Controller monitoring system facilitating batch flashing, and vehicle
By setting up multiple control branches connected to the mode configuration pins in the controller monitoring system, and using the pin signals of the DC-DC chip and watchdog chip for control, the microcontroller can be automatically reset and its status monitored. This solves the problem of the controller monitoring system reducing the efficiency of vehicle mass production and improves the reliability and safety of the system.
Patent Information
- Application Number
- PCT/CN2025/103576
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-06-26
- Filing Date
- 2025-06-25
- Publication Date
- 2026-01-02
AI Technical Summary
In the existing technology, the controller monitoring system cannot effectively monitor the status of the microcontroller when the system is powered on for the first time, resulting in low mass production efficiency. In particular, it cannot restart in time when abnormal situations occur during the microcontroller startup process, which affects the mass production efficiency of the whole vehicle.
By setting up multiple control branches and connecting them to the mode configuration pins in the controller monitoring system, and utilizing the enable pin of the watchdog chip to sleep or work under specific signal levels, combined with the signal control of the power status indicator pin of the DC-DC chip and the watchdog output pin, the microcontroller can be automatically reset and its status monitored. This ensures that the watchdog chip sleeps in flashing mode and automatically enters working mode after the flashing process is completed.
It improves the efficiency of mass production of the whole vehicle, avoids the defect that the watchdog chip cannot work when the microcontroller is not started, ensures that the system can be reset in time under abnormal conditions, and improves the reliability and safety of the system.
Smart Images

Figure CN2025103576_02012026_PF_FP_ABST
Abstract
Description
Controller monitoring system facilitating batch flashing and vehicle TECHNICAL FIELD
[0001] The present application relates to the technical field of controller monitoring, in particular to a controller monitoring system facilitating batch flashing and a vehicle. The present application claims priority to the patent application with the application number 202410841163.6, the title of which is "Controller monitoring system facilitating batch flashing and vehicle", which was filed with the State Intellectual Property Office of China on June 26, 2024. BACKGROUND
[0002] With the rapid development of the automobile industry, each link of vehicle manufacturing becomes more intelligent and specialized. Whether in the research and development stage of regional controllers or in the vehicle assembly stage, each vehicle manufacturer is striving to improve the efficiency of mass production and ensure system reliability. Under normal circumstances, after the patch factory completes batch patching, the system needs to be powered on for the first time and the software program of the microcontroller needs to be flashed to complete the function test of the controller and ensure the normal and safe operation of the controller. However, as the scale of mass production increases and the number of controllers increases, it is difficult to ensure that all microcontrollers are running normally throughout the process, so an external monitoring chip needs to be added to ensure that the monitoring chip can effectively identify and reset the microcontroller when the main chip (e.g., MCU) encounters abnormal conditions such as program running dead. However, during the first power-on of the system, the microcontroller has no software program, and during this period, the watchdog chip needs to be put into a sleep state, and after the burning is completed, the watchdog chip needs to be put into a working state to monitor the state of the microcontroller. In the prior art, the enable pin of the watchdog chip is provided with an enable signal through the pin of the controller MUC, that is, the watchdog chip needs to be controlled to work after the controller MUC is started. If the controller MUC encounters an abnormal condition such as freezing during startup, the watchdog chip does not enter a working state at this time, and the restart function cannot be realized, thereby reducing the software program burning efficiency during the mass production offline stage and reducing the efficiency of vehicle mass production. SUMMARY
[0003] The main purpose of the present application is to provide a controller monitoring system facilitating batch flashing and a vehicle to solve the problem that the controller monitoring system will reduce the efficiency of vehicle mass production when working.
[0004] In order to achieve the above object, according to one aspect of the present application, a controller monitoring system facilitating batch flashing is provided, comprising: an MCU chip, the MCU chip being provided with a reset pin, an interface pin and a plurality of mode configuration pins, wherein the reset pin is used to reset the MCU chip to an initial state, each mode configuration pin is connected with a power supply and turned on, and when the plurality of mode configuration pins are in a specific level state combination, the MCU chip enters a flashing mode; a watchdog chip, the watchdog chip being provided with a watchdog input pin, a watchdog output pin and a watchdog enable pin, the watchdog input pin being connected with the interface pin and turned on, the interface pin being used to periodically send a feed dog signal to the watchdog input pin, and the watchdog output pin being connected with the reset pin and turned on; wherein the watchdog enable pin has an open state for opening the feed dog mode under a first level signal, and the watchdog enable pin has a dormant state for closing the feed dog mode under a second level signal; and a control circuit, the control circuit having a plurality of control branches, the plurality of control branches being correspondingly provided with the plurality of mode configuration pins, each control branch being connected with the power supply and turned on, and each control branch being used to adjust the level state of the corresponding mode configuration pin, when the MCU chip is in the flashing mode, at least one of the plurality of control branches is connected with the watchdog enable pin and turned on, so that the control branch controls the second level signal to be sent to the watchdog enable pin.
[0005] Further, the controller monitoring system facilitating batch flashing further comprises: a DCDC chip, the DCDC chip being provided with a DCDC output pin, the MCU chip being provided with a power supply input pin, the DCDC output pin being connected with the power supply input pin and turned on, and the DCDC chip being used to transmit the external power supply after voltage conversion to the MCU chip.
