Resetting restoration method and related apparatus
By obtaining variable information before reset in the vehicle microcontroller and directly recovering the controller's functional status, the problem of the problem that the function cannot be restored quickly after the vehicle controller is reset, improving the user experience and reducing safety risks.
Patent Information
- Application Number
- PCT/CN2025/071981
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-18
- Filing Date
- 2025-01-13
- Publication Date
- 2025-07-24
AI Technical Summary
After the vehicle controller is reset, the function cannot be quickly restored to the state before reset, resulting in poor user experience and may bring about safety risks.
By obtaining variable information before reset in the microcontroller, skipping the start condition judgment logic of the target function, directly restore the function state to the state before reset, using the variable information to quickly determine abnormal reset, and complete the function state recovery within the first preset time.
The use status of the vehicle controller is realized after resetting the vehicle controller, reducing safety risks and improving user experience.
Smart Images

Figure CN2025071981_24072025_PF_FP_ABST
Abstract
Description
Reset recovery method and related device
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on January 18, 2024, with application number 202410074191.X, and priority to the Chinese patent application entitled “Reset Recovery Method and Related Devices”, all contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of vehicle technology, and in particular to a reset recovery method and related devices. Background Art
[0003] With the advancement of vehicle technology, the computing power of vehicle controllers is increasing, and the software functions they carry are becoming increasingly complex. Therefore, during vehicle use, controller resets are inevitable for various reasons. After a controller reset, many of its functions undergo a re-evaluation process. If the activation conditions for a function are not met, the function cannot be restored to its pre-reset state, resulting in a poor user experience and even posing a safety hazard to passengers in certain operating conditions. Therefore, how to quickly restore the function to its pre-reset state after a controller reset is an urgent technical challenge. Summary of the Invention
[0004] The present application provides a reset recovery method and related devices, which can quickly restore the functional usage status after the vehicle controller is reset, reduce safety hazards, and improve the user's car experience.
[0005] In a first aspect, the present application provides a reset recovery method, which is applied to a microcontroller of a vehicle, and comprises:
[0006] completing software initialization in response to a reset instruction;
[0007] Acquiring variable information; the variable information includes state information of a target function before the reset occurs, the target function including a function of the vehicle starting before the reset occurs;
[0008] When the variable information indicates that the reset is an abnormal reset, the start condition judgment logic of the target function is skipped, and the state of the target function is set to a target state based on the variable information, and the target state is the functional state of the target function before the reset.
[0009] In the above solution, an abnormal reset can be determined based on the variable information itself, and the functional state before the reset can then be restored based on the variable information. Compared to the existing technology, this solution does not require re-determining the activation conditions of the vehicle's functional state, nor does it require comparing the current vehicle state with the state before the reset. This can greatly reduce processing time and can quickly restore the functional state after the vehicle controller is reset.
[0010] In a possible implementation, obtaining variable information includes:
[0011] The variable information is obtained in the first operating system scheduling cycle after the software initialization is completed.
[0012] In the above solution, the variables stored before the reset are retrieved during the first OS scheduling cycle after reset initialization. Because the stored variables remain unchanged by software execution during the first scheduling cycle, they still represent the most recent vehicle function status information stored before the reset. Therefore, an abnormal reset can be detected based on this variable information alone.
[0013] In a possible implementation, when the variable information indicates that the reset is an abnormal reset, the method further includes: closing an external information transmission channel of the microcontroller;
[0014] After setting the state of the target function to the target state based on the variable information, the method further includes: opening an external information sending channel of the microcontroller.
[0015] In the above solution, during the microcontroller reset process, the microcontroller is essentially in a node-lost state on the entire vehicle. To prevent malfunctions in peripheral controllers after the controller is reset, the controller's external communication channel can be disabled and then reopened after the recovery is complete.
[0016] In one possible implementation, the variable information includes power system readiness information of the vehicle; and the variable information indicates that the reset is an abnormal reset, including:
[0017] When the power system preparation status information indicates that the power system is ready, the reset is an abnormal reset.
[0018] In the above solution, whether it is an abnormal reset can be quickly determined through the power system preparation status information, thereby greatly reducing the processing time of the status recovery.
[0019] In a possible implementation, after setting the state of the target function to the target state based on the variable information, the method further includes:
[0020] Obtaining the latest torque information of the vehicle;
[0021] Torque filtering is performed based on the latest torque information.
[0022] In the above solution, after recovery, torque filtering is used to achieve a rapid transition of the torque before reset to the latest target torque, thereby reducing vehicle vibration and improving user experience.
[0023] In one possible implementation, the variable information includes battery charge and discharge status information of the vehicle; and the variable information indicates that the reset is an abnormal reset, including:
[0024] When the battery charge and discharge status information indicates that the battery is in a charging state or an external discharging state, the reset is an abnormal reset; the external discharging state includes the battery supplying power to a device other than the vehicle.
[0025] In the above solution, whether it is an abnormal reset can be quickly determined through the battery charge and discharge status information, thereby greatly reducing the processing time of the status recovery.
[0026] In a possible implementation, setting the state of the target function to the target state based on the variable information includes:
[0027] Within a first preset time period, the state of the target function is set to the target state based on the variable information; the value of the first preset time period is between three and eight times the time period of the scheduling period.
[0028] In the above scheme, the vehicle functional status can be restored within three to eight scheduling cycles, which is much better than the recovery time of the existing scheme.
[0029] In a possible implementation, within the first preset time period, setting the state of the target function to the target state based on the variable information includes:
[0030] Generate a first notification message and a second notification message; the first notification message and the second notification message are generated at a time interval of the first preset duration, the first notification message is used to instruct the target function to be restored to the target state, and the second notification message indicates the function start condition judgment logic of the target function before the reset is restored;
[0031] In response to the first notification information, the state of the target function starts to be set to the target state based on the variable information, and the restoration of the target state is completed before the function start condition judgment logic is restored in response to the second notification information.
[0032] In the above solution, through the coordination of the first notification information and the second notification information, the target functional module can complete the recovery operation within the preset time and restore the function start condition judgment logic in time to ensure the safety of vehicle use.
[0033] In a possible implementation, within the first preset time period, setting the state of the target function to the target state based on the variable information includes:
[0034] Starting at a first moment, the state of the target function is set to the target state based on the variable information, and the target state is restored before a second moment; the first moment and the second moment are separated by the first preset time length;
[0035] The function start condition judgment logic of the target function before the reset is restored at the second moment.
[0036] In the above solution, the microcontroller can set a timer and restore their previous judgment logic when the time is up to ensure the safety of the car.
[0037] In a possible implementation, the acquiring of the variable information includes: acquiring the variable information in a target storage area; the target storage area belongs to the internal memory or external memory of the microcontroller;
[0038] In the above scheme, the variable information is stored in the memory of the microcontroller for quick access.
[0039] Optionally, completing software initialization in response to a reset instruction includes: completing initialization of a target memory of the microcontroller in response to the reset instruction; if the target storage area belongs to the memory of the microcontroller, the target storage area belongs to a memory area outside the target memory.
[0040] In the above solution, the target storage area is not affected by the memory initialization during reset, so that the information before the reset can be retained.
[0041] In a possible implementation, the target storage area is used to periodically write status information of the target function; before obtaining the variable information in the target storage area, the method further includes: pausing the target storage area writing function based on the reset instruction.
[0042] In the above scheme, the microcontroller notifies each application layer functional software to suspend writing variable information to the target storage area (disabling writing to the target storage area) based on the reset instruction to ensure that the information in the target storage area is the last written information before the reset. After obtaining the information in the target storage area, it notifies each application layer software to continue storing variable information in the target storage area (enabling writing to the target storage area). This ensures that the variable information in the target storage area after the reset has not changed due to software operation and is still the latest vehicle function status information stored before the reset. Therefore, an abnormal reset can be determined based on this variable information itself.
[0043] In a possible implementation, the acquiring the variable information includes: receiving the variable information from a target device; the target device is a device independent of the microcontroller and capable of storing the variable information.
[0044] In the above solution, the target device may be a server or other controller in a vehicle, and the microcontroller may interact with the target device to store or read the variable information. In this implementation, the storage of the variable information is not affected by resetting the microcontroller.
[0045] Optionally, the variable information includes one or more of the following: vehicle energy control request, vehicle high-voltage mode request, high-voltage enable flag, battery management system high-voltage status, vehicle high and low voltage status, charge and discharge status, powertrain readiness status, vehicle gear position, pedal learning value, powertrain anti-theft status, vehicle mode, driving mode, single-pedal mode, scenario mode, steering mode, and electronic stability control system mode. This solution can achieve rapid recovery of multiple functional states and has a wide range of applications.
