Computer-implemented method to monitor a function of a vehicle

A centralized monitoring module in vehicle systems verifies data transmission events and activates corrective actions to ensure reliable function monitoring and compliance with safety integrity levels, addressing the challenge of monitoring heterogeneous vehicle systems.

WO2025146353A1PCT designated stage expired Publication Date: 2025-07-10VALEO SCHALTER & SENSOREN GMBH
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/087014
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-04
Filing Date
2024-12-18
Publication Date
2025-07-10

AI Technical Summary

Technical Problem

Existing vehicle systems lack a reliable and efficient method to monitor the data flow of vehicle functions, particularly in heterogeneous systems with mixed criticality components, to detect malfunctions and react to violations in a decoupled and distributed manner, which is crucial for ensuring safety and compliance with automotive safety integrity levels.

Method used

A computer-implemented method utilizing a centralized monitoring module that verifies data transmission events against predefined constraints, activating reaction mechanisms to correct deviations, and a scalable architecture that allows integration with various vehicle functions without requiring specific libraries or code, enabling real-time monitoring and adaptive responses.

Benefits of technology

The method provides reliable and efficient monitoring of vehicle functions, ensuring compliance with automotive safety integrity levels, allowing seamless recovery from violations and adapting to dynamic behavior, while being adaptable to new functions and reducing platform integration constraints.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024087014_10072025_PF_FP_ABST
    Figure EP2024087014_10072025_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a computer-implemented method to monitor a function (2) of a vehicle (1), comprising: providing (S1) a function information (11) describing a data flow generated when executing the function (2) in the vehicle (1), wherein the data flow comprises at least one scheduled and / or preconfigured data transmission event; receiving (S2) at least one message (13) describing an occurred data transmission event that occurred during executing the function (2); verifying (S3) if the occurred data transmission event matches the scheduled and / or preconfigured data transmission event by analyzing the provided function information (11) and the at least one received message (13); if this is the case, continuing (S4) to operate the function (2); and / or if this is not the case, activating (S5) at least one predetermined reaction mechanism to at least reduce a deviation between the occurred data transmission event and the scheduled and / or preconfigured data transmission event.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Computer-implemented method to monitor a function of a vehicle

[0002] The invention relates to a computer-implemented method to monitor a function of a vehicle. Besides, the invention relates to a control device for a vehicle, a vehicle and a computer program product to perform such a computer-implemented method.

[0003] A vehicle may provide at least one function. The function may be a driver assistance system or driver assistance function. In order to ensure that the function has been operating correctly up to now and is operating correctly at a current point in time, it should be monitored as closely as possible.

[0004] DE 10 2017 100 119 A1 discloses a control system for a motor vehicle with at least one first control unit and one second control unit. The first control unit operates a first function and the second control unit operates a different second function. The first control unit monitors a functionality of the second control unit. In case of failure of the second control device, the second function is executed by the first control unit.

[0005] DE 10 2017 100 118 A1 discloses a scalable control system for a motor vehicle. A processing device of the vehicle is configured to carry out at least two functional applications. The processing device comprises a hypervisor and at least two separate processing units. Each processing unit comprises a hypervisor control component by which the respective processing unit is controllable by the hypervisor.

[0006] It is the object of the invention to monitor a function of the vehicle during operation of the function.

[0007] The independent claims solve the object.

[0008] A first aspect of the invention relates to a computer-implemented method to monitor a function of a vehicle. The function may be a driver assistance system or driver assistance function. Alternatively, it may be any other function of the vehicle that causes at least one data transmission event during its operation. In one example, the function of the vehicle may be an adaptive cruise control. The function may alternatively be understood as an application or as a functional application of the vehicle or it may comprise at least one application and / or functional application.

[0009] The invention is at least partially based on the following observations: When the function is active in the vehicle, several data transmission events are executed according to a precisely defined schedule and / or at least one precisely defined constraint. There is thus a predefined data flow for the function. For example, a camera of the vehicle may capture a camera image and transmit it to an object detection module. The object detection module may receive the camera image and analyze it to determine, for example, an object information that describes at least one object in the camera image. Afterwards, the object detection module may transmit the object information to another module for further steps of the function. In this example, transmitting the camera image and transmitting the object information are data transmission events that are essential parts of the function. If at least one of the data transmission events does not occur or occurs at the wrong time, meaning that it, for example, violates the at least one precisely defined constraint, this indicates a malfunction of the function. Monitoring the data flow of the function may therefore enable a fast and reliable detection of the malfunction.

[0010] Preferably, a software or a part of a software performs the computer-implemented method. A control device, in particular a control device of the vehicle, may execute the software or the part of the software. Alternatively, the computer-implemented method may be understood as a method to monitor a function of a vehicle.

[0011] The computer-implemented method comprises providing a function information. A monitoring module provides the function information. Alternatively, the monitoring module may be referred to as data flow monitor master. The monitoring module may be a part of the control device or may be comprised by the control device. The monitoring module may be understood as a software or a part of a software that the control device may execute. The function information describes a data flow generated when executing the function in the vehicle. The data flow comprises at least one scheduled and / or preconfigured data transmission event. Alternatively, the function information may be referred to as data flow information or data flow graph. The function information preferably provides details on all exchanges of data that are part of the function or that are necessary to execute the function. The data transmission events are thus steps of the executed function that involve transmitting and / or receiving data. Transmitting data in the sense of the invention comprises sending data. However, the function information may not only describe a timeline of all data transmission events but may in general describe at least one execution constraint. The at least one execution constraint may be defined during designing the function and should be monitored during the runtime of the function. Therefore, the function information may comprise other data transmission related properties to be checked that were preconfigured and go further than just timing and / or periodicities. Therefore, the at least one execution constraint may be a value range for at least one data element involved in the data transmission event. For example, if the data element describes a command for a drive system of the vehicle, the value range may depend on a predetermined maximum and / or minimum velocity of the vehicle. In other words, the function information may comprise a value range checker to validate that the data element does not overshoot and / or undershoot an expected value range for the data element. If the data element is, for example, a camera image and / or other sensor data, the expected value range may define a size range for the camera image or the other sensor data, respectively. In case of the adaptive cruise control as function, the data flow may comprise transmitting a camera image or a camera information from the camera to the object detection module and transmitting the object information from the object detection module to another module such as a control command determination module configured to determine a control command for the vehicle based on the object information. The function information for the adaptive cruise control hence describes a data flow that comprises at least two different data transmission events. Moreover, receiving the camera information and receiving the object information may also be understood as data transmission events. Preferably, at least one of the data transmission events of the function involves transmitting a control command information describing a control command for longitudinal and / or transversal guidance of the vehicle, meaning for a brake system, a drive system and / or a steering system of the vehicle.