[0006] Further, the DCDC chip is provided with a power supply state indication pin, the power supply state indication pin being connected with the reset pin and turned on, the power supply state indication pin being used to input a high level signal to the reset pin when it is detected that the output voltage of the DCDC chip is within a preset interval, the power supply state indication pin being used to input a low level signal to the reset pin when it is detected that the output voltage of the DCDC chip is outside the preset interval, the watchdog output pin being used to input a low level signal to the reset pin when no feed dog signal is received in at least one period of the watchdog input pin, and the watchdog output pin being used to input a high level signal to the reset pin when the feed dog signal is received in each period of the watchdog input pin, and the reset pin being used to reset the MCU chip to the initial state when at least one of the level signals sent by the power supply state indication pin and the level signals sent by the watchdog output pin is a low level signal.
[0007] Further, the first level signal is a low level signal, and the second level signal is a high level signal.
[0008] Further, the first level signal is a high level signal, and the second level signal is a low level signal.
[0009] Further, one end of each control branch is connected with the power supply, and the other end of each control branch is connected with the corresponding mode configuration pin, and each control branch is configured with a control resistor and a flying needle switch, wherein the opening and closing state of the flying needle switch can adjust the level signal sent by the control branch to the mode configuration pin.
[0010] Further, the watchdog chip is provided with a power supply module, the power supply module is provided with a power supply input pin, the power supply input pin is connected with the power supply state indication pin and is in conduction, and the power supply state indication pin is used to input an enable signal to the power supply input pin to power on the watchdog chip.
[0011] According to another aspect of the present application, a control method of a controller monitoring system is provided, the controller monitoring system is monitored by the control method of the controller monitoring system, the controller monitoring system is the controller monitoring system convenient for batch flashing, and the method comprises the following steps: step S1, when it is detected that the MCU chip has a flashing requirement, the flying needle switches on each control branch are controlled and adjusted to make the MCU chip enter a flashing mode and the watchdog chip enter a hibernation state; step S2, after it is detected that the MCU chip finishes flashing, the flying needle switches on each control branch are controlled and adjusted again to make the MCU chip exit the flashing mode and the watchdog chip enter a start state; step S3, the watchdog chip is controlled to periodically acquire a feed dog signal, and the watchdog output pin is used to input a low level signal to the reset pin in the case that the watchdog output pin does not receive the feed dog signal in at least one period of the watchdog input pin, and the watchdog output pin is used to input a high level signal to the reset pin in the case that the watchdog output pin receives the feed dog signal in each period of the watchdog input pin; step S4, the power supply state indication pin is used to input a high level signal to the reset pin in the case that it is detected that the output voltage of the DCDC chip is located in a preset interval, and the power supply state indication pin is used to input a low level signal to the reset pin in the case that it is detected that the output voltage of the DCDC chip is located outside the preset interval; and step S5, the reset pin is controlled to reset the MCU chip to an initial state in the case that at least one of the level signals sent by the power supply state indication pin and the level signals sent by the watchdog output pin is a low level signal.
[0012] Further, the control method further comprises: controlling the reset pin to keep the existing running state of the MCU chip in the case that the level signals sent by the power supply state indication pin and the level signals sent by the watchdog output pin are both high level signals.
[0013] According to another aspect of the present application, a vehicle is provided, comprising the controller monitoring system facilitating batch flashing, and the controller monitoring system facilitating batch flashing is the controller monitoring system facilitating batch flashing as described above.
[0014] According to the technical solution of the present application, a plurality of control branches are correspondingly arranged with a plurality of mode configuration pins, and at least one of the plurality of control branches is connected with the watchdog enable pin and turned on when the MCU chip is in the flashing mode, so that the control branch controls the second level signal to be sent to the watchdog enable pin, and the control branch controls the MCU chip to enter the flashing mode while sending the second level signal to the watchdog enable pin to hibernate the watchdog chip, avoiding the defect that the watchdog chip needs to be enabled by the MCU chip in the prior art. When the control branch controls the MCU chip to end the flashing, the watchdog enable pin no longer receives the second level signal and automatically enters the open state. The present application solves the problem that the controller monitoring system in the prior art will reduce the efficiency of the whole vehicle mass production when working. BRIEF DESCRIPTION OF DRAWINGS
[0015] The accompanying drawings, which form a part of the present description, are included to provide a further understanding of the application, and are incorporated herein for explanation by way of exemplification. The present description and the accompanying drawings are not limited to the exact details shown and described, but are assumed to be illustrative only.
[0016] FIG. 1 shows a hardware structure schematic diagram of an embodiment of the controller monitoring system facilitating batch flashing according to the present application. DETAILED DESCRIPTION
[0017] It should be noted that the embodiments and features in the present application can be combined with each other without conflict. The present application will be described in detail below with reference to the accompanying drawings and in conjunction with the embodiments.
[0018] It should be noted that the terms used herein are only for the purpose of describing specific embodiments, and are not intended to limit the exemplary embodiments according to the present application. As used herein, the singular form is intended to include the plural form unless the context clearly indicates otherwise, and it should also be understood that when the terms "comprise" and / or "include" are used in the specification, there is a presence of the features, steps, operations, devices, components and / or combinations thereof.