[0046] In a possible implementation, the opening of the microcontroller's external information transmission channel includes: opening the microcontroller's external information transmission channel after a second preset time period has passed after the microcontroller's external information transmission channel is closed.
[0047] In the above solution, a timeout protection mechanism for closing the outgoing channel is designed. As long as the closure reaches the second preset time, it will be turned on to prevent the adverse effects caused by excessive interruption of communication.
[0048] In a second aspect, the present application provides a microcontroller, the microcontroller comprising:
[0049] a processing unit, configured to complete software initialization in response to a reset instruction;
[0050] an acquiring unit, configured to acquire variable information; the variable information including state information of a target function before the reset occurs, the target function including a function of the vehicle starting before the reset occurs;
[0051] The processing unit is also used to skip the start condition judgment logic of the target function when the variable information indicates that the reset is an abnormal reset, and set the state of the target function to a target state based on the variable information, wherein the target state is the functional state of the target function before the reset.
[0052] In a possible implementation, the acquiring unit is specifically configured to:
[0053] The variable information is obtained in the first operating system scheduling cycle after the software initialization is completed.
[0054] In a possible implementation, the processing unit is further configured to:
[0055] When the variable information indicates that the reset is an abnormal reset, closing the external information transmission channel of the microcontroller;
[0056] After setting the state of the target function to the target state based on the variable information, the microcontroller's external information sending channel is opened.
[0057] In one possible implementation, the variable information includes power system readiness information of the vehicle; and the variable information indicates that the reset is an abnormal reset, including:
[0058] When the power system preparation status information indicates that the power system is ready, the reset is an abnormal reset.
[0059] In a possible implementation, the processing unit is further configured to:
[0060] After setting the state of the target function to a target state based on the variable information, acquiring the latest torque information of the vehicle;
[0061] Torque filtering is performed based on the latest torque information.
[0062] In one possible implementation, the variable information includes battery charge and discharge status information of the vehicle; and the variable information indicates that the reset is an abnormal reset, including:
[0063] When the battery charge and discharge status information indicates that the battery is in a charging state or an external discharging state, the reset is an abnormal reset; the external discharging state includes the battery supplying power to a device other than the vehicle.
[0064] In a possible implementation, the processing unit is specifically configured to:
[0065] Within a first preset time period, the state of the target function is set to the target state based on the variable information; the value of the first preset time period is between three and eight times the time period of the scheduling period.
[0066] In a possible implementation, the processing unit is specifically configured to:
[0067] Generate a first notification message and a second notification message; the first notification message and the second notification message are generated at a time interval of the first preset duration, the first notification message is used to instruct the target function to be restored to the target state, and the second notification message indicates the function start condition judgment logic of the target function before the reset is restored;
[0068] In response to the first notification information, the state of the target function starts to be set to the target state based on the variable information, and the restoration of the target state is completed before the function start condition judgment logic is restored in response to the second notification information.
[0069] In a possible implementation, the processing unit is specifically configured to:
[0070] Starting at a first moment, the state of the target function is set to the target state based on the variable information, and the target state is restored before a second moment; the first moment and the second moment are separated by the first preset time length;
[0071] The function start condition judgment logic of the target function before the reset is restored at the second moment.
[0072] In a possible implementation, the acquiring unit is specifically configured to:
[0073] Acquire the variable information in a target storage area; the target storage area belongs to the internal memory or external memory of the microcontroller;
[0074] In a possible implementation, the processing unit is specifically configured to: complete initialization of a target memory of the microcontroller in response to the reset instruction;
[0075] If the target storage area belongs to the memory of the microcontroller, the target storage area belongs to a memory area outside the target memory.
[0076] In a possible implementation, the target storage area is used to periodically write status information of the target function;
[0077] Before acquiring the variable information in the target storage area, the processing unit is further configured to: suspend a writing function of the target storage area based on the reset instruction.
[0078] In one possible implementation, the variable information includes one or more of the following:
[0079] Vehicle energy control request, vehicle high-voltage mode request, high-voltage enable flag, battery management system high-voltage status, vehicle high and low voltage status, charge and discharge status, power system readiness status, vehicle gear position, pedal learning value, power anti-theft status, vehicle mode, driving mode, single-pedal mode, scenario mode, steering mode, and electronic stability control system mode.
[0080] In a possible implementation, the processing unit is specifically configured to: after a second preset time period has elapsed since the microcontroller's external information transmission channel was closed, open the microcontroller's external information transmission channel.
[0081] In a third aspect, the present application provides a microcontroller comprising a processor and a memory. The memory is coupled to the processor, and when the processor executes a computer program or computer instructions stored in the memory, the method described in any one of the first aspects can be implemented. The microcontroller may also include a communication interface for communicating between the microcontroller and other microcontrollers. Exemplarily, the communication interface may be a transceiver, circuit, bus, module, or other type of communication interface.
[0082] In one possible implementation, the microcontroller may include:
[0083] Memory for storing computer programs or computer instructions;
[0084] Processor for:
[0085] completing software initialization in response to a reset instruction;
[0086] Acquiring variable information; the variable information includes state information of a target function before the reset occurs, the target function including a function of the vehicle starting before the reset occurs;
[0087] When the variable information indicates that the reset is an abnormal reset, the start condition judgment logic of the target function is skipped, and the state of the target function is set to a target state based on the variable information, and the target state is the functional state of the target function before the reset.
[0088] It should be noted that the computer program or computer instructions in the memory of this application can be pre-stored or downloaded from the Internet and stored when the microcontroller is used. This application does not specifically limit the source of the computer program or computer instructions in the memory. The coupling in the embodiments of this application is an indirect coupling or connection between devices, units or modules, which can be electrical, mechanical or other forms, and is used for information exchange between devices, units or modules.
[0089] In a fourth aspect, the present application provides a controller comprising a system base chip, a transceiver and a microcontroller; wherein the microcontroller is the microcontroller described in any one of the above second aspects, or the microcontroller described in the above third aspect; the system base chip is used to power the microcontroller; and the transceiver is used to provide external communication for the microcontroller.
[0090] In a fifth aspect, the present application provides a vehicle, comprising the microcontroller described in any one of the second aspects above, or the microcontroller described in the third aspect above.
[0091] In a sixth aspect, the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program or computer instructions, and the computer program or computer instructions are executed by a processor to implement the method described in any one of the first aspects above.
[0092] In a seventh aspect, the present application provides a computer program product. When the aforementioned computer program product is executed by a processor, the method described in any one of the aforementioned first aspects will be implemented.
[0093] The solutions provided in the second to seventh aspects are used to implement or cooperate with the corresponding methods provided in the first aspect, and therefore can achieve the same or corresponding beneficial effects as the corresponding methods in the first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0094] FIG1 is a schematic structural diagram of a vehicle controller provided in an embodiment of the present application;
[0095] FIG2 is a schematic diagram of a reset initialization process according to an embodiment of the present application;
[0096] FIG3 is a schematic diagram of a method flow chart provided in an embodiment of the present application;
[0097] 4 and 5 are schematic diagrams of the structure of the microcontroller provided in the embodiments of the present application. DETAILED DESCRIPTION
[0098] In the embodiment of the present application, "multiple" refers to two or more. In the embodiment of the present application, "and / or" is used to describe the association relationship of associated objects, indicating three relationships that can exist independently. For example, A and / or B can be expressed as follows: A exists alone, B exists alone, or A and B exist at the same time. The description methods such as "at least one of a1, a2, ... and an" used in the embodiment of the present application include the situation where any one of a1, a2, ... and an exists alone, and also include any combination of any multiple of a1, a2, ... and an, each of which can exist alone; for example, the description method of "at least one of a, b and c" includes the situation where a is alone, b is alone, c is alone, a and b combination, a and c combination, b and c combination, or abc combination.
[0099] In this application, the terms "first," "second," and the like are used to distinguish between identical or similar items having substantially the same function or effect. It should be understood that "first," "second," and "nth" do not have a logical or temporal dependency, nor do they limit the quantity or order of execution. It should also be understood that although the following description uses the terms "first," "second," and the like to describe various elements, these elements should not be limited by these terms. These terms are simply used to distinguish one element from another.
[0100] In the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between the various embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.
[0101] During the use of the vehicle, the controller reset will inevitably occur. Reset can include soft reset (i.e., software reset) and hard reset (i.e., hardware reset). Soft reset refers to a reset triggered by the microcontroller unit (MCU) chip in the controller itself. Hard reset refers to a reset triggered by hardware outside the MCU chip or by power supply, such as a reset triggered by the system base chip, etc. The controller reset involved in the embodiments of the present application includes soft reset and hard reset of the MCU.