[0012] The respective data transmission event may involve modules, sensor devices and / or other components of the vehicle. Alternatively or additionally, it may involve at least one module, sensor device and / or other device that is located outside the vehicle, such as another vehicle, an external control device and / or an external sensor device. In this case, for example, receiving data by a communication device of the vehicle may be one of the data transmission events of the data flow. The method comprises receiving at least one message by the monitoring module from a bus. The message describes an occurred data transmission event that occurred during executing the function. The module, sensor device or other component may generate the message when or after it performs or at least participates in the data transmission event. In case of the transmitted camera information, the camera may create the message and provide it. The message may describe at least that the camera information was transmitted. The control device that performs the method may receive the at least one message. The message is in other words a confirmation that a specific data transmission event occurred and was hence performed.

[0013] The bus may alternatively be referred to as a databus. The bus transfers the message to the monitoring module, in particular to the control device that comprises the monitoring module. The bus may be understood as a communication system in the vehicle that may transfers data, such as the at least one message, between components inside the vehicle, in particular between computers in the vehicle.

[0014] The monitoring module and hence the control device that performs the computer- implemented method has so far access to the function information and the at least one received message. The function information may be stored in a storage unit in the vehicle, which is preferably part of the control device that performs the computer-implemented method. The function information may be stored at least temporarily in the storage unit of the control device and / or the vehicle. In an example, the at least one received message may be stored in the storage unit as well. The function information may be determined by an application or a module that may be executed by, for example, the control device or a control unit in the vehicle or by an external computing unit that is configured to determine the function information. Preferably, the function information is provided when the function is implemented in the vehicle.

[0015] The function information may comprise the at least one message that is expected for the data transmission event. For example, it may describe a message description for the expected message. The message description may describe the at least one execution constraint of the data transmission event. Therefore, the message description and hence the expected received message may be stored in the storage unit as a part of the function information or alternatively as additional information available when performing the method. The method comprises verifying if the occurred data transmission event matches the scheduled and / or preconfigured data transmission event by analyzing the provided function information and the at least one received message. The monitoring modules performs this verification. The scheduled and / or preconfigured data transmission event may alternatively be referred to as a scheduled and / or contained data transmission event or as a scheduled and / or preconfigured contained data transmission event. “Scheduled” in the sense of the invention may be understood as expected. The control device hence checks if for every data transmission event that is described by the function information, the respective message was received that describes that this data transmission event was actually conducted. Only if this is the case, the scheduled and hence planned data transmission event matches the occurred and hence performed data transmission element.

[0016] If, for example, the function information describes that the camera information should be transmitted every 30 seconds, but the received message describes that the camera information was transmitted 50 seconds after a latest transmission, a deviation between the occurred data transmission event and the scheduled and / or preconfigured data transmission event is detected. In this example, the occurred data transmission event does not match the scheduled and / or preconfigured data transmission event. However, if the message describes that the camera information was transmitted 30 seconds after the latest transmission, the occurred data transmission event matches the scheduled and / or preconfigured data transmission event.

[0017] In summary, the monitoring module provides the function information and receives the at least one message from the bus. This means that the monitoring module may be understood as the component of the vehicle, that verifies if the occurred data transmission event matches the scheduled and / or preconfigured data transmission event by analyzing the provided function information and the received at least one message.

[0018] If the occurred data transmission event matches the scheduled and / or preconfigured data transmission event, the method comprises continuing to execute the function. This means that if it is verified that the function is carried out as planned because the data transmission events follow the data flow, no influence or change of the function is necessary. Therefore, the function may continue as before. For example, the module, sensor device or other component that performed or at least participated in the data transmission event continues to execute the function, in particular a part or sub-function of the function that involves the data transmission event without any interference from the monitoring module. Thus, the monitoring module on one hand and the module, sensor device and / or other component that executes the function on the other hand are executed independently and the monitoring module only acts if the occurred data transmission event does not match the scheduled and / or preconfigured data transmission event.

[0019] If the occurred data transmission event does not match the scheduled and / or preconfigured data transmission event, the method comprises activating at least one predetermined reaction mechanism to at least reduce the deviation between the occurred data transmission event and the scheduled and / or preconfigured data transmission event by a reaction module. Preferably, the deviation is not just reduced but is prevented. Then, activating the predetermined reaction mechanism may correlate the occurred data transmission event with the scheduled transmission event. Activating the at least one predetermined reaction mechanism may comprise taking measures to increase a frequency of the data transmission event. For example, it may result in increasing the frequency of camera information transmission to one camera information per 30 seconds. Then in the above-described example, the occurred data transmission event will match the scheduled data transmission element. To increase the frequency of the data transmission event, the reaction mechanism may change a configuration of the involved module, sensor device or other component and / or increase the bandwidth available for the data transmission event. Other or additional reaction mechanisms are possible.

[0020] In other words, the at least one reaction module activates the at least one predetermined reaction mechanism if the occurred data transmission event does not match the scheduled and / or preconfigured data transmission event. Alternatively, the reaction module may be referred to as data flow monitor reactor. The reaction module is a different module than the monitoring module. The reaction module and the monitoring module may be two individual software programs or parts of software. They may run independently from one another but may exchange information. The reaction module may comprise means to, for example, determine what kind of reaction mechanism should be activated. It also comprises means to execute the activated reaction mechanism. However, the reaction module is, for example, not activated and may remain deactivated in case the occurred data transmission event matches the scheduled and / or preconfigured data transmission event. The tasks of detecting the deviation (monitoring module) and reducing it by activating the reaction mechanism (reaction module) are therefore distributed among two modules, which facilitates, for example, real-time monitoring of the function.

