System and method for safe duplicated start-stop of on-board controller, microcircuit and intelligent vehicle

A system with keeper, process control, and health control components addresses the challenge of safely and efficiently managing controller application startups and shutdowns, enhancing vehicle safety and reliability through functional grouping and hierarchical structuring.

RU2865649C2Active Publication Date: 2026-07-07ЧОНГКИНГ ЧАНГАН ТЕХНОЛОДЖИ КО ЛТД
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
RU · RU
Patent Type
Patents
Current Assignee / Owner
ЧОНГКИНГ ЧАНГАН ТЕХНОЛОДЖИ КО ЛТД
Filing Date
2024-07-11
Publication Date
2026-07-07

AI Technical Summary

Technical Problem

Current on-board controller systems struggle to safely and efficiently manage the starting and stopping of controller applications, leading to potential points of failure and complicating maintenance, which affects the safe operation of vehicles.

Method used

A system comprising keeper, process control, state control, and health control components that manage the starting and stopping of controller applications through functional grouping and hierarchical structuring, ensuring safe and duplicated operation.

Benefits of technology

Effectively manages the starting and stopping of controller applications under various circumstances, ensuring safe vehicle operation by preventing repeated restarts and improving processing efficiency and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000001_ABST
    Figure 00000001_ABST
Patent Text Reader

Abstract

FIELD: automobile industry.SUBSTANCE: invention relates to a system and method for safe duplicated start-stop of an on-board controller, a microcircuit and an intelligent vehicle. The essence of the solution is to create a hierarchical structure from a storage component, a process control component, a state control component, and a health control component, whereby the storage component launches and controls the process control component, which, in turn, launches and controls the remaining components and applications of the controller, ensuring the collection of information about their activity, recording of abnormal situations, and targeted restart of target programs based on the exchange of application exit messages and start / stop messages.EFFECT: increase in the safety and fault tolerance of the on-board controller by localizing software failures at the level of specific processes and ensuring their point recovery within milliseconds, which eliminates the need for a complete reboot of the vehicle operating system in the event of abnormal situations, prevents the freezing of associated applications and minimizes the number of points of failure of the on-board equipment of the domain.13 cl, 4 dwg
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims priority to Chinese Patent Application No. 202410099586.5, entitled "Safe Redundant Start-stop System and Method for Onboard Controller, Chip, and Intelligent Vehicle", filed with the National Intellectual Property Administration of China on January 22, 2024, the contents of which are incorporated herein by reference in their entirety.

[0002] Technical field

[0003] The present invention relates to the technical field of intelligent vehicles, in particular, to a system and method for safe duplicated start-stop of an on-board controller, a microcircuit and an intelligent vehicle.

[0004] State of the art

[0005] As vehicles become more intelligent, the variety and number of different embedded controllers in vehicles has increased, and their complexity has also increased. The requirements for the safe operation of embedded controllers have also increased. During vehicle operation, it is necessary to effectively manage the start and stop of the onboard controller under various circumstances to ensure safe vehicle operation.

[0006] Currently, the application software of a vehicle's on-board controller (abbreviated as controller apps) is directly managed by the system-on-chip (SOC), making the SOC more complex and potentially leading to more points of failure, complicating maintenance. Furthermore, when a controller app malfunctions, the SOC has difficulty starting or stopping the controller app in a timely manner. This means that current on-board controller systems struggle to safely and efficiently manage the starting and stopping of controller apps, affecting the safe operation of vehicles.

[0007] Disclosure of the essence of the invention

[0008] One of the objectives of the present invention is to provide a system for safely and duplicately starting and stopping an on-board controller to solve the problem of the prior art that it is difficult to safely and efficiently control the starting and stopping of controller applications, which affects the safe operation of vehicles, the second objective is to provide a method for safely and duplicately starting and stopping an on-board controller, the third objective is to provide a microcircuit, and the fourth objective is to provide an intelligent vehicle.

[0009] In order to achieve the above objectives, the present invention adopts the following technical solutions:

[0010] A system for safe, duplicated start-stop of an on-board controller is proposed, comprising:

[0011] keeper component, process control component, state control component and health control component;

[0012] wherein the storage component is configured to start and control the process control component and restart the process control component when the process control component stops working;

[0013] the process control component is configured to: start and control the state management component, the health management component, and each controller application; restart the component that has stopped working when any of the state management component and the health management component stops working; generate an application exit message for the controller application that has stopped working when the controller application stops working, and send the application exit message to the state control component; and restart the controller application and / or the state management component specified in the start-stop message in response to the received start-stop message;

[0014] the health management component is configured to: receive process activity information of the state management component and each application of the controller; generate a start-stop message in accordance with an object that has encountered an abnormal situation when, in accordance with the process activity information, it is determined that any object of the state management component and the applications of the controller has encountered an abnormal situation, and send the start-stop message to the process management component; and

[0015] the state management component is configured to generate a start-stop message in accordance with an application exit message received from the process management component, send the start-stop message to the process management component, and periodically send process activity information about its own process to the health management component.

[0016] According to the above technical means, the control of starting and stopping the controller applications through functional grouping and hierarchical structuring can effectively manage the starting and stopping of the controller applications under various circumstances, achieve safe and duplicated starting and stopping of the controller applications, and ensure the safe operation of vehicles.

