Computer-implemented method to execute a functional application in a vehicle

The method of migrating functional applications from a failing control unit to a secondary unit in vehicle systems addresses the challenge of maintaining uninterrupted vehicle functions by ensuring seamless continuity and resilience.

WO2025146352A1PCT designated stage expired Publication Date: 2025-07-10VALEO SCHALTER & SENSOREN GMBH
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/086985
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-04
Filing Date
2024-12-18
Publication Date
2025-07-10

AI Technical Summary

Technical Problem

Existing vehicle control systems face challenges in maintaining robust execution of functional applications when one or more control units fail, leading to potential disruptions in vehicle functions such as driver assistance systems.

Method used

A method and system for migrating functional applications from a failing control unit to a secondary control unit, utilizing a storage unit to temporarily store and transfer the application, along with state information or replicas, ensuring seamless continuity and resilience.

Benefits of technology

Ensures uninterrupted operation of vehicle functions by enabling fast recovery and continuation of functional applications on a secondary control unit, enhancing robustness and reducing downtime.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024086985_10072025_PF_FP_ABST
    Figure EP2024086985_10072025_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a computer-implemented method and a control system (2) to execute a functional application (10) in a vehicle (1). The vehicle (1) comprises a first control unit (3), a separate second control unit (4) and a storage unit (5), wherein the functional application (10) is stored in the storage unit (5). The method comprises the following steps in order: assigning the functional application (10) to the first control unit (3); by the first control unit (3) receiving the functional application (10) from the storage unit (5) and executing the received functional application (10); during the execution of the functional application (10), detecting a failure of the first control unit (3); reassigning the functional application (10) to the second control unit (4); by the second control unit (4) receiving the functional application (10) from the storage unit (5) and executing the received functional application (10).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Computer-implemented method to execute a functional application in a vehicle

[0002] The invention relates to a computer-implemented method to execute a functional application in a vehicle. Besides, the invention relates to a control system for a vehicle, a vehicle and a computer program product to perform such a computer-implemented method.

[0003] A vehicle may comprise several control units or control devices, each of which is configured to execute a functional application of the vehicle. A functional application is, for example, software for a function of the vehicle. The function may be a driver assistance system or driver assistance function.

[0004] DE 10 2017 100 116 A1 discloses a control system for a vehicle with a central control unit and at least two further control units. Each of the further control units is configured to execute a functional application, wherein the functional applications are only loaded to the further control units but are stored in the central control unit. During a starting process of the respective further control unit, it receives the functional application from the central control unit.

[0005] DE 10 2017 100 118 A1 discloses a scalable control system for a motor vehicle. A processing device of the vehicle is configured to carry out at least two functional applications. The processing device comprises a hypervisor and at least two separate processing units. Each processing unit comprises a hypervisor control component by which the respective processing unit is controllable by the hypervisor.

[0006] DE 10 2017 100 119 A1 discloses a control system for a motor vehicle with at least one first control unit and one second control unit. The first control unit operates a first function and the second control unit operates a different second function. The first control unit monitors a functionality of the second control unit. In case of failure of the second control device, the second function is executed by the first control unit.

[0007] It is the object of the invention to improve executing a functional application in a vehicle, in particular in case of a failure of at least one control unit of the vehicle.

[0008] The independent claims solve the object. A first aspect of the invention relates to a computer-implemented method to execute a functional application in a vehicle. The functional application comprises at least a part of a software, in particular the entire software, to provide a function of the vehicle. The function may be a driver assistance system or driver assistance function, such as, for example, a lane assist, a park assist and / or an adaptive cruise control. The functional application may, for example, comprise commands to analyze at least one sensor information captured and provided by at least one sensor of the vehicle. Preferably, the functional application comprises determining a control command for longitudinal and / or transversal guidance of the vehicle. This means that preferably the functional application determines a control command for a brake system, a drive system and / or a steering system of the vehicle.

[0009] The vehicle comprises a first control unit, a separate second control unit and a storage unit. The storage unit may alternatively be referred to as a network data center. The storage unit is accessible by the first control unit and the second control unit. This means that an information or data stored in the storage unit may be transmitted to the first control unit and / or the second control unit. Then, the first control unit and / or the second control unit may receive the transmitted information and / or data. The functional application is stored in the storage unit. Preferably, the functional application is only stored in the storage unit. The storage unit may alternatively be referred to as a memory unit, memory device, or random-access memory (RAM).