[0019] It is to be understood that the terms "first", "second", and the like, used in the description and the claims of the present application as well as the foregoing drawings should not be construed as necessarily implying a specific order or sequence of steps or sequences. It is to be understood that the terms so used are merely intended to differentiate between similar objects and not necessarily for describing a specific sequential order, unless otherwise indicated by the context. Further, use of the terms "including", "comprising", "having" and variations thereof herein are intended to encompass the inclusion of a feature, step, element, or component but not the exclusion of any other feature, step, element, component, or set of features, steps, elements, components. Further, use of the term "or" is intended to encompass both exclusive and inclusive "or" unless otherwise indicated by the context.
[0020] Now, exemplary embodiments according to the present application will be described in more detail with reference to the accompanying drawings. However, these exemplary embodiments can be implemented in various different forms, and should not be construed as being limited to only the embodiments set forth herein. It is to be understood that the embodiments are provided so as to make the present disclosure thorough and complete, and to fully convey the concept of the exemplary embodiments to those skilled in the art, and in the drawings, the thicknesses of layers and regions are exaggerated for clarity, and the same reference numerals are used throughout the drawings to designate the same elements, and thus a description thereof will be omitted.
[0021] The basic principle and function of a watchdog timer (WDT) is as follows:
[0022] Basic principle:
[0023] Countdown mechanism: The watchdog timer has a built-in timer that starts counting down after the system is powered on or reset.
[0024] Feeding operation: During normal system operation, software needs to send a signal to the watchdog timer (called "feeding" or "serving the watchdog") through a specific I / O operation before the timer reaches the preset time, to reset the timer.
[0025] Timeout response: If the timer is not reset within the preset time, the watchdog timer will consider that the system has failed or is abnormal, at which time it will trigger a reset signal to the microcontroller (MCU) or other processor, forcing the system to reset.
[0026] Hardware circuit: The watchdog timer can be a separate hardware device or integrated into a microcontroller or other processor.
[0027] The function of the watchdog timer:
[0028] Prevent dead loops: The main function of the watchdog chip is to prevent the program from entering a dead loop or infinite loop, ensuring the stable operation of the system.
[0029] System monitoring: It monitors the running state of the system, and if it finds an abnormality such as a runaway program, it will take timely measures.
[0030] Improve reliability: By periodically resetting the system, the watchdog chip can improve the reliability and stability of the system.
[0031] Fault recovery: When the system fails, the watchdog chip can force the system to reset, helping the system recover from abnormal states.
[0032] Security mechanism: In some critical applications, the watchdog chip serves as a security mechanism to ensure that the system can safely stop or restart when encountering an unrecoverable error.
[0033] According to the specific embodiments of the present application, a controller monitoring system convenient for batch flashing is provided, as shown in FIG. 1, which includes: an MCU chip, the MCU chip is provided with a reset pin, an interface pin, and a plurality of mode configuration pins, wherein the reset pin is used to reset the MCU chip to an initial state, each mode configuration pin is connected with the power supply and turned on, and when the plurality of mode configuration pins are in a specific combination of level states, the MCU chip enters a flashing mode; a watchdog chip, the watchdog chip is provided with a watchdog input pin, a watchdog output pin, and a watchdog enable pin, the watchdog input pin is connected with the interface pin and turned on, the interface pin is used to periodically send a feed dog signal to the watchdog input pin, and the watchdog output pin is connected with the reset pin and turned on; wherein the watchdog enable pin has an open state under a first level signal to open the feed dog mode, and the watchdog enable pin has a dormant state under a second level signal to close the feed dog mode; a control circuit, the control circuit has a plurality of control branches, the plurality of control branches are correspondingly provided with the plurality of mode configuration pins, each control branch is connected with the power supply and turned on, and each control branch is used to adjust the level state of the corresponding mode configuration pin, when the MCU chip is in the flashing mode, at least one of the plurality of control branches is connected with the watchdog enable pin and turned on, so that the control branch controls the second level signal to be sent to the watchdog enable pin.
[0034] The technical scheme of the application is applied, a plurality of control branches are correspondingly arranged with a plurality of mode configuration pins, and when the MCU chip is in the flashing mode, at least one of the plurality of control branches is connected with the watchdog enable pin and is turned on, so that the control branch controls the sending of the second level signal to the watchdog enable pin, so that the control branch controls the MCU chip to enter the flashing mode and sends the second level signal to the watchdog enable pin to hibernate the watchdog chip, avoiding the defect that the watchdog chip needs to be enabled by the MCU chip in the prior art, and when the control branch controls the MCU chip to end the flashing, the watchdog enable pin no longer receives the second level signal and automatically enters the start state. The application solves the problem of the controller monitoring system in the prior art, which reduces the efficiency of whole vehicle production.
[0035] Optionally, when the MCU chip exits the flashing mode, the plurality of control branches are all disconnected from the watchdog enable pin, so that the watchdog enable pin stops receiving the second level signal, and the watchdog enable enters the start state.
[0036] As shown in FIG. 1, BOOTMODE0 to BOOTMODE3 are mode configuration pins of the MCU, the control circuit includes four control branches, and four flying needle switches S1 to S4 and four resistors R1, R6, R7 and R8 are correspondingly arranged on the four control branches. The four flying needle switches S1 to S4 control the on-off of the four control branches, and further control whether the four corresponding mode configuration pins are at high level or low level. The Bootmode pin is mainly used for mode control. When the production is offline, a specific level combination needs to be provided to make the microcontroller enter the download mode. For example, the normal working mode: Bootmode0: Bootmode1: Bootmode2: Bootmode3=0000, the download mode: Bootmode0: Bootmode1: Bootmode2: Bootmode3=0111 corresponds to the download mode. In this power supply scheme, one of the pins is selected, for example, Bootmode3, to control the enablement of the watchdog chip. Therefore, the control branch connected with Bootmode3 is also connected with the watchdog enable pin and is turned on.
