zone architecture value.
[0338] Without being limited to any other aspect of the present disclosure, embodiments herein provide systems and procedures for implementing a zonal network architecture in a vehicle to avoid or mitigate system risks including loss or degradation of network control components, for example, enabling selection and / or transfer of control responsibility of the zonal network.
[0339] Referring to FIG. 46 , an example system 6700 includes a vehicle having a multi-zone network including multiple network zones, each of the network zones including at least one zone manager, one of the at least one zone managers including a central zone manager (although not shown, the system 6700 can be deployed in any vehicle configuration as described throughout this disclosure). The multiple network zones are configured according to a network topology description of a selected zone architecture. In certain embodiments of the example of FIG. 46 , the responsibilities of the central zone manager are transferred in response to a central zone manager emergency 6702 (e.g., loss of communication with and / or degradation of the central zone manager's capabilities, loss of communication with and / or degradation of the central zone endpoints' capabilities, loss of communication with and / or degradation of the central zone endpoints' capabilities, presence of a fault condition associated with the central zone, etc.). In certain embodiments, the system 6700 includes a central zone directly communicatively coupled to at least two other zone managers, and in certain embodiments, the central zone is directly communicatively coupled to each of the other zone managers.
[0340] The example system 6700 includes a network management controller 5002 including a zone enforcement circuit 5004 that interprets a zoned architecture communication scheme 5014, a zone manager command circuit 5006 that interprets zone manager command descriptions 5016 for each of the zone managers in accordance with the zoned architecture communication scheme 5014, and a zone execution circuit 5008 that provides corresponding zone manager command descriptions 5016 to each of the zone managers. The example system 6700 includes each zone manager responsive to a corresponding zone manager command description 5016 to control communications between endpoints in the corresponding network zone and endpoints in at least one other of the network zones. The example system 6700 includes a network management controller 5002 at least partially disposed in a central zone manager.
[0341] The illustrative zoned architecture communication scheme 5014 includes a central zone manager succession scheme, which may include information such as which central zone manager emergency 6702 dictates that the central zone manager's responsibilities should be transferred to another zone controller, which of the central zone manager's responsibilities should be included in the transfer, etc. For example, in particular embodiments, the central zone manager may have responsibilities such as acting as the zone manager for the central zone, distributing zone manager command descriptions 5016 to other zone managers, maintaining service registers and / or managing publication and registration for a service-oriented architecture (SOA; see, e.g., Figures 67-72 and related discussion), acting as a PTP grandmaster for network time management operations (see, e.g., Figures 73-76 and related discussion), and / or hosting one or more or all aspects of the network management controller 5002. In particular embodiments, some of these responsibilities, if present, may be transferred to an alternate zone controller in response to a central zone manager emergency 6702, while others may not be transferred. For example, one or more of these duties may not be performed by the central zone manager in a given embodiment. In another example, a subsequent zone manager for a designation may be able to perform one set of duties (e.g., distributing zone manager command descriptions 5016), but may not be best suited for another set of duties (e.g., acting as a PTP grandmaster). In particular embodiments, the central zone manager succession scheme may include transferring some duties to the first zone controller and transferring other duties to one or more other zone controllers. In another example, if communication to the central zone is lost, for example, as part of a central zone manager emergency 6702, some duties of the central zone manager may not be available for transfer, such as operating as a zone controller for the central zone.It will be appreciated that for certain responsibilities of a central zone manager, the ability to transfer responsibilities will not be available if the successor zone manager does not already have some data available that may be stored in the central zone manager and therefore potentially become unavailable as part of a central zone manager emergency 6702. For example, if the central zone manager maintains a service register, the service register may be lost along with the central zone manager. Thus, in certain embodiments, the central zone manager succession scheme of the zonal architecture communication scheme 5014 includes data that the successor zone manager always maintains as a backup and / or maintains a periodically updated backup. Examples of such backup data include, without limitation, policies, portions of policies related to the zonal architecture communication scheme, and / or service registers.
[0342] The example zone execution circuitry 5008 determines a central zone manager emergency 6702 and transitions the central zone manager duties to another zone manager (e.g., by providing a zone manager transition command 6704 to the subsequent zone) in accordance with a central zone manager succession scheme. In particular embodiments, the operations for providing the zone manager transition command 6704 may alternatively be performed by the hardware redundancy implementation circuitry 5010 or the control redundancy implementation circuitry 5012.
[0343] Referring to Figure 47, an example zoned architecture communication scheme 5014 includes Zone Manager communication obligations 6802 (and / or a subset of these obligations intended for migration), Zone Manager security obligations 6804 (e.g., permissions to register in service, and per Zone and Zone Manager security parameters for communications to external devices and / or permitted or prohibited external addresses), Zone Manager local configuration files 6806, Zone Manager global configuration files 6808 (e.g., configuration aspects common across Zone Managers, configuration aspects that apply to all network zones, configuration aspects parsed from policies, e.g., as storage records), and / or or configuration aspects to facilitate future parsing operations for updated policies), a central zone manager succession scheme 6810 (e.g., measures for determining a central zone manager emergency 6702, the duties to be transferred, and subsequent local managers), network security descriptions 6812 (e.g., security policies that are applied globally and / or specific to the duties of the central zone manager), and / or network connectivity descriptions 6814 (e.g., communication routing for messages from endpoints, zones, flows, applications, etc., including redundancy descriptions that will be utilized during various emergency events in the network).
[0344] In certain embodiments, the network topology description includes the communication connectivity configuration of the network zones. Illustrative and non-limiting network topology descriptions include the communication connectivity configuration as a star configuration, as a mesh configuration, and / or as a ring configuration. It will be understood that in a pure star configuration (e.g., where a multi-zone network logically operates as a star configuration during operation, even with additional hardware connections, and where there are no backup connections between zones, e.g., unused or lightly used backup connections), if the central zone manager is also the hub zone of the star configuration, loss of the central zone manager would prevent the transfer of most of the central zone manager's duties because the network zone would become isolated. In certain embodiments, even if the network zone becomes isolated, some operation of the vehicles may be possible, depending on the system's redundancy plans and the ability of independent zones to operate without any cross-network communication using these redundancy plans. If another zone manager serves as the hub zone of the star configuration, loss of the central zone manager in the star configuration would allow the transfer of the central zone manager's duties.
[0345] 48, an example procedure 6900 for operating a multi-zone network in a vehicle is generally depicted. The example procedure 6900 includes an operation 6902 for interpreting a zonal architecture communication scheme, an operation 6904 for interpreting a zone manager command description for each zone manager in accordance with the zonal architecture communication scheme, an operation 6906 for providing the zone manager command description to the zone managers, and an operation 6908 for operating each zone manager in accordance with the corresponding zone manager communication description (e.g., for controlling communications between endpoints in different network zones). Referring to FIG. 49, the example operation 6904 includes interpreting a central zone manager command description for a central zone manager in accordance with the zonal architecture communication scheme, e.g., the central zone manager command description includes one or more of the duties of the central zone manager.
[0346] Referring to FIG. 50, example procedure 7100 includes procedure 6900 and further includes an operation 7102 for interpreting a central zone manager succession scheme (e.g., from a zonal architecture communication scheme), an operation 7104 for determining a central zone manager emergency, and an operation 7106 for transferring the duties of one or more central zone managers to another zone manager in accordance with the central zone manager succession scheme.
[0347] Without being limited to any other aspect of the present disclosure, embodiments herein provide systems and procedures for implementing a zonal network architecture in a vehicle to enhance system security, including providing the ability to physically or logically isolate communications from critical or non-critical endpoints to provide enhanced capabilities and greater control of features to more parties involved with the vehicle (e.g., owner, dealer, fleet manager, service personnel) while still maintaining communication security and the ability of the network to manage critical communications for the vehicle's mission functions. Additionally, security responsibilities can be decentralized, allowing for rapid updates, immediate response to changes, and the like, while maintaining the simplicity and security of centralized control.
[0348] 29, an example system 5000 includes a vehicle having a multi-zone network including a plurality of network zones, each of the network zones including at least one zone manager, one of the at least one zone managers including a central zone manager. The network zones are configured according to a network topology description of a selected zone architecture, and the central zone manager includes a network management controller 5002. The network management controller 5002 includes a zone enforcement circuit 5004 that interprets a zone-based architecture communication scheme 5014, the zone-based architecture communication scheme 5014 including a network security description 6812 (see FIG. 51) and a network connectivity description. The network management controller 5002 further includes a zone manager command circuit 5006 that interprets a zone manager command description 5016 for each of the zone managers in response to the zone-based architecture communication scheme 5014, and a zone execution circuit 5008 that provides the corresponding zone manager command description 5016 to each of the zone managers. The example system 5000 includes each of the Zone Managers responsive to a corresponding Zone Manager command description 5016 for controlling communications between endpoints in the corresponding network zone and endpoints in at least one other zone. In particular embodiments, a central Zone Manager is communicatively coupled directly to each of the other zones (e.g., in a star, mesh, or mixed configuration).
[0349] The example system 5000 includes a zone enforcement circuit 5004 that interprets the zoned architecture communication scheme update (e.g., as a new zoned architecture communication scheme 5014), the zone manager command circuit 5006 further interprets zone manager command descriptions 5016 for each of the zone managers in response to the updated zoned architecture communication scheme 5014, and the zone execution circuit 5008 provides corresponding updated zone manager command descriptions 5016 to each of the zone managers. In particular embodiments, the zone execution circuit 5008 provides the corresponding updated zone manager command descriptions 5016 during runtime operation (e.g., as soon as the zoned architecture communication scheme update is received). In particular embodiments, in the case of the updated zone manager command descriptions 5016 as a configuration file without software changes, and if the operations expressed in the updated zone manager command descriptions 5016 allow for runtime changes, the updated zone manager command descriptions 5016 are implemented immediately. In particular embodiments, the updated zone manager command descriptions 5016 include a flag indicating whether they should be implemented immediately or at the next vehicle start event; this flag may be provided as part of the zonal architecture communication scheme 5014 and / or may be determined by the zone manager command circuitry 5006 (e.g., by screening for a particular type of change that indicates that an immediate runtime change should not be implemented). When the updated zone manager command descriptions 5016 are implemented at a subsequent start event, operation of the system 5000 facilitates ease and speed of updates compared to previously known systems, as each zone manager already has the appropriate commands available for immediate implementation.