[0102] After a controller is reset, many of its functions will undergo a re-evaluation process. If the activation conditions for a function are not met, the function cannot be restored to its pre-reset state, resulting in a poor user experience and even a potential safety hazard to passengers in certain operating conditions.
[0103] For example, in one scenario, if a vehicle controller (such as an electronic control unit (ECU)) is reset while the vehicle is charging, the controller may not be able to re-enter the charging state. If the user returns to the vehicle several hours later and finds that the vehicle is still in a low battery state, the user experience will be affected.
[0104] For example, in another scenario, a vehicle usually needs to meet at least two conditions to enter a drivable state: 1. The gear is in P (parking gear) or N (neutral gear), and 2. The vehicle speed is 0. If the vehicle is driving at a constant speed on the highway or accelerating to overtake, if the vehicle controller is reset at this time. Since the vehicle cannot meet these two conditions at this time, the controller cannot re-enter the driving state. The vehicle will lose power and the user must pull over and re-power on and shift gears, which poses a safety risk.
[0105] For example, in another scenario, if a vehicle is turning while using an advanced driving assistance system (ADAS), if the vehicle controller is reset, the vehicle may lose power and the ADAS's lateral control capability as well, posing a safety risk.
[0106] It will be understood that the above-described scenarios are merely examples and do not constitute a limitation to the embodiments of the present application.
[0107] Given the problem of poor user experience or safety hazards caused by vehicle controller resets, quickly restoring functional functionality after a controller reset is crucial. To address this issue, embodiments of the present application provide a reset and recovery method and related apparatus that can quickly restore functional functionality after a vehicle controller reset, reducing safety hazards and improving the user experience. An exemplary description is provided below.
[0108] First, referring to FIG1 , a schematic diagram illustrating the structure of a vehicle controller 100 according to an embodiment of the present application is shown. As can be seen, the controller 100 may include a microcontroller unit (MCU) 110, a system basic chip (SBC) 120, and a transceiver 130. The SBC 120 and the transceiver 130 are connected to the microcontroller 110.
[0109] Exemplarily, the microcontroller 110 integrates multiple functional units such as a microprocessor, a memory, an input / output interface, a timer and a counter. In addition, the microcontroller 110 is also deployed with an operating system (OS) software and one or more application layer software. The one or more application layer software can be used to implement one or more of the following functions: a vehicle's high-voltage management function, a powertrain (PT) ready arbitration function, a gear arbitration function, a vehicle mode arbitration function, a driving mode arbitration function, a single-pedal mode arbitration function, an accelerator pedal processing function, a power anti-theft function, and a torque filtering function, etc. It will be understood that the description of the functions that can be implemented by the application layer software here is only an example and does not constitute a limitation on the embodiments of the present application. In a specific implementation, the application layer software deployed in the microcontroller 110 can also implement other more or fewer functions, and the embodiments of the present application are not limited to this.
[0110] For example, in a specific implementation, the system basis chip 120 may be used to supply power to the microcontroller 110 and to perform functions such as detecting and diagnosing the safety status of the microcontroller 110 .
[0111] For example, the transceiver 130 can enable communication between the microcontroller 110 and other controllers or components in the vehicle. For example, the transceiver 130 can be a controller area network (CAN) transceiver, a local interconnect network (LIN) transceiver, or an Ethernet transceiver (e.g., a port physical layer (PHY) chip).
[0112] For example, the controller 100 may be a vehicle control unit (VCU), a hybrid control unit (HCU), a vehicle domain controller (VDC), a vehicle intranet unit (VIU), or an intelligent driving controller, etc. The embodiments of the present application do not limit the specific type of the controller 100.
[0113] Illustratively, after the microcontroller 110 receives power from the system basis chip 120, it first needs to complete a power-up process. This power-up process is illustrated in FIG2 . Illustratively, after the microcontroller 110 receives power from the system basis chip 120, it first performs a hardware self-test. This hardware self-test process is entirely performed by the internal circuitry of the microcontroller 110.
[0114] In one possible implementation, the hardware self-test is not a required process for powering on the controller. For example, whether to perform a hardware self-test during power-on can be configured based on actual application needs. This embodiment of the present application is not limited to this. The description of the embodiment of the present application uses the configuration of a hardware self-test as an example.
[0115] After the microcontroller 110 completes the hardware self-test, it enters the software startup (boot) phase. In this phase, the first line of code starts to run. For example, under normal circumstances, the application layer software and data are stored in flash memory (flash) or in read-only memory (ROM). In one possible implementation, in the boot phase, the microcontroller 110 can load the application layer software and data into the memory space of the microcontroller 110 (for example, into the internal random access memory (RAM)) for execution. In another possible implementation, in the boot phase, the microcontroller 110 does not need to load the application layer software and data into the memory space of the microcontroller 110, and can run directly in the flash.
[0116] After the above-mentioned boot phase is completed, the software initialization phase begins. For example, the software initialization phase mainly includes steps such as software security self-check, driver initialization, operating system startup and communication protocol stack initialization. Among them, the software security self-check can ensure the security of the software and prevent it from being maliciously tampered with. Driver initialization can realize external driving. Operating system startup can provide an environment for normal operation of application layer software. Communication protocol stack initialization can prepare for communication between the microcontroller 110 and the outside. The communication protocol stack can communicate with the transceiver 130 to realize communication between the microcontroller 110 and the outside. It can be understood that the software initialization process shown in Figure 2 is only an example. In the specific implementation, the order of the various steps in the software initialization phase may not be restricted, or the software initialization phase may include more or fewer steps, which can be set specifically according to actual application requirements. The embodiments of the present application do not impose any restrictions on this.
[0117] After the above software initialization phase is completed, the operating system starts to schedule the application layer software, and the application layer software starts to run normally.
[0118] 2 , when the microcontroller 110 is operating normally, it periodically outputs a signal to the watchdog timer (WTD) in the system basis chip 120. This process is called "watchdog feeding" and is used to detect whether the microcontroller 110 is operating normally.
[0119] It can be understood that the structure of the controller 100 shown in Figures 1 and 2 is only an example and does not constitute a limitation to the embodiments of the present application.
[0120] Based on the above introduction, in order to quickly restore the vehicle's functional state after the vehicle controller is reset, the present application provides a reset recovery method. For example, see Figure 3. The method includes but is not limited to the following steps:
[0121] S301 : The microcontroller completes software initialization in response to a reset instruction.
[0122] Exemplarily, the microcontroller may be the microcontroller 110 shown in FIG. 1 or 2 .
[0123] In a specific implementation, the microcontroller is triggered to reset due to the detection of an abnormality. For example, the microcontroller usually has corresponding reliability and safety requirements. Therefore, after the software is running, the reset trigger detection function module (which can be a software module or a hardware module) in the system basis chip (such as the system basis chip 120 shown in Figure 1 or Figure 2 above) and / or the microcontroller can detect the microcontroller abnormality by polling. And when an abnormality is detected, a reset instruction is sent to the microcontroller to trigger the reset of the microcontroller. For example, the reset instruction can be, for example, an electrical signal or a variable that notifies the microcontroller to reset, etc., and the embodiments of the present application are not limited to this.
[0124] For example, the polling detection may continue until the entire driving cycle ends (eg, until power-off ends). Resetting is a common controller recovery measure, and system transient failures can usually be repaired by resetting, allowing the controller to continue operating.
[0125] For example, the above-mentioned abnormality may be a self-test error of the microcontroller, a stack overflow error, or a program flow monitoring error, etc., which is not limited in the present embodiment. For ease of understanding, the following is an exemplary introduction in conjunction with a specific vehicle usage scenario.
[0126] For example, in scenario one, the vehicle is operating normally, the PTReady state is ready, the gear is in R (reverse), N (neutral), or D (drive), the vehicle is driving in the first driving mode (such as sport mode or economy mode), and the vehicle's single-pedal mode is in the single-pedal off state. In this scenario, if the vehicle's microcontroller detects an anomaly, such as a scheduling timeout in the program flow, it will trigger a reset of the microcontroller, attempting to resolve the anomaly by resetting and restarting.
[0127] For example, in scenario 2, the vehicle is stationary, the PTReady state is not ready, and the gear is in P. The vehicle is charging or discharging externally (for example, when camping, using the vehicle's high-voltage battery to power external electrical devices). In this scenario, if the vehicle's microcontroller detects an anomaly, such as a self-test error, it will trigger a microcontroller reset, attempting to resolve the anomaly through a reset and restart.
[0128] It is understood that the above-mentioned reset scenario is only an example and does not constitute a limitation on the embodiments of the present application. In specific implementations, there may be more other reset scenarios, which are not limited by the embodiments of the present application.