[0037] The BOOTMODE pin or similar pin is usually used to determine the startup mode or configuration of the device. The following are some common uses of the BOOTMODE pin:
[0038] Startup mode selection: The state (level high or low) of the BOOTMODE pin can determine which type of storage medium the MCU starts from, for example, from internal FLASH, external NOR FLASH, external NAND FLASH or SRAM, etc.
[0039] System configuration: At power-up or reset, the level state of the BOOTMODE pin can be used to set system configuration parameters, such as clock source selection, operating frequency, etc.
[0040] Firmware update: During firmware upgrade or burning process, the BOOTMODE pin can be used to indicate the MCU to enter a specific programming mode.
[0041] The application provides a microcontroller power supply scheme of a domestic discrete power supply chip, which can effectively solve the above problems. The power supply scheme uses an external watchdog chip with watchdog enablement. When the system is working normally, the watchdog chip can monitor the state of the microcontroller throughout the process. If the watchdog chip cannot feed the watchdog due to an error, it will output an error signal to reset the microcontroller. When powered on for the first time, the watchdog chip is put into a sleep state by building a peripheral circuit during batch flashing. When the flashing stage is exited, the watchdog chip is activated again to complete the state monitoring of the microcontroller.
[0042] This scheme requires the watchdog chip to monitor throughout the process to ensure the safety and reliability of the system, and also requires the watchdog chip to remain in a sleep state during batch flashing to improve production efficiency. At the same time, the shortage of domestic power supply chips SBC and PMIC is solved, and the technical difficulties of replacing domestic chips with discrete devices to achieve the above functions are solved.
[0043] Further, the batch flashing controller monitoring system further comprises a DCDC chip, the DCDC chip is provided with a DCDC output pin, the MCU chip is provided with a power input pin, the DCDC output pin (OUT pin in FIG. 1) is connected with the power input pin (VDD pin on the MCU in FIG. 1) and is conductive, and the DCDC chip is used to transmit the external power supply after voltage conversion to the MCU chip.
[0044] In FIG. 1, there are multiple VDD pins, power input: VDD pin is the positive input of the power supply of integrated circuits or other electronic components, which receives voltage from the power supply. VDD is usually used to represent the positive of the working voltage of the device, and VSS or GND represents the negative of the power supply or the ground. In digital circuits, VDD provides a reference for the logic "high" level, that is, when the input or output signal exceeds a certain threshold of VDD, it is considered as a logic "1". The VDD pin is part of the power supply path, which ensures that current can flow to various parts inside the chip. In some systems, the VDD pin may be adjusted through a power management circuit to meet different power requirements or achieve energy saving.
[0045] Further, the DCDC chip is provided with a power state indication pin (PG pin in FIG. 1), the power state indication pin is connected with the reset pin (RST pin in FIG. 1) and is turned on, the power state indication pin is used for inputting a high-level signal to the reset pin in the case that it is detected that the output voltage of the DCDC chip is located in a preset interval, the power state indication pin is used for inputting a low-level signal to the reset pin in the case that it is detected that the output voltage of the DCDC chip is located outside the preset interval, the watchdog output pin is used for inputting a low-level signal to the reset pin in the case that no feed dog signal is received by the watchdog input pin (WD_EN pin in FIG. 1) at least one period, the watchdog output pin (WDO pin in FIG. 1) is used for inputting a high-level signal to the reset pin in the case that a feed dog signal is received by the watchdog input pin in each period, and the reset pin is used for controlling the MCU chip to reset to an initial state when at least one of the level signals sent by the power state indication pin and the level signals sent by the watchdog output pin is a low-level signal.
[0046] The RST pin, commonly known as the "Reset" pin, is a control signal used in electronic devices and integrated circuits (ICs) for resetting or resetting. Here are some main uses and features of the RST pin:
[0047] System reset: The RST pin provides a signal that, when activated, can reset the entire system or specific components to their initial state.
[0048] Fault recovery: When the system encounters a fault or anomaly, the RST pin can be used to restart the system to help restore normal operation.
[0049] Power-on reset: When the device is powered on, the RST pin may be used to ensure that the system starts running only after the power supply is stable.
[0050] Software control: Software can activate the RST pin by controlling GPIO (General Purpose Input Output) pins or other control logic to achieve software reset.
[0051] The PG pin usually refers to the "Power Good" pin, which is a signal in the power management circuit indicating that the output voltage of the power supply (PSU) or power module has stabilized and reached a safe power supply level. Here are some main uses and features of the PG pin:
[0052] Power ready indication: The PG pin outputs a signal indicating that the power supply has completed the startup process and the output voltage is stable within the specified range.
[0053] Startup sequence control: In complex systems, the PG signal can be used to control the startup sequence of different components to ensure that the system starts safely in the predetermined order.
[0054] Power Status Monitoring: The PG pin can be read by a microcontroller or other monitoring circuit to enable real-time monitoring of the power status.
[0055] Protection Mechanism: If the PG signal indicates unstable power output, the system can take protective measures such as delaying startup, shutting down sensitive loads, or issuing warnings.