[0017] Optionally, the health management component also monitors the watchdog component and obtains the state of the controller system's resources. When the watchdog component fails and / or the controller system detects an abnormal resource condition, the health management component sends a signal to the watchdog software to restart the controller system.

[0018] The above technical means allow us to solve the problem of abnormal situations in the controller system and abnormal operation of the guardian component to ensure the safe operation of the domain controller.

[0019] Optionally, upon receiving a start-stop message sent by the state management component, the process management component restarts the controller application specified in the start-stop message; and upon receiving a start-stop message sent by the health management component, the process management component restarts the controller application and / or the state management component specified in the start-stop message.

[0020] The above technical means can solve the problems associated with different operating conditions and objects through the state management component and the health management component, which can improve the processing efficiency and reliability of the system.

[0021] Optionally, the state control component includes a counting unit, wherein the counting unit is configured to accumulate the number of restarts when the state control component is restarted by the process control component if, in accordance with the restart parameters of the state control component, it is determined that the state control component is restarted after an abnormal output, and send a restart signal to the watchdog software of the controller system when the accumulated number of restarts exceeds a predetermined threshold value,

[0022] According to the above technical means, the restart parameters are set so as to prevent the state management component from restarting repeatedly within a short period of time and solve the problems caused by the operating conditions under which the state management component cannot restart successfully, thereby improving the reliability of the system.

[0023] Optionally, the process control component includes a control and recovery unit, wherein the control and recovery unit is configured to send to the restartable component, upon restart of any of the health control component and the state control component, the current state of each controller application controlled by the restartable component, in order to restore control of the controller application by the restartable component.

[0024] According to the above technical means, restoring the current state of the controlled controller application can avoid restarting the controlled controller application due to restarting the health management component or the state management component, thus improving the restart efficiency.

[0025] Optionally, the process control component includes a tool package block, wherein the tool package block is configured to read the configurations of the service-oriented architecture (SOA) tool package and obtain the startup logic information when starting the controller application, and start the controller application according to the startup logic information.

[0026] According to the above technical means, the startup logic is controlled through the configuration of the SOA tool package to more conveniently control the startup process of the controller application.

[0027] Optionally, both the state management component and the health management component include a tool package block, wherein the tool package block is configured to read the configurations of the tool package, obtain the operation logic information, and generate a start-stop message in accordance with the operation logic information and the controller application that has stopped working or encountered an abnormal situation.

[0028] According to the above technical means, the configuration of the SOA tool package is read by the tool package block, which makes the start-stop logic of the controller application that has stopped working or encountered an abnormal situation suitable for configuration, thereby improving the efficiency and convenience of management.

[0029] Optionally, the state management component and the health management component further include an application combination unit, wherein the application combination unit is configured to receive a combination of controller applications in accordance with the operation logic information and the controller application that has stopped operating or encountered an abnormal situation, and to generate a start-stop message in accordance with the combination.

[0030] According to the above technical methods, by determining the functional group to which the controller application that has stopped working or encountered an abnormal situation or the related controller applications belongs, logic operations can be performed on the entire combination of controller applications, thereby improving the security of the domain controller.

[0031] The method of safe duplicated start-stop of the on-board controller includes:

[0032] preliminary creation of a first-level functional component, a second-level functional component and a third-level functional component, wherein the first-level functional component is configured to start and control the second-level functional component, the second-level functional component is configured to start and control the third-level functional component, and the third-level functional component is configured to receive process activity information or an exit message from the application of each controller application;

[0033] Start the first-level functional component in the guardian process mode;

[0034] Restart of the second-level functional component by the first-level functional component when the first-level functional component detects that the second-level functional component has stopped working;

[0035] restarting the third-level functional component by the second-level functional component when the second-level functional component detects that the third-level functional component has stopped working; generating an application exit message according to the controller application that stops working when the second-level functional component detects that the controller application has stopped working, and sending the application exit message to the third-level functional component; restarting the controller application specified in the start-stop message by the second-level functional component when the second-level functional component receives the start-stop message sent by the third-level functional component; and

[0036] Generating a start-stop message according to the controller application that has encountered an abnormal situation, when the third-level functional component determines that the controller application has encountered an abnormal situation based on the process activity information; or generating a start-stop message according to the application exit message and sending the start-stop message to the second-level functional component.

[0037] Optionally, the third-level functional component includes a state management component and a health management component, wherein the state management component is configured to receive a message about exiting the application sent by the second-level functional component, and the health management component is configured to receive information about the process activity of each application of the controller.

[0038] According to the above technical methods, the problems arising from different operating conditions are solved by using the state management component and the health management component, which can improve the processing efficiency and the reliability of the system.

[0039] Optionally, the health management component further receives the process activity information of the state management component, and when it determines that the state management component has encountered an abnormal situation based on the process activity information of the state management component, the health management component generates a start-stop message and sends the start-stop message to the second-level functional component.

[0040] According to the above technical methods, the health management component is configured to monitor whether the state management component has encountered an abnormal situation, so that when the state management component encounters an abnormal situation, it can be restarted in a timely manner, thereby improving the reliability of the system.