[0021] If there are multiple deviations and / or if multiple reaction mechanism are activated, there may be multiple reaction modules, for example, one to activate exactly one reaction mechanism. The multiple reaction modules may be comprised by one control device or by different control devices.

[0022] By comparing the occurred data transmission event with the scheduled and / or preconfigured data transmission event, the computer-implemented method monitors the function of the vehicle. This is possible due to the provided function information and the received message that are, for example, both gathered by the control device that performs the computer-implemented method. The described computer-implemented method is therefore a reasonable and straightforward solution to monitor the function of the vehicle. Moreover, it provides a high-level abstract way to monitor a function that may be executed by multiple modules, sensor devices and / or other components of the vehicle. The computer-implemented method is adaptable to any function of the vehicle by providing the function information for this function. This means, for example, that the computer- implemented method can react more reliably and openly to new functions in the vehicle compared to a classic software timer, such as a watchdog.

[0023] Further advantages of the inventive method are that it is easy to integrate in the vehicle, because no specific libraries or code is need for it to be integrated inside the functions that build the data flow. Moreover, it provides an end-to-end mechanism that may relax platform automotive safety integrity level (ASIL) constraint to host the application that builds the function information. For example, it could be hosted in a quality management (QM) operating system (OS) instead of an ASIL-OS. The method may provide a way to measure / monitor and react to the dynamic behavior of the function and / or allow decoupling of system-level design of the end-to-end data flow from its realization. Further, a scalable architecture of the method allows extending means to perform the reaction mechanism to produce more specific reactions based on the approach of the feature realization. A scalable architecture that allow extending the monitored function information so that a new function information may be added for monitoring by a safety monitor component in run-time. The method also allows seamless recovery of violations (deviations). For example, in some cases the reaction for the violation is to reset the function or the system on a chip. By applying the method such violation may be handled during run-time without a reset of the function by activating an appropriate reaction mechanism.

[0024] An embodiment comprises that the function information describes for the respective data transmission event a data element that is involved in the data transmission event.

[0025] Moreover, it describes the at least one execution constraint. The at least one execution constraint is preferably a time specification of the data transmission event. In case of the transmitted camera information, the function information may describe that the involved data element is the camera information. The camera information comprises, for example, a camera image or multiple camera images. The time specification is in particular a time interval. The time interval specifies a frequency of the data transmission element. The time specification thus preferably describes a number of data transmission events per time. In case of the above-described example, the time specification may be 30 seconds because the data flow prescribes one transmitted camera information every 30 seconds. This is just an example. Other data elements and / or execution constraints other than the described time specifications are possible.

[0026] The function information thus comprises details on the transmitted data and the expected time of transmission. It is preferably possible to ignore a source or an origin of the data element and a destination of the data element, meaning that the modules, sensor devices and / or other components that are involved by the data transmission event are not necessarily described by the function information. This means that the function information does not require any specifications on the individual hardware components that are involved in the data transmission event. Alternatively, the function information may describe the involved modules, sensor devices and / or other components. This allows that the computer-implemented method is independent of the hardware but only relies on the messages that describe that certain data transmission events occurred.

[0027] A preferred embodiment comprises that the at least one data transmission event occurs between a transmitting unit and a receiving unit in the vehicle. In the above-described example, the transmitting unit is, for example, the camera and the receiving unit is the object detection module that receives the camera information from the camera. The transmitting unit and / or the receiving unit generates the message and transmits it to the bus. For example, the camera and the object detection module or only the camera or only the object detection module may transmit a respective message to the bus. It is therefore possible to create the messages directly in the module, sensor device and / or other component that is involved in the data transmission events so that the at least one received message is particularly reliable.

[0028] The monitoring module may be comprised by the transmitting unit and / or the receiving unit. Preferably, a first control device or control unit of the vehicle comprises the monitoring module and a second control device or control unit of the vehicle creates the at least one message and transmits it to the bus. The second control device or control unit may be comprised by the sensor device or the other component of the vehicle that is involved in the data transmission event. Alternatively or additionally, it may comprise the module that is involved in the data transmission event.

[0029] According to another embodiment, the bus is an enterprise service bus. The enterprise service bus may alternatively be referred to as service orientated bus or as service orientated application service bus. The enterprise service bus may be a software layer or a part of a network in the vehicle that is configured to transfer messages between individual components of the vehicle. A message transmitted by the enterprise service bus may be received by a software, the control device, the receiving unit, another module, a sensor device and / or another component of the vehicle. The enterprise service bus may be understood as a centralized software part configured to, for example, share the received messages with the control device that provides the function information, receives the message, and verifies if the occurred data transmission event matches the scheduled and / or preconfigured data transmission event.

[0030] A further embodiment comprises that to receive the at least one message the monitoring module sends a monitoring request to the bus. The monitoring request requests the at least one message for the at least one data transmission event that is comprised by the data flow and hence described by the function information. The monitoring request may be understood as a registration on the bus to receive all the messages that are relevant for the monitoring module according to the function information. In case of, for example, the adaptive cruise control as function, the monitoring request may request messages about the camera information and the object information. The monitoring module may hence only receive messages that relate to the camera information and the object information but no messages that relate to other information that are available in the vehicle, such as, for example, a message about a data transmission event involving a temperature information describing a temperature in a cabin of the vehicle. This shows how the relevant messages are received to perform the computer-implemented method.

[0031] Another embodiment comprises that the monitoring module sends the monitoring request after determining a predetermined activation event. Alternatively, it sends it after being turned on, meaning after it has been switched on. It is thus possible to define a trigger event that starts the computer-implemented method and therefore starts monitoring the function of the vehicle. For example, when the function of the vehicle is activated, the monitoring module may notice this activation and send the monitoring request to the bus. In the above-described example, this is the case when the adaptive cruise control is manually activated by a driver of the vehicle or automatically activated. Turning on the monitoring module may occur when the vehicle is turned on. The vehicle may be turned on by pressing a Start / Stop-button in the vehicle, by opening at least one door of the vehicle, by unlocking the vehicle, and / or by starting to move the vehicle. For example, monitoring the function may continue until a predetermined deactivation event is determined and / or until the monitoring module, in particular the vehicle, is turned off. The deactivation event may be a manual or automatic deactivation of the function. Therefore, the computer-implemented method only runs when it is required, for example, to be particularly resource-efficient.