[0056] Power Failure Response: In the event of unstable or failed power output, the PG signal can be used to trigger system failure response mechanisms to prevent damage to loads.
[0057] Power Testing and Debugging: During power testing and debugging, the PG pin can serve as a useful reference point to help determine if the power is functioning properly.
[0058] Power Normal Operation Confirmation: In some systems, the PG signal can be used to confirm that the power is in a normal operating state, preventing critical operations from being performed when the power is unstable.
[0059] Power Management: The PG pin can be combined with power management circuits to implement more complex power control logic, such as soft start and soft shutdown of the power supply.
[0060] System Reliability: By using the PG signal, system reliability can be improved, ensuring that sensitive electronic devices are only started when the power supply is stable.
[0061] The reset pin is used to control the MCU chip to reset to the initial state when at least one of the level signals sent by the power status indication pin and the level signals sent by the watchdog output pin is a low-level signal. That is, the level signals sent by the power status indication pin and the level signals sent by the watchdog output pin are subjected to AND logic operation before being input to the reset pin.
[0062] Among them, "AND Logic" (AND Logic) is a basic operation in digital logic and Boolean algebra, which involves two or more input signals and produces an output signal according to the following rules:
[0063] When all input signals are logically "true" (usually represented as high level or logical "1" in digital logic), the output result is logically "true" (1).
[0064] If any one of the input signals is logically "false" (usually represented as low level or logical "0" in digital logic), the output result is logically "false" (0).
[0065] In a watchdog timer (WDT), the WD-EN pin typically represents "Watchdog Enable." This pin controls the start and stop of the watchdog timer. Here are some specific uses and features of the WD-EN pin:
[0066] Enable control: Through the WD-EN pin, you can software control the start (enable) or stop (disable) of the watchdog timer.
[0067] Initialization phase: In the initialization phase after power-on or reset, the WD-EN pin may be set to low to disable the watchdog, preventing the system from being accidentally reset during initialization.
[0068] Runtime control: After the system is running normally, the WD-EN pin can be set to high to start the watchdog timer to monitor the system running state.
[0069] Dynamic disable: In some cases, you may need to temporarily disable the watchdog timer for system debugging or handling specific tasks. By setting the WD-EN pin to low, you can safely disable the watchdog.
[0070] Protection mechanism: In the case of special conditions, you can control the WD-EN pin through software to disable the watchdog to prevent accidental system reset.
[0071] Status indication: The state of the WD-EN pin can be used as an indication of the watchdog enable state, making it easier for system monitoring and debugging.
[0072] Compatibility: The WD-EN pin may have different implementations in different watchdog chips, but it usually provides similar enable control functions.
[0073] Safety features: In some watchdog chips, the WD-EN pin may have special safety features, such as automatically disabling the watchdog in certain fault conditions to protect the system.
[0074] The WDO pin usually represents "Watchdog Output." The main functions of this pin are as follows:
[0075] Reset signal: The WDO pin outputs a low (or high, depending on the design) level after the watchdog timer times out. This signal is usually connected to the reset (RST) pin of the microcontroller (MCU) or other processor, triggering system reset.
[0076] Status indication: The state of the WDO pin can serve as an indication of the watchdog timer status, for example, if the WDO output is low, it may indicate that the watchdog timer has timed out.
[0077] Fault response: In the event of a system failure or anomaly, such as a program loop or system hang, the signal output by the WDO pin can serve as a response mechanism to force the system to restart and return to a normal state.
[0078] System monitoring: The WDO pin can be read by the system monitoring circuit to determine whether the system has been reset due to the watchdog timer timing out.
[0079] Further, the first level signal is a low level signal, and the second level signal is a high level signal.
[0080] That is, when the MCU chip is in the flashing mode, at least one of the multiple control branches is connected to the watchdog enable pin and is turned on, so that the control branch controls the sending of a high level signal to the watchdog enable pin. When the MCU chip exits the flashing mode, the control branch is disconnected, and it stops sending a high level signal to the watchdog enable pin. At this time, the watchdog enable pin receives a low level signal and enters the start state.
[0081] Further, the first level signal is a high level signal, and the second level signal is a low level signal.
[0082] Further, one end of each control branch is connected to the power supply, and the other end of each control branch is connected to the corresponding mode configuration pin. Each control branch is configured with a control resistor and a flying needle switch, and the opening and closing state of the flying needle switch can adjust the level signal sent by the control branch to the mode configuration pin. The control flying needle switch is S1 to S4 in FIG. 1, and the control resistor is R1, R6, R7, and R8 in FIG. 1. When the flying needle switch is closed, the corresponding mode configuration pin receives a high level.
[0083] Further, the watchdog chip is provided with a power supply module, and the power supply module (i.e. the POWER module in FIG. 1) is provided with a power supply input pin (i.e. the EN pin in the POWER module in FIG. 1). The power supply input pin is connected to the power supply state indication pin and is turned on, and the power supply state indication pin is used to input an enable signal to the power supply input pin to power on the watchdog chip.
[0084] Also shown in Figure 1 is the GPIO pin, in a microcontroller unit (MCU), a GPIO (General Purpose Input Output) pin is a multi-purpose pin used to interface with external devices or signals. The specific identification "GPIOI" can refer to a part of a group of GPIO pins in a certain MCU, where "I" can indicate the Ith in a group of GPIOs. Here are some main uses of GPIO pins in an MCU:
[0085] Digital Input: A GPIO can be configured as a digital input to read the state of an external digital signal, such as a button press or a sensor output.