[0041] A microcircuit is proposed, wherein a program for safe duplicated start-stop of an on-board controller is stored in the microcircuit, and when executed by the processor, the program for safe duplicated start-stop of an on-board controller implements the stages of any of the methods for safe duplicated start-stop of an on-board controller.

[0042] An intelligent vehicle is proposed, wherein the intelligent vehicle comprises a memory, a processor and a program for safe duplicated start-stop of an on-board controller, which is stored in the memory and is configured to be executed by the processor, and when executed by the processor, the program for safe duplicated start-stop of an on-board controller implements the steps of any of the methods for safe duplicated start-stop of an on-board controller.

[0043] Advantageous effects of the present invention: instead of restarting the controller system every time the controller application encounters an abnormal situation or exits, the operating conditions of different controller applications are managed through functional grouping and hierarchical structuring, enabling safe and efficient management of the controller application startup and shutdown, ensuring the safe operation of the vehicle. Furthermore, when combined with an SOA-based service architecture, the system can be quickly iterated and quickly adapted to various embedded controllers throughout the vehicle.

[0044] Brief description of drawings

[0045] Fig. 1 is a functional diagram of the architecture of a safe dual start-stop system according to an embodiment of the present invention.

[0046] Fig. 2 is a flow chart of the interactions of a state management component according to an embodiment of the present invention.

[0047] Fig. 3 is a flow chart of the interactions of a health management component according to an embodiment of the present invention.

[0048] Fig. 4 is a schematic diagram of an intelligent vehicle according to an embodiment of the present invention.

[0049] Implementation of the invention

[0050] The implementation of the present invention will be described below with reference to the accompanying drawings and optional embodiments. Those skilled in the art will easily understand other advantages and effects of the present patent application, which follow from the content disclosed in this specification. The present invention can also be implemented or applied using other specific implementation methods, and various details in this specification can also be modified or changed in various ways depending on various aspects and fields of application within the scope of the present invention. It is understood that the optional embodiments are intended only to illustrate the present invention and are not intended to limit the scope of legal protection of the present invention.

[0051] It should be noted that the diagrams shown in the following embodiments of the invention only schematically illustrate the basic idea of ​​the present invention. Therefore, the diagrams only show the components relevant to this invention, and not their number, shape, and size in an actual implementation. In an actual implementation, the types, quantities, and proportions of each component may be arbitrarily changed, and the component arrangement may be more complex.

[0052] The vehicle embedded controller (also known as the on-board controller) mainly consists of a microcontroller unit (MCU) and a system-on-chip (SOC). The SOC runs systems such as Linux and QNX (i.e., the controller system) and application software (i.e., the controller application). The controller application is capable of controlling and monitoring various vehicle functions and systems, such as internal combustion engine control, vehicle stability control, braking system control, air conditioning system control, vehicle multimedia system control, etc.

[0053] With the development of software-controlled vehicles, the intelligent capabilities of automobiles are becoming increasingly sophisticated, and the requirements for the safe operation of embedded controllers throughout the vehicle are becoming more stringent. During vehicle operation, effectively managing the start and stop of controller applications under various circumstances has become a challenge that needs to be addressed.

[0054] In response to the existing problem of difficulties in safely and efficiently managing the start and stop of controller applications, the present invention manages the start and stop of controller applications by creating a plurality of components through functional grouping and hierarchical structuring to efficiently manage the start and stop of controller applications in various situations, and ensures safe and duplicated start and stop of controller applications.

[0055] The secure, duplicated start-stop system of the on-board controller according to the present invention can be deployed on a domain controller (such as a cockpit domain controller, a multimedia domain controller, a power domain controller, etc.) of a vehicle to ensure secure and duplicated start-stop of controller applications on this domain controller. The secure, duplicated start-stop system of the on-board controller can also be deployed on a central domain controller (such as an ECU) to ensure secure and duplicated start-stop of controller applications throughout the vehicle.

[0056] The secure, duplicated startup / shutdown system for an on-board controller in the embodiments of the present invention operates on an embedded domain controller, wherein the domain controller consists of a single-chip microcomputer (MCU) and multiple systems-on-chips (SOCs). The MCU is responsible for power management of the entire embedded domain controller. Each chip of the domain controller generates corresponding interface code through a service-oriented architecture (SOA) according to its own needs and integrates the interface code into each controller application for deployment and operation accordingly. It should be noted that this system is not limited to use in a domain controller with only one MCU and one or more SOCs. It can also be used in a domain controller with multiple MCUs and multiple SOCs.

[0057] In particular, as shown in Fig. 1, the above system includes: a custodian component SWC_RUN, a process control component SWC_EM, a state control component SWC_SM, and a health control component SWC_PHM.

[0058] The guardian component is a functional component that the onboard controller calls immediately after startup. A guardian component can be a module or a piece of code. For example, if the onboard controller runs systems such as Linux or QNX, the guardian component is managed and executed by the system (the system and service manager are responsible for starting, stopping, and managing the protection process); if the onboard controller is a real-time system such as a single-chip microcomputer (MCU), UCOS, or RTOS, the guardian component is a component of a task initiated after the controller is powered on (by a code fragment in a while(true) loop). When the guardian component starts, it starts and controls the SWC_EM process control component.During the monitoring process, when a normal or abnormal exit from the SWC_EM process control component is detected for unknown reasons, the guardian component is responsible for quickly restarting, within milliseconds, the SWC_EM process control component.