[0350] Referring to Figure 51, an example network security description 6812 includes permission values utilized for aspects of network control operations described herein. The permissions depicted in Figure 51 are actor-based permissions, or permissions based on associated actors (e.g., applications, flows, endpoints, network zones, functions, etc.).Illustrative and non-limiting permission values for the network security description 6812 include network zone permission values 7202 (e.g., permissions associated with a network zone including data allowed in the zone, including from various sources, such as endpoints, flows, applications, functions, etc.; bandwidth permissions for a zone and / or for various sources, including absolute and / or relative bandwidth permissions, where inter-zone communication restrictions include data rates to or from a zone and / or various sources allowed to communicate between specified zones, and / or traffic types allowed in a zone, such as highly confidential data, audiovisual data, etc.); flow permission values 7204 (e.g., permissions associated with a flow, including whether an actor in the flow is the source or destination of a message; flow permissions allow a specified zone in a particular zone, The permissions may relate to permissions between, among, etc., and the actors of a flow may be endpoints, applications (e.g., algorithms running on controllers, where the algorithm is part of the flow but the controller need not be, e.g., with a container-type control element in one embodiment), application permission values 7206 (e.g., permissions associated with applications), function permission values 7208 (e.g., permissions associated with particular logically grouped operations, which may be performed between various sources and are logically grouped into applications such as "vehicle tow management"), and / or endpoint permission values 7210 (e.g., permissions associated with endpoints such as sensors, actuators, controllers, etc. that exist in the network as endpoints in one of the network zones). It will be appreciated that a given message may have multiple tags that are at least conceptually available, e.g., a message provided by endpoint A may also be part of flow B and application C.Arbitration of these instances may be performed according to the policies and / or measures described in the zoned architecture communication scheme, and may follow rules such as "highest permission-related wins" or "lowest permission-related wins." The rules may be more complex; for example, a particular application may have a limited permission value, regardless of other associated flags. In another example, a message associated with a particular application may have a high permission value when provided by a first endpoint, but a low permission value when provided by another endpoint. Additionally or alternatively, all of the flags may be available with the message (e.g., based on metadata), and / or only the winning flag may remain with the message. The use of permission values and arbitration between conflicting permission values may be determined based on the system's security scheme and the purpose of arbitrating the permission values. In general, the rules and arbitration scheme will be selected to ensure that important messages for important functions or applications are always sent from the appropriate source or to the appropriate destination, but that these messages are not made available to inappropriate sources or destinations.
[0351] Referring to FIG. 52, example and non-limiting permission values 7302 are depicted. The example of FIG. 51 allows for permissions to be based on the source or destination of a message (actor-based permissions), while the example of FIG. 52 provides available actions to be implemented or limited based on permission values, which can be applied to any of the actor-based permissions. Example and non-limiting permission values include data provider permissions 7306 (e.g., whether an actor is allowed to make data available as a provider of this data), data receiver permissions 7308 (e.g., whether an actor is allowed to receive this data), communication bandwidth permissions 7304 (e.g., whether an actor is allowed to consume bandwidth resources, e.g., of a network zone, zone manager, etc.), service subscription permissions 7310 (e.g., whether an actor is allowed to subscribe to a service), service provider emission 7312 (e.g., whether an actor is allowed to provide a service), and service visibility permissions 7314 (e.g., whether an actor is allowed to make a service visible). or where an actor can make a service visible but not provide the service, or can provide a service but not make the service visible, e.g., a deprecated service - see Figures 47 and 50 and related discussion), service publishing permissions 7316 (e.g., whether an actor is allowed to publish a service, which is a similar but entirely different concept to service visibility), and / or endpoint communication permissions 7318 (e.g., whether a given endpoint is allowed to send messages to or receive messages from another specified endpoint or class of endpoint).In particular embodiments, permissions may be further based on the class of the actor - for example, service publishing permission 7316 may specify that an actor is allowed to publish services to other actors with permission class A, but not to actors with permission class B. All of the permissions depicted in Figures 51 and 52 may involve permission interactions between the actors involved, i.e., between a requester of information and a provider of information, and / or some permissions may be specified for a requester or provider independent of any other actors involved.
[0352] Referring to FIG. 53 , an example connectivity scheme 7402 is depicted, provided, for example, as part of a network connectivity scheme. The example connectivity scheme 7402 may relate to connections between network zones; e.g., the connectivity scheme may apply to inter-zone communications between network zones A and B, with the associated zone manager applying the zone manager command description 5016 to implement the respective connectivity scheme 7402. Note that any of the connectivity schemes 7402 may be anisotropic—e.g., A→B communications may have a first rate limit, while B→A communications may have a different rate limit (e.g., network zone A may be a critical network zone, allowing for controlling outgoing utilization while limiting incoming utilization). Note further that any of the connectivity schemes 7402 may be based on source and / or destination endpoint values; e.g., a particular controller on the network may have a particular metric for messages to be sent thereto, and the metric for this endpoint may override and / or adjust one or more aspects of the connectivity scheme 7402. For example, communications from zone A→B may have a general scheme using SI units for messages, and endpoint Z has a requirement for American Engineering units that may override the general scheme for messages with a destination of endpoint Z (e.g., depending on how the zoned architecture communications scheme is set up, permissions associated with endpoint Z or the associated application or flow, etc.). Note further that any of the connection schemes 7402 may be based on the network types involved; for example, A→B and A→C communications may have different values for connection scheme 7402 based on the network types of B and C. In another example, D→A and E→A communications may have different values for connection scheme 7402 based on the network types of D and E.
[0353] An illustrative and non-limiting connection scheme 7402 may include communication rate values 7404 (e.g., data rates, including burst rates and / or time-averaged rates allowed between network zones), communication protocol values 7406 (e.g., communication protocols to be applied or followed for messages between zones), sampling rate values 7408 (e.g., message rates to be utilized and / or dynamics to be reflected in the data, which can be adjusted with upsampling or downsampling operations to provide, for example, a 20 ms vehicle speed value for a limited capability endpoint in CAN that expects 20 ms data and does not have the ability to parse time data from messages), communication header values 7410 (e.g., format, size, and content of message header information), communication metadata values 7412 (e.g., message metadata format, size, and content), a communication unit value 7414 (e.g., units such as SI units, American Engineering Units, etc., and / or scaling of absolute number data, e.g., for fixed-point data; in particular embodiments, the byte depth and / or type of data may be specified in the connection scheme 7402), a communication encapsulation description 7416 (e.g., specifying whether the communication should be encapsulated, e.g., keeping the original CAN message within an Ethernet message, to enable CAN-CAN communication over an intervening network, keeping original metadata within the message for monitoring or later analysis, etc.), and / or a communication timestamp description 7418 (e.g., size, location, and format of the timestamp, utilization of a PTP timestamp, keeping or removing any local timestamp previously associated with the message, etc.).
[0354] 54, an example procedure 7500 for controlling communications between endpoints of a multi-zone network of vehicles is generally depicted. The example procedure 7500 includes an operation 7502 for interpreting a zonal architecture communication scheme for a multi-zone network of vehicles including a plurality of network zones, an operation 7504 for interpreting zone manager command descriptions for each zone manager in accordance with the zonal architecture communication scheme, an operation 7506 for providing corresponding zone manager command descriptions to each of the zone managers, and an operation 7508 for controlling communications between endpoints of each of the plurality of network zones in accordance with the zone manager command descriptions.
[0355] Referring to Figure 55, example operation 7504 includes an operation 7602 for parsing a policy including a zoned architecture communication scheme, and an operation 7604 for determining associated Zone Manager command descriptions for each Zone Manager in accordance with the policy. Referring to Figure 56, example operation 7506 includes communicating corresponding command descriptions from the central Zone Manager to each individual Zone Manager.
[0356] With reference to Figure 57, example procedure 7800 includes procedure 7500 and further includes an operation 7802 for interpreting the zonal architecture communication scheme update, an operation 7804 for interpreting updated zone manager command descriptions for each zone manager in response to the zonal architecture communication scheme update, and an operation 7806 for providing corresponding updated zone manager command descriptions to each of the zone managers. With reference to Figure 58, example procedure 7900 further includes an operation 7902 for controlling communications between respective endpoints of the network zone in response to the updated zone manager command descriptions. With reference to Figure 59, example procedure 8000 further includes an operation 8002 for immediately beginning to control communications between endpoints of the network zone in response to the updated manager command descriptions. With reference to Figure 60, example procedure 8100 further includes an operation 8102 for beginning to control communications between endpoints of the network zone in response to the updated manager command descriptions and a subsequent vehicle start event. Referring to FIG. 61 , the example procedure 8200 further includes an operation 8202 for determining an implementation scheme for the update in response to the updated zone manager command description, and an operation 8204 for beginning to control communications between respective endpoints of the network zone in response to the updated zone manager command description and further in response to the implementation scheme.
[0357] Without being limited to any other aspect of the present disclosure, embodiments herein provide systems and procedures for implementing a zonal network architecture to simplify and enhance network communication control in a zonal network architecture. For example, the systems and procedures herein provide embodiments that enable endpoints in disparate zones, with different communication payloads, metadata, device capabilities, and the like, to communicate in an operable and easily configured secure manner that takes into account the additional complexities of a zonal network environment. The systems and procedures herein protect the ability of a zonal network architecture to perform critical functions and to support flexible additional functionality by balancing the load and utilization of network components, such as backbone and zone controllers.
[0358] Referring to FIG. 29, an example system 5000 includes a zoned architecture communication scheme 5014 that includes a network security description and a network connectivity description. Referring to FIG. 62 , an example network connectivity description 6814 includes one or more of an inter-zone bandwidth description 8302 (e.g., the bandwidth allowed between selected zones, which may be anisotropic); an inter-zone network routing value 8304 (e.g., some communications passing between zones may be routed first through other zones and / or some communications passing between zones may have multiple routes available, and the inter-zone network routing value 8304 provides the route to be utilized, where the routing may be anisotropic and may vary depending on the message and the actors involved in the message); an inter-zone priority value 8306 (e.g., the priority of messages between zones based on the zones themselves and / or routing or other connectivity aspects depending on the priority of the message and / or priorities associated with the actors involved in the message); and / or an inter-zone permission value 8308 (e.g., permissions associated with messages based on the zones themselves and / or permissions associated with messages depending on the permissions associated with the message and / or the actors involved in the message). In particular embodiments, any one or more of the network connectivity descriptions 6814 may be further determined depending on the operational state of the vehicle, for example, messages may be low priority and / or routed in a first manner in a first operational state (e.g., a parked vehicle state) and may be high priority and / or routed in a second manner in a second operational state (e.g., a driving vehicle state). The inter-zone permission values 8308 may include any aspect of a permission value as described throughout this disclosure, including without limitation a sampling rate description, a data resolution description, or a data latency description.