[0086] Digital Output: A GPIO can be configured as a digital output to drive an external device, such as an LED light, a relay, or a motor controller.
[0087] Analog Input: Some GPIO pins can be configured as analog inputs to read analog signals, such as the output of a temperature sensor or a pressure sensor.
[0088] Communication Interface: A GPIO can be used to implement various communication protocols, such as I2C, SPI, or UART, for communication with sensors, displays, or other MCUs.
[0089] The present application uses a watchdog chip to feed the dog operation, complete the state of the microcontroller. The present application adopts the safety indication pin of the front power supply and the WDO to reset the microcontroller, even if the microcontroller is not powered on, the state monitoring can be performed, and the watchdog can be closed when programming. The present application automatically closes the watchdog chip through the configuration change of the microcontroller when programming, and the peripheral circuit is more simple and reliable.
[0090] The present monitoring system contains three main parts, which are DCDC switching power supply chip, watchdog chip and microcontroller;
[0091] The first part is the DCDC power supply chip, which mainly provides power for the microcontroller to ensure the normal work of the microcontroller. The EN pin is the DCDC enable pin, which is pulled high to enable the power supply chip, so that the DCDC enters the working state and outputs voltage. The PG pin is a normal state indication pin, which is generally an open drain structure. The external is connected to the power supply through a pull-up resistor, when the DCDC output is in the normal output voltage threshold, the pin is in high resistance state, and the external pull-up power supply finally outputs a high level signal. If the detected output voltage is lower than the normal limit, the PG pin is pulled down to the ground and outputs a low level.
[0092] The second part is a watchdog chip, which mainly monitors the working state of the microcontroller. When working normally, the GPIO1 pin of the microcontroller needs to be continuously fed according to the period (provide a pulse within a specific time window). If the watchdog chip's WDI pin does not receive the feeding signal within a certain time, it will record an error. When the error value accumulates to a certain value (for example, 7 times), the watchdog chip will determine that the feeding is failed, the MCU program is error, and then pull down the WDO pin, which is directly connected to the reset pin of the microcontroller. By pulling down the pin, the microcontroller is reset. The watchdog chip waits if the MCU can continuously feed the watchdog chip, then the WDO of the watchdog chip will continuously output high level. The power supply of the watchdog chip can be flexibly selected according to the actual situation. Some watchdog chips have built-in LDO, which can be directly logically powered; some watchdog chips are independent, which need external power supply.
[0093] The third part is a microcontroller, which mainly receives sensor signals, safety signals and control signals, manages the power-on and power-off of the entire system load, and detects the power rail. The microcontroller is the master control of the entire system, and all control logic is almost determined by the microcontroller. The microcontroller has rich resources, and only relevant pins are listed in this application for scheme description. The Bootmode pin is mainly mode control. When the product is out of line, a specific level combination needs to be provided to make the microcontroller enter the download mode, for example, normal working mode: Bootmode0: Bootmode1: Bootmode2: Bootmode3=0000, download mode: Bootmode0: Bootmode1: Bootmode2: Bootmode3=0111 corresponds to the download mode. In this power supply scheme, one of the pins is selected, for example, Bootmode3, to control the enable of the watchdog chip. VDD is the power supply pin of the microcontroller, which is the premise of the controller working. The RST pin is the reset pin of the microcontroller, which is generally triggered by low level. When working normally, the pin needs to be guaranteed to be high level. When the pin is pulled down, the microcontroller enters the reset and restart operation. The GPIO pin is a flexible configuration pin of the microcontroller, which can be configured as input or output according to the actual situation.
[0094] The working principle of the power supply scheme is as follows: after the wake-up source (for example, KL15, CAN_INH) of the system is pulled high, the DCDC is enabled, the DCDC outputs 3.3V, and the MCU is powered. When the output reaches 90% to 110% of the output range, the status indication pin PG is pulled high. The PG signal enables the power supply of the watchdog chip. If the watchdog chip has a built-in LDO, the LDO is pulled high. If it is a dedicated watchdog chip, the logic power supply of the watchdog chip is controlled. For a chip with a low-level enabled watchdog, the circuit schematic is shown in watchdog1. R3 is pulled down to GND1, at this time, the watchdog chip is enabled and enters the waiting stage of the feeding dog signal, and the WDO pin outputs high. The WDO signal and the PG signal are output high through the AND logic, the RST pin of the microcontroller is pulled high, the microcontroller enters the working state, and the feeding dog operation is started through GPIO1. If the feeding dog operation is completed within the normal waiting time of the watchdog chip, the WDO of the watchdog chip continues to be pulled high. If an abnormal situation occurs in the middle of the way, for example, the microcontroller software runs dead, the WDO of the watchdog chip will not be able to receive the feeding dog signal, and when the maximum feeding dog waiting time of the watchdog chip is reached, the system will determine that the feeding dog fails and pull down the WDO pin. Since WDO and PG are AND logic, the RST of the microcontroller will be pulled low and re-enter the feeding dog waiting stage, and then the microcontroller is restarted.
[0095] The advantage of the scheme is that the watchdog chip does not need to be controlled by the microcontroller, and it starts monitoring when the microcontroller has not started yet, which can effectively solve the problem of software deadlocking during the startup process of the microcontroller.