[0059] The process control component is a functional component that manages operations such as starting, stopping, sleeping, and restarting controller applications and combinations of controller applications on the onboard controller. Once started, the process control component starts and monitors the SWC_SM state management component, the SWC_PHM health management component, and each controller application by creating child processes and subtasks. During monitoring, when the SWC_SM state management component or the SWC_PHM health management component exits normally or exits abnormally and stops running, it is responsible for promptly restarting the stopped state management component or health management component within milliseconds.

[0060] Controller applications can be linked to each other. For example, a voice recognition application can be linked to a door lock switch application to enable voice-activated locking. If a controller application is simply restarted after a controller application terminates, this may cause other controller applications linked to that controller application to operate abnormally, affecting the safe operation of the vehicle. Therefore, when a controller application is detected to terminate, the terminated controller application is packaged in an application exit message. For example, the process name and process identifier (PID) of the terminated controller application are packaged in the application exit message, and the application exit message is then sent to the state management component.Thus, other controller applications associated with this controller application are determined through the state management component according to the associations between controller applications, and then the process management component restarts this controller application and other controller applications associated with this controller application.

[0061] In this embodiment, the process control component further includes a tool package block. When starting the controller application, the tool package block reads the service-oriented architecture (SOA) tool package configuration to obtain startup logic information. The startup logic information is configured to determine the startup parameters, startup sequence, and so on of the controller application. The controller application is started according to the startup logic information, i.e., the process control component first starts the state management component SWC_SM and the health management component SWC_PHM.After the state management component and the health management component operate normally according to the dependency relationship configured in the SOA toolkit and the relationship between the functional groups to which the pre-start and post-start applications belong, etc., the process management component starts and monitors the controller applications: APP1, APP2, …, APPn.

[0062] When the controller application starts, it can also generate code to report its startup, exit, or other statuses in accordance with the SOA toolkit configuration. This allows the controller application to report its running state to the process control component after it has started. If the process control component does not accept the running state of the controller application within the time specified in the SOA toolkit configuration, the process control component will either restart the controller application (first exit it, then start it) or not restart the controller application in accordance with the rules in the SOA toolkit configuration.If the process control component still does not get the running state after restarting, it will continuously restart the controller application multiple times (the number of restarts can be configured) to complete the controller application startup as required by the logic.

[0063] When the controller application is running, it can also call the interface as needed to "inform" the process control component of its corresponding operating state, such as: starting, exiting, waiting state, updating, restarting, user state, etc.

[0064] The state management component is a functional component that performs logical management of the controller application state. After the state management component starts and receives an application exit message from the process management component, the state management component retrieves the controller application that terminated according to the application exit message. The state management component then searches for the application functional group to which the terminated controller application belongs or, according to preconfigured association rules between controller applications, other controller applications associated with the terminated controller application.The state management component then packages the terminated controller application and any other related controller applications into a start / stop message and sends this start / stop message to the process management component. Upon receiving the start / stop message, the process management component reads the controller applications that need to be restarted from the start / stop message and performs the restart operation.

[0065] In this embodiment, to ensure flexible configuration and management of controller applications, the SOA toolkit configuration specifies the operation logic of controller applications that encounter an abnormal situation, such as the number of restarts, restart parameters, etc. Accordingly, the state management component also includes a toolkit block. The toolkit block can read the information in the SOA toolkit configuration, obtain logic information, package the logic information and the controller application that has stopped running, and generate start-stop information so that the SWC_EM process control component executes operations in accordance with the logic configured in the SOA toolkit.

[0066] For example, the configuration of the SOA toolkit can also specify the operating logic of a controller application combination (related controller applications or functional groups to which the controller applications belong). The state management component also includes an application combination block. The application combination block can read the information in the SOA toolkit configuration and obtain the controller application combination corresponding to the controller application that has stopped running. The operating state of the controller applications in the application combination can also be determined. The configuration of the SOA toolkit determines whether logic operations need to be performed on these controller applications. If necessary, the logic information is obtained according to the configuration of the SOA toolkit.The controller applications that require operations, logic information, and the controller application that has terminated are packaged together as start-stop information and sent to the process control component. Thus, the SWC_SM state management component not only manages the operational logic of a single controller application but can also manage the operational logic of a combination of controller applications. Based on the operational state of each controller application in a given situation and the overall state of the application combination, the process control component can perform start-stop operations according to the logic configured in the SOA toolkit.

[0067] For example, when the process control component restarts the state control component, the state control component's abnormality-inducing parameter is re-added. When the state control component determines, according to the abnormality-inducing parameter, that it is a restart after an abnormal exit, the state control component records the number of restarts to prevent repeated restarts. For example, when the number of restarts exceeds a preset threshold, a signal is sent to the watchdog software to restart the controller system. Specifically, a "command" indicating a restart of the SOC system is sent to the MCU in combination with hardware communication methods such as SPI, GPIO, and UART. For example, the MCU can determine whether the SOC state is abnormal by checking whether the signal inversion range is normal. If the SOC state is determined to be abnormal, an interface is called to notify the MCU.In addition to detecting the SOC software guard on the domain controller, the domain controller's MCU also detects the software and hardware guards of its own MCU in order to restart the MCU itself and the entire domain controller.