[0359] Referring to FIG. 63, example procedure 8400 includes operation 7502 for interpreting a zonal architecture communication scheme for a vehicular multi-zone network including multiple network zones, including a network security description and a network connectivity description; operation 8402 for determining a bandwidth description of the network connectivity description for at least one element (e.g., an endpoint, a flow, a function, or an application); and optional operation 8404 for further determining the bandwidth description as a function of vehicle operating conditions.
[0360] Referring to FIG. 64 , example procedure 8500 includes operation 7502 for interpreting a zonal architecture communication scheme for a vehicular multi-zone network including multiple network zones, including a network security description and a network connectivity description; operation 8502 for determining a network routing value of the network connectivity description for at least one element (e.g., an endpoint, a flow, a function, or an application); and optional operation 8504 for further determining the network routing value as a function of a vehicle operating state.
[0361] Referring to FIG. 65, an example procedure 8600 includes an operation 7502 for interpreting a zonal architecture communication scheme for a vehicular multi-zone network including multiple network zones, including a network security description and a network connectivity description; an operation 8602 for determining a priority value of the network connectivity description for at least one element (e.g., an endpoint, a flow, a function, or an application); and an optional operation 8604 for further determining the priority value as a function of a vehicle operating state.
[0362] Referring to FIG. 66, example procedure 8700 includes operation 7502 for interpreting a zoned architecture communication scheme for a vehicular multi-zone network including multiple network zones, including a network security description and a network connectivity description; operation 8702 for determining a permission value of the network connectivity description for at least one element (e.g., an endpoint, a flow, a function, or an application); and optional operation 8704 for further determining the permission value depending on a vehicle operating state.
[0363] Without being limited to any other aspect of the present disclosure, embodiments herein provide systems and procedures for implementing a zonal network architecture to simplify and enhance network communication control in a zonal network architecture. For example, the systems and procedures herein provide embodiments that implement a selected security and permission scheme for a network without requiring a user to have complete knowledge of every endpoint on the network and / or the location of every piece of data within the network. Furthermore, embodiments herein enable a user to create or adjust a security and permission scheme for an entire zonal network through simple operation with a single access point, and to adjust mitigation plans, such as implementing redundancy and / or taking over responsibility, through simple operation with this single access point.
[0364] Referring to FIG. 67, an example system 8800 for operating a service-oriented architecture for a vehicle (not depicted) having a multi-zone network including several network zones, each of the network zones including at least one zone manager, the several network zones configured according to a network topology description of a selected zone architecture. The system 8800 includes a service management controller 8802 including a service register circuit 8806 that maintains a service register 8902 (see FIG. 68) that includes several services and service descriptions for each of the services; a service publication circuit 8810 that, in response to a service publication request 8906, exposes at least one service from the several services to a requesting source 8908; and a service subscription circuit 8808 that, in response to a service subscription request 8904, registers the requesting source 8908 (e.g., the requesting source 8908 may be the same source or a different source; the requesting source 8908 is the source of a given request, which may be a publication request and / or a subscription request) with the at least one service and updates the service register 8902 in response to the registration. The system 8800 further includes a network management controller 8804 including a zone enforcement circuit 8812 that interprets the zoned architecture communication scheme 5014, a zone manager command circuit 8814 that interprets zone manager command descriptions 5016 for each of the zone managers in accordance with the zoned architecture communication scheme, and a zone execution circuit 8816 that provides corresponding zone manager command descriptions 5016 to each of the zone managers. The zone managers respond to the corresponding zone manager command descriptions 5016 and the service registers 8902 to control communications between endpoints in the corresponding network zone and endpoints in at least one other zone of the plurality of network zones.
[0365] The example system 8800 includes a service management controller 8802 disposed at least in part in a central zone manager of zone managers. The example central zone manager is directly communicatively coupled to each of the other zone managers. The example system 8800 includes a network management controller 8804 disposed at least in part in the central manager.
[0366] Referring to FIG. 69 , a non-limiting example of a service 9002 is schematically depicted. The example service 9002 includes the provision of any data value available in the system and / or that can be determined from data available in the system, and may additionally or alternatively include any function, available action, and the like. A service can be provided by any actor on the vehicle, typically from an endpoint that makes the service available for registration, and another actor on the vehicle can use the service (e.g., begin receiving messages, exercising functions, etc.) once registered. Permissions may be associated with any aspect of the service; for example, permissions may apply to provide the service, make the service visible, publish the service including the scope of visibility or publication, deem the service available, subscribe to the service, or the like. Examples of services 9002 include data values 9004, mathematical functions 9006 (e.g., providing mathematical functions that may be useful in a vehicle or generally utilized; utilizing a function as a service may allow processing resources to be shifted between devices in the system and / or allow an actor on the system to provide the function as a black box where other actors can call the function and get a return value, but the actual operation performed need not be visible. Example functions include any moderately complex function, such as a function that may require access to specific system aspects that are not generally available, such as determining an average value, trigonometric representation, and / or a random number generator based on system time or another seed parameter), processing functions 9008 (e.g., providing sophisticated processing functions available for utilization, which may also shift processing resources within the system, hide dedicated functionality in a black box, and / or allow infrequently used sophisticated operations to be centralized and managed from a single location. Example functions include smoothing, feature detection, and / or frequency banding, interpolation, spline fitting,Dynamic processing of data streams, such as upsampling or downsampling and / or dynamic filtering operations for Fourier or other frequency analysis operations, operation of target search or optimization algorithms on input sets, operation of lookup tables and / or conversion of lookup tables to analytical models, data compression operations, sparse data reconstruction, running compensation algorithms for aging or degraded sensors, etc.); communication functions (e.g., packaging communications for use elsewhere in the system, particularly where packaging operations for communications, such as, for example, encapsulating, adding, or removing headers, metadata, timestamps, or the like, would be operationally "expensive" for lower capability devices and / or Zone Managers or switches to perform); data storage functions (e.g., allowing subscribers to check in, check out, change stored values, retrieve stored values, etc. with data, e.g., allowing lower capability devices to access data from higher capability devices with low implementation overhead). 9014 (e.g., allowing devices to control actuators; services providing actuator control may limit the range and / or dynamics of control of actuators through the service compared to, for example, the basic control of actuators available; further, services may be able to, for example, perform actuator "checkouts," apply hysteresis between multiple requests to prevent dithering or other potentially undesirable behavior;and / or may prioritize among multiple subscribers for a service by favoring usage by higher priority users over lower priority users), command functions 9016 (e.g., enabling various system command services, such as requesting system status (e.g., is the vehicle speed governor currently active), setting the state of some parameter—e.g., headlights on—retrieving diagnostic values or status), and / or control functions 9018 (e.g., enabling access to some control parameters, for example, for potential adjustment of observations, which may be within a tolerance range that may depend on the actor requesting the service—e.g., a vehicle owner convenience application that allows a user to adjust the cruise control minimum speed may have a different range of capabilities than an engineering tool application using the same service, while another example is a parent allowing a teen driver to adjust, albeit within a limited range, vehicle maximum power or top speed, etc.). It will be appreciated that certain parameters accessed or adjusted by service 9002 may be understood as data values, command functions, or control functions (e.g., setting a headlight value to request that the headlights be on may be understood as a control function, command function, or actuator function). The particular category of service 9002 is not important; the categories together illustrate various aspects of the vehicle, network, endpoints, applications, and the like that can be exercised through the use of service 9002. In particular embodiments, service 9002 can be a complex function that, for example, engages an ADAS system, requests an automated parallel parking maneuver, or the like, while other services 9002 may be much simpler services that extend the capabilities of less capable devices, shift processing resources within a system, simplify repetitive or complex tasks, and / or reduce the deployment and maintenance of common processes to a single location.
[0367] Referring to FIG. 70 , an example illustrative data structure for a service register 8902 is schematically depicted. In a particular embodiment, the service register 8902 tracks services available on the system, whether the service is published, who is subscribed to the service, and the like. Some fields in the service register 8902 may be more informative than active; for example, the service capability description may be a text field for display on a user device (e.g., services made available for a user, for display on a service tool, engineering tool, mobile device, or the like), while other fields may be active, such as the service ID, which may be an actual identifier utilized by the service management controller 8802 to specifically identify and track the service 9002. The example service register 8902 includes at least one of a service identifier, a service provider description, a service permission description, or a service capability description for each service of a plurality of services. The example service register 8902 further includes at least one of a service input description, a service active or inactive flag, a service deprecated flag, a service registrant description, or a service participant description (e.g., other endpoints, controllers, applications, etc., accessed by the service provider as part of the operation of the service) for each service among the plurality of services.
[0368] The illustrative service publishing circuitry 8810 exposes the services 9002 by listing the service register 8902 in a data structure provided to a requesting source; for example, a requesting source can request a listing of the services 9002 and / or the list of services 9002 may be provided periodically. The data structure provided to the requesting source will be limited to services that the requesting source has permission to view and / or subscribe to, but will be based on the service register 8902 and / or services 9002 that are likely to be of interest to the requesting source.
[0369] The illustrative service publishing circuit 8810 exposes services 9002 by listing them in known locations (e.g., memory locations accessible to actors on the network). In particular embodiments, several data structures with the service listings may be provided, for example, based on common permission classes of actors on the network. For example, a first permission class may allow access to a first table that lists only services that access low-security data or functions, and a second permission class may allow access to a second table that lists services that access more sensitive data or functions. There may be any number of permission classes. In particular embodiments, service listings may be generated on demand, with services filtered according to the overall permission scheme applicable to the requesting source. A requesting source may be any actor on the system (e.g., an endpoint, application, flow, controller, etc.) and / or may include an actor outside the system (e.g., a user interacting with an external device, such as a tool in the cloud or a service tool in communication with the vehicle, requesting a service that provides data or enables functionality to be accessed by the user), and will similarly be restricted by an appropriate permission scheme applicable to the user, the external device, and / or the tool utilized to request the service. In particular embodiments, a service provider may be an external device, for example, that allows an actor on the vehicle to access data, processing functionality, or any other aspect of a service provided by the external device (again, subject to disclosure and other permissions applicable to the external device).