[0032] A further embodiment comprises that the monitoring module determines a deviation information if the occurred data transmission event does not match the scheduled and / or preconfigured data transmission event. The deviation information describes at least that the occurred data transmission event does not match the scheduled and / or preconfigured data transmission event. Moreover, it may comprise details on the deviation. It may, for example, describe in which way the occurred data transmission event deviates from the scheduled and / or preconfigured data transmission event. In the above-described example, it may describe that the camera information was transmitted 20 seconds too late, meaning after 50 seconds instead of after 30 seconds. However, the deviation information may only comprise that there was a deviation between the occurred data transmission event and the scheduled data transmission without further specifying it. The monitoring module transmits the determined deviation information to the at least one reaction module. This is thus how the reaction module is informed about the occurred deviation so that it activates the at least one predetermined reaction mechanism. Preferably, the bus receives the deviation information from the monitoring module and the reaction module receives it from the bus. All communication between the monitoring module and the at least one reaction modules preferably happens via the bus. There may be a deviation request sent by the reaction module to the bus that requests for the deviation information when the bus receives a deviation information from the monitoring module. Therefore, the reaction module is reliably and quickly informed about the occurred deviation between the occurred data transmission event and the scheduled and / or preconfigured data transmission event.

[0033] A preferred embodiment comprises that the at least one predetermined reaction mechanism comprises at least one of the following actions or mechanisms: a restart of the function and / or a sub-function of the function, and / or deactivating the function and / or the sub-function, and / or changing at least one configuration for the data transmission event, and / or downgrading the function and / or the sub-function, and / or changing a bandwidth for data flow related services, and / or changing a priority of the data transmission event. In some cases, it may be sufficient to restart the function, for example, to restart the adaptive cruise control, after detecting the deviation. Afterwards, the function may be monitored again and it may be verified that the deviation was at least reduced or even terminated by the restart. However, in other cases it may be necessary to deactivate the function at least temporarily, for example, if a sensor failure caused the deviation. It may in other cases be reasonable to change at least one configuration to at least reduce the deviation. For example, a speed for a data capture step and / or a data processing step is changed to achieve a more or less frequent data transmission event that matches the scheduled and / or preconfigured data transmission event. Downgrading the function and / or the subfunction may comprise changing to an older version of the function and / or the subfunction. This may be helpful if the deviation occurs after an update of the function. Changing the bandwidth of the data flow related services may, for example, be helpful to encourage a higher frequency in data transmission events in cases in which there was a delay in data transmission events. By changing the priority and especially by increasing the priority of the data transmission event it may be possible to match the scheduled and the occurred data transmission event. Further or other reaction mechanisms are possible. In general, it is possible to react specifically to a certain situation, for example, depending on the deviation information.

[0034] Another embodiment comprises that the monitoring module and the at least one reaction module are executed on different cores of one control device. If the control device comprises a first core and a second core, the monitoring module may run on the first core and the at least one reaction module on the second core. For example, if the control device comprises a real-time (RT) core and a Big-A core it is possible to, for example, run the monitoring module on the RT core and the at least one reaction module on the Big-A core. If there are multiple reaction modules, they may all run on the Big-A core or an individual cores. Alternatively, the monitoring module and the at least one reaction module are executed on different control devices. However, they may communicate with each other via the bus. In general, the monitoring module and the reaction module or modules may be executed by any possible computer and hence control device in the vehicle.

[0035] According to another embodiment, the monitoring of the function by the monitoring module and the at least one reaction module fulfills a predetermined functional safety requirement. The predetermined functional safety requirement is in particular at least the requirement for automotive safety integrity level (ASIL) B and / or ASIL C and / or ASIL D. In other words, it may at least fulfil the requirements of ASIL A and ASIL B. Preferably, it also fulfils the requirements of ASIL C and in particular of ASIL D. ASIL is a risk classification scheme defined by the ISO 26262 - Functional Safety for Road Vehicles standard. There are four ASILs identified by the standard, which are ASIL A, ASIL B, ASIL C, ASIL D. ASIL D dictates the highest integrity requirements and ASIL A the lowest. Verifying if the occurred data transmission event matches the scheduled and / or preconfigured data transmission event and activating the at least one predetermined reaction mechanism in case they do not match hence achieves to meet the predetermined functional safety requirement. The computer-implemented method therefore particularly suitable for software environments in the field of safe driving.

[0036] A further embodiment comprises that multiple function information for multiple functions are provided. All the multiple functions are monitored simultaneously. The monitoring module may not just provide one function information and monitor it at a time but may monitor more than one function at the same time. In this case, the monitoring module may register for multiple message services by the bus, for example, by generating and transmitting multiple monitoring requests. The method may hence monitor the adaptive cruise control, a lane assist, and / or other functions at once. It is hence not necessary to have an additional individual monitoring module for each function of the vehicle. The computer-implemented method is therefore particularly suitable for automotive use.

[0037] Another embodiment comprises that the monitored function is configured for at least semiautomatic driving. In particular, it is configured for fully-automatic driving. Preferably, the function that is monitored has a certain safety relevance because it is configured to control, for example, the brake system, the drive system and / or the steering system of the vehicle. Therefore, it is particularly useful to monitor the function by the computer- implemented method due to its high relevance with respect to the control of the vehicle. However, it is alternatively or additionally possible to monitor a comfort function or any other function of the vehicle.

[0038] In the sense of the invention, a module may be understood as a hardware module or as a software module. In particular, a module may comprise a hardware and a software portion implemented on the hardware. The monitoring module and the reaction module, however, may only be understood as a portion of software code functionally connected and combined to a unit. Such a software module may comprise or implement several processing steps and / or data structures.