[0068] For example, after detecting that a state management component has undergone an abnormal restart due to abnormal startup parameters, various controller applications monitored by the state management component are retrieved. The process association component synchronizes the states of these controller applications with the state management component during restart, so that the state management component resumes monitoring of these controller applications. This eliminates the need to first exit these monitored controller applications and then restart them due to the state management component restart.

[0069] The health management component is a functional component that collects and arbitrates the operational data of the controller application process and performs other monitoring and management tasks. Specifically, the various operating conditions during the lifecycle of the controller application of each embedded domain controller and embedded domain controller-level controller in a vehicle include not only normal exits and abnormal exits, but also abnormal situations such as "hangs" and "slowdowns" caused by abnormal operating logic of the controller application software itself or other reasons (during this period, the process task does not exit). Therefore, after the health management component starts, it receives the "heartbeat" and health information sent by each controller application. The "heartbeat" and health information are collectively referred to as process activity information.The above health information is used to represent information about the process's operational state, such as process runtime information, function execution logic information, and user information, and its specific content is not limited. When an abnormal state of the controller application is determined based on process activity information, the controller application that encountered the abnormal situation is packaged into a start / stop message and sent to the process management component. Upon receiving the start / stop message, the process management component restarts the controller application specified in the start / stop message.

[0070] In one example, after the operation logic for the controller application that encountered an abnormal situation is specified in the SOA toolkit configuration, the health management component also includes a toolkit block. The toolkit block can read the controller application operation logic in the SOA toolkit configuration, obtain logic information, and package the logic information and the controller application that encountered an abnormal situation to generate start-stop information so that the SWC_EM process management component can perform operations according to the logic configured in the SOA toolkit, such as restarting, shutting down, switching to background operation, and entering an update process.

[0071] For example, in the SOA toolkit configuration, controller application exception logic is defined, allowing for the configuration of the controller application's abnormal behavior determination and making it easier to manage these rules. After receiving process activity information, the controller application's abnormal behavior can be determined in accordance with the aforementioned exception logic. The logic information and controller applications identified as abnormal are packaged to form start / stop information. After the process management component receives the start / stop information, it restarts the controller applications specified in the start / stop message.

[0072] For example, after the operational logic is defined in the SOA toolkit configuration, the health management component also contains an application combination block. The application combination block can read this information in the SOA toolkit configuration, obtain the controller application combination corresponding to the abnormally running controller applications, and determine the operational states of these controller applications for the controller applications in the application combination. Whether logic operations need to be executed on these controller applications can also be determined according to the SOA toolkit configuration.If required, logic information is obtained in accordance with the configuration of the SOA toolkit, and the controller applications that require operations, logic information, and the controller applications that have stopped running are packaged together as start-stop information and sent to the process control component. Thus, like the state control component, the SWC_PHM health control component not only manages the operational logic of a single controller application but can also manage the operational logic of a combination of controller applications. The health control component can enable the process control component to perform start-stop operations in accordance with the logic configured in the SOA toolkit, based on the operational states of each controller application in a given situation and the overall state of the application combination.

[0073] In this embodiment, the storage component is a first-level functional component, and the process control component is a second-level functional component. The first-level functional component is configured to start and control the second-level functional component. The state management component and the health management component are third-level functional components, and their start and control are performed by the second-level functional component. The state management component is configured to control the operation logic upon completion of the controller application, and the health management component is configured to determine the operation logic in accordance with the process activity information of the controller application.By managing the controller application's startup and shutdown through functional grouping and hierarchical structuring, abnormal controller application states can be effectively managed in various situations. Furthermore, if the controller application exits abnormally, it can be promptly restarted, thereby implementing controller application redundancy and ensuring safe vehicle operation.

[0074] In this application, the SOA-based service of each controller application is implemented using distributed communication technologies such as SOME / IP and DDS. A unified interface is formed, allowing for the configuration of business logic to adapt to the secure, duplicated start and stop of each embedded controller in the entire vehicle. This includes the business logic for heartbeat, health information, evaluation, shutdown, and restart of the controlled controller application. The deployment and operation of each embedded controller can be quickly implemented and maintained using an iterative approach, and other vehicle models can be quickly adapted.

[0075] During operation, the process control component SWC_EM, the state control component SWC_SM, and the health control component SWC_PHM, which implement safe, duplicated start-stop, may also experience abnormal output or abnormal operation, such as "hanging" and "slowing down" (without exiting process tasks), caused by communication failures with the platform. Therefore, to improve the reliability of the system, this embodiment addresses problems associated with abnormal situations of functional components to enhance the safety of the controller.

[0076] Specifically, to ensure the safe operation of the SWC_EM process control component in the event of an abnormal termination of the process control component, the guardian component will restart the process control component within milliseconds to ensure its continued operation in real time. If the process control component restarts, the SWC_SM state management component, the SWC_PHM health management component, and other monitored controller applications will first be shut down and then restarted. When the process control component "hangs" or "slows down" due to the state of system resources, the health management component is used to monitor the process control component.When a process control component fails, and when the process control component fails to operate normally after repeated restarts within a short period of time, a signal will be sent to the software watchdog to restart the controller system.