[0129] For example, after the microcontroller is reset, it will re-enter the boot phase and then restart the power-on process from the boot phase. That is, the microcontroller will re-initialize the software. For details, please refer to the introduction of Figure 2 above and will not be repeated here.
[0130] S302. The microcontroller obtains variable information; the variable information includes state information of a target function before the reset occurs, and the target function includes a function started by the vehicle before the reset occurs.
[0131] For example, the target functions may include one or more of the following: high-voltage management, powertrain readiness arbitration, gear position, vehicle mode, single-pedal mode, accelerator pedal processing, powertrain anti-theft, and torque filtering. It should be understood that the functions described herein are merely examples and do not constitute limitations on the embodiments of this application. In specific implementations, more or fewer functions may be included, and this embodiment does not impose any limitations thereto.
[0132] For example, to facilitate the following description, the software module used to implement the above-mentioned target function is referred to as the target function module. For example, the target function module includes one or more of the following: a high-voltage management module, a power system preparation completion arbitration module, a gear arbitration module, a vehicle mode arbitration module, a single-pedal mode arbitration module, an accelerator pedal processing module, a power anti-theft module, and a torque filtering module. It will be understood that the function modules described here are merely examples and do not constitute a limitation on the embodiments of the present application. In a specific implementation, more or fewer function modules may be included, and this embodiment does not impose any limitation on this.
[0133] Exemplarily, the above-mentioned variable information may include one or more of the following: vehicle energy control request, vehicle high-voltage mode request, high-voltage enable flag, battery management system (BMS) high-voltage status, vehicle high and low voltage status, charge and discharge status, PTready status, vehicle gear, pedal learning value, power anti-theft status, vehicle mode, driving mode, single pedal mode, scenario mode, steering mode, and electronic stability control system (ESC) mode. It will be understood that the variable information introduced here is only an example and does not constitute a limitation on the embodiments of the present application. In a specific implementation, more or less variable information may be included, and this embodiment does not limit this.
[0134] For example, in a specific implementation, the microcontroller may obtain variable information after completing software initialization. In one possible implementation, the variable information may be obtained from a target storage area of the microcontroller. For example, in a specific implementation, during normal vehicle operation, the vehicle may periodically store the status of the target function in the target storage area. After the microcontroller resets, the variable information obtained from the target storage area may be the status information of the target function last stored in the target storage area before the reset.
[0135] Exemplarily, the above-mentioned target storage area is not affected by software initialization. Exemplarily, during the software initialization phase, the target memory in the microcontroller is also initialized. That is, the data in the target memory will be erased. In an embodiment of the present application, in one possible implementation, the above-mentioned target storage area may be a storage area of the microcontroller's memory. And when configuring memory initialization, the address segment of the target storage area is excluded, that is, the address segment is not on the target memory address segment of memory initialization. That is, the target storage area does not belong to the area in the target memory. Therefore, the data written before the reset can still be saved after the reset initialization. In another possible implementation, the target storage area may also not be affected by the hardware reset, that is, the data in the target storage area will not be erased after the hardware reset. Therefore, the state before the reset can be quickly restored based on the data in the target storage area.
[0136] In another embodiment, the target storage area may be a storage area of an external memory of the microcontroller, and the external memory may not be erased along with software initialization, so that data written before the reset can still be saved after the reset initialization.
[0137] For example, the memory of the microcontroller or the external memory of the microcontroller may be a memory that can be both written and read. For example, it may be a random access memory (RAM) or a flash memory. The embodiment of the present application does not limit the type of the memory.
[0138] In one possible implementation, to ensure the security of the data in the target storage area, a security mechanism with the highest security level may be configured for the target storage area. For example, one or more of the following protection mechanisms may be configured: an error checking and correction code (ECC) mechanism, an error detection and correction bit (EDC) mechanism, and an access protection mechanism. This embodiment of the present application is not limited to this.
[0139] In one possible implementation, after the microcontroller completes the software initialization in response to the reset, the operating system in the microcontroller begins to schedule the application layer software (including the target function module) to run. That is, the vehicle starts to operate normally. Since the vehicle will periodically store the status of the target function in the target storage area during normal operation. After the software scheduling of the application layer is completed, new status information will be generated and stored in the target storage area. In order to ensure that the variable information obtained from the target storage area is the status information stored for the last time before the reset, the microcontroller can read the variable information from the target storage area within the first operating system scheduling cycle after the software initialization is completed. Exemplarily, the operating system scheduling cycle can be, for example, 1 millisecond to 100 milliseconds, for example, 5 milliseconds, 10 milliseconds or 20 milliseconds, etc. The implementation of this application does not impose any restrictions on the length of the scheduling cycle.
[0140] In another possible implementation, since the vehicle periodically stores the status of the target function in the target storage area during normal operation, after the reset occurs, the microcontroller can suspend the write function of the target storage area in response to the reset instruction. And after the microcontroller completes the software initialization, the variable information is read from the target storage area in a timely manner. Exemplarily, the microcontroller can read the variable information from the target storage area within one to three scheduling cycles after the software initialization is completed. After the microcontroller reads the variable information, the write function of the target storage area can be enabled. This allows the vehicle to continue to periodically store the status of the target function in the target storage area during normal operation, in preparation for use when the next reset occurs.
[0141] For example, the microcontroller may suspend the write function of the target storage area in response to the reset instruction. For example, the microcontroller may send a notification to the application layer software including the target functional module to suspend the storage of status information to the target storage area. Alternatively, the microcontroller may directly disable the write function of the target storage area, for example, by causing the storage controller of the target storage area to no longer write information to the target storage area. It should be understood that the description herein is merely illustrative and does not constitute a limitation on the embodiments of the present application.
[0142] In another possible implementation, after the microcontroller completes software initialization, it can receive the variable information from the target device. The target device is a device independent of the microcontroller and can be used to store the variable information. For example, the target device can be a cloud server, or a terminal device that can communicate with the vehicle (such as a mobile phone, tablet or smart wearable device, etc.), or other controllers in the vehicle, etc., and the embodiments of the present application are not limited to this.
[0143] For example, in a specific implementation, during normal vehicle operation, the vehicle may periodically or trigger-wise transmit the target function status to the target device for storage. After the microcontroller resets, the microcontroller may transmit a request to the target device to obtain the variable information. The target device, in response to the request, transmits the variable information to the microcontroller. The variable information transmitted by the target device to the microcontroller may be the target function status information last stored in the target device before the reset.
[0144] S303. When the variable information indicates that the reset is an abnormal reset, the microcontroller skips the start condition judgment logic of the target function and sets the state of the target function to a target state based on the variable information, where the target state is the functional state of the target function before the reset.
[0145] For example, in a specific implementation, after obtaining the variable information, the microcontroller can determine whether the reset is an abnormal reset based on the variable information. Specifically, it can determine whether the reset occurred while the vehicle was providing the target function. If so, it is an abnormal reset. To facilitate understanding, the following examples are presented in conjunction with the two scenarios in step S301.
[0146] For example, in Scenario 1, where a reset occurs, the variable information obtained by the microcontroller after software reinitialization may include PTready status information. Based on this PTready status information, the microcontroller can determine whether the reset is abnormal. Specifically, if the PTready status information indicates that the powertrain is ready, i.e., in the ready state, this indicates that the vehicle was already operating normally before the reset (e.g., see the vehicle status described above for Scenario 1). If a reset occurs at this point, it can be determined to be an abnormal reset.
[0147] Alternatively, for example, for scenario 1 above, the variable information obtained by the microcontroller after software reinitialization may include vehicle gear information. The microcontroller can then determine whether the reset is abnormal based on the vehicle gear information. For example, if the vehicle gear information indicates that the vehicle is in R, N, or D, this indicates that the vehicle was reversing (corresponding to R), temporarily parked (corresponding to N), or moving forward normally (corresponding to D) before the reset occurred. If a reset occurs at this time, it can be determined that the reset is abnormal.
[0148] Alternatively, for example, in scenario 1 above, the variable information obtained by the microcontroller after software reinitialization may include information about the vehicle's driving mode. The microcontroller can then determine whether the reset is abnormal based on the driving mode information. For example, if the driving mode information indicates that the vehicle is in Sport mode or Economy mode, this indicates that the vehicle was operating normally before the reset occurred. If a reset occurs at this point, it can be determined to be an abnormal reset.
[0149] It is understood that the above description of determining an abnormal reset in Scenario 1 is merely an example. In a specific implementation, abnormal reset can also be determined based on status information such as the vehicle energy control request, vehicle high-voltage mode request, high-voltage enable flag, BMS high-voltage status, vehicle high and low voltage status, pedal learning value, power anti-theft status, vehicle mode, single-pedal mode, scenario mode, steering mode, or ESC mode. This embodiment of the present application does not elaborate on this one by one.