[0039] The invention may be part of an operating system for the vehicle. The operating system may comprise a real-time core that, for example, is configured for booting and / or monitoring of individual software parts, software modules, software units and / or software applications that are part of the operating system. On the real-time core e.g. a classical AUTOSAR (Automotive System Architecture) software / platform, a MCAL software / firmware or the like can run. The operating system may further comprise or be based on a hypervisor and a BSP (Board Support Package). The hypervisor can be e.g. as described in DE 10 2017 100 118 A1 , which is incorporated by reference herewith. The BSP (Board Support Package) can be used (or can be software) to connect to the underlying hardware chip or board. The operating system may comprise a node foundation unit, an automotive foundation unit and / or a sensor service unit. The sensor service unit may be understood as a sensor service software unit. Moreover, the operating system may comprise or run applications (e.g. on Virtual Machines), e.g. a first application, a second application and / or a third application. More or less applications are possible. The application may be the functional application or the at least one function of the vehicle. The network that connects all these parts of the operating system, meaning the real-time core, the node foundation unit, the automotive foundation unit, the sensor service unit and the different applications may be the enterprise service bus. It may be the above-described bus.

[0040] The node foundation unit may comprise an orchestrator (assignment module), a system monitor (another monitoring module), a software update module, a data flow monitor master (monitoring software module), and / or a debug agent. The data flow monitor master is the above-described monitoring module. Other or more or less components may be possible. All the listed components may be software parts of the node foundation unit. The orchestrator may assign and / or reassign a functional application to the control unit in the vehicle. Alternatively or additionally, it may detect a failure of the control unit. The system monitor may monitor a data exchange between control units and / or other components in the vehicle, such as storage units. The data flow monitor master may monitor data transmission events of a function or a functional application of the vehicle (as described above for the monitoring module as the data flow monitor master). The automotive foundation unit may comprise means for vehicle communication, security, logging, error detection, and / or configurations. Other or more or less components are possible.

[0041] The sensor service unit may comprise a sensor server, an ultrasonic sensor provider, a camera provider, a radar provider, a lidar provider and / or a log and tracer. It may be configured to provide an abstracted sensor information to the different applications. The sensor server may provide the general software for this whereas the individual providers comprise specific software parts to handle different kinds of sensor information, for example captured by an ultrasonic sensor, a camera, a radar device and / or a lidar device, respectively.

[0042] Another aspect of the invention relates to a control device for a vehicle. The control device is configured to perform the computer-implemented method. It performs the computer- implemented method.

[0043] The control device may be understood as a computing unit or as a data processing device with processing circuitry. The control device may therefore perform computing operations in order to process data and hence the computer-implemented method. The computing operations may also include indexed accesses to a data structure, for example a look-up table (LUT). In particular, the control device may comprise at least one computer, at least one microcontroller, and / or at least one integrated circuit, for example, at least one applicationspecific integrated circuit (ASIC), at least one field-programmable gate array (FPGA), and / or at least one system on a chip (SoC). The control device may comprise at least one processor, for example, at least one microprocessor, at least one central processing unit (CPU), at least one graphics processing unit (GPU), and / or at least one signal processor, in particular at least one digital signal processor (DSP). The control device may comprise a physical or a virtual cluster of computers or other of said units.

[0044] The control device may comprise at least one hardware and / or software interface and / or at least one storage unit or memory unit. The storage or memory unit may be implemented as a volatile data memory, for example a dynamic random access memory (DRAM), or a static random access memory (SRAM), or as a non-volatile data memory, for example a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a flash memory or flash EEPROM, a ferroelectric random access memory (FRAM), a magnetoresistive random access memory (MRAM), or a phase-change random access memory (PCRAM).

[0045] A further aspect relates to a vehicle with the control device. The vehicle may perform the computer-implemented method. The vehicle is preferably a motor vehicle, for example, a passenger car, a truck, a bus, a motorcycle and / or a moped.

[0046] An aspect of the invention relates to a computer program product. The computer program product is a computer program. The computer program product comprises instructions which, when the program is executed by a computer, such as the control device, cause the computer to perform the computer-implemented method.

[0047] The embodiments described in connection with the computer-implemented method, both individually and in combination with each other, apply accordingly, when applicable, to the inventive control device, vehicle, and computer program product. The invention comprises combinations of the described embodiments.

[0048] The figures show in: Fig. 1 a schematic representation of a vehicle with a function,

[0049] Fig. 2 a schematic representation of a computer-implemented method to monitor a function of a vehicle, and

[0050] Fig. 3 a schematic representation of an operating system in a vehicle.

[0051] In the figures, same components are labeled with the same reference signs.

[0052] Fig. 1 shows a vehicle 1 . The vehicle 1 comprises a function 2, which may be, as an example, an adaptive cruise control. Another function 2 or an additional function 2 is possible. In particular, the function 2 may be configured for at least semi-automatic driving, in particular for fully-automatic driving. The function 2 may thus comprise determining and executing a control command for a brake system, a drive system and / or a steering system of the vehicle 1 .

[0053] Here, the function 2 is performed by multiple components of the vehicle 1 . For example, a camera 3 located at an upper area of a windshield of the vehicle 1 , an object detection module 4, a control command determination module 5, and a vehicle control module 6 may each perform at least one step or sub-function of the function 2. The vehicle control module 6 may be configured to operate the brake system, the drive system, and / or the steering system of the vehicle 1 . The vehicle 1 may comprise one control device or individual control devices for the brake system, the drive system and / or the steering system. The vehicle control module 6 may operate the control device or the control devices.

[0054] Fig. 2 shows steps of a computer-implemented method to monitor the function 2 of the vehicle 1 . Here, computer-implemented method is explained for the adaptive cruise control as function 2. However, this is purely exemplary and can be transferred to any other function 2.

[0055] The camera 3 may capture a camera information 7 that, for example, describes an environment of the vehicle 1 in front of the vehicle 1 . The camera 3 may transmit the camera information 7 to the object detection module 4. The object detection module 4 may determine an object information 8 describing at least one object in the environment. The object detection module may transmit the determined object information 8 to the control command determination module 5. The control command determination module 5 may receive the object information 8 and determine a control command information 9 describing at least one control command for the brake system, drive system and / or steering system of the vehicle 1 . The control command determination module 5 may transmit the determined control command information 9 to the vehicle control module 6 so that the vehicle control module 6 may execute the received control command information

[0056] 9. Therefore, the function 2 comprises here at least three individual data transmission events, which are the transmission of the camera information 7, the object information 8 and the control command information 9. Moreover, it may comprise three data transmission events that comprise receiving data, which are here the receipt of the camera information 7, the object information 8 and the control command information 9.