[0370] The illustrative service publication circuitry 8810 interprets a service publication request 8906 for a new service from a new service provider (e.g., a provider of a new service, which may be a new requesting source or a requesting source publishing a new service), determines a new service description according to the service publication request 8906 and the new service provider (e.g., determined from data fields in the service publication request 8906 and / or interpreted from operations performed by the service), and maintains the service register 8902 by adding the new service 9002 as one of the services in the register.
[0371] The example service publication circuitry 8810 further adds the new service to the service register 8902 depending on a permission value associated with the new service provider, e.g., denying the request, not publishing the service but adding the service to the service register 8902, and / or by making an appropriate entry in a permission field of the service register 8902 (e.g., a field specifying permissions for visibility and / or registration of the service).
[0372] The example service publication circuitry 8810 maintains a service register 8902 by removing a service from a plurality of services in response to a service publication request 8906, which may include deleting an associated entry from the service register 8902, adjusting the service register entry so that the service is no longer visible and published, and / or setting an inactive flag in the associated entry from the service register 8902 (e.g., thereby enabling tracking of services that have become available and / or simplifying the process for adding the service back at a later time).
[0373] The illustrative service publication circuitry 8810 maintains the service register by deprecating the service from the services in the service register in response to the service publication request 8906 (e.g., the service publication request 8906 is a request to stop publishing the service). As used herein, deprecating a service allows the service to continue to be used by subscriber actors that were registered at the time of deprecation, but does not allow new requestors to see or use the service 9002 and blocks further registrations of the service. The deprecation action allows the service to be dropped from the system when a subscriber stops using the service 9002. As used herein, deactivating a service 9002 does not necessarily remove the requestor's registration status, but the service 9002 will not be used until the service is reactivated.
[0374] The example service publishing circuit 8810 further maintains the service register 8902 by removing the service from the available services in response to determining that at least one aspect of the service is no longer available (e.g., the endpoint used by the service no longer exists, the service subscriber no longer benefits from the service, and / or the service provider appears to be unresponsive to the service 9002). In particular embodiments, removing the service from the available services includes setting an inactive flag and / or deleting the entry for the service 9002 from the service register 8902.
[0375] Once a service is activated, a subscriber can actively or passively engage with the service, depending on the nature and configuration of the service. For example, utilizing a service 9002 can include passively receiving data, which may be sent directly from the service provider to the subscriber as a data communication and / or the data may be sent to the service management controller 8802 for storage in a location accessible to the subscriber when needed or convenient. In another example, a service may include a call from a subscriber passing data parameters that inform the service—e.g., a number to be passed to the service provider and a function value to be returned after the call, parameters for actuator settings requested by the subscriber, and / or a data block for processing (e.g., a stream of data values on which the service's processing is performed). In particular embodiments, the service register 8902 stores service call formats and information, which are then available to the subscriber to utilize the service 9002.
[0376] In particular embodiments, the service permission description includes service publication permissions, service subscription permissions, and / or service visibility permissions. In particular embodiments, the service register 8902 may be stored on an external device, and the external device may be added to a local version of the service register 8902. In particular embodiments, the service register 8902 stored on the external device may differ from the local version, for example, only active services are listed externally and / or services listed on the external device are removed from the local version.
[0377] 71 , an example procedure 9200 includes an operation 9202 for maintaining a service register including a plurality of services and a service description for each of the plurality of services in a vehicle having a multi-zone network including a plurality of network zones; an operation 9204 for exposing at least one service from the plurality of services to a requesting source in response to a service publication request; an operation 9206 for registering the requesting source with the at least one service in response to a service subscription request and updating the service register in response to the registration; an operation 9208 for interpreting a zonal architecture communication scheme; an operation 9210 for interpreting a zone manager command description for each of the at least one zone manager in accordance with the zonal architecture communication scheme (e.g., adjusting the zone manager command description based on an activity performed for the service); an operation 9212 for providing a corresponding zone manager command description to each of the at least one zone manager; and an operation 9214 for controlling communications between an endpoint in the corresponding network zone and an endpoint in at least one other zone of the plurality of network zones in response to the corresponding zone manager command description and the service register.
[0378] Examples of operation 9204 for exposing at least one service include listing the services in a data structure provided to the requesting source and / or listing the services in a data structure available to the requesting source.
[0379] Referring to FIG. 72, example procedure 9300 includes procedure 9200 and further includes an operation 9202 for interpreting a service publication request for a new service from a new service provider, an operation 9204 for determining a new service description in response to the service publication request and the new service provider, and an operation 9206 for maintaining a service register by adding the new service as one of a plurality of services.
[0380] Without being limited to any other aspect of the present disclosure, embodiments herein provide systems and procedures for implementing a zone network architecture for controlling time management of communications on the network, including time management for control purposes (e.g., synchronizing operations among distributed controllers) and / or for data analysis (e.g., comparing streams of data to detect events, plan or perform diagnostic or troubleshooting actions, etc.).
[0381] 73, an example system 9400 includes a vehicle (not shown) having a multi-zone network including multiple network zones, each of the network zones including at least one zone manager; and a network management controller 5002, the network management controller 5002 including a zone enforcement circuit 5004 that interprets a zoned architecture communication scheme 5014, the zoned architecture communication scheme 5014 including a time management scheme 9502 (see FIG. 74), the zone enforcement circuit 5004 that communicates with each of the at least one zone manager in response to the zoned architecture communication scheme 5014. a zone manager command circuit 5006 that interprets a zone manager command description 5016 for the plurality of network zones, the zone manager command description 5016 further including a time management implementation 9402, and a zone execution circuit 5008 that provides the corresponding zone manager command description 5016 to each of the at least one zone manager, each of the at least one zone manager responsive to the corresponding zone manager command description 5016 to control communications between endpoints in the corresponding network zone and endpoints in at least one other zone of the plurality of network zones.
[0382] The example system 9400 includes a time management scheme that includes designating one of the zone managers to act as a Precision Time Protocol (PTP) grandmaster for the multi-zone network. The example system 9400 may further include other zone managers designated as boundary clocks for corresponding network zones. In particular embodiments, a central zone manager may act as the PTP grandmaster for the multi-zone network, although any other zone manager may act as the PTP grandmaster, with the central zone manager acting as the boundary clock for the central zone.
[0383] In certain embodiments, one or more endpoints may alternatively act as the clock for a given zone, including the PTP Grand Master for a multi-zone network, and one or more endpoints may act as the boundary clock for its respective zone. In certain embodiments, a mix of selected endpoints and / or Zone Managers may act as the clock, including the PTP Grand Master and / or the boundary clock for each zone.
[0384] The illustrative system includes a zone enforcement circuit 5004 that operates a best master clock algorithm to determine a designated one Zone Manager and / or endpoint to act as the PTP Grandmaster. In certain embodiments, the zone enforcement circuit 5004 may further operate a best master clock algorithm for the endpoints and Zone Manager of a given zone to determine and designate a boundary clock for the given zone. In certain embodiments, the best master clock algorithm may be operated off-vehicle, such as in a built environment and / or a monitored environment, as depicted in Figures 78 and 93 and the related description, to determine the best PTP Grandmaster and / or boundary clock. In certain embodiments, the best PTP grandmaster and / or boundary clock may be determined based on certain criteria, such as, for example, based on the criticality of the functions performed in a given zone (e.g., important and / or high rate functions such as powertrain control may drive the selection of a PTP grandmaster for this zone) and / or based on the sensitivity of the functions performed in a given zone (e.g., functions with extreme time sensitivity may drive the selection of a PTP grandmaster for this zone).
[0385] The example zone enforcement circuit 5008 further determines a PTP grandmaster time loss event 9404, the zone enforcement circuit 5004 further operates a best master clock algorithm to determine an alternative one of the at least one Zone Manager to act as the PTP Grandmaster, and the zone enforcement circuit 5008 further designates the alternative one of the Zone Managers to act as the PTP Grandmaster. In a particular embodiment, the alternative best PTP Grandmaster is specified in a time management scheme, and the zone enforcement circuit 5008 further determines a PTP grandmaster time loss event 9404 and designates the specified alternative one of the Zone Managers to act as the PTP Grandmaster. In a particular embodiment, the PTP grandmaster may be one of the Zone Managers or the Endpoints, the Zone Enforcement Circuit 5008 further determines a PTP grandmaster time loss event 9404, the Zone Enforcement Circuit 5004 further operates a best master clock algorithm to determine an alternative endpoint and / or Zone Manager that will operate at the PTP grandmaster, and the Zone Enforcement Circuit 5008 further designates the determined alternative endpoint and / or Zone Manager to operate as the PTP grandmaster. In a particular embodiment, the PTP grandmaster may be one of the Zone Managers or the Endpoints, the alternative best PTP grandmaster is defined in the time management scheme as one of the Zone Managers or the Endpoints, and the Zone Enforcement Circuit 5008 further determines a PTP grandmaster time loss event 9404 and designates the defined alternative one of the Zone Managers or the Endpoints as the PTP grandmaster.
[0386] The example system 9400 includes a zone controller that applies a common PTP timestamp to at least a portion of communications provided in a corresponding network zone. The example system 9400 includes a zone controller that directs the application of a common PTP timestamp to at least a portion of communications provided in a corresponding network zone.
[0387] The example system 9400 includes a zone controller that removes local timestamps from at least a portion of communications provided in a corresponding one of a plurality of network zones. The example system 9400 includes a zone controller that commands the removal of local timestamps from at least a portion of communications provided in a corresponding network zone. In certain embodiments, the local timestamps are preserved and / or moved to different parts of the message. Preserving the original local timestamps enables certain post-processing actions, verification of PTP grandmaster performance and selection, detection of systematic problems in the overall timekeeping and synchronization scheme, and the like.
[0388] 74, the example zoned architecture communication scheme 5014 includes a communication priority scheme 9504. The example system 9400 includes a zone manager that responds to communication priority values (e.g., values associated with communications and / or actors associated with communications) and the communication priority scheme 9504 to control communications between endpoints in a corresponding network zone and endpoints in at least one other zone of the plurality of network zones.
[0389] An example communications priority scheme 9504 includes network routing values 9506 that, for example, provide shorter routes, lower activity routes, and / or quicker travel time routes for high priority communications, and provide longer routes, higher activity routes, and / or longer travel time routes for low priority communications. An example communications priority scheme 9504 includes communications scheduling values 9508 that, for example, provide higher priority scheduling for high priority communications, and provide lower priority scheduling, potentially including as "as available" or "best effort" scheduling, for lower priority communications. In particular embodiments, credit-based scheduling may be utilized to prioritize high priority communications while allowing some lower priority communications to proceed.