[0150] In another possible implementation, to more accurately determine whether a reset is abnormal, a comprehensive determination can be made using one or more of the aforementioned information. For example, if more than half of the multiple pieces of information can be used to determine an abnormality, then the reset can be determined to be abnormal. Alternatively, for example, a weighted calculation can be performed on the judgment results of the multiple pieces of information to ultimately determine whether the reset is abnormal. It should be understood that the descriptions herein are merely examples and do not constitute a limitation on the embodiments of the present application.
[0151] For example, for the above scenario 2, that is, the above reset occurs under the situation of this scenario 2, the above variable information obtained by the microcontroller after re-initializing the software may include information on the charge and discharge status of the battery in the vehicle. Then, the microcontroller can determine whether it is an abnormal reset based on the indication of the battery charge and discharge status information. Specifically, if the battery charge and discharge status information indicates that the battery is in a charging state or in an external discharge state (for example, the battery supplies power to electrical equipment outside the vehicle), it indicates that before the reset occurs, the vehicle is providing a high-voltage management function and / or a vehicle mode arbitration function (arbitration provides a charging mode or a discharge mode). If a reset occurs at this time, it can be determined that the reset is an abnormal reset.
[0152] It will be understood that the above description on determining abnormal reset is merely an example and does not constitute a limitation to the embodiments of the present application.
[0153] In a specific implementation, after the microcontroller determines that the reset is an abnormal reset, it can skip the target function's start condition determination logic and directly set the target function's state to the state before the reset based on the variable information. For ease of description below, the state of the target function before the reset will be referred to as the target state.
[0154] In one possible implementation, the state of the above-mentioned target function can be restored within a first preset duration. Exemplarily, the value of the first preset duration is between three times the scheduling period and eight times the scheduling period. The scheduling period is the scheduling period of the operating system in the above-mentioned microcontroller. For example, assuming that the scheduling period is 10 milliseconds, the microcontroller can complete the state of the above-mentioned target function between 30 milliseconds and 80 milliseconds. For another example, assuming that the scheduling period is 20 milliseconds, the microcontroller can complete the state of the above-mentioned target function between 60 milliseconds and 160 milliseconds. It will be understood that the description of the first preset duration here is only an example and does not constitute a limitation to the embodiments of the present application. For ease of understanding, the following is an exemplary introduction.
[0155] In one possible implementation, the above-mentioned setting of the state of the target function to the target state based on the variable information within the first preset time period may include the following steps: generating a first notification message and a second notification message; the generation time interval of the first notification message and the second notification message is the first preset time period, the first notification message is used to indicate that the target function is restored to the target state (or it may also indicate that this initialization power-on process belongs to a reset power-on process), and the second notification message indicates the function start condition judgment logic of the target function before the reset is restored; in response to the first notification message, starting to set the state of the target function to the target state based on the variable information, and completing the restoration of the target state before restoring the function start condition judgment logic in response to the second notification message.
[0156] Exemplarily, the above-mentioned first notification information and the second notification information can be two values of the first target parameter generated by the microcontroller. The first target parameter can, for example, be a parameter generated by the application layer software module (referred to as the reset recovery module) newly deployed in the microcontroller in the embodiment of the present application. For example, the first target parameter can be specifically expressed as a flag bit, and the value of the flag bit is the above-mentioned first notification information or the second notification information. Exemplarily, the first notification information can be, for example, 0, and the second notification information can be, for example, 1. Alternatively, the first notification information can be, for example, 1, and the second notification information can be, for example, 0. It can be understood that the introduction of the values of the first notification information and the second notification information here is only an example and does not constitute a limitation to the embodiments of the present application.
[0157] For example, in one possible implementation, if the reset occurs while the vehicle is in motion (e.g., see Scenario 1 above), then the flag may be referred to as a "driving reset recovery flag." Alternatively, for example, in one possible implementation, if the reset occurs while the vehicle is in the process of charging or discharging (e.g., see Scenario 2 above), then the flag may be referred to as a "charge and discharge reset recovery flag." It will be understood that the names of the flags herein are merely examples and do not constitute limitations on the embodiments of the present application.
[0158] Specifically, after the microcontroller determines that the reset is an abnormal reset, it may first generate the first notification information. Below, the reset recovery module generates the first notification information as an example. After the reset recovery module generates the first notification information, it may send the first notification information to the target functional module. Furthermore, after the microcontroller determines that the reset is an abnormal reset, the reset recovery module may also send the acquired variable information to the target functional module.
[0159] Exemplarily, the reset recovery module can package the variable information obtained above into a structure, and then send the structure to the target functional module through the runtime environment (RTE). RTE is a specific implementation of the virtual functional bus of the ECU, which supports communication between application layer software components, between basic software (including operating systems, virtualization modules, middleware and other software), and between application layer software components and basic software. It will be understood that the introduction here is only an example and does not constitute a limitation to the embodiments of the present application. In a specific implementation, other methods can also be used to send variable information to the target functional module.
[0160] After the target function module receives the first notification information and variable information, it can start setting the state of the target function to the target state based on the variable information based on the instruction of the first notification information. In addition, after the reset recovery module generates the first notification information, it generates the second notification information after the first preset time period. And send the second notification information to the target function module. Then, the target function module can restore its own function start condition judgment logic based on the instruction of the second notification information. Then, the target function module can complete the restoration of the target state before restoring its own function start condition judgment logic in response to the second notification information. For ease of understanding, the following examples are given in combination with the above-mentioned scenarios one and two.
[0161] For the reset that occurs in the above scenario 1, an exemplary process of recovering the target functional state may include one or more of the following.
[0162] For example, assume that the target functional module includes a high-voltage management module. Upon receiving the first notification message and variable information, the high-voltage management module determines that the first notification message indicates that the function should be restored to its pre-reset state. Based on this, the judgment logic of the high-voltage management module's power-on state machine is skipped, i.e., the logic for determining the startup conditions of the high-voltage management function is skipped, and the state of the high-voltage management function is forcibly set to the high-voltage management function state indicated by the high-voltage enable flag in the variable information. Then, upon receiving the second notification message, the high-voltage management module restores the judgment logic of the high-voltage management module's power-on state machine, i.e., performs a real-time determination based on the vehicle's high-voltage state.
[0163] For example, assume that the target functional module includes a PT Ready arbitration module. Upon receiving the first notification message and variable information, the PT Ready arbitration module determines that the first notification message indicates a function restoration to its pre-reset state. Based on this, assuming the PTready state in the variable information indicates a ready state, the PT Ready arbitration module skips the logic for determining the start condition for the ready state and forcibly sets the PTready state to the ready state. Then, upon receiving the second notification message, the PT Ready arbitration module restores its logic for determining the ready state in real time.
[0164] For example, assume the target functional module includes a gear arbitration module. Upon receiving the first notification and variable information, the gear arbitration module determines that the first notification indicates a function should be restored to its pre-reset state. Based on this, the module bypasses the judgment logic of its gear determination state machine, specifically the logic for determining the activation condition for that gear. The module then forcibly resets the gear state to the actual gear indicated by the vehicle gear position in the variable information. Then, upon receiving the second notification, the module resumes its real-time gear determination logic.
[0165] For example, assuming the target functional module includes a vehicle mode arbitration module (or a single-pedal mode arbitration module). Upon receiving the first notification message and variable information, the vehicle mode arbitration module (or single-pedal mode arbitration module) determines that the first notification message indicates a function restoration to a pre-reset state. Based on this, the vehicle mode arbitration module (or single-pedal mode arbitration module) bypasses its mode activation condition determination logic and forcibly sets the vehicle mode (or single-pedal mode) to the actual mode indicated by the variable information. Then, upon receiving the second notification message, the vehicle mode arbitration module (or single-pedal mode arbitration module) restores its logic for real-time mode determination.
[0166] For example, assume the target functional module includes an accelerator pedal processing module. Upon receiving the first notification message and variable information, the accelerator pedal processing module determines that the first notification message indicates a function restoration to its pre-reset state. Based on this, the accelerator pedal learning process is skipped, specifically, the logic for determining the activation condition for the accelerator pedal state is skipped, and the accelerator pedal's learned value is forcibly set to the value indicated by the pedal learning value in the variable information. Then, upon receiving the second notification message, the accelerator pedal processing module restores its logic for determining the vehicle's accelerator pedal's learned value in real time.