[0096] In the mass production stage, when the software program of the microcontroller is burned, the levels of BOOTMODE0 to BOOTMODE3 are generally adjusted through flying needles or jump caps. In this scheme, 0111 is taken as an example to enter the program burning mode. When S1 is closed externally, the WD_EN of watchdog IC1 is pulled high, at this time the watchdog chip enters the sleep state, and the WDO pin is always pulled high. When the software burning is completed, S1 is disconnected, and the watchdog chip also enters the normal working state with the microcontroller exiting the program burning state. If the selected watchdog chip is high-level enabled, the circuit structure of watchdog IC2 is used, WD_EN is pulled up to VDD externally through R5, and by default it is always in the working state and can continuously monitor the state of the microcontroller. When the software of the microcontroller is burned in the mass production stage, when S1 is closed, the base level of Q2 is pulled down, Q2 enters the conduction mode, WD_EN is pulled down to the ground, and the watchdog chip enters the sleep state. When the software burning of the microcontroller is completed and S1 is disconnected, Q2 is not conductive, WD_EN is pulled high, and watchdog IC2 enters the monitoring state.
[0097] According to another aspect of the present application, a control method of a controller monitoring system is provided, the controller monitoring system is monitored by the control method of the controller monitoring system, the controller monitoring system is the controller monitoring system facilitating batch flashing in the above embodiments, and the method comprises:
[0098] Step S1, when it is detected that the MCU chip has a flashing requirement, the flying probe switches on each control branch are controlled and adjusted so that the MCU chip enters a flashing mode and the watchdog chip enters a hibernation state;
[0099] Step S2, after it is detected that the MCU chip finishes flashing, the flying probe switches on each control branch are controlled and adjusted again so that the MCU chip exits the flashing mode and the watchdog chip enters an activation state;
[0100] Step S3, the watchdog chip is controlled to periodically obtain a feed signal, and the watchdog output pin is controlled to input a low-level signal to the reset pin in the case that the watchdog input pin does not receive the feed signal within at least one period, and the watchdog output pin is used to input a high-level signal to the reset pin in the case that the watchdog input pin receives the feed signal within each period;
[0101] Step S4, the power state indication pin is controlled to input a high-level signal to the reset pin in the case that it is detected that the output voltage of the DCDC chip is within a preset interval, and the power state indication pin is controlled to input a low-level signal to the reset pin in the case that it is detected that the output voltage of the DCDC chip is outside the preset interval;
[0102] Step S5, the reset pin is controlled to reset the MCU chip to an initial state in the case that at least one of the level signals sent by the power state indication pin and the level signals sent by the watchdog output pin is a low-level signal.
[0103] Further, the control method further comprises: the reset pin is controlled to keep the existing running state of the MCU chip in the case that the level signals sent by the power state indication pin and the level signals sent by the watchdog output pin are both high-level signals.
[0104] According to another aspect of the present application, a vehicle is provided, comprising the controller monitoring system facilitating batch flashing, and the controller monitoring system facilitating batch flashing is the controller monitoring system facilitating batch flashing in the above embodiments.
[0105] From the above description, it can be seen that the above embodiments of the present application achieve the following technical effects:
[0106] The scheme takes into account the watchdog chip working characteristics of different chip manufacturers, and can be flexibly adjusted for watchdog chips with different working principles, ensuring the flexibility and reliability of the scheme, improving the safety and reliability of the system, solving the software program burning problem in the production line stage, and improving the efficiency of vehicle production.
[0107] For ease of description, spatial relative terms such as "on", "above", "upper surface", "upper", and the like can be used herein to describe the spatial relationship between one device or feature and another device or feature as shown in the drawings. It should be understood that the spatial relative terms are intended to include different orientations of the device in use or operation in addition to the orientation of the device described in the drawings. For example, if the device in the drawing is inverted, the device described as "above" or "on" the other device or structure will be positioned "below" or "under" the other device or structure. Thus, the exemplary term "above" can include both the "above" and "below" orientations. The device can also be positioned in other different ways (rotated 90 degrees or in other orientations), and the spatial relative descriptions used herein are interpreted accordingly.
[0108] In addition to the above, it should also be noted that the "one embodiment", "another embodiment", "embodiment", and the like mentioned in the specification refer to specific features, structures, or characteristics described in connection with the embodiment, which are included in at least one embodiment described in the general description of the application. The same expression appearing in several places in the specification does not necessarily refer to the same embodiment. Further, when a specific feature, structure or characteristic is described in connection with any embodiment, it is claimed that the implementation of such feature, structure or characteristic in connection with other embodiments also falls within the scope of the application.
[0109] In the above embodiments, the description of each embodiment has its own emphasis, and the parts not described in detail in a certain embodiment can be referred to the relevant description of other embodiments.
[0110] The above only describes the preferred embodiments of the present application and is not intended to limit the present application. For those skilled in the art, the present application can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. made within the spirit and principles of the present application shall be included in the protection scope of the present application.