[0390] In certain embodiments, vehicle operating conditions are utilized to determine the scheduling and / or routing of high and low priority messages and / or to determine or adjust the priority of messages. For example, during normal operation, AV messages may be high priority messages due to the time sensitivity of such messages, but during certain operating conditions, such as when significant network traffic for control messages is high and / or the network is degraded, AV messages may be treated as low priority messages until vehicle operation returns to normal and / or the degradation is resolved.
[0391] 75 , an example procedure 9600 includes an operation 9602 for interpreting a zonal architecture communication scheme for a multi-zone network of vehicles, the zonal architecture communication scheme including a time management scheme; an operation 9604 for interpreting a zone manager command description for each of at least one zone manager in accordance with the zonal architecture communication scheme, the zone manager command description further including a time management implementation; an operation 9606 for providing a corresponding zone manager command description to each of the at least one zone manager; and an operation 9608 for controlling communications between an endpoint of the corresponding network zone and an endpoint of at least one other zone of the plurality of network zones in accordance with the zone manager command description.
[0392] Referring to FIG. 76, example procedure 9700 includes procedure 9600 as well as operation 9702 for determining a PTP grandmaster time loss event, operation 9704 for nominating an alternative PTP grandmaster, and operation 9706 for continuing to control communications between endpoints of the corresponding network zone.
[0393] In certain embodiments, procedure 9600 includes nominating endpoints and / or zone managers as boundary clocks per zone, with one endpoint and / or zone manager being designated as the PTP grandmaster. In certain embodiments, procedure 9600 includes running a best master clock algorithm for nominating endpoints and / or zone managers as PTP grandmasters. In certain embodiments, procedure 9700 includes running a best master clock algorithm for nominating an alternate PTP grandmaster. In certain embodiments, nominating a PTP grandmaster, alternate PTP grandmaster, and / or boundary clock includes determining the PTP grandmaster, alternate PTP grandmaster, and / or alternate clock based on the master zone having the most critical and / or most time-critical operations occurring therein.
[0394] Without being limited to any other aspect of the present disclosure, embodiments herein provide systems and procedures for configuring and / or adjusting a zonal network architecture, whether in the design phase (e.g., planning a zonal network architecture for a new vehicle) or the runtime phase (e.g., monitoring, verifying, or troubleshooting an existing vehicle in operation). Embodiments herein include tools for quickly designing new systems, verifying expected operation, diagnosing abnormal operation, comparing different configurations, leveraging lessons learned and configuration options across vehicles, and rolling out updated configurations with a high degree of certainty that the updated configurations will operate as expected and without downtime.
[0395] 77, an example system 9800 is schematically depicted including a build environment circuit 9804 that provides a virtual network build environment 9908 (see FIG. 78) to a user interface 9904 (see FIG. 78), a network modeling circuit 9806 that builds a virtual multi-zone network model 10004 (see FIG. 79) of the vehicle in response to user input on the user interface 9904, and a vehicle multi-zone architecture configuration platform 9802 that includes the virtual multi-zone network model 10004 including a zone controller located in each zone of the virtual multi-zone network model 10004. The vehicle for which the virtual multi-zone network model 10004 is built may be an existing vehicle or a future vehicle (e.g., planning a zone network architecture for a new vehicle, a new model for a vehicle, an upgrade and / or recall plan for an existing vehicle, etc.).
[0396] The illustrative system 9800 includes an endpoint modeling circuit 9808 that populates the virtual multi-zone network model 10004 with endpoints based on the vehicle control model 10006. In particular embodiments, the endpoint modeling circuit 9808 is empirical and / or low-resolution, populating the endpoints with data providers that simulate traffic on the vehicle's network at realistic rates, e.g., based on monitoring data from vehicles in service. In particular embodiments, the endpoint modeling circuit 9808 is high-resolution and / or first-principles based, utilizing actual applications, flows, endpoints, or the like installed in the vehicle (and / or representative installations) that enable response to inputs including environmental parameters, sensors, and / or operator inputs, for true generation of traffic. In particular embodiments, both low-resolution and high-resolution models may be utilized, e.g., using a low-resolution realistic network traffic emulator to detect gross network problems, and then using a high-resolution full endpoint model to perform granular diagnosis of network performance, test whether new control algorithms or updates will create any unexpected problems, or the like. In certain embodiments, operator inputs, sensor inputs, and the like may be fully simulated, for example, utilizing a software interface to simulate the vehicle interior and controls available to the operator, and / or utilizing actual hardware elements interfacing with the vehicle multi-zone architecture configuration platform 9802 to simulate the operator inputs. In certain embodiments, simple interface screens may be utilized depicting available switches and operator inputs along with numeric or graphical selection of the operator input positions.
[0397] The example vehicle multi-zone architecture configuration platform 9802 includes a network modeling circuit 9806 that further builds the virtual multi-zone network model 10004 by applying a zonal architecture communication scheme 10008, such as an actual full zone manager control scheme according to embodiments herein, and may also have a low-resolution simplified version and a high-resolution realistic or actual version for fully testing the planned control environment for the vehicle. The example vehicle multi-zone architecture configuration platform 9802 includes a network execution circuit 9810 that simulates the runtime operation of the vehicle's multi-zone network in response to the virtual multi-zone network model 10004, the vehicle control model 10006, and / or the zonal architecture communication scheme 10008. Depending on whether the aspect is a zonal architecture design, a multi-zone network, and / or vehicle control, one or more aspects of the virtual multi-zone network model 10004, the vehicle control model 10006, and / or the zonal architecture communication scheme 10008 may be provided in a low-resolution or high-resolution mode. Additionally or alternatively, vehicle operation may be performed in response to digitally fed operations involving, for example, driving behavior, torque feedback, environmental conditions, and operation through a digitally specified sequence (e.g., simulating a driving route intended to test control features, specific tests, diagnostics, network monitoring operations, or the like, and / or running the network under selected conditions) through manual operator input (e.g., using some elements including inside the virtual vehicle and / or actual hardware in the loop). The illustrative vehicle multi-zone architecture configuration platform 9802 includes a zonal architecture evaluation circuit 9812 that provides a network operation report 10010 in response to the simulation.
[0398] Referring to FIG. 78 , a system 9900 is schematically depicted that includes a vehicle 9902, which may be wholly or partially simulated and may represent an actual or future vehicle. The system 9900 includes a vehicle multi-zone architecture configuration platform 9802 that provides a virtual network construction environment 9908 to a user interface 9904. A user interacts with the user interface 9904 using a user device 9906, which may be a laptop, desktop, mobile computing device, terminal communicatively coupled to the vehicle multi-zone architecture configuration platform 9802, and / or a dedicated engineering tool or station for virtual modeling of the multi-zone network and / or network configuration operations as described in FIGS. 78-88 and related figures. In certain embodiments, aspects of the vehicle 9902 (e.g., switches, pedals, and / or other vehicle controls), along with, for example, hardware elements in the loop, may themselves be part of the user device 9906, including, for example, when a dedicated engineering tool or station is utilized in the system 9900. In certain embodiments, the user interface 9904 is provided on the user device 9906, for example, as a dedicated application on the user device 9906 and / or as a mobile application on a mobile device (e.g., a phone, tablet, or lean laptop) that performs the display and interaction for the vehicle multi-zone architecture configuration platform 9802. In certain embodiments, the user device 9906 is provided with the user interface 9904 through a web portal running in a web browser (e.g., with JavaScript implementation) or otherwise using an internet connection and / or through a direct networking connection such as a LAN, WLAN, using a tunneling application, through a VPN, or the like.
[0399] In particular embodiments, operations for building the virtual multi-zone network model 10004 include allowing a user to start with a pre-built model, which may be selected from a list or menu of base network selection values 10502 (see, e.g., FIG. 84). Some example base network selection values 10502 that may be available include network topology selection 10504 (e.g., selecting a schematic picture of the topology selection and / or selecting a topology from a drop-down menu, e.g., 2-node, 3-node, or 4-node, including variations in the configuration, and / or selecting an “n” node configuration, and specifying a star, mesh, and / or ring configuration), network zone distribution selection 10506 (e.g., weighting zones to the front or rear of the vehicle, assigning a central zone and central zone manager, and / or assigning redundancy parameters such as a zone manager serving as a central zone manager in response to hardware or control emergency events, adjusting the connections between zones from the default layout applied by the topology selection, if used, and otherwise configuring the connections as desired). network type selection 10508 (e.g., Ethernet, speed rating, cable and / or connector type, if applicable, and / or how many ports are available for the zone managers and / or switches in the system, any networks based on other systems such as CAN, LIN, etc.); communication protocol selection 10510 (e.g., protocol to be utilized for communication, industry standard for compliance, etc.); cross-network sampling scheme 10512 (e.g., upsampling or downsampling operation for particular cross-zone communications, sampling rate to be implemented for particular network zones and / or endpoints, etc.); cross-network encapsulation scheme 10514 (e.g., encapsulation operation to be implemented for communications between particular zones and / or endpoints);The basic network selection values 10502 listed are non-limiting examples, some of which may overlap, and not all of which may be present in a given embodiment. In particular embodiments, the available basic network selection values 10502 may be defined by the user and / or may vary according to the characteristics of the user device 9906, the user interface 9904, and / or the version of the vehicle multi-zone architecture configuration platform 9802.
[0400] In particular embodiments, a user can add elements by dragging and dropping elements onto the virtual network construction environment 9908, for example, by pulling zone managers, switches, endpoints, network connections, and the like into the virtual network construction environment 9908 and / or using menu selections and / or keyboard shortcuts to insert elements into the virtual network construction environment 9908. In particular embodiments, exemplary interface elements are provided on the virtual network construction environment 9908, for example, allowing a user to select a device and drag the device to a different location, alternatively select a device (e.g., with a right-click, shift-click, hold-click, etc.) to obtain a device properties menu, and the like. In particular embodiments, devices will be populated with actual instance hardware, including, for example, actual device capabilities and characteristics (e.g., ports, processing power, memory, communication speed, etc.) and / or device cost. In particular embodiments, endpoints may be configured as sensors, actuators, and computing devices (e.g., ECUs), which may additionally be selected from a menu of actual devices with user-defined and / or default properties. In particular embodiments, the model implements a high-resolution network hardware model 10014 that is populated with actual network hardware and includes, for example, connectors 10702, cable descriptions 10704, shielding descriptions 10706, and / or cooling descriptions 10708 (e.g., based on fins, nearby environment, environmental conditions, etc.) for potentially temperature-sensitive components (see FIG. 86).