[0167] For example, assume the target functional module includes a power anti-theft module. Upon receiving the first notification message and the variable information, the power anti-theft module determines that the first notification message indicates a function restoration to its pre-reset state. Based on this, the power anti-theft module bypasses the judgment logic of its anti-theft authentication state machine, specifically the logic for determining the activation conditions for the power anti-theft function. The power anti-theft state is forcibly reset to the state indicated by the variable information. Then, upon receiving the second notification message, the power anti-theft module resumes its logic for real-time anti-theft status determination.
[0168] For the reset in the above scenario 2, an exemplary process may include one or more of the following target functional state recovery processes.
[0169] For example, assume that the target functional module includes a high-voltage management module. Upon receiving the first notification message and variable information, the high-voltage management module determines that the first notification message indicates that the function should be restored to its pre-reset state. Based on this, the judgment logic of the high-voltage management module's power-on state machine is skipped, i.e., the logic for determining the startup conditions of the high-voltage management function is skipped, and the state of the high-voltage management function is forcibly set to the high-voltage management function state indicated by the high-voltage enable flag in the variable information. Then, upon receiving the second notification message, the high-voltage management module restores the judgment logic of the high-voltage management module's power-on state machine, i.e., performs a real-time determination based on the vehicle's high-voltage state.
[0170] For example, assume that the target functional module includes a vehicle mode arbitration module. Upon receiving the first notification message and the variable information, the vehicle mode arbitration module determines that the first notification message indicates a function should be restored to its pre-reset state. Based on this, the vehicle mode arbitration module's mode activation condition determination logic is bypassed, and the vehicle mode state is forcibly set to the state indicated by the charge / discharge status in the variable information. Then, upon receiving the second notification message, the vehicle mode arbitration module resumes its logic for real-time determination of the vehicle's charge / discharge mode.
[0171] It is understood that the above description is only an example and does not constitute a limitation on the embodiments of the present application. In a specific implementation, other functional modules may be included to perform corresponding operations in response to the first notification information and the second notification information, which will not be described in detail.
[0172] In one possible implementation, the reset recovery module may periodically send a first notification message to the target functional module within the first preset duration. In this case, the first notification message that triggers the target functional module to begin setting the state of the target function to the target state based on the variable information may be the first notification message sent by the reset recovery module to the target functional module.
[0173] In the above example, the reset recovery module packages the acquired variable information and sends it to each functional module. In another implementation, the reset recovery module can send the variable information required by each functional module to the corresponding functional module. For example, using the PT Ready arbitration module as an example, the reset recovery module can send the variable information required by the PT Ready arbitration module (such as the PTready status) to the PT Ready arbitration module. The remaining variable information can be omitted, thereby saving transmission bandwidth.
[0174] It can be understood that the reset recovery module and the target function module are software modules running in a microcontroller, so the operations performed by these modules described above are all operations performed by the microcontroller.
[0175] In another possible implementation, the above-mentioned setting of the state of the target function to the target state based on the variable information within the first preset time period may include the following steps: starting at a first moment, setting the state of the target function to the target state based on the variable information, and completing the restoration of the target state before a second moment; the first moment and the second moment are separated by the first preset time period; and starting at the second moment to restore the function start condition judgment logic of the target function before the reset.
[0176] Exemplarily, after the microcontroller determines that the reset is an abnormal reset, the reset recovery module can send the variable information obtained above to the target function module. The specific sending introduction can refer to the above introduction and will not be repeated here. After the target function module receives the variable information, it can set the state of the target function to the above target state based on the variable information starting from the first moment. The specific implementation of the recovery can refer to the above introduction and will not be repeated here. Then, the recovery of the target state is completed within the first preset time length starting from the first moment. The function start condition judgment logic of the target function before the reset is restored at the second moment. Exemplarily, a timer can be set from the first moment, and the timer duration is the first preset time length. When the timer time is up, the function start condition judgment logic of the target function before the reset can be restored. The implementation of the specific recovery condition judgment logic can refer to the above introduction and will not be repeated here.
[0177] Alternatively, the reset recovery module may, for example, begin timing when sending variable information to the target functional module. For example, by using a timer. After a first predetermined duration has elapsed, a third notification message may be sent to the target functional module. This third notification message, like the second notification message, may be used to instruct the target functional module to restore the function activation condition judgment logic for the target function prior to the reset. For details, please refer to the relevant description of the second notification message and will not be repeated here.
[0178] It can be understood that the above introduction on the specific implementation of setting the state of the target function to the target state based on variable information within the first preset time period is only an example and does not constitute a limitation to the embodiments of the present application.
[0179] In one possible implementation, assuming the microcontroller is an MCU in a controller that responds to vehicle torque demands, such as the MCU in a VCU, HCU, VIU, or VDC, if the reset occurs during normal vehicle operation (e.g., as described in Scenario 1), torque filtering can be performed after the target state is restored to quickly transition the pre-reset vehicle torque to the vehicle's latest target torque.
[0180] For example, in a specific implementation, if a microcontroller reset occurs while the vehicle is driving, the microcontroller cannot respond to the vehicle's torque requirements during the reset period, resulting in a decrease in vehicle torque. To quickly transition to the vehicle's latest target torque, torque filtering can be implemented using this latest target torque as a target. This latest target torque is calculated by the microcontroller based on the vehicle's latest actual accelerator pedal position and the vehicle's latest actual speed.
[0181] For example, an open-loop or closed-loop torque filtering approach can be used. If an open-loop torque filtering approach is used, the microcontroller can start filtering from 0. That is, the filtering process uses 0 as the initial value of the filtered torque and the latest target torque as the target value for filtering. If a closed-loop torque filtering approach is used, the microcontroller can obtain the vehicle's current actual torque from the motor and then use this actual torque as the initial value of the filtered torque and the latest target torque as the target value for filtering.
[0182] Exemplarily, the torque filtering operation can be implemented by a torque filtering module in a microcontroller. The torque filtering module can receive a notification message (e.g., the second notification message or the third notification message) after the target state is restored. Then, the filtering operation is performed in response to the notification message. After the target state is restored, the torque before the reset is quickly transitioned to the latest target torque through torque filtering, which can reduce vehicle shock and improve user experience.
[0183] In one possible implementation, the microcontroller is unable to properly respond to external requests during the reset process, effectively rendering the vehicle in a node-lost state. To prevent the microcontroller from affecting the normal functioning of peripheral controllers during the reset process, the microcontroller may temporarily disable its external information transmission channels. After the target state is restored, the microcontroller's external information transmission channels are reopened.
[0184] For example, in a specific implementation, the microcontroller's external information transmission channel is constructed by the communication protocol stack within the microcontroller. Therefore, after the microcontroller determines that the reset is an abnormal reset, the reset recovery module may also send a notification message to the communication protocol stack. This notification message may, for example, be the first notification message or another notification message different from the first notification message, although this embodiment of the present application is not limited thereto. The communication protocol stack may, in response to this notification message, close the external information transmission channel. For example, referring to Figure 1 or Figure 2, after closing the external information transmission channel, the communication protocol stack will no longer send information to the transceiver 130. However, it may receive external information from the transceiver 130, such as the torque information from the motor. Subsequently, after the target state is restored, for example, after the reset recovery module sends the notification message to the communication protocol stack and the first preset time has elapsed, the reset recovery module may send another notification message to the communication protocol stack. This other notification message may, for example, be the second notification message, the third notification message, or another notification message, although this embodiment of the present application is not limited thereto. The communication protocol stack may, in response to this other notification message, open the external information transmission channel. For example, referring to FIG. 1 or FIG. 2 , after the external information transmission channel is opened, the communication protocol stack can send information to the transceiver 130 .
[0185] In one possible implementation, in order to prevent the external information transmission channel from being closed for a long time, resulting in the microcontroller still being unable to respond normally to external needs after the target state is restored, a timeout protection mechanism for closing the external information transmission channel can be set. For example, after the communication protocol stack closes the external information transmission channel, if it still does not receive a notification message to open the external information transmission channel after a second preset time period, it will not continue to wait for the notification message, but directly open the external information transmission channel. Exemplarily, the value range of the second preset time period is 200ms to 300ms.
[0186] In summary, the embodiments of the present application can detect an abnormal reset based on the variable information itself, and then restore the functional state before the reset based on the variable information. Compared to the existing technology, this solution does not require re-determining the activation conditions of the vehicle's functional state, nor does it require comparing the current vehicle state with the state before the reset. This can greatly reduce processing time and can quickly restore the functional state after the vehicle controller is reset.
[0187] The above mainly introduces the reset recovery method provided in the embodiment of the present application. It is understandable that, in order to realize the corresponding functions mentioned above, each control unit or device includes a hardware structure and / or software module corresponding to the execution of each function. In combination with the units and steps of each example described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0188] The embodiment of the present application can divide the functional modules of the device according to the above method example. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of modules in the embodiment of the present application is schematic and is only a logical function division. In actual implementation, there may be other division methods.