[0010] The first control unit and the second control unit are configured to receive the functional application from the storage unit and store it temporarily on a local storage unit, a local memory unit or a local RAM of the respective control unit. This means that they may load the functional application. At the beginning of performing the computer-implemented method, the functional application is not yet provided to the respective control unit, so that it is only available for the storage unit. Therefore, the respective control unit has no access to the functional application unless it has been transmitted to it.

[0011] The computer-implemented method comprises the following steps in the following order: It comprises assigning the functional application to the first control unit. This means that in a first step of the method, the first control unit is chosen as the control unit to execute the functional application. The method then comprises receiving the functional application from the storage unit by the first control unit and executing the received functional application by the first control unit. This means that, for example, all data stored in the storage unit that are necessary to execute the functional application, are transmitted or sent to the first control unit. Thus, the first control unit loads the functional application and then performs or runs it. If, for example, the functional application is a software to provide a park assist, the first control unit executes all software related to the park assist. Executing the received functional application may comprise multiple application steps which take place one after another in order to perform the function of the received functional application.

[0012] The vehicle may comprise a software and / or hardware module that controls the storage unit and determines when and to which control unit the functional application may be transmitted. The module may run as a software on the storage unit and / or may be a third control unit that is configured to control the storage unit. The module may be referred to as a storage unit control module.

[0013] As a next step, the method comprises detecting a failure of the first control unit during the execution of the functional application by the first control unit. The failure is thus detected while the first control unit is executing the functional application. The failure may be detected, for example, by a failure detection application that may provide a failure message to the storage unit and / or the storage unit control module. Detecting the failure may comprise analyzing at least one sensor information captured by a sensor device configured to monitor a functionality of the first control unit. The failure of the first control unit may comprise, for example, at least an error on a hardware level of the first control unit and / or an error on a software level.

[0014] After detecting the failure of the first control unit, the method comprises reassigning the functional application to the second control unit. It is hence decided that the second control unit should execute the functional application instead of the first control unit. Then, the method comprises receiving the functional application from the storage unit by the second control unit and executing the received functional application by the second control unit. In other words, the second control unit takes over the task, meaning executing the functional application, of the first control unit in case of the failure of the first control unit. This means that the functional application is migrated to another available control unit, if the control unit in charge experiences the failure.

[0015] By migrating the functional application from the first control unit to the second control unit, the robustness of the functional application and in particular of the vehicle is increased. This improves executing a functional application in a vehicle, in particular, in case of a failure of at least one control unit of the vehicle. Preferably, the vehicle comprises only the first control unit and the second control unit to execute all functional application of the vehicle. Therefore, each control unit may execute several functional applications simultaneously. It is assumed here that the second control unit has enough available computational power and / or available storage space capacities to additionally execute the functional application or the several functional applications which the first control unit had been executing until the failure of the first control unit was detected.

[0016] Preferably, a software or a part of a software performs the computer-implemented method. Alternatively, the computer-implemented method may be understood as a method to execute a functional application in a vehicle. The so far described computer- implemented method may alternatively be referred to as a cold migration of the functional application.

[0017] An embodiment comprises that the vehicle comprises another storage unit. The other storage unit may alternatively be referred to as a network memory module or as a network memory center. While executing the functional application, the executing control unit transmits a state information. Before the detection of the failure, the first control unit is the executing control unit. After the detection of the failure, the second control unit is the executing control unit. The executing control unit is hence a control unit that is executing the functional application and / or another functional application.

[0018] The state information describes a current state of the executed functional application. The state information is transmitted to the other storage unit. The other storage unit is preferably different from the storage unit. The state information describes, for example, at least a latest state of the executed functional application. Alternatively or additionally, it may describe several states that were reached while executing the functional application by the first control unit. In case of a park assist as functional application, the state information describes, for example, a last determined velocity, steering angle, acceleration and / or position of the vehicle. Besides, the state information may differentiate between multiple states of the functional application which, for example, differentiate between a starting state, an activated or running state, a waiting state and / or a deactivated state.

[0019] Other or additional states are possible. This means that the state information comprises at least one information on a current situation and / or condition of the functional application. The state information may at least contribute to predict and / or determine at least one further step and / or state of the functional application. The state information is hence some sort of report or message on the execution of the functional application so far wherein this report or message is provided to the other storage unit. This increases transparency of the method because details on the executed functional application are determined and provided.