Claims
1. A controller monitoring system that facilitates bulk flashing, the system comprising: The application relates to a controller monitoring system facilitating batch flashing. An MCU chip is provided with a reset pin, an interface pin and a plurality of mode configuration pins, wherein the reset pin is used for resetting the MCU chip to an initial state, each mode configuration pin is connected with a power supply and turned on, and when a plurality of mode configuration pins are in a specific level state combination, the MCU chip enters a flashing mode. A watchdog chip is provided with a watchdog input pin, a watchdog output pin and a watchdog enable pin, the watchdog input pin is connected with the interface pin and turned on, the interface pin is used for periodically sending a feed dog signal to the watchdog input pin, and the watchdog output pin is connected with the reset pin and turned on. The watchdog enable pin has an open state for opening the feed dog mode under a first level signal, and the watchdog enable pin has a dormant state for closing the feed dog mode under a second level signal. A control circuit is provided with a plurality of control branches corresponding to the plurality of mode configuration pins, each control branch is connected with a power supply and turned on, and each control branch is used for adjusting the level state of the corresponding mode configuration pin; when the MCU chip is in the flashing mode, at least one of the plurality of control branches is connected with the watchdog enable pin and turned on, so that the control branch controls the second level signal to be sent to the watchdog enable pin.
2. The controller monitoring system for facilitating bulk flashing of claim 1, wherein, The controller monitoring system facilitating batch flashing further comprises: A DCDC chip is provided with a DCDC output pin, and the MCU chip is provided with a power input pin; the DCDC output pin is connected with the power input pin and turned on, and the DCDC chip is used for transmitting the voltage of an external power supply to the MCU chip after voltage conversion.
3. The controller monitoring system for facilitating bulk flashing of claim 2, wherein, The DCDC chip is provided with a power state indication pin connected with the reset pin and turned on; the power state indication pin is used for inputting a high level signal to the reset pin when it is detected that the output voltage of the DCDC chip is within a preset interval, and the power state indication pin is used for inputting a low level signal to the reset pin when it is detected that the output voltage of the DCDC chip is outside the preset interval; the watchdog output pin is used for inputting a low level signal to the reset pin when the watchdog input pin does not receive the feed dog signal within at least one period, and the watchdog output pin is used for inputting a high level signal to the reset pin when the watchdog input pin receives the feed dog signal within each period; and the reset pin is used for resetting the MCU chip to the initial state when at least one of the level signals sent by the power state indication pin and the level signals sent by the watchdog output pin is a low level signal.
4. The controller monitoring system for facilitating bulk flashing of claim 1, wherein, The first level signal is a low level signal, and the second level signal is a high level signal.
5. The controller monitoring system for facilitating bulk flashing of claim 1, wherein, The first level signal is a high level signal, and the second level signal is a low level signal.
6. The controller monitoring system for facilitating bulk flashing of claim 1, wherein, One end of each control branch is connected with the power supply, the other end of each control branch is connected with the corresponding mode configuration pin, and a control resistor and a flying needle switch are arranged on each control branch, wherein the opening and closing state of the flying needle switch is controlled to adjust the level signal sent by the control branch to the mode configuration pin.
7. The controller monitoring system for facilitating bulk flashing of claim 3, wherein, The watchdog chip is provided with a power supply module, the power supply module is provided with a power supply input pin, the power supply input pin is connected with the power supply state indication pin and is in conduction, and the power supply state indication pin is used to input an enable signal to the power supply input pin to power on the watchdog chip.
8. A control method of a controller monitoring system that monitors using the control method of the controller monitoring system, characterized by, The controller monitoring system is the controller monitoring system convenient for batch flashing as claimed in any one of claims 1 to 7, and the method comprises: Step S1, when it is detected that the MCU chip has a flashing requirement, the flying needle switches on each control branch are controlled and adjusted to make the MCU chip enter a flashing mode and the watchdog chip enter a hibernation state; Step S2, after it is detected that the MCU chip finishes flashing, the flying needle switches on each control branch are controlled and adjusted again to make the MCU chip exit the flashing mode and the watchdog chip enter a starting state; Step S3, the watchdog chip is controlled to periodically acquire a watchdog feeding signal, and the watchdog output pin is controlled to input a low-level signal to the reset pin in the case that the watchdog input pin does not receive the watchdog feeding signal in at least one period, and the watchdog output pin is controlled to input a high-level signal to the reset pin in the case that the watchdog input pin receives the watchdog feeding signal in each period; Step S4, the power supply state indication pin is controlled to input a high-level signal to the reset pin in the case that it is detected that the output voltage of the DCDC chip is in a preset interval, and the power supply state indication pin is controlled to input a low-level signal to the reset pin in the case that it is detected that the output voltage of the DCDC chip is out of the preset interval; Step S5, the reset pin is controlled to reset the MCU chip to an initial state in the case that at least one of the level signals sent by the power supply state indication pin and the level signals sent by the watchdog output pin is a low-level signal.
9. The control method according to claim 8, characterized by, The control method further comprises: controlling the reset pin to keep the existing running state of the MCU chip in the case that the level signals sent by the power supply state indication pin and the level signals sent by the watchdog output pin are both high-level signals.
10. A vehicle comprising a controller monitoring system to facilitate bulk flashing, characterized in that, The controller monitoring system convenient for batch flashing is the controller monitoring system convenient for batch flashing as claimed in any one of claims 1 to 7.
Citation Information
Patent Citations
Watchdog signal shielding module
CN114021102A
Watchdog control circuit and device
CN114610514A
Watchdog control circuit
CN115220943A
Watchdog circuit and control method thereof
CN118245266A
Controller monitoring system convenient for batch flashing and vehicle
CN118672187A