Electronic and electrical system, control method, controller, vehicle and storage medium
By introducing first and second controllers into the vehicle's electronic and electrical system, with the second controller taking over the safety control responsibilities when the first controller fails, the safety problem caused by the failure of the vehicle control system is solved, and the reliability and safety of vehicle control are improved.
Patent Information
- Application Number
- PCT/CN2025/077033
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-08-05
- Filing Date
- 2025-02-12
- Publication Date
- 2026-02-12
AI Technical Summary
In the prior art, when the vehicle control system fails, the vehicle may be unable to drive normally, threatening the lives of the driver and passengers.
Design a vehicle electronic and electrical system, including a first controller and a second controller. The first controller is responsible for basic safety control functions. The second controller takes over the responsibilities of the first controller when the first controller fails, implements safety control functions, and monitors the status of the first controller through pulse width modulation messages and heartbeat messages to determine whether it has failed.
This ensures that the vehicle control system remains uninterrupted in the event of a first controller failure, improving the safety and reliability of vehicle control. It supports a variety of safety control functions without requiring additional controllers, saving costs and storage space.
Smart Images

Figure CN2025077033_12022026_PF_FP_ABST
Abstract
Description
Electronic and electrical system, control method, controller, vehicle and storage medium
[0001] This application claims priority to Chinese Patent Application No. 202411063423.8, filed on August 5, 2024, the entire contents of which are incorporated herein by reference. TECHNICAL FIELD
[0002] The present disclosure relates to the field of automotive technology, and in particular, to an electronic and electrical system, a control method, a controller, a vehicle and a storage medium. BACKGROUND
[0003] With the continuous development of the automotive industry, users pay more and more attention to the safety of the automobile. For example, for the power control, power management, steering and braking of the automobile during driving, and other vehicle control functions related to vehicle safety, the reliability and safety are the primary consideration of users. SUMMARY
[0004] The present disclosure provides an electronic and electrical system, a control method, a controller, a vehicle and a storage medium, which can improve the safety and reliability of vehicle control.
[0005] In one aspect, an electronic and electrical system of a vehicle is provided, comprising a first controller and a second controller, the first controller being connected with the second controller. The control function of the first controller comprises a safety control function. The second controller is configured to perform area control, and the second controller is further configured to implement the safety control function in the case that the first controller fails.
[0006] In another aspect, a control method of a vehicle is provided, applied to an electronic and electrical system of the vehicle, the method comprising: a second controller confirming that a first controller fails. The second controller implements a safety control function.
[0007] In yet another aspect, a control method of a vehicle is provided, applied to an electronic and electrical system of the vehicle, the method comprising: in the case that the first controller is able to work, the first controller implements a safety control function of the vehicle. The first controller sends an indication message to the second controller, so that the second controller determines whether the state of the first controller is a failure state according to the reception of the indication message.
[0008] In yet another aspect, a first controller is provided, comprising: a processor and a memory configured to store instructions executable by the processor. The processor is configured to execute the instructions, so that the first controller performs the above-mentioned control method of the vehicle.
[0009] In yet another aspect, a second controller is provided, comprising a processor and a memory configured to store instructions executable by the processor. The processor is configured to execute the instructions such that the second controller performs the control method of the vehicle as described above.
[0010] In yet another aspect, a vehicle is provided, comprising the electronic and electrical system, or comprising the first controller and the second controller.
[0011] In yet another aspect, a computer-readable storage medium is provided, having stored thereon computer program instructions, which when executed on a computer, cause the computer to perform the control method of the vehicle as described above.
[0012] In yet another aspect, a computer program product is provided, comprising computer program instructions, which when executed on a computer, cause the computer to perform the control method of the vehicle as described above.
[0013] The electronic and electrical system of the vehicle provided by the embodiments of the present disclosure, on one hand, can realize the safety control function of the vehicle through the first controller, and in the case of failure of the first controller, the second controller can continue to realize the safety control function to replace the first controller, so as to ensure that the vehicle control will not be interrupted in the case of failure of the first controller, and improve the safety and reliability of the vehicle control. On the other hand, more types of safety control functions can be supported or integrated, which is not limited to a single function, and the safety of the vehicle control is improved. In yet another aspect, the detection focus of the fault is placed on the second controller, so that even if the first controller cannot accurately convey its own fault condition, the second controller can accurately determine whether the first controller is failed, and realize the safety control function in the case of failure of the first controller. BRIEF DESCRIPTION OF DRAWINGS
[0014] The accompanying drawings are included to provide a further understanding of the technical solutions of the present disclosure, and constitute a part of the specification, and are used together with the embodiments of the present disclosure to explain the technical solutions of the present disclosure, and do not constitute a limitation on the technical solutions of the present disclosure.
[0015] FIG. 1 is a block diagram of an electronic and electrical system of a vehicle according to some embodiments;
[0