[0020] Another embodiment comprises that after detecting the failure and reassigning the functional application to the second control unit, the second control unit receives the state information from the other storage unit. It is therefore possible to, for example, send the state information from the other storage unit to the second control unit which is now assigned to execute the functional application. In case of reassigning the functional application, the new control unit (here the second control unit) receives available details on the previous execution of the functional application by receiving the state information so that it may base its next steps on the received state information. Therefore, it is advantageous to provide the state information from the first control unit to the second control unit.

[0021] A further embodiment comprises that after receiving the state information the second control unit executes the functional application under consideration of the state information. This means that the second control unit adapts a way of executing the functional application to, for example, at least a latest state described by the state information. In other words, the second control unit may start executing the functional application from the beginning but is aware of the state until which the functional application has already been executed. For example, if the latest detected current speed of the vehicle is described by the state information, the second control unit may determine a control command for the drive system and / or the brake system of the vehicle dependent on the latest detested current speed. Therefore, it may start its first speed calculation based on the received state information. In case of a calculation of a driving trajectory for the vehicle, certain restrictions for this calculation may be taken from the state information. Although, the second control unit may restart the functional application from start, specific details on the current state of the vehicle are available so that, for example, the restart and re-execution of the functional application can be performed with an increased speed compared to executing the functional application without the state information. This allows a fast execution of the functional application by the second storage unit.

[0022] A preferred embodiment comprises that the respective control unit comprises a storage unit access library and accesses it to determine the state information. This library allows to determine and / or to analyze and / or to process the state information. It may also allow to synchronize the state information from the first control unit with the second control unit when the second control unit receives the state information. In other words, the storage unit access library may be necessary on a software level to handle the state information by the respective control unit and / or the other storage unit.

[0023] The embodiments with the state information may alternatively be referred to as an application aware hot migration.

[0024] Another embodiment comprises that the vehicle comprises another storage unit. During the execution of the functional application, the executing control unit transmits a replica of the executed functional application to the other storage unit. Here, at least the first control unit transmits the replica to the other storage unit. The replica is a copy of the executed functional application at its latest moment of execution or at the moment in which the replica was transmitted. Preferably, it describes the executed functional application at a last moment before the failure of the first control unit occurred. This means that full information on the execution of the functional application is available for the other storage unit.

[0025] According to a further embodiment, the method comprises that after detecting the failure and reassigning the functional application to the second control unit, the second control unit receives the replica from the other storage unit. There is hence no extraction of important features and / or information from the replica to, for example, reduce an amount of data that is transmitted between the other storage unit and the second control unit, but the entire replica of the functional application is provided to the second control unit. Therefore, the other storage unit, for example, transmits the replica to the second control unit as a whole, in particular in individual data packages. The replica, for example, may be stored in the local storage unit, the local memory unit or the local RAM of the second control unit. The replica is hence not kept in the other storage unit but may be provided to the second control unit, in particular analogously to the above-mentioned state information.

[0026] A preferred embodiment comprises that after receiving the replica, the second control unit executes the functional application under consideration of the replica so that the second control unit resumes the execution of the functional application. In this situation, the second control unit may start executing the functional application at exactly the moment the replica was generates, in particular at the last moment before the failure of the first control unit. This is possible because all information on the execution of the functional application so far are comprised by the replica so that the second control unit may take over directly from the first control unit and does not have to start executing the functional application from the beginning. This may be storage space and data transmission intensive but is time effective. For example, an already determined parking trajectory of the park assist can be taken right away without further determination or calculation steps because of the replica. This is thus a particularly fast way to continue executing the functional application.

[0027] According to a further embodiment, a storage space required for the replica on the other storage unit is equal to a storage space required for the replica on the respective control unit, in particular in the local storage unit, the local memory unit or the local RAM of the respective control unit. Here, the storage space is required in the local storage unit, the local memory unit or the local RAM of the second control device. This means that no data compressions or otherwise reduction of storage space is performed when generating, transmitting, receiving and / or storing the replica. The replica is therefore a one-to-one copy and an exact equivalent of the executed functional application. This clarifies the need for storage space both on the other storage unit as well as on the respective control unit that receives the replica.

[0028] The embodiments with the replica may alternatively be referred to as an application unaware hot migration.