[0189] In the case of dividing each functional module according to each function, the embodiment of the present application also provides an apparatus for implementing any of the above methods. For example, the provided apparatus includes units (or means) for implementing each step in any of the above methods.
[0190] For example, please refer to Figure 4, which is a schematic diagram of the structure of a microcontroller 400 provided in an embodiment of the present application. The microcontroller 400 shown in Figure 4 can be a microcontroller for implementing any embodiment of the reset recovery method described above. The microcontroller 400 may include a processing unit 401 and an acquisition unit 402.
[0191] The processing unit 401 is configured to complete software initialization in response to a reset instruction;
[0192] An acquisition unit 402 is configured to acquire variable information; the variable information includes state information of a target function before the reset occurs, the target function including a function started by the vehicle before the reset occurs;
[0193] The processing unit 401 is also used to skip the start condition judgment logic of the target function when the variable information indicates that the reset is an abnormal reset, and set the state of the target function to the target state based on the variable information, and the target state is the functional state of the target function before the reset.
[0194] In a possible implementation, the acquiring unit 402 is specifically configured to:
[0195] The variable information is obtained in the first operating system scheduling cycle after the software is initialized.
[0196] In a possible implementation, the processing unit 401 is further configured to:
[0197] When the variable information indicates that the reset is an abnormal reset, closing the external information transmission channel of the microcontroller;
[0198] After the state of the target function is set to the target state based on the variable information, the microcontroller's external information sending channel is opened.
[0199] In one possible implementation, the variable information includes power system readiness information of the vehicle; and the variable information indicates that the reset is an abnormal reset, including:
[0200] In the case where the power system preparation status information indicates that the power system is ready, the reset is an abnormal reset.
[0201] In a possible implementation, the processing unit 401 is further configured to:
[0202] After setting the state of the target function to a target state based on the variable information, obtaining the latest torque information of the vehicle;
[0203] Torque filtering is performed based on the latest torque information.
[0204] In one possible implementation, the variable information includes battery charge and discharge status information of the vehicle; and the variable information indicates that the reset is an abnormal reset, including:
[0205] When the battery charge and discharge status information indicates that the battery is in a charging state or an externally discharging state, the reset is an abnormal reset; the externally discharging state includes the battery supplying power to a device other than the vehicle.
[0206] In a possible implementation, the processing unit 401 is specifically configured to:
[0207] Within a first preset time period, the state of the target function is set to the target state based on the variable information; the value of the first preset time period is between three and eight times the length of the scheduling cycle.
[0208] In a possible implementation, the processing unit 401 is specifically configured to:
[0209] Generate a first notification message and a second notification message; the first notification message and the second notification message are generated at a time interval equal to a first preset time length, the first notification message is used to indicate that the target function is restored to the target state, and the second notification message indicates that the function start condition judgment logic of the target function before the reset is restored;
[0210] In response to the first notification information, the state of the target function starts to be set to the target state based on the variable information, and the restoration of the target state is completed before the function start condition judgment logic is restored in response to the second notification information.
[0211] In a possible implementation, the processing unit 401 is specifically configured to:
[0212] Starting at a first moment, setting the state of the target function to the target state based on the variable information, and completing the restoration of the target state before a second moment; the first moment and the second moment are separated by a first preset time length;
[0213] At the second moment, the function start condition judgment logic of the target function before the reset is restored.
[0214] In a possible implementation, the acquiring unit 402 is specifically configured to:
[0215] Obtain the variable information in a target storage area; the target storage area belongs to the memory or external memory of the microcontroller;
[0216] In a possible implementation, the processing unit 401 is specifically configured to: complete initialization of the target memory of the microcontroller in response to the reset instruction;
[0217] If the target storage area belongs to the memory of the microcontroller, the target storage area belongs to a memory area outside the target memory.
[0218] In one possible implementation, the target storage area is used to periodically write status information of the target function;
[0219] Before acquiring the variable information in the target storage area, the processing unit 401 is further configured to: suspend a write function to the target storage area based on the reset instruction.
[0220] In one possible implementation, the variable information includes one or more of the following:
[0221] Vehicle energy control request, vehicle high-voltage mode request, high-voltage enable flag, battery management system high-voltage status, vehicle high and low voltage status, charge and discharge status, power system readiness status, vehicle gear position, pedal learning value, power anti-theft status, vehicle mode, driving mode, single-pedal mode, scenario mode, steering mode, and electronic stability control system mode.
[0222] In a possible implementation, the processing unit 401 is specifically configured to: after closing the microcontroller's external information transmission channel and after a second preset time period has passed, open the microcontroller's external information transmission channel.
[0223] The specific operations and beneficial effects of each unit in the microcontroller 400 shown in FIG. 4 can be found in the corresponding descriptions in FIG. 2 and its possible embodiments, and will not be repeated here.
[0224] FIG5 is a schematic diagram of a possible hardware structure of a microcontroller provided in this application, which can be the microcontroller used in the method described in the above embodiment. Microcontroller 500 includes a processor 501, a memory 502, and a communication interface 503. Processor 501, communication interface 503, and memory 502 can be interconnected or connected via a bus 504.
[0225] Exemplarily, the memory 502 is used to store computer programs and data of the microcontroller 500. The memory 502 may include, but is not limited to, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), or portable read-only memory (CD-ROM).
[0226] The software or program codes required for the functions of all or part of the units of the terminal device in the above method embodiment are stored in the memory 502 .
[0227] In one possible implementation, if the software or program code required for the functions of some units is stored in the memory 502, the processor 501, in addition to calling the program code in the memory 502 to implement some functions, can also cooperate with other components (such as the communication interface 503) to jointly complete other functions described in the method embodiment (such as the function of receiving or sending data).
[0228] There may be multiple communication interfaces 503 for supporting the microcontroller 500 to communicate, such as receiving or sending data or signals.
[0229] Exemplarily, processor 501 may be a central processing unit (CPU), a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic device (PLD), a transistor logic device (TLD), a hardware component, or any combination thereof. A processor may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and so on. Processor 501 may be configured to read programs stored in memory 502 and execute the operations performed by the microcontroller in the method described in FIG. 2 and its possible embodiments.
[0230] The specific operations and beneficial effects of each unit in the microcontroller 500 shown in FIG5 can be found in the corresponding descriptions in the above method embodiments, which will not be repeated here.
[0231] An embodiment of the present application also provides a vehicle, which includes the microcontroller described in any of the above embodiments or the controller 100 shown in Figure 1 above.
[0232] An embodiment of the present application further provides a computer-readable storage medium storing a computer program, which is executed by a processor to implement the operations performed by the microcontroller of any one of the above-mentioned embodiments and possible embodiments thereof.
[0233] The embodiments of the present application also provide a computer program product. When the computer program product is read and executed by a computer, the operations performed by the microcontroller in any of the above embodiments and possible embodiments thereof will be executed.
[0234] It should be understood that in the various embodiments of the present application, the size of the serial number of each process does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0235] It will also be understood that the term “comprise” (also known as “includes,” “including,” “comprises,” and / or “comprising”) when used in this specification specifies the presence of stated features, integers, steps, operations, elements, and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0236] It should also be understood that references throughout this specification to "one embodiment," "an embodiment," or "one possible implementation" mean that specific features, structures, or characteristics associated with that embodiment or implementation are included in at least one embodiment of the present application. Therefore, the appearance of "in one embodiment," "in an embodiment," or "one possible implementation" throughout this specification does not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
[0237] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some or all of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present application.
Claims
1. A reset and recovery method, characterized in that, The method is applied to a microcontroller of a vehicle, and the method includes: Completing software initialization in response to a reset instruction; Obtaining variable information; the variable information includes the status information of a target function before the reset occurs, and the target function includes the functions that the vehicle starts before the reset occurs; In the case where the variable information indicates that the reset belongs to an abnormal reset, skipping the startup condition judgment logic of the target function, and setting the status of the target function to a target status based on the variable information, where the target status is the functional status of the target function before the reset.
2. The method according to claim 1, characterized in that, The obtaining of the variable information includes: Obtaining the variable information within the first operating system scheduling cycle after the software initialization is completed.
3. The method according to claim 1 or 2, characterized in that, In the case where the variable information indicates that the reset belongs to an abnormal reset, the method further includes: closing the information sending channel of the microcontroller to the outside; After setting the status of the target function to the target status based on the variable information, it further includes: opening the information sending channel of the microcontroller to the outside.