[0401] In particular embodiments, endpoints, zone managers, or other elements can be populated with actual controls—e.g., naming software builds from configuration libraries, which can be synchronized with actual production and / or engineering databases for high-resolution simulations. In particular embodiments, even when a complete software build is integrated into the virtual network construction environment 9908, for example, a selection of simulation resolution can enable the simulation to switch between simple network traffic modeling or actual vehicle runtime modeling. In particular embodiments, the selection can include environmental modeling (e.g., vehicle environment model 10012) that determines temperatures, vibration profiles, water intrusion or road splash, or the like for network components, including, for example, models for temperature generation, heat rejection, warm-up, and / or cool-down behavior of controllers and nearby vehicle devices (e.g., engine, electric motor, turbocharger, radiator, wheels, brakes, etc.), as well as environmental heat conduction. Referring to FIG. 85, the example vehicle environment model 10012 includes one or more of a temperature environment model 10602, a vibration environment model 10604, a water intrusion model 10606, and / or an EMI model 10608.
[0402] In certain embodiments, a user can select a previous build, a build from an actual vehicle, or the like. In certain embodiments, the vehicle may be depicted schematically (e.g., as a schematic that may or may not have the appropriate relative size), omitted entirely, and / or realistically depicted (e.g., from a CAD file, a drawing prepared for the platform, etc.). In certain embodiments, the vehicle may be depicted as an empty shell with major parts (e.g., powertrain components, engine, tires, vehicle interior, etc.) in the appropriate locations and / or as a high-resolution model of the vehicle (e.g., enabling footprint analysis, high-resolution determination of installation feasibility, modeling of environmental parameters, and / or integration challenges). The example network modeling circuit 9806 builds a virtual multi-zone network model of the vehicle by pre-populating the virtual multi-zone network model 10004.
[0403] Referring to FIG. 80, an example zoned architecture communication scheme 10008 includes, at least in full resolution mode, at least one of a network security description 10102, a network connection description 10104, a time management scheme 10108, and / or a communication priority scheme 10106.
[0404] The example vehicle control model 10006 includes a model of a multi-zone network endpoint that simulates vehicle control behavior, including actual network traffic, vehicle responses, and / or actual vehicle control commands and data.
[0405] The example network execution circuitry 9810 simulates runtime operation of the multi-zone network by simulating an emergency condition, such as, for example, a particular hardware, control, and / or operational failure. The example network execution circuitry 9810 simulates the emergency condition by simulating at least one condition selected from the loss of an endpoint, the loss of a network component, a selected vehicle operating state, or a selected operator action.
[0406] The example network modeling circuit 9806 constructs a virtual multi-zone network model 10004 for the vehicle by applying the network topology description. The example network topology description includes applying a selected network topology for a zone of the multi-zone network and assigning zone controllers to the zones of the multi-zone network. The example network modeling circuit 9806 applies the network topology description in response to user input at a user interface.
[0407] The example network operation report 10010 includes an operational capability value (e.g., describing simulation results, comparison to expectations and / or specifications, etc.), a vehicle network performance description 10202 (see, e.g., FIG. 81 ), and / or a vehicle performance network impact description 10204. Referring to FIG. 82 , the example vehicle network performance description 10202 includes at least one of a latency value 10302 between at least two endpoints of the multi-zone network, a bandwidth value 10304 between at least two endpoints of the multi-zone network, a hardware redundancy description 10308 for the multi-zone network (e.g., the capability and / or performance to meet a hardware redundancy target), or a control redundancy description 10306 for the multi-zone network (e.g., the capability and / or performance to meet a control redundancy target).
[0408] Referring to FIG. 83 , an example vehicle performance network impact description 10204 includes at least one of an installed hardware cost value 10402 of the multi-zone network (e.g., determined from a parts list of actual network components), a mission capability description 10404 of the multi-zone network (e.g., determined from a summary of performance against targets or specifications and / or actual performance values), an integration cost description 10406 of the multi-zone network (e.g., based on interfaces, installation difficulty estimates, etc.), an operational cost description 10408 of the multi-zone network (e.g., based on processing resources, power consumption, and / or maintenance operations estimated from simulations), a redundancy capability description 10410 of the multi-zone network (e.g., a comparison of redundancy capability and / or performance against redundancy targets and / or specifications), and / or a reliability description 10412 of the multi-zone network (e.g., based on wear models, temperature environment, vibration environment, and / or water intrusion on network components).
[0409] In particular embodiments, the high-resolution simulation of network operation includes the network modeling circuit 9806 constructing a virtual multi-zone network model 10004 by performing one or more of (see FIG. 80 ): interpreting a zoned architecture communication scheme 10008 for the multi-zone network, interpreting a time management scheme 10108 for the multi-zone network, interpreting a communication priority scheme 10106 for the multi-zone network, interpreting a network security description 10102 for the multi-zone network, and / or interpreting a network connectivity description 10104 for the multi-zone network.
[0410] The example vehicle multi-zone architecture configuration platform 9802 further includes a zonal architecture rollout circuit 9814 that constructs a zonal architecture communication scheme 10008 in response to user actions at the interface and / or simulation results. The example zonal architecture rollout circuit 9814 communicates the zonal architecture communication scheme 10008 to a network management controller of the target vehicle, enabling the vehicle multi-zone architecture configuration platform 9802 to directly execute the zonal architecture rollout circuit 9814. In particular embodiments, the zonal architecture rollout circuit 9814 can provide communications or final outputs including any aspect of the virtual multi-zone network model 10004, the vehicle control model 10006, the vehicle environment model 10012, the network hardware model 10014, a schematic of the built environment, a network operation report 10010, a bill of materials for the network components, and any simulation parameters, configurations, or results.
[0411] Referring to FIG. 87 , example procedure 10800 includes an operation 10802 for providing a virtual network construction environment in a user interface; an operation 10804 for constructing a virtual multi-zone network model of the vehicle in response to user input in the user interface, the virtual multi-zone network model including a zone controller disposed for each zone of the virtual multi-zone network model; an operation 10806 for populating the virtual multi-zone network model with endpoints based on the vehicle control model; an operation 10809 for simulating runtime operation of the multi-zone network of the vehicle in response to the virtual multi-zone network model, the vehicle control model, and the zoned architecture communication scheme; and an operation 10810 for providing a network operation report in response to the simulation, wherein operation 10804 for constructing the virtual multi-zone network model further includes operation 10808 of applying the zoned architecture communication scheme.
[0412] Referring to FIG. 88, example procedure 10900 includes procedure 10800 and further includes operation 10902 for establishing a zoned architecture communication scheme in response to user interaction at a user interface, and operation 10904 for communicating the zoned architecture communication scheme to a network management controller of a target vehicle.
[0413] Without being limited to any other aspect of the present disclosure, embodiments herein provide systems and procedures for monitoring and / or analyzing zonal network architectures and / or future zonal network architectures in order to utilize the network monitoring and / or analysis in performing diagnostics, identifying problems, responding to problems, planning mitigation actions for problems, performing fault tree analysis, planning updates or recalls, developing a deeper understanding of activities on the vehicle and / or the vehicle effects of possible or actual failures or emergency actions, or the like.
[0414] 89 , an example system includes a vehicle multi-zone monitoring platform 11002 including a network layout circuit 11004 that interprets a virtual network layout 11010 for a vehicle having a multi-zone network, a network characterization circuit 11006 that interprets network activity 11012 for the vehicle, and a network analysis circuit 11008 that determines a virtual network map 11014 in response to the virtual network layout 11010 and the network activity 11012 and provides the virtual network map 11014 to a user interface. In particular embodiments, the network characterization circuit 11006 interprets the network activity 11012 for the vehicle via direct communication with the vehicle, for example, over a high-rate data connection that performs sniffing operations in the vehicle's network zone. Additionally or alternatively, the network characterization circuit 11006 interprets the network activity 11012 for the vehicle via data collection operations, for example, collecting data from a mirrored port of the vehicle's network to determine network activity in the network and / or selected zones of the network.
[0415] The illustrative virtual network map 11014 includes, for example, a representation of two-way network activity with graphical depictions of traffic flows between endpoints and / or network zones, bandwidth utilization descriptions, statistical data such as lost packets, comparisons to expected values, and the like. In particular embodiments, the virtual network map 11014 may include any data or depictions such as those depicted in Figures 22-27 of U.S. Patent Application No. 17 / 570,738 (SONA-0007-U01-C01). The illustrative virtual network map 11014 includes, for example, a color-coded schematic layout of the network identifying components (e.g., endpoints, zone managers, network zones, etc.) that are suspect, out of specification, overworked (e.g., having problems but appearing to be operating within design parameters), and / or have active fault or failure conditions.
[0416] The example network analysis circuit 11008 further provides network detail values 11018 (see FIG. 90 ) in response to user selections in the user interface. Example and non-limiting network detail values include a network traffic description 11102, a zoned architecture communication scheme 11104, network statistics 11106, and / or network event notifications 11108. The example vehicular multi-zone monitoring platform 11002 further includes a network configuration circuit 11016 that interprets the network adjustment values 11020 and updates the virtual network map 11014 in response to the network adjustment values 11020. In certain embodiments, the network adjustment values 11020 include user-entered adjustments and / or automatically calculated adjustments, where the adjustments are in response to observed problems and / or in response to meeting capacity adjustments or upgrades of the multi-zone network. Example and non-limiting network adjustment values 11020 include any one or more of different hardware components, zoned architecture communication scheme 10008 adjustments, zone manager command description adjustments, timing scheme adjustments, connection scheme adjustments, and / or permission value adjustments. In particular embodiments, the network adjustment values 11020 may include adjustments to any configuration, command value, or scheme value as described throughout this disclosure. The example network analysis circuit 11008 determines a network impact value 11022 in response to the network adjustment values 11020 and provides the network impact value 11022 to a user interface (e.g., as confirmation that the adjustment was expected to be successful and / or noting any gaps, uncertainties, or values that should not be estimated). In particular embodiments, the network analysis circuit 11008 utilizes the vehicle multi-zone architecture configuration platform 9802 to operate a high-resolution model of the virtual network layout 11010, for example, utilizing an API interface and / or driving the user interface 9904 and the virtual network construction environment 9908 to perform at least a portion of the determination of the network impact value 11022.