[0029] According to a further embodiment, a monitoring module of the vehicle monitors the execution of the functional application. Alternatively or additionally, it monitors a data exchange between the respective control unit and the respective storage unit. It may, for example, monitor the transmission of the state information and / or the replica from, for example, the first control unit to the other storage unit and / or from the second control unit to the other storage unit. Alternatively or additionally, it monitors the transmission of the functional application from the storage unit to the first control unit and / or the second control unit. The monitoring module may alternatively be referred to as a system module. The monitoring module may be a software component that runs on or is executed by the first control unit and the second control unit. Another embodiment comprises that an assignment module of the vehicle assigns and reassigns the functional application to the respective control unit. Alternatively or additionally, it detects the failure of the respective control unit. The assignment module may alternatively be referred to as an orchestrator of the respective control unit. It may be a part of a software that runs on or is executed by the first control unit and the second control unit. The assignment module hence decides which control unit should execute the functional application. It may also be the module to realize or detect that the first control unit or alternatively the second control unit is affected by the failure. The assignment module may at least organize the functional application assignment to the respective control unit. It does that also after detecting the failure.

[0030] According to an embodiment, the computer-implemented method comprises assigning a further functional application to the second control unit. It also comprises receiving the further functional application from the storage unit by the second control unit and executing the received further functional application by the second control unit regardless of executing the functional application. This means, that there may be another functional application that is already executed by the second control unit or may be executed by the second control unit in the future or while the second control unit still executes the functional application. The two functional applications may be executed simultaneously by the second control unit after failure of the first control unit. Before the failure, it may only execute the further functional application. It is hence possible that from the start of the method not just the first control unit has a functional application assigned to it, but also the second control unit. The two functional applications may be referred to as a first functional application and a second functional application. The first functional application may be intended for executing the first functional application and second functional application may be intended for executing the second functional application and later also the first functional application. The two functional applications may be parts of a single vehicle function or individual functions for the vehicle, such as two different driver assistance systems or functions. However, the storage space on the second control unit is here always large enough to allow the execution of both functional applications at the same time if necessary.

[0031] In the sense of the invention, a module may be understood as a hardware module or as a software module. In particular, a module may comprise a hardware and a software portion implemented on the hardware. The monitoring module and the assignment module, however, may only be understood as a portion of software code functionally connected and combined to a unit. Such a software module may comprise or implement several processing steps and / or data structures.

[0032] Transfer of data, such as the functional applications, the state information, and / or the replica, may be performed by a bus, in particular by an enterprise service bus, in the vehicle. The bus may alternatively be referred to as a data bus. The bus may be understood as a communication system in the vehicle that may transfer data, such as the functional applications, the state information and / or the replica, between components inside the vehicle, in particular between computers, such as control units and / or storage units in the vehicle. The bus is hence a communication network within the vehicle.

[0033] The invention may be part of an operating system for the vehicle. The operating system may comprise a real-time core that, for example, is configured for booting and / or monitoring of individual software parts, software modules, software units and / or software applications that are part of the operating system. On the real-time core e.g. a classical AUTOSAR (Automotive System Architecture) software / platform, a MCAL software / firmware or the like can run. The operating system may further comprise or be based on a hypervisor and a BSP (Board Support Package). The hypervisor can be e.g. as described in DE 10 2017 100 118 A1 , which is incorporated by reference herewith. The BSP (Board Support Package) can be used (or can be software) to connect to the underlying hardware chip or board. The operating system may comprise a node foundation unit, an automotive foundation unit and / or a sensor service unit. The sensor service unit may be understood as a sensor service software unit. Moreover, the operating system may comprise or run applications (e.g. on Virtual Machines), e.g. a first application, a second application and / or a third application. More or less applications are possible. The application may be the functional application of the vehicle. The network that connects all these parts of the operating system, meaning the real-time core, the node foundation unit, the automotive foundation unit, the sensor service unit and the different applications may be an enterprise service bus. It may be the above-described bus.

[0034] The node foundation unit may comprise an orchestrator (assignment module), a system monitor (monitoring module), a software update module, a data flow monitor master (monitoring software module), and / or a debug agent. Other or more or less components may be possible. All the listed components may be software parts of the node foundation unit. The orchestrator may assign and / or reassign a functional application to the control unit in the vehicle. Alternatively or additionally, it may detect a failure of the control unit. The system monitor may monitor a data exchange between control units and / or other components in the vehicle, such as storage units. The data flow monitor master may monitor data transmission events of a function or a functional application of the vehicle. The automotive foundation unit may comprise means for vehicle communication, security, logging, error detection, and / or configurations. Other or more or less components are possible.