[0057] The method comprises providing a function information 11 in a step S1 . The function information 11 describes a data flow generated when executing the function 2 in the vehicle 1 . The data flow comprises at least one scheduled and / or preconfigured data transmission event. In the example, the data flow comprises the above-listed data transmission events. The function information 11 may be provided by a monitoring module

[0058] 10. This means that the monitoring module 10 performs the step 1. The monitoring module 10 may alternatively be referred to as data flow monitoring master. The monitoring module 10 is preferably a software or at least a part of a software.

[0059] The function information 11 may comprise for each data transmission event of the data flow a data element that is involved in the data transmission event and at least one execution constraint, such as a time specification. In particular, it may describe a time interval for the data transmission event. In an example, the function information 11 may describe that the camera information 7 as data element has to be transmitted every 30 seconds and / or has to be received every 30 seconds. It may be irrelevant for the function information 11 to specify the component of the vehicle 1 that transmits or sends the data element and the component of the vehicle 1 that receives the data element. This means that the function information 11 may not comprise that the camera 3 transmits the camera information 7 to the object detection module 4, but only that the camera information 7 is transmitted within the vehicle 1 . More precisely, the data transmission event may occur between a transmitting unit 14 and a receiving unit 15. In case of transmission of the camera information 7, the transmitting unit 14 is the camera 3 and the receiving unit 15 is the object detection module 4. Besides, the object detection module 4 may be the receiving unit 15 for the camera information 7 but also the transmitting unit 14 for the object information 8. The control command determination module 5 may be the receiving unit 15 for the object information 8 and the transmitting unit 14 for the control command information 9. The vehicle control module 6 may be the receiving unit 15 for the control command information 9.

[0060] The method comprises transmission of at least one message 13 describing an occurred data transmission event that occurred during executing the function 2. A bus 12 in the vehicle 1 , which is in this example an enterprise service bus 12 in the vehicle 1 , may receive the at least one message 13 from the respective transmitting unit 14 and / or receiving unit 15 that is involved in the data transmission event. The transmitting unit 14 and / or receiving unit 15 may also generate the message 13 in a step S6 and transmit it to the enterprise service bus 12 afterwards in a step S7. The enterprise service bus 12 may provide the at least one message 13 to the monitoring module 10 so that in a step S2 the monitoring module 10 receives the at least one message 13 from the bus 12, which is here the enterprise service bus 12. Here, four messages 13 are sketched as an example. More or less messages 13 are possible.

[0061] A step S3 comprises verifying if the occurred data transmission event matches the scheduled data transmission event by analyzing the provided function information 11 and the at least one received message 13. The monitoring module 10 performs the step S3. If the scheduled and / or preconfigured data transmission event matches the occurred data transmission event a step S4 is performed. Step S4 comprises that it is continued to operate the function 2. This means that, for example the function 2 remains unaffected.

[0062] If however the occurred data transmission event does not match the scheduled and / or preconfigured data transmission event, a step S5 comprises activating at least one predetermined reaction mechanism to at least reduce the deviation between the occurred data transmission event and the scheduled and / or preconfigured data transmission event. Preferably, the reaction mechanism allows to correlate the occurred data transmission event with the scheduled and / or preconfigured data transmission event so that no further deviation is observed. At least one reaction module 18 performs the step S5. The described reaction mechanisms may be performed by the at least one reaction module 18. There may be multiple reaction mechanisms which are each performed by one of multiple reaction modules 18. Therefore, the at least one reaction module 18 may activate the at least one predetermined reaction mechanism if the occurred data transmission event does not match the scheduled and / or preconfigured data transmission event.

[0063] The monitoring module 10 may determine a deviation information 17 if the occurred data transmission event does not match the scheduled and / or preconfigured data transmission event. The deviation information 17 may describe at least that the occurred data transmission event does not match the scheduled and / or preconfigured data transmission event. Preferably, it may describe the deviation and, for example, comprise at least some details on why and / or how the occurred data transmission event deviates from the scheduled and / or preconfigured data transmission event. It may then describe, for example, a wrong timing of the occurred data transmission event compared to the scheduled and / or preconfigured data transmission event.

[0064] The monitoring module 10 may transmit the determined deviation information 17 to the at least one reaction module 18 in a step S9. However, the monitoring module 10 may first transmit the deviation information 17 to the enterprise service bus 12 and then the enterprise service bus 12 may transmit the received deviation information 17 to the at least one reaction module 18.

[0065] The reaction mechanism that is performed may comprise at least one of the following actions: restart of the function 2 and / or a sub-function of the function 2, and / or deactivating the function 2 and / or the sub-function, and / or changing at least one configuration for the data transmission event, and / or downgrading the function 2 and / or the sub-function and / or changing a bandwidth for data flow related services, and / or changing a priority of the data transmission event. The sub-function may only provide a part of the function 2 of the vehicle 1 , such as at least one data transmission event. It may, for example, be a sub-function to determine the object information 8 and another sub-function to determine the control command information 9 for the vehicle control module 6. Other sub-functions may be possible. To receive the at least one message 13, the monitoring module 10 may transmit a monitoring request 16 to the enterprise service bus 12 in a step S8. With the monitoring request 16 it may request the at least one message 13 for the at least one data transmission event comprised by the data flow according to the function information 11 . This means that the monitoring module 10 may register for receiving the messages 13 from the enterprise service bus 12. It is also possible that the monitoring request 16 is transmitted after determining a predetermined activation event or after turning on the monitoring module 10, in particular the vehicle 1 .

[0066] Preferably, there are multiple function information 11 for multiple functions 2 that are provided by the monitoring module 10. The monitoring module 10 may monitor all the multiple functions 2 simultaneously.

[0067] The monitoring module 10 and the at least one reaction module 18 may be executed on different cores 20, 21 of one control device. Here the first core 20 is intended to execute the monitoring module 10 and a second core 21 is intended to execute the at least one reaction module 18. If there are multiple reaction modules 18, there may be multiple second cores 21 or one shared second core 21 . Alternatively, the method may be executed by one shared control device in exchange with the enterprise service bus 12 that receives the messages 13 from the individual modules, units, sensors and so on that are necessary to perform the function 2 (transmitting units 14 and / or receiving units 15).