4. The method according to any one of claims 1 to 3, characterized in that The variable information includes the power system readiness status information of the vehicle; The variable information indicating that the reset belongs to an abnormal reset includes: In the case where the power system readiness status information indicates that the power system is ready, the reset belongs to an abnormal reset.
5. The method according to claim 4, wherein After setting the status of the target function to the target status based on the variable information, it further includes: Obtaining the latest torque information of the vehicle; Performing torque filtering based on the latest torque information.
6. The method according to any one of claims 1-5, characterized in that The variable information includes the battery charge and discharge status information of the vehicle; The variable information indicating that the reset belongs to an abnormal reset includes: In the case where the battery charge and discharge status information indicates that the battery is in a charging state or an external discharging state, the reset belongs to an abnormal reset; The external discharging state includes the battery supplying power to devices outside the vehicle.
7. The method according to any one of claims 1-6, characterized in that, The setting of the status of the target function to the target status based on the variable information includes: Within a first preset duration, setting the status of the target function to the target status based on the variable information; the value of the first preset duration is between three and eight times the duration of the scheduling cycle.
8. The method according to claim 7, wherein The setting of the status of the target function to the target status within the first preset duration based on the variable information includes: Generating a first notification message and a second notification message; the generation time interval between the first notification message and the second notification message is the first preset duration, the first notification message is used to indicate restoring the target function to the target status, and the second notification message indicates restoring the function startup condition judgment logic before the reset; In response to the first notification message, starting to set the status of the target function to the target status based on the variable information, and completing the restoration of the target status before restoring the function startup condition judgment logic in response to the second notification message.
9. The method according to claim 7, characterized in that, The setting of the status of the target function to the target status within the first preset duration based on the variable information includes: At the first moment, start setting the state of the target function to the target state based on the variable information, and complete the restoration of the target state before the second moment; the first moment and the second moment are separated by the first preset duration; At the second moment, start restoring the function startup condition judgment logic of the target function before the reset.
10. The method according to any one of claims 1-9, characterized in that, The obtaining the variable information includes: Obtaining the variable information in the target storage area; the target storage area belongs to the internal memory or external memory of the microcontroller.
11. The method according to claim 10, characterized in that, The responding to the reset instruction to complete the software initialization includes: responding to the reset instruction to complete the initialization of the target memory of the microcontroller; If the target storage area belongs to the internal memory of the microcontroller, the target storage area belongs to the memory area outside the target memory.
12. The method according to claim 10 or 11, characterized in that, The target storage area is used to periodically write the status information of the target function; before obtaining the variable information in the target storage area, it further includes: suspending the writing function of the target storage area based on the reset instruction.
13. The method according to any one of claims 1 to 10, characterized in that, The obtaining the variable information includes: Receiving the variable information from the target device; the target device is independent of the microcontroller and can be used to store the variable information.
14. The method according to any one of claims 1-13, characterized in that, The variable information includes one or more of the following: Vehicle energy control request, vehicle high-voltage mode request, high-voltage enable flag, battery management system high-voltage state, vehicle high-low voltage state, charge-discharge state, powertrain ready state, vehicle gear, pedal learning value, power anti-theft state, vehicle mode, driving mode, single-pedal mode, scenario mode, steering mode, and electronic stability control system mode.
15. The method according to claim 3, wherein The opening the information sending channel of the microcontroller to the outside includes: After a second preset duration from closing the information sending channel of the microcontroller to the outside, open the information sending channel of the microcontroller to the outside.
16. A microcontroller, characterized in that, The microcontroller includes: A processing unit for responding to the reset instruction to complete the software initialization; An obtaining unit for obtaining variable information; the variable information includes the status information of the target function before the reset occurs, and the target function includes the function of starting the vehicle before the reset occurs; The processing unit is further configured to, when the variable information indicates that the reset belongs to an abnormal reset, skip the function startup condition judgment logic of the target function, and set the state of the target function to the target state based on the variable information, and the target state is the function state of the target function before the reset.
17. The microcontroller according to claim 16, characterized in that, The obtaining unit is specifically configured to: Obtain the variable information within the first operating system scheduling cycle after the software initialization is completed.
18. The microcontroller according to claim 16 or 17, characterized in that, The processing unit is further configured to: When the variable information indicates that the reset belongs to an abnormal reset, close the information sending channel of the microcontroller to the outside; And after setting the state of the target function to the target state based on the variable information, open the information sending channel of the microcontroller to the outside.
19. The microcontroller according to any one of claims 16-18, characterized in that, The variable information includes the powertrain ready state information of the vehicle; The variable information indicating that the reset belongs to an abnormal reset includes: When the power system preparation status information indicates that the power system is ready, the reset belongs to an abnormal reset.
20. The microcontroller according to claim 19, characterized in that, The processing unit is further configured to: After setting the state of the target function to the target state based on the variable information, obtain the latest torque information of the vehicle; Perform torque filtering based on the latest torque information.
21. The microcontroller according to any one of claims 16-20, characterized in that, The variable information includes the battery charge and discharge status information of the vehicle; The variable information indicating that the reset belongs to an abnormal reset includes: When the battery charge and discharge status information indicates that the battery is in a charging state or an external discharging state, the reset belongs to an abnormal reset; The external discharging state includes the battery supplying power to devices outside the vehicle.
22. The microcontroller according to any one of claims 16-21, characterized in that, The processing unit is specifically configured to: Within a first preset duration, set the state of the target function to the target state based on the variable information; the value of the first preset duration is between three and eight times the duration of the scheduling period.
23. The microcontroller according to claim 22, characterized in that, The processing unit is specifically configured to: Generate a first notification message and a second notification message; the generation time of the first notification message and the second notification message is separated by the first preset duration, the first notification message is used to indicate restoring the target function to the target state, and the second notification message indicates restoring the function startup condition judgment logic of the target function before the reset; In response to the first notification message, start setting the state of the target function to the target state based on the variable information, and complete the restoration of the target state before restoring the function startup condition judgment logic in response to the second notification message.
24. The microcontroller according to claim 22, wherein The processing unit is specifically configured to: Start setting the state of the target function to the target state based on the variable information at a first moment, and complete the restoration of the target state before a second moment; the first moment and the second moment are separated by the first preset duration; Start restoring the function startup condition judgment logic of the target function before the reset at the second moment.
25. The microcontroller according to any one of claims 16-24, characterized in that, The obtaining unit is specifically configured to: Obtain the variable information in the target storage area; the target storage area belongs to the internal memory or external memory of the microcontroller.
26. The microcontroller according to claim 25, characterized in that, The processing unit is specifically configured to: in response to the reset instruction, complete the initialization of the target memory of the microcontroller; If the target storage area belongs to the internal memory of the microcontroller, the target storage area belongs to the memory area outside the target memory.
27. The microcontroller according to claim 25 or 26, characterized in that, The target storage area is used to periodically write the status information of the target function; Before obtaining the variable information in the target storage area, the processing unit is further configured to: pause the write function of the target storage area based on the reset instruction.
28. The microcontroller according to any one of claims 16-27, characterized in that, The variable information includes one or more of the following: Vehicle energy control request, vehicle high-voltage mode request, high-voltage enable flag, battery management system high-voltage state, vehicle high and low voltage state, charge and discharge state, power system preparation state, vehicle gear, pedal learning value, power anti-theft state, vehicle mode, driving mode, single-pedal mode, scenario mode, steering mode, and electronic stability control system mode.
29. The microcontroller according to claim 18, wherein, The processing unit is specifically configured to: after a second preset duration has passed since the information sending channel of the microcontroller to the outside is closed, open the information sending channel of the microcontroller to the outside.
30. A microcontroller, characterized in that, The microcontroller includes a processor and a memory. Among them, the memory is used to store computer programs or computer instructions, and the processor is used to execute the computer programs or computer instructions stored in the memory, so that the microcontroller executes the method described in any one of claims 1-15.
31. A controller, characterized in that, The controller includes a system base chip, a transceiver, and a microcontroller; among them, the microcontroller is the microcontroller described in any one of claims 16-29, or the microcontroller described in claim 30; the system base chip is used to supply power to the microcontroller; the transceiver is used to provide external communication for the microcontroller.
32. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer programs or computer instructions, and the computer programs or computer instructions are executed by a processor to implement the method described in any one of claims 1-15.
Citation Information
Patent Citations
Reset recovery method and related device
CN120363933A
Monitoring method and device based on polling protocol, and readable storage medium
CN108632108A
Abnormity recovery method and device of whole vehicle network, vehicle and storage medium
CN115220379A
Vehicle control method and device, vehicle and storage medium
CN115431900A
Power recovery method and device for new energy automobile, terminal and storage medium
CN115891655A