[0035] The sensor service unit may comprise a sensor server, an ultrasonic sensor provider, a camera provider, a radar provider, a lidar provider and / or a log and tracer. It is configured to provide an abstracted sensor information to the different applications. The sensor server may provide the general software for this whereas the individual providers comprise specific software parts to handle different kinds of sensor information, for example captured by an ultrasonic sensor, a camera, a radar device and / or a lidar device, respectively.

[0036] Another aspect of the invention relates to a control system for a vehicle to execute a functional application in the vehicle. The control system is configured to perform the computer-implemented method. It performs the computer-implemented method. The control system comprises a first control unit, a separate second control unit and a storage unit accessible by the first control unit and the second control unit. The functional application is stored in the storage unit. The control system is configured to assign the functional application to the first control unit; by the first control unit to receive the functional application from the storage unit and to execute the received functional application; during the execution of the functional application, to detect a failure of the first control unit; to reassign the functional application to the second control unit; and by the second control unit to receive the functional application from the storage unit and to execute the received functional application.

[0037] The control system may be understood as a computing device or as a data processing device with processing circuitry. The control system may therefore perform computing operations in order to process data and hence the computer-implemented method. The computing operations may also include indexed accesses to a data structure, for example a look-up table (LUT).

[0038] In particular, the control system may comprise at least one computer, at least one microcontroller, and / or at least one integrated circuit, for example, at least one application- specific integrated circuit (ASIC), at least one field-programmable gate array (FPGA), and / or at least one system on a chip (SoC). The control system may comprise at least one processor, for example, at least one microprocessor, at least one central processing unit (CPU), at least one graphics processing unit (GPU), and / or at least one signal processor, in particular at least one digital signal processor (DSP). The control system may comprise a physical or a virtual cluster of computers or other of said units.

[0039] The control system may comprise at least one hardware and / or software interface and / or at least one storage unit or memory unit. The storage or memory unit may be implemented as a volatile data memory, for example a dynamic random access memory (DRAM), or a static random access memory (SRAM), or as a non-volatile data memory, for example a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a flash memory or flash EEPROM, a ferroelectric random access memory (FRAM), a magnetoresistive random access memory (MRAM), or a phase-change random access memory (PCRAM).

[0040] A further aspect of the invention relates to a vehicle with the control system. The vehicle may perform the computer-implemented method. The vehicle is preferably a motor vehicle, for example, a passenger car, a truck, a bus, a motorcycle and / or a moped.

[0041] An aspect of the invention relates to a computer program product. The computer program product is a computer program. The computer program product comprises instructions which, when the program is executed by a computer, such as the control system, cause the computer to perform the computer-implemented method.

[0042] The embodiments described in connection with the computer-implemented method, both individually and in combination with each other, apply accordingly, when applicable, to the inventive control system, vehicle, and computer program product. The invention comprises combinations of the described embodiments.

[0043] The figures show in:

[0044] Fig. 1 a schematic representation of a vehicle with a control system;

[0045] Fig. 2 a schematic representation of a first embodiment of a computer- implemented method; Fig. 3 a schematic representation of a second embodiment of a computer- implemented method;

[0046] Fig. 4 a schematic representation of a third embodiment of a computer- implemented method; and

[0047] Fig. 5 a schematic representation of an operating system in a vehicle.

[0048] In the figures, same components are labeled with the same reference signs.

[0049] Fig. 1 shows a vehicle 1 that comprises a control system 2. The control system 2 comprises a first control unit 3, a separate second control unit 4 and a storage unit 5. The storage unit 5 is accessible by the first control unit 3 and the second control unit 4.

[0050] Besides, the control system 2 may comprise another storage unit 6 which is as well accessible by the first control unit 3 and the second control unit 4.

[0051] Fig. 2 shows a first embodiment of a computer-implemented method. The method aims at executing a functional application 10 in the vehicle 1 . The functional application 10 may be a software part of a function of the vehicle 1 , such as a driver assistance system or driver assistance function. For example, the functional application 10 is configured to at least partially control a longitudinal and / or transversal guidance of the vehicle 1 , for example, by operating a brake system, a steering system and / or a drive system of the vehicle 1 .

[0052] The functional application 10 is stored in the storage unit 5. The functional application 10 is at first not stored in the first control unit 3 and / or in the second control unit 4. This means that the respective control unit 3, 4 may receive and hence load the functional application 10 and store it temporarily when the computer-implemented method is performed. This means that, for example, before assigning the functional application 10 the respective control unit 3, 4, the functional application 10 is not available in the respective control unit 3, 4.