[0077] The health management component is also used to monitor the watchdog component and obtain the resource status of the controller system in which the process management component operates. When the watchdog component fails and / or the controller system is determined to be in an abnormal state based on resource status (e.g., 100% CPU utilization for an extended period, and other indicators such as disk and I / O abnormalities), a signal is sent to the watchdog software to restart the controller system.

[0078] To ensure the safe operation of the SWC_SM state management component, as shown in Fig. 2, when an abnormal exit from the state management component is detected, the process management component saves the current state of each controller application monitored by the state management component. After the state management component starts, it sends the current state of each controller application to the state management component to resume monitoring of the controller applications by the state management component, eliminating the need to first exit the monitored controller applications and then restart them due to the restart of the state management component itself. In addition, the state management component notifies the health management component of its own state.In response to possible "hang" or "slow" situations of the state management component, the state management component periodically sends process activity messages (containing heartbeat and health information) of its own process to the health management component. If the health management component detects an abnormal heartbeat packet of the state management component and determines that the state management component is in a "hang" or "slow" state, based on the logic and health information configured in the SOA toolkit, the health management component generates a start-stop message and sends the start-stop message to the process management component so that the process management component restarts the state management component.

[0079] To ensure the safe operation of the health management component, as shown in Figure 3, upon detecting an abnormal exit from the health management component, the process management component immediately restarts the health management component and saves the current state of each controller application monitored by the health management component. After the health management component starts, the current state of each controller application is sent to the health management component to resume monitoring of the controller applications by the health management component, eliminating the need to first exit the monitored controller applications and then restart them due to the restart of the health management component itself.

[0080] For example, when the health management component and the process control component are in abnormal state, the controller system is restarted through the interaction of the hardware watchdog of the controller hardware and the software watchdog of the controller system.

[0081] Therefore, in this embodiment, there is no need to restart the controller system when the controller application encounters an abnormal situation or terminates. Instead, various operating conditions (normal shutdown, abnormal shutdown, hang, OTA update, etc.) are resolved one by one through functional grouping and hierarchical structuring. Combined with the SOA-based service, the deployment and operation of various embedded controllers in a vehicle can be quickly iterated and supported, for example, the deployment and operation of a domain controller with only one microcontroller unit (MCU) and one system-on-chip (SOC) and a domain controller with multiple MCUs and multiple SOCs.In the event of a vehicle-wide exception involving inter-chip or inter-domain controllers, the exception can also be resolved using a chip-by-chip or domain controller-by-domain approach.

[0082] Based on the safe dual start-stop system of the on-board controller, the present invention also provides a safe dual start-stop method and an on-board controller. First, a first-level functional component, a second-level functional component, and a third-level functional component are pre-created. Then, the first-level functional component is launched as a guardian process. After the first-level functional component is launched, the second-level functional component is launched and controlled. After the second-level functional component is launched, the third-level functional component and each controller application are launched and controlled. The third-level functional component is also used to receive process activity information or application exit messages from each controller application.

[0083] When a first-level functional component detects that a second-level functional component has terminated, the first-level functional component is used to restart the second-level functional component.

[0084] When the second-level functional component detects that the third-level functional component has stopped working, the second-level functional component is used to restart the third-level functional component; when the second-level component detects that the controller application has stopped working, the second-level functional component generates a controller application exit message according to the controller application that has stopped working, and sends the application exit message to the third-level functional component; and when the second-level functional component receives a start-stop message sent by the third-level functional component, the second-level functional component is used to restart the controller application specified in the start-stop message.

[0085] When determining that the controller application is running abnormally based on the process activity information, the third-level functional component generates a start-stop message according to the abnormal controller application or generates a start-stop message according to the application exit message, and sends the start-stop information to the second-level functional component.

[0086] In this embodiment, the first-level functional component is the SWC_RUN watchdog component, and the second-level functional component is the SWC_EM process control component. The third-level functional components are the SWC_SM state management component and the SWC_PHM health management component. Application components with redundancy mechanisms that satisfy the functional safety requirements are pre-developed, including SWC_watchdog, SWC_RUN, SWC_EM, SWC_SM, SWC_PHM, etc. SWC_watchdog is a functional service component for starting, stopping, and restarting the hardware platforms of various embedded control chips in the entire vehicle and platform system, also called a hardware watchdog or software watchdog.

[0087] The state management component is used to receive the application exit message sent by the second-level functional component, and the health management component is used to receive the process activity information of each controller application and the process activity information of the state management component.When determining, in accordance with the process activity information of the state management component, that the state management component has encountered an abnormal situation, the health management component generates a start-stop message and sends a start-stop message to the second-level functional component to restart the state management component; when determining, in accordance with the process activity information of the controller application, that the controller application has encountered an abnormal situation, the health management component generates a start-stop message and sends a start-stop message to the second-level functional element to restart the controller application.

[0088] In particular, the specific functions of the above-described method for safely dual start-stopping the on-board controller in this embodiment, refer to the corresponding descriptions of the above-described system for safely dual start-stopping the on-board controller, the details of which will not be repeated here.