[0417] The vehicle multi-zone monitoring platform 11002 further includes a zonal architecture rollout circuit 9814 that establishes the zonal architecture communication scheme 10008 in response to the network adjustment values 11020. The example zonal architecture rollout circuit 9814 further communicates the zonal architecture communication scheme 10008 to a vehicle or a network management controller of the offset vehicle (e.g., as part of upgrading an offset vehicle that is within the same vehicle class and / or may share relevant similarities in network configuration).
[0418] 91 , an example procedure 11200 includes an operation 11202 for interpreting a virtual network layout for a vehicle having a multi-zone network, an operation 11204 for interpreting network activity for the vehicle, an operation 11206 for determining a virtual network map responsive to the virtual network layout and the network activity, and an operation 11208 for providing the virtual network map to a user interface, which may be provided as an interactive network activity representation that enables a user to make adjustments, adjust displayed results and / or layouts, and / or perform simulations. In particular embodiments, the interactive network activity representation is operated as an interface to a virtual network construction environment 9908 that provides a user on the vehicle multi-zone monitoring platform 11002 with any of the capabilities described in FIGS. 77-88 and the associated description. In particular embodiments, procedure 11200 includes an operation (not shown) for providing network detail values responsive to a user selection in the user interface. The example network detail values include one or more of a network traffic description, a zonal architecture communication scheme, network statistics, and / or network event notifications.
[0419] Referring to FIG. 92 , example procedure 11300 includes procedure 11200 and further includes an operation 11302 for interpreting the network adjustment value and updating the virtual network map in response to the network adjustment value, an operation 11304 for determining a network impact value in response to the network adjustment value and providing the network impact value to a user interface, and an operation 11306 for establishing a zonal architecture communication scheme in response to the network adjustment value and communicating the zonal architecture communication scheme to at least one network management controller of the vehicle or offset vehicle.
[0420] Without being limited to any other aspect of the present disclosure, embodiments herein provide systems and procedures for monitoring and / or analyzing a zonal network architecture, such monitoring operating on a vehicle, capable of quickly identifying and responding to problems as experienced on the vehicle with a rapid response, or perhaps an immediate and / or automated response. Actions to respond include, without limitation, implementing redundancy plans, changing the configuration of zonal network operations (e.g., prioritizing critical communications and operations and / or changing the routing or configuration of communications), transferring responsibility for security and / or control operations, and / or providing notifications and / or relevant data to selected off-vehicle locations.
[0421] Referring to FIG. 93 , an example system 11400 includes a vehicle (not shown) having a multi-zone network including multiple network zones, each of the network zones including at least one zone manager, a network monitoring controller 11402 including a network layout circuit 11004 that interprets a zoned architecture communication scheme 10008 and a network layout 11406 for the vehicle, a network characterization circuit 11006 that interprets network activity 11012 for the vehicle and determines network performance events 11408 in response to the network activity 11012, and a network reaction circuit 11404 that performs network event actions 11410 in response to the network performance events 11408. Example network event actions include collecting event information 11412 in response to a network performance event 11408 (e.g., information collected to determine that an event occurred, traffic information about endpoints, flows, applications, network zones, or the like related to the event, system information, vehicle operating status, fault code information, vehicle speed, load, environmental conditions, time since startup or last shutdown, or a base set of commonly collected characterization information for a network event, and / or a planned set of information based on an identifier for the event) and communicating the event information to an external device.
[0422] The example network reaction circuit 11404 collects one or more aspects of the event information as post-event activity. The example network reaction circuit 11404 collects one or more aspects of the event information as pre-event information, for example, captured from a rolling buffer and / or captured from non-transient information (e.g., status or fault codes) that survived the event period. The example network reaction circuit 11404 collects event information by capturing network activity 11012 that is utilized to determine network performance events 11408. Referring to FIG. 94, example and non-limiting network event actions 11410 include one or more actions such as collecting event information 11502, performing network tests 11504, performing diagnostics 11506, adjusting a zoned architecture communication scheme 11508, implementing a redundancy plan 11510 (e.g., switching responsibility of an endpoint, controller, zone manager, etc. in the system, which may further include disabling one or more components, running tests on one or more components, and / or placing one or more components in a limited operational state), and / or adjusting control responsibility of an endpoint 11512.
[0423] Referring to FIG. 95 , an example procedure 11600 includes an operation 11602 for interpreting a zonal architecture communication scheme and network layout for a vehicle having a multi-zone network including multiple network zones, each of the network zones including at least one zone manager; an operation 11604 for interpreting network activity for the vehicle; an operation 11606 for determining network performance events in response to the network activity; and an operation 11608 for performing network event actions in response to the network performance events.
[0424] The methods and systems described herein may be deployed partially or wholly through machines having computers, computing devices, processors, circuits, and / or servers that include computer-readable instructions, program code, hardware configured to execute instructions and / or functionally perform one or more operations of the methods and systems herein. As used herein, the terms computer, computing device, processor, circuit, and / or server ("computing device") should be understood broadly.
[0425] An illustrative computing device includes any type of computer capable of accessing instructions stored on a non-transitory computer-readable medium or the like when communicated to the computer, such that the computer performs the operations of the computing device when executing the instructions. In particular embodiments, such instructions themselves comprise a computing device. Additionally or alternatively, a computing device may be a separate hardware device, one or more computing resources distributed across hardware devices, and / or may include aspects such as logic circuits, embedded circuits, sensors, actuators, input and / or output devices, network and / or communication resources, memory resources of any type, processing resources of any type, and / or hardware devices configured to respond to determined conditions to functionally perform one or more operations of the systems and methods herein.
[0426] Network and / or communication resources include, without limitation, local area networks, wide area networks, wireless, the Internet, or any other known communication resources and protocols. Illustrative and non-limiting hardware and / or computing devices include, without limitation, general-purpose computers, servers, embedded computers, mobile devices, virtual machines, and / or emulated computing devices. A computing device may be distributed resources included as aspects of several devices, included as an interoperable set of resources for performing the described functionality for the computing device, whereby the distributed resources function together to perform the operations of the computing device. In particular embodiments, each computing device may be on separate hardware, and / or one or more hardware devices may include aspects of two or more computing devices, e.g., as separately executable instructions stored on the devices and / or as logically partitioned aspects of a set of executable instructions, with some aspects comprising one portion of a first computing device and some aspects comprising another portion of a computing device.
[0427] The computing device may be part of a server, client, network infrastructure, mobile computing platform, stationary computing platform, or other computing platform. A processor may be any type of computational or processing device capable of executing program instructions, code, binary instructions, and the like. A processor may be or include any variant, such as a signal processor, digital processor, embedded processor, microprocessor, or coprocessor (mathematics coprocessor, graphics coprocessor, communication coprocessor, and the like), that can directly or indirectly facilitate the execution of program code or program instructions stored therein. Additionally, a processor may enable the execution of multiple programs, threads, and codes. Threads may be executed simultaneously to enhance processor performance and facilitate simultaneous operation of applications. As an example of implementation, the methods, program codes, program instructions, and the like described herein may be implemented with one or more threads. A thread may spawn other threads, which may have assigned priorities associated with the other threads, and the processor may execute these threads based on priority or any other order based on instructions provided in the program code. The processor may include memory that stores methods, codes, instructions, and programs as described herein and elsewhere. The processor may access, through an interface, a storage medium that may store methods, codes, and instructions as described herein and elsewhere. Storage media associated with the processor for storing methods, programs, codes, program instructions, or other types of instructions capable of being executed by a computing or processing device may include, but are not limited to, one or more of a CD-ROM, a DVD, memory, a hard disk, a flash drive, RAM, ROM, cache, and the like.
[0428] A processor may include one or more cores, which may enhance the speed and performance of a multiprocessor. In embodiments, a process may be a dual-core processor, a quad-core processor, other chip-level multiprocessor, and the like, which combines two or more independent cores (called a die).
[0429] The methods and systems described herein may be deployed, in part or in whole, through machines executing computer-readable instructions on servers, clients, firewalls, gateways, hubs, routers, or other such computers and / or networking hardware. The computer-readable instructions may be associated with a server, which may include a file server, a print server, a domain server, an Internet server, an intranet server, and other variations such as secondary servers, host servers, distributed servers, and the like. A server may include one or more of memory, a processor, computer-readable transitory and / or non-transitory media, storage media, ports (physical and virtual), communication devices, and interfaces capable of accessing other servers, clients, machines, and devices through wired or wireless media, and the like. Methods, programs, or codes as described herein and elsewhere may be executed by a server. Additionally, other devices required for the execution of methods as described in this application may be considered part of the infrastructure associated with the server.
[0430] The server may provide an interface to other devices, including, without limitation, clients, other servers, printers, database servers, print servers, file servers, communication servers, distributed servers, and the like. Additionally, this coupling and / or connection may facilitate remote execution of instructions across a network. Networking some or all of these devices may facilitate parallel processing of program code, instructions, and / or programs in one or more locations without departing from the scope of this disclosure. In addition, all devices connected to the server through an interface may include at least one storage medium capable of storing methods, program code, instructions, and / or programs. A central repository may provide program instructions to be executed on different devices. In this implementation, the remote repository may function as a storage medium for methods, program code, instructions, and / or programs.
[0431] Methods, program codes, instructions, and / or programs may be associated with a client, which may include a file client, a print client, a domain client, an Internet client, an intranet client, and other variations such as a secondary client, a host client, a distributed client, and the like. A client may include one or more of a memory, a processor, a computer-readable transitory and / or non-transitory medium, a storage medium, a port (physical and virtual), a communication device, and an interface capable of accessing other clients, servers, machines, and devices through a wired or wireless medium, and the like. Methods, program codes, instructions, and / or programs as described herein and elsewhere may be executed by a client. Additionally, other devices required for the execution of methods as described in this application may be considered part of the infrastructure associated with the client.
[0432] Clients may provide interfaces to other devices, including, without limitation, servers, other clients, printers, database servers, print servers, file servers, communication servers, distributed servers, and the like. Additionally, this coupling and / or connection may facilitate remote execution of methods, program code, instructions, and / or programs across a network. Networking some or all of these devices may facilitate parallel processing of methods, program code, instructions, and / or programs in one or more locations without departing from the scope of this disclosure. In addition, all devices connected to clients through interfaces may include at least one storage medium capable of storing methods, program code, instructions, and / or programs. A central repository may provide program instructions to be executed on different devices. In this implementation, remote repositories may serve as storage media for methods, program code, instructions, and / or programs.