[0053] The method comprises assigning the functional application 10 to the first control unit 3 in a step S1 . Then in a step S2, the first control unit 3 receives the functional application 10 from the storage unit 5 and executes the received functional application 10. Therefore, the control unit 3, 4 may comprise a monitoring module 12 and an assignment module 13. The monitoring module 12 may monitor the execution of the functional application 10 and / or monitor a data exchange between the respective control unit 3, 4 and the respective storage unit 5, 6. The assignment module 13 may assign and reassign the functional application 10 to the respective control unit 3, 4. Alternatively or additionally, it may detect a failure of at least one of the controls unit 3, 4.

[0054] A step S3 may happen during the execution of the functional application 10. In step S3 the first control unit 3 detects a failure of the first control unit 3. Afterwards in a step S4, the method comprises reassigning the functional application 10 to the second control unit 4. In a step S5, the second control unit 4 receives the functional application 10 from the storage unit 5 and executes the received functional application 10.

[0055] In this example, reassigning the functional application 10 to the second control unit 4 may be performed by the assignment module. Receiving the functional application 10 may be organized by the monitoring module 12.

[0056] Fig. 2 also shows an application memory 14 provided by the respective control unit 3, 4. The application memory may store temporarily the functional application 10. The application memory 14 may alternatively be referred to as a memory unit, memory device, random-access memory (RAM) of the respective control unit 3, 4.

[0057] Here, a further functional application 11 is assigned the second control unit 4, for example, at the same time when the functional application 10 is assigned to the first control unit 3. The second control unit 4 receives the further functional application 11 from the storage unit 5 and executes it. Therefore after the failure, the second control unit 4 may execute both the further functional application 11 and the functional application 10 simultaneously. The so far described computer-implemented method may alternatively be referred to as cold migration.

[0058] Fig. 3 shows a second embodiment of the computer-implemented method. The second embodiment may be referred to as an application aware hot migration. Here, the storage unit 5 also provides the functional application 10 and, in particular, the further functional application 11 to the respective control unit 3, 4. However, the other storage unit 6 is involved, too. During the execution of the functional application 10 by the first control unit 3, the executing control unit 3, 4, which is here the first control unit 3 and the second control unit 4, transmits a state information 16 to the other storage unit 6. The state information 16 describes a current state of the executed functional application 10, 11. It, for example, comprises at least a latest state of the vehicle 1 , such as the last determined or captured speed, acceleration, steering angle and / or position of the vehicle 1 during the execution of the functional application 10 by the first control unit 3. Analogously, the state information 16 may be determined and transmitted for the further functional application 11 by the second control unit 4.

[0059] Once the failure of the first control unit 3 is detected, the method comprises that the functional application 10 is reassigned to the second control unit 4 so that the storage unit

[0060] 5 may provide the functional application 10 to the second control unit 4. Moreover, the second control unit 4 receives the state information 16 from the other storage unit 6. This is here the state information 16 from the first control unit 3 about the functional application 10. After receiving the state information 16, the second control unit 4 may execute the functional application 10 under consideration of the state information 16, so that the second control unit 4 adapts a way of executing the functional application 10 to at least the latest state described by the state information 16. Although the functional application 10 has to start from the beginning when being executed by the second control unit 4, this new execution may at least consider the information provided by the state information 16, such as the latest detected speed, acceleration, steering angle and / or position of the vehicle 1 .

[0061] The control units 3, 4 may comprise a storage unit access library 15 and access it to determine the state information 16. The storage unit access library 15 may allow the respective control unit 3, 4 to receive, store, open, read and / or process the received state information 16.

[0062] Fig. 4 shows a third embodiment of the computer-implemented method. The third embodiment may be referred to as an application unaware hot migration. The third embodiment requires the other storage unit 6. Here, during the execution of the functional application 10, the executing control unit 3, 4 transmits a replica 17 of the executed functional application 10 to the other storage unit 6. Here, the first control unit 3 may generate and transmit a replica 17 of the functional application 10 to the other storage unit

[0063] 6 and the second control unit 4 may generate and transmit a replica 17 of the further functional application 11 to the other storage unit 6. A storage space 18 required for the replica 17 on the other storage unit 6 may be equal to a storage space 18 required for the replica 17 on the respective control unit 3, 4, and hence on the application memory 14. When the failure has been detected, the functional application 10 is reassigned to the second control unit 4. Then, the second control unit 4 may receive the replica 17 from the other storage unit 6. The received replica 17 is the transmitted replica 17 of the functional application 10. After receiving the replica 17, the second control unit 4 executes the functional application 10 under consideration of the replica 17, so that the second control unit 4 resumes the execution of the functional application 10. Here, the execution of the functional application 10 may continue at the moment or state at or in which the first control unit 3 had to stop due to the failure and / or at or in which the replica was generated and transmitted.