[0089] Based on the above embodiments, the present invention provides an intelligent vehicle. As shown in Fig. 4, the above-mentioned intelligent vehicle includes a processor and a memory connected by system buses. The processor of the intelligent vehicle is configured to provide computing capabilities and control capabilities. The memory of the intelligent vehicle includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a safe dual start-stop program of the on-board controller. The internal memory provides an environment for the operation of the operating system and the safe dual start-stop program of the on-board controller, stored on the non-volatile storage medium.When executing the safe duplicated start-stop program, the processor implements the stages of any of the above methods of safe duplicated start-stop of the on-board controller.

[0090] Embodiments of the present invention also provide a microchip, such as a SOC microchip. A program for the safe dual start-stop of the on-board controller is stored in the above-mentioned microchip, and when executed by a processor, the program for the safe dual start-stop of the on-board controller implements the steps of any of the methods for the safe dual start-stop of the on-board controller provided by embodiments of the present invention.

[0091] In this specification, terms such as "in an embodiment," "in some embodiments," "in an example," "in a particular example," or "in some examples" mean that specific features, structures, materials, or characteristics described in connection with an embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the above terms used in the language do not necessarily refer to the same embodiment or example. Furthermore, the described specific features, structures, materials, or characteristics may be combined appropriately in any one or N embodiments or examples.Furthermore, those skilled in the art may combine and interoperate various embodiments or examples and features of various embodiments or examples set forth in this specification, as long as they do not conflict with each other.

[0092] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying the relative importance or indirectly indicating the number of the specified technical features. Therefore, features designated as "first" and "second" may explicitly or implicitly include at least one such feature. In the description of the present invention, "N" means at least two, for example, two, three, etc., unless specifically and clearly defined otherwise.

[0093] Any description of a process or method, represented in the form of a flow chart or otherwise described herein, may be understood as representing a module, segment, or portion of code that includes one or N executable instructions for implementing custom logical functions or processes. Furthermore, the scope of optional implementations of the present invention includes additional implementations, wherein the functions may be executed not in the order shown or discussed, including substantially simultaneously or in reverse order, depending on the functions involved. This should be understood by those skilled in the art to which the present invention pertains.

[0094] The logic and / or steps shown in the flow charts or otherwise described herein, for example, which can be viewed as a list of executable instructions specified in a certain sequence for implementing logical functions, may be embodied in any computer-readable medium for use by a system, apparatus or device for executing instructions (e.g., a computer-based system, a system containing a processor, or other systems that can call instructions from a storage medium and execute the instructions by a system, apparatus or device for executing instructions), or the logic and / or steps can be used in conjunction with such systems, apparatuses or devices for executing instructions.For the purposes of this specification, a "machine-readable storage medium" may be any device that can contain, store, transmit, distribute, or transport a program for use by or in conjunction with a system, apparatus, or device for executing instructions. More specific examples (non-exhaustive list) of machine-readable storage media include the following: an electrical connector (electronic device) with one or N wires, a portable floppy disk (magnetic device), random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), fiber optic device, and compact disc read-only memory (CDROM).In addition, the machine-readable medium may even be paper or other suitable medium on which the program can be printed, since the program can be obtained in electronic form by optically scanning the paper or other medium, followed by editing, interpretation or other suitable processing, if required, and then the program can be stored in the computer memory.

[0095] It is understood that various parts of the present invention can be implemented using hardware, software, firmware, or a combination of both. In the above embodiments, N steps can be implemented using software or firmware that is stored in a memory and can be executed by a suitable system for executing instructions. For example, if implemented using hardware, as in another embodiment, this can be implemented using any of the following technologies well known in the art, or a combination thereof: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, specialized integrated circuits having suitable combinational logic gate circuits, programmable gate arrays (PGA), field programmable gate arrays (FPGA), etc.d.

[0096] Those skilled in the art will appreciate that all or part of the steps performed in the methods of the above embodiments may be executed by appropriate hardware under the control of a program. The program may be stored on a machine-readable storage medium. When executed, the program includes one or a combination of the steps of the method embodiments.

[0097] Furthermore, the functional units in each embodiment of the present invention may be combined into a processing module, or each unit may physically exist independently, or two or more units may be combined into a single module. The aforementioned combined module may be implemented as hardware or as software functional modules. If the combined module is implemented as a software functional module and sold or used as a standalone product, it may also be stored on a machine-readable storage medium.

[0098] The above embodiments are provided only to fully illustrate the present invention, and the scope of protection of the present invention is not limited by them. Any equivalent substitutions or changes made by those skilled in the art based on the present invention fall within the scope of protection of the present invention.

Claims

1. A system for safe, duplicated start-stop of an on-board controller, comprising: a keeper component, a process control component, a state control component, and a health control component; wherein the storage component is configured to start and control the process control component and restart the process control component when the process control component stops working; the process control component is configured to: start and control the state management component, the health management component and each controller application; restart the component that has stopped working when any of the state management component and the health management component stops working; generate an application exit message for the controller application that has stopped working when the controller application stops working, and send the application exit message to the state control component; and restart the controller application and / or the state management component specified in the start-stop message in response to the received start-stop message; the health management component is configured to: receive information about the process activity of the state management component and each application of the controller; generate a start-stop message in accordance with the object that has encountered an abnormal situation, when, in accordance with the process activity information, it is determined that any object from the state management component and the applications of the controller has encountered an abnormal situation, and send a start-stop message to the process management component; and the state management component is configured to generate a start-stop message in accordance with an application exit message received from the process management component, send a start-stop message to the process management component, and periodically send process activity information about its own process to the health management component.