[0433] The methods and systems described herein may be deployed partially or entirely through a network infrastructure. The network infrastructure may include elements such as computing devices, servers, routers, hubs, firewalls, clients, personal computers, communication devices, routing devices, and other active and passive devices, modules, and / or components as known in the art. The computing and / or non-computing devices associated with the network infrastructure may include, apart from other components, storage media such as flash memory, buffers, stacks, RAM, ROM, and the like. The methods, program codes, instructions, and / or programs described herein and elsewhere may be executed by one or more of the network infrastructure elements.
[0434] The methods, program codes, instructions, and / or programs described herein and elsewhere may be implemented on a cellular network having multiple cells. The cellular network may be a Frequency Division Multiple Access (FDMA) network or a Code Division Multiple Access (CDMA) network. The cellular network may include mobile devices, cell sites, base stations, repeaters, antennas, towers, and the like.
[0435] The methods, program codes, instructions, and / or programs described herein and elsewhere may be implemented on or through a mobile device. Mobile devices may include navigation devices, cell phones, mobile phones, mobile personal digital assistants, laptops, palmtops, netbooks, pagers, e-readers, music players, and the like. These devices may include, among other components, storage media such as flash memory, buffers, RAM, ROM, and one or more computing devices. The computing device associated with the mobile device may be enabled to execute methods, program codes, instructions, and / or programs stored on the mobile device. Alternatively, the mobile device may be configured to execute instructions in collaboration with other devices. The mobile device may communicate with a base station interfaced with a server and configured to execute methods, program codes, instructions, and / or programs. The mobile device may communicate in a peer-to-peer network, a mesh network, or other communication network. The methods, program codes, instructions, and / or programs may be stored in a storage medium associated with the server and executed by a computing device embedded within the server. The base station may include a computing device and a storage medium. The storage device may store methods, program codes, instructions, and / or programs executed by computing devices associated with the base station.
[0436] The methods, program code, instructions, and / or programs may be stored and / or accessed on machine-readable, transient and / or non-transitory media, which may include computer components, devices, and other computer memory such as recording media that hold digital data used for computation for a period of time, semiconductor storage known as random access memory (RAM), forms of magnetic storage like optical disks, hard disks, mass storage for typically more permanent storage such as tape, drums, cards, and other types, processor registers, cache memory, volatile memory, non-volatile memory, optical storage like CDs, DVDs, flash memory (e.g., USB sticks or keys), floppy disks, magnetic tape, paper tape, punch cards, standalone RAM disks, Zip drives, removable mass storage, offline, and the like, dynamic memory, static memory, read / write storage, mutable storage, read-only, random access, sequential access, location addressable, file addressable, content addressable, network attached storage, storage area networks, bar codes, magnetic links, and the like.
[0437] Certain operations described herein include interpreting, receiving, and / or determining one or more values, parameters, inputs, data, or other information (“receiving data”). Operations for receiving data include, without limitation, receiving data via user input, receiving data over any type of network, reading a data value from a memory location while communicating with the receiving device, utilizing a default value as the received data value, estimating, calculating, or deriving a data value based on other information available to the receiving device, and / or updating any of these in response to a later received data value. In certain embodiments, a data value may be received by a first operation and later updated by a second operation as part of receiving the data value. For example, a first receiving operation may be performed when communication is down, intermittent, or interrupted, and an updated receiving operation may be performed when communication is restored.
[0438] To illustrate aspects of the present disclosure, particular logical groupings of operations herein, such as methods or procedures of the present disclosure, are provided. The operations described herein are generally described and / or depicted, and operations may be combined, divided, rearranged, added, or removed in a manner consistent with the disclosure herein. While the context of the operation description may require an ordering for one or more operations and / or an order for one or more operations may be explicitly disclosed, it is understood that the order of operations should be understood broadly, and that any equivalent grouping of operations to provide an equivalent outcome of the operations is specifically contemplated herein. For example, if a value is used in an operation step, determination of the value may be required prior to this operation step in certain contexts (e.g., where a time delay of data for the operation is important to achieve a particular effect), but may not be required prior to this operation step in other contexts (e.g., where use of a value from a previous execution cycle of the operation should be sufficient for these purposes). Thus, in certain embodiments, the ordering of operations and grouping of operations as described are expressly contemplated herein, and in certain embodiments, reordering, subdivision, and / or different grouping of operations are expressly contemplated herein.
[0439] The methods and systems described herein can transform physical and / or intangible items from one state to another. The methods and systems described herein can also transform data representing physical and / or intangible items from one state to another.
[0440] The above-described methods and / or processes, and steps thereof, may be implemented in hardware, program code, instructions, and / or programs, or in any combination of hardware, methods, program code, instructions, and / or programs appropriate for a particular application. Hardware may include dedicated or specific computing devices, specific aspects or components of a specific computing device, and / or configurations of hardware components and / or logic circuitry for performing one or more of the operations of the methods and / or systems. The processes may be implemented in one or more microprocessors, microcontrollers, embedded microcontrollers, programmable digital signal processors, or other programmable devices, along with internal and / or external memory. The processes may also, or instead, be embodied in application-specific integrated circuits, programmable gate arrays, programmable array logic, or any other device or combination of devices that can be configured to process electronic signals. It will further be recognized that one or more of the processes may be implemented as computer-executable code capable of being executed on a machine-readable medium.
[0441] The computer-executable code may be written using a structured programming language such as C, an object-oriented programming language such as C++, or any other high-level or low-level programming language (including assembly language, hardware description languages, and database programming languages and techniques) that can be stored, compiled, or interpreted for execution by one of the above devices, as well as heterogeneous combinations of processors, processor architectures, or combinations of different hardware and computer-readable instructions, or any other machine capable of executing program instructions.
[0442] Thus, in one aspect, each of the methods and combinations of methods described above may be embodied in computer-executable code that performs its steps when executed on one or more computing devices. In another aspect, the methods may be embodied in a system that performs its steps, may be distributed across devices in some manner, or all of the functionality may be integrated into a dedicated stand-alone device or other hardware. In another aspect, the means for performing the steps associated with the processes described above may include any of the hardware and / or computer-readable instructions described above. All such permutations and combinations are intended to be within the scope of the present disclosure.
[0443] While the present disclosure has been disclosed in conjunction with specific embodiments shown and described in detail, various modifications and improvements to the present disclosure will be readily apparent to those skilled in the art. Accordingly, the scope of the present disclosure should not be limited by the foregoing examples, but should be understood in the broadest sense allowable by law.
Claims
1. The steps of interpreting a vehicle network performance description having a hardware redundancy description for a multizone network via at least one processor, A step of determining a zone architecture value via at least one processor in accordance with a vehicle performance network impact description comprising a vehicle network performance description and a reliability description for the multizone network, wherein the zone architecture value comprises a network type value for each zone of the multizone network. The steps include installing the multi-zone network configured according to the zone architecture value in the vehicle, and Methods that include...
2. The aforementioned vehicle network performance description is, The latency value between at least two endpoints of the multizone network, or The bandwidth value between at least two endpoints of the multizone network The method according to claim 1, comprising at least one of the following.
3. The aforementioned vehicle performance network impact description is, The installed hardware cost value of the multizone network, or Mission capability description of the aforementioned multi-zone network The method according to claim 1, comprising at least one of the following.
4. The method according to claim 1, wherein the zone architecture value comprises a network topology description.
5. The method according to claim 4, wherein the zone architecture value further comprises a zone manager distribution description.
6. The method according to claim 1, wherein the zone architecture value further comprises network protocol values for each zone of the multizone network.
7. The method according to claim 1, wherein the zone architecture value further comprises a specification value for at least one hardware component of the multizone network.
8. The method according to claim 1, wherein the multizone network is configured according to the network topology description of the zone architecture values.
9. The method according to claim 1, wherein the multizone network is configured according to the zone manager distributed description of the zone architecture values.
10. The method according to claim 1, wherein the vehicle network performance description comprises a control redundancy description for the multizone network.
11. The method according to claim 1, wherein the vehicle performance network impact description comprises a redundancy capability description for the multizone network.
12. A step of interpreting a plurality of vehicle network performance descriptions via at least one processor, wherein each of the vehicle network performance descriptions corresponds to one of a plurality of selected vehicle classes and comprises a hardware redundancy description for a multizone network corresponding to the one of the plurality of selected vehicle classes, A step of determining a zone architecture value via at least one processor in accordance with the plurality of vehicle network performance descriptions and the vehicle performance network impact descriptions for each of the plurality of selected vehicle classes, wherein the vehicle performance network impact description comprises a reliability description for the multizone network corresponding to each corresponding one of the plurality of selected vehicle classes, and the zone architecture value comprises a network type value for each zone of the multizone network. A step of installing the multizone network configured according to the zone architecture value in a first vehicle and a second vehicle, respectively, wherein the first vehicle comprises a first member of the plurality of selected vehicle classes and the second vehicle comprises a second member of the plurality of selected vehicle classes. Methods that include...
13. Each of the above multiple vehicle network performance descriptions is, The latency value between at least two endpoints of the multizone network corresponding to one of the plurality of selected vehicle classes, The bandwidth value between at least two endpoints of the multizone network corresponding to one of the plurality of selected vehicle classes, or Control redundancy description for the multizone network corresponding to one of the plurality of selected vehicle classes. The method according to claim 12, comprising at least one of the following.
14. The vehicle performance network impact description corresponding to each of the aforementioned multiple selected vehicle classes is, The installed hardware cost value of the multizone network corresponding to one of the multiple selected vehicle classes, A mission capability description of the multizone network corresponding to one of the aforementioned multiple selected vehicle classes, or Redundancy capability description of the multizone network corresponding to one of the multiple selected vehicle classes. The method according to claim 12, comprising at least one of the following.
15. The method according to claim 12, wherein the zone architecture value comprises a network topology description.
16. The method according to claim 15, wherein the zone architecture value further comprises a zone manager distribution description.
17. The method according to claim 12, wherein the multizone network in each of the first and second vehicles is configured according to the network topology description of the zone architecture values.
18. The method according to claim 12, wherein the multizone network in each of the first and second vehicles is configured according to the zone manager distributed description of the zone architecture values.