[0064] Fig. 5 gives an overview of an operating system 40 for the vehicle 1 . The operating system 40 may be based on a SoC (system on a chip) as a node or board. The operating system 40 may comprise a real-time core (or real-time processing unit, i.e. RPU) 41 that, for example, is configured for booting and / or monitoring of individual software parts, software modules, software units and / or software applications that are part of the operating system 40. On the real-time core 41 e.g. a classical AUTOSAR (Automotive System Architecture) software / platform, a MCAL software / firmware or the like can run. The operating system 40 may further comprise or be based on a hypervisor (e.g. QNX Mikrokernel Hypervisor (PO SIX)) and a BSP (Board Support Package), both not shown in Fig. 5. The hypervisor can be e.g. as described in DE 10 2017 100 118 A1 .The BSP (Board Support Package) can be used (or can be software) to connect to the underlying hardware chip or board, e.g. the SoC (system on a chip) as a node or board.

[0065] The operating system 40 may comprise a node foundation unit 42, an automotive foundation unit 43 and / or a sensor service unit 44. The sensor service unit 44 may be understood as a sensor service software unit 24. Moreover, the operating system 40 may comprise or run applications (e.g. on Virtual Machines), e.g. a first application 45, a second application 46 and / or a third application 47, as shown in Fig. 5. More or less applications 45, 46, 47 are possible. The application 45, 46, 47 may be the functional application 10 in the vehicle 1 . The network 48 that connects all these parts of the operating system 40, meaning the real-time core 41 , the node foundation unit 42, the automotive foundation unit 43, the sensor service unit 44 and the different applications 45, 46, 47 may be an enterprise service bus. It may be a bus.

[0066] The node foundation unit 42 may comprise an orchestrator 49 (e.g. assignment module 13), a system monitor 50 (e.g. monitoring module 12), a software update module 51 , a monitoring software module 52 (that may alternatively be referred to as a data flow monitor master), and / or a debug agent 53. Other or more or less components may be possible. All the listed components may be software parts of the node foundation unit 42.

[0067] The automotive foundation unit 43 may comprise means for vehicle communication 54, security 55, logging 56, error detection 57 and / or configurations 58. Other or more or less components are possible.

[0068] The sensor service unit 44 may comprise a sensor server 26, an ultrasonic sensor provider 27, a camera provider 28, a radar provider 29, a lidar provider 30 and / or a log and tracer 31 . The sensor service unit 44 is configured to provide sensor data (in particular an abstracted sensor information) to the different applications 45, 46, 47.

[0069] In summary, the invention shows a seamless automotive application migration. When a computer node (e.g. first control unit 3) undergoes a certain failure the control system 2 may take care of migrating the functional application 10 to another free node (e.g. second control unit 4) and the control system 2 takes care of the required resources associated with this functional application 10. Also the activation conditions of this migration is subject to the scheduling policy and safety priorities defined in the control system 2 to ensure robustness of the control system 2.

[0070] In the first embodiment, the functional application 10 is migrated providing a continuity of its operation but with a new life cycle. In the second and third embodiments, the method ensures a seamless user experience where feature resumption is needed adding more robustness to the cold migration approach where the user experience is interrupted by the new app life cycle with two techniques either app aware or unaware.

[0071] In the second embodiment, the functional application 10 is implemented with awareness of resumption requirements where states and resumption insights (e.g. state information 16) are logged from the functional application 10. In this case the control system 2 provides the storage unit access library 15 to store these insights on the network memory (e.g. other storage unit 6) to be synced in case of recovery. In this embodiment, the data stored on the network RAM (e.g. other storage unit 6) is less but increases the effort in application deployment.

[0072] In the third embodiment, the functional application 10 is implemented normally without any awareness for resumption but is marked in the control system 2 as a resumable application. In this case the control system 2 allocates the replica 17 of the RAM on the network memory module (e.g. other storage unit 6) to be retrieved by the control system 2 on another node (e.g. second control unit 4) in case of application rescheduling due to control unit failure. In this embodiment, the development of the functional application 10 is not impacted. However, the amount of allocated network memory is exactly equal to the allocated memory on the control unit 3, 4.