[0068] The monitoring of the function 2 by the monitoring module 10 and the at least one reaction module 18, at least according to the steps S1 to S5, fulfills a predetermined functional safety requirement. In particular, it fulfills the requirement at least for automotive safety integrity level B, automotive safety integrity level C and / or automotive safety integrity level D.

[0069] Fig. 3 gives an overview of an operating system 40 for the vehicle 1 . The operating system 40 may be based on a SoC (system on a chip) as a node or board. The operating system 40 may comprise a real-time core (or real-time processing unit, i.e. RPU) 41 that, for example, is configured for booting and / or monitoring of individual software parts, software modules, software units and / or software applications that are part of the operating system 40. On the real-time core 41 e.g. a classical AUTOSAR (Automotive System Architecture) software / platform, a MCAL software / firmware or the like can run. The operating system 40 may further comprise or be based on a hypervisor (e.g. QNX Mikrokernel Hypervisor (PO SIX)) and a BSP (Board Support Package), both not shown in Fig. 5. The hypervisor can be e.g. as described in DE 10 2017 100 118 A1 .The BSP (Board Support Package) can be used (or can be software) to connect to the underlying hardware chip or board, e.g. the SoC (system on a chip) as a node or board.

[0070] The operating system 40 may comprise a node foundation unit 42, an automotive foundation unit 43 and / or a sensor service unit 44. The sensor service unit 44 may be understood as a sensor service software unit. Moreover, the operating system 40 may comprise or run applications (e.g. on Virtual Machines), e.g. a first application 45, a second application 46 and / or a third application 47, as shown in Fig. 3. More or less applications 45, 46, 47 are possible. The application 45, 46, 47 may be a functional application and / or the function 2 in the vehicle 1 . The network 48 that connects all these parts of the operating system 40, meaning the real-time core 41 , the node foundation unit 42, the automotive foundation unit 43, the sensor service unit 44 and the different applications 45, 46, 47 may be the bus. It may be the enterprise service bus 12.

[0071] The node foundation unit 42 may comprise an orchestrator 49 (assignment module), a system monitor 50 (another monitoring module), a software update module 51 , a monitoring software module 52 (that may alternatively be referred to as the data flow monitor master), and / or a debug agent 53. The monitoring software module 52 may be the above-described monitoring module 10. Other or more or less components may be possible. All the listed components may be software parts of the node foundation unit 42.

[0072] The automotive foundation unit 43 may comprise means for vehicle communication 54, security 55, logging 56, error detection 57 and / or configurations 58. Other or more or less components are possible.

[0073] The sensor service unit 44 may comprise a sensor server 26, an ultrasonic sensor provider 27, a camera provider 28, a radar provider 29, a lidar provider 30 and / or a log and tracer 31 . The sensor service unit 44 may be configured to provide sensor data (in particular an abstracted sensor information) to the different applications 45, 46, 47.

[0074] In summary, the invention shows real-time data flow monitoring in a vehicle 1 . In other words, it shows a service-oriented based end-to-end dataflow system monitor with extendable reactors. A technical problem leading to the invention is that heterogeneous systems on a chip (SOC) within domain controllers electronic control units (ECU) have mixed criticality components that require deterministic timing and providing safety integrity level features. For example, the camera 3 produces frames (camera information 7) that could be handled / processed inside a Linux hosted artificial intelligence (Al) application to detected objects. Such objects (object information 8) may be delivered to a dynamic mapping application that might be hosted in another Linux / QNX / Android Automotive operating system (OP) application. Such applications produce vehicle control messages for a vehicle control unit (VCTL) component that is hosted on a real time (RT)-Core with classical automotive open system architecture (AUTOSAR), for example, to control the steering system and the brake system. All such applications are communicating through a service oriented approach. There is thus a need to monitor the overall system end-to-end violation and react to such violations in a decoupled distributed manner which imposes more integration constrains for such applications.

[0075] The above-described method comprises utilizing a service oriented technique to build a data flow like graph (function information 11) with timing and quality of service (QoS) constrains. A centralized system monitor component (monitoring module 10) registers for all data from the graph and implement a violation detection algorithm from such graph (receiving the messages 13 and verifying them in step S3). The system monitor component (monitoring module 10) publishes detected violation (deviations) as a service for distributed reactors (reaction modules 18) to take corrective action for the violation (reaction mechanisms). The system could allow hosting one or more reactors (reaction modules 18) that handle violations detected by the system monitor component (monitoring module 10).

[0076] For example, in the context of reaction mechanisms there may be QoS reactors that adaptively adjust a runtime of the QoS setting of the hosted services to allow more bandwidth toward data-flow related services. There may be adaptive scheduling reactors (reaction modules 18) that adaptively change the scheduling parameters and / or attributes for the applications that contribute to the data-flow related services (function 2 or subfunction).

[0077] If one assumes a domain controller ECU that hosts the adaptive cruise control the ECU comprises multiple SOCs, the method may comprise the following actions: 1 . A computer-vision SOC (CV-SOC) handles a stream from the camera 3 and produced a set of detected objects.

[0078] 2. An integration SOC (l-SOC) that receives the detected objects (object information 8) from the CV-SOC fuses it with objects received from multiple sensors and / or ECUs through vehicle networks and produces the driving polices data (control command information 9).

[0079] 3. A real time SOC (RT-SOC) (vehicle control module 6) that receives the driving polices data (control command information 9) executes it against steering and braking control ECU(s).

[0080] In this example an offline tool "data-flow designer" is used to build and / or design an end- to-end data flow. This means that the offline tool determined the function information 11 . For the use-case such data flow (function information 11 ) comprises the service definition for each data provider and QoS constrains for each data node (for example latencies, periodicities, and so on).

[0081] Then, the method may comprise the following further actions:

[0082] 4. Export such data flow (function information) with the QoS constrains and add it to the system monitor component (monitoring module 10) that may register to all services that provide such data (for example by the monitoring request 16).

[0083] 5. The system monitor component (monitoring module 10) may perform a runtime analysis of the data-flow end-to-end (analyze the function information 11 and the messages 13) and publish a violation notifications (deviation information 17) for the reactors (reactor modules 18).