2. The system for safe, duplicated start-stop of the on-board controller according to claim 1, in which the operability management component is further configured to monitor the guardian component and receive the state of the resources of the controller system, as well as send a signal to the watchdog software to restart the controller system when the guardian component encounters an abnormal situation and / or, in accordance with the state of the resources, determines that the controller system has encountered an abnormal situation.

3. The system for safe, duplicated start-stop of the on-board controller according to claim 1, in which, upon receiving a start-stop message sent by the state management component, the process management component restarts the controller application specified in the start-stop message; and upon receiving a start-stop message sent by the health management component, the process management component restarts the controller application and / or the state management component specified in the start-stop message.

4. The system for safe duplicated start-stop of the on-board controller according to claim 1, in which the state control component includes a counting unit, and the counting unit is configured to accumulate the number of restarts when the state control component is restarted by the process control component, if, in accordance with the restart parameters of the state control component, it is determined that the state control component is restarted after an abnormal output, and to send a restart signal of the controller system to the watchdog software when the accumulated number of restarts exceeds a specified threshold value.

5. The system for safe, duplicated start-stop of an on-board controller according to claim 1, in which the process control component comprises a control and recovery unit, wherein the control and recovery unit is configured to send to the restartable component, upon restart of any of the health control component and the state control component, the current state of each controller application controlled by the restartable component, in order to restore control of the controller applications by the restartable component.

6. The system for safe duplicated start-stop of the on-board controller according to claim 1, in which the process control component comprises a tool package unit, and the tool package unit is configured to read configurations of the service-oriented architecture (SOA) tool package, obtain information about the startup logic when starting the controller application, and start the controller application according to the information about the startup logic.

7. The system for safe, duplicated start-stop of the on-board controller according to claim 1, in which both the state management component and the operability management component comprise a tool package unit, and the tool package unit is configured to read the configurations of the tool package, obtain information about the operating logic and generate a start-stop message in accordance with the information about the operating logic and the controller application that has stopped working or encountered an abnormal situation.

8. The system for safe duplicated start-stop of the on-board controller according to claim 7, in which both the state management component and the operability management component further comprise an application combination unit, wherein the application combination unit is configured to receive a combination of controller applications in accordance with information about the operating logic and the controller application that has stopped working or encountered an abnormal situation, and to generate a start-stop message in accordance with the combination.

9. A method for safe, duplicated start-stop of an on-board controller, comprising: pre-creation of a first-level functional component, a second-level functional component and a third-level functional component, wherein the first-level functional component is configured to start and control the second-level functional component, the second-level functional component is configured to start and control the third-level functional component, and the third-level functional component is configured to receive information about the activity of a process or an exit message from the application of each controller application; launching a first-level functional component in the keeper process mode; restarting the second-level functional component by the first-level functional component upon detection by the first-level functional component of the termination of the second-level functional component; restarting a third-level functional component by a second-level functional component upon detection by the second-level functional component of the termination of the third-level functional component; generating an application exit message in accordance with the controller application that is terminating upon detection by the second-level functional component of the controller application of terminating operation, and sending the application exit message to the third-level functional component; restarting the controller application specified in the start-stop message by the second-level functional component upon receipt by the second-level functional component of the start-stop message sent by the third-level functional component; and generating a start-stop message in accordance with the controller application that has encountered an abnormal situation, when the third-level functional component determines that the controller application has encountered an abnormal situation based on the process activity information; or generating a start-stop message in accordance with the application exit message and sending the start-stop message to the second-level functional element.

10. A method for safe, duplicated start-stop of an on-board controller according to claim 9, wherein the third-level functional component comprises a state management component and a performance management component, wherein the state management component is configured to receive a message about exiting the application sent by the second-level functional component, and the performance management component is configured to receive information about the process activity of each application of the controller.

11. The method for safe, duplicated start-stop of an on-board controller according to claim 10, wherein the health management component additionally receives information about the activity of the process of the state management component and, when it determines that the state management component has encountered an abnormal situation, based on the information about the activity of the process of the state management component, the health management component generates a start-stop message and sends the start-stop message to the second-level functional component.

12. A microcircuit in which the program for safe duplicated start-stop of the on-board controller is stored, and when executed by the processor, the program for safe duplicated start-stop of the on-board controller implements the steps of the method for safe duplicated start-stop of the on-board controller according to any of paragraphs 9-11.

13. An intelligent vehicle, wherein the intelligent vehicle comprises a memory, a processor and a safe duplicated start-stop program for an on-board controller, which is stored in the memory and is configured to be executed by the processor, and when executed by the processor, the safe duplicated start-stop program for the on-board controller implements the steps of the method for safe duplicated start-stop of the on-board controller according to any of paragraphs 9-11.