Claims

Claims1 . Computer-implemented method to execute a functional application (10) in a vehicle (1), wherein the vehicle (1 ) comprises a first control unit (3), a separate second control unit (4) and a storage unit (5) accessible by the first control unit (3) and the second control unit (4), wherein the functional application (10) is stored in the storage unit (5), comprising the following steps in order:- assigning the functional application (10) to the first control unit (3);- by the first control unit (3) receiving the functional application (10) from the storage unit (5) and executing the received functional application (10);- during the execution of the functional application (10), detecting a failure of the first control unit (3);- reassigning the functional application (10) to the second control unit (4);- by the second control unit (4) receiving the functional application (10) from the storage unit (5) and executing the received functional application (10).

2. Computer-implemented method according to claim 1 , wherein the vehicle comprises another storage unit (6) and during the execution of the functional application (10) the executing control unit (3, 4) transmits a state information (16) that describes a current state of the executed functional application (10) to the other storage unit (6).

3. Computer-implemented method according to claim 2, wherein after detecting the failure and reassigning the functional application (10) to the second control unit (4), the second control unit (4) receives the state information (16) from the other storage unit (6).

4. Computer-implemented method according to claim 3, wherein after receiving the state information (16) the second control unit (4) executes the functional application (10) under consideration of the state information (16) so that the second control unit (4) adapts a way of executing the functional application (10) to at least a latest state described by the state information (16).

5. Computer-implemented method according to any one of claims 2 to 4, wherein the respective control unit (3, 4) comprises a storage unit access library (15) and accesses it to determine the state information (16).

6. Computer-implemented method according to claim 1 , wherein the vehicle comprises another storage unit (6) and during the execution of the functional application (10) the executing control unit (3, 4) transmits a replica (17) of the executed functional application (10) to the other storage unit (6).

7. Computer-implemented method according to claim 6, wherein after detecting the failure and reassigning the functional application (10) to the second control unit (4), the second control unit (4) receives the replica (17) from the other storage unit (6).

8. Computer-implemented method according to claim 7, wherein after receiving the replica (17) the second control unit (4) executes the functional application (10) under consideration of the replica (17) so that the second control unit (4) resumes the execution of the functional application (10).

9. Computer-implemented method according to any one of the claims 6 to 8, wherein a storage space (18) required for the replica (17) on the other storage unit (6) is equal to a storage space (18) required for the replica (17) on the respective control unit (3, 4).

10. Computer-implemented method according to any one of the preceding claims, wherein a monitoring module (12) monitors the execution of the functional application (10) and / or a data exchange between the respective control unit (3, 4) and the respective storage unit (5, 6).11 . Computer-implemented method according to any one of the preceding claims, wherein an assignment module (13) assigns and reassigns the functional application (10) to the respective control unit (3, 4) and / or detects the failure of the respective control unit (3, 4).

12. Computer-implemented method according to any one of the preceding claims, comprising assigning a further functional application (11) to the second control unit(4), by the second control unit (4) receiving the further functional application (11 ) from the storage unit (5) and executing the received further functional application (11 ) regardless of executing the functional application (10), in particular simultaneously.

13. Control system (2) for a vehicle (1 ) to execute a functional application (10) in the vehicle (1), wherein the control system (2) comprises a first control unit (3), a separate second control unit (4) and a storage unit (5) accessible by the first control unit (3) and the second control unit (4), wherein the functional application (10) is stored in the storage unit (5), the control system (2) is configured to:- assign the functional application (10) to the first control unit (3);- by the first control unit (3) receive the functional application (10) from the storage unit (5) and execute the received functional application (10);- during the execution of the functional application (10), detect a failure of the first control unit (3);- reassign the functional application (10) to the second control unit (4); and- by the second control unit (4) receive the functional application (10) from the storage unit (5) and execute the received functional application (10).

14. Vehicle (1) configured to perform a method according to any one of claims 1 to 12.

15. Computer program product comprising instructions which, when the program is executed by a computer, cause the computer to perform a method according to any one of claims 1 to 12.

Citation Information

Patent Citations

  • Control system for a motor vehicle with a central control unit and several other control units

    DE102017100116A1

  • scalable control system for a motor vehicle

    DE102017100118A1

  • Motor vehicle control system with hardware failover

    DE102017100119A1

  • controller

    EP3614216A1

  • Fail-operational system design pattern based on software code migration

    US20180059963A1