[0084] 6. Deployed QoS reactors may register to the system monitor events and adapt the QoS profile for each service provider taking into consideration all the services that contribute directly to the data flow graph (data flow) during monitoring or do not contribute at all for such graph.

[0085] In other words, the proposed platform supports automotive safety integrity level (ASIL) application development through a centralized system monitor component (monitoring module 10) which registers to the data events of the data flow graph (function information 11) and detects any violations (deviations) for this flow or the assigned QoS settings. Once a violation is detected, the system monitor component (monitoring module 10) publishes the violation to the distributed reactors (reaction modules 18) for taking the necessary actions (reaction mechanisms).

[0086] The reactor (reaction module 18) is the software component which is responsible for registering to the system monitor violations events and try to react and / or handle such violation scenario. The reactor is platform independent and could run on bare metal (Native QNX or PikeOs partition) or in hypervisor level. No safe Linux kernel may be needed. The reactor may mitigate performance degradation of parallel programs in the virtualized system. It may manage resources assignation for each virtual machine (VM) (hypervisor control reactor) in runtime. The monitoring module 10 and the reactor (reaction module 18) may provide an end-to-end mechanism that relaxes platform ASIL constraint to host the application that build the data flow graph, meaning it may be hosted in quality management (QM) operating system (OS) instead of ASIL-OS.

[0087] There are different types of reactors (reaction modules 18) that may be used if the system monitor component (monitoring module 10) inspects real-time constraint violation such as: real time QoS adapter (it may adapt QoS policies in runtime according to the detected failure) and / or dynamic scheduling adapter (it may change process priorities to avoid violating real time safety constraints such as fault tolerant time interval (FTTI)). The reactors may be inside the VM that changes the scheduling attributes for applications, or in the hypervisor level to react on the scheduling attributes for the VM level. Based on project’s need, the rectors (reaction modules 18) are scalable to extend.

Claims

Claims1 . Computer-implemented method to monitor a function (2) of a vehicle (1 ), comprising:- providing (S1 ) a function information (11 ) describing a data flow generated when executing the function (2) in the vehicle (1) by a monitoring module (10), wherein the data flow comprises at least one scheduled and / or preconfigured data transmission event;- receiving (S2) at least one message (13) describing an occurred data transmission event that occurred during executing the function (2) by the monitoring module (10) from a bus (12);- verifying (S3) by the monitoring module (10) if the occurred data transmission event matches the scheduled and / or preconfigured data transmission event by analyzing the provided function information (11) and the at least one received message (13);- if this is the case, continuing (S4) to operate the function (2); and / or- if this is not the case, activating (S5) at least one predetermined reaction mechanism to at least reduce a deviation between the occurred data transmission event and the scheduled and / or preconfigured data transmission event by at least one reaction module (18).

2. Computer-implemented method according to claim 1 , wherein the function information (11) describes for the respective data transmission event a data element that is involved in the data transmission event and at least one execution constraint, in particular a time specification, of the data transmission event.

3. Computer-implemented method according to any one of the preceding claims, wherein the at least one data transmission event occurs between a transmitting unit (14) and a receiving unit (15) in the vehicle (1) and the transmitting unit (14) and / or the receiving unit (15) generates (S6) the message (13) and transmits (S7) it to the bus (12).

4. Computer-implemented method according to any one of the preceding claims, wherein the bus (12) is an enterprise service bus (12).

5. Computer-implemented method according to any one of the preceding claims, wherein to receive the at least one message (13) the monitoring module (10) sends (S8) a monitoring request (16) to the bus (12), wherein the monitoring request (16) describes the data transmission events comprised by the data flow.

6. Computer-implemented method according to claim 5, wherein the monitoring module (10) sends the monitoring request (16) after determining the occasion of a predetermined activation event or after being turned on.

7. Computer-implemented method according to any one of the preceding claims, wherein the monitoring module (10) determines a deviation information (17) if the occurred data transmission event does not match the scheduled and / or preconfigured data transmission event, wherein the deviation information (17) describes at least that the occurred data transmission event does not match the scheduled and / or preconfigured data transmission event, and transmits (S9) the determined deviation information (17) to the at least one reaction module (18).

8. Computer-implemented method according to any one of the preceding claims, wherein the at least one predetermined reaction mechanism comprises:- a restart of the function (2) and / or a sub-function of the function (2); and / or- deactivating the function (2) and / or the sub-function; and / or- changing at least one configuration for the data transmission event; and / or- downgrading the function (2) and / or the sub-function; and / or- changing a bandwidth for data flow related services; and / or- changing a priority of the data transmission event.

9. Computer-implemented method according to any one of the preceding claims, wherein the monitoring module (10) and the at least one reaction module (18) are executed on different cores (20, 21) of one control device or in different control devices.

10. Computer-implemented method according to any one of the preceding claims, wherein the monitoring of the function (2) by the monitoring module (10) and the at least one reaction module (18) fulfills a predetermined functional safety requirement, in particular at least for automotive safety integrity level B, automotive safety integrity level C and / or automotive safety integrity level D.11 . Computer-implemented method according to any one of the preceding claims, wherein multiple function information (11) for multiple functions (2) are provided and all the multiple functions (2) are monitored simultaneously.

12. Computer-implemented method according to any one of the preceding claims, wherein the monitored function (2) is configured for at least semi-automatic driving, in particular for fully automatic driving.

13. Control device for a vehicle (1 ) configured to perform a method according to any one of the preceding claims.

14. Vehicle (1) with a control device, wherein the vehicle is configured to perform a method according to any one of claims 1 to 12.

15. Computer program product comprising instructions which, when the program is executed by a computer, cause the computer to perform a method according to any one of claims 1 to 12.

Citation Information

Patent Citations

  • scalable control system for a motor vehicle

    DE102017100118A1

  • Motor vehicle control system with hardware failover

    DE102017100119A1

  • System and method for securing communication and information of IoT devices through a controlled cellular communication network

    US11399276B2

  • Bus guardian with improved channel monitoring

    US20090262649A1

  • Voltage scaling architecture on system-on-chip platform

    US20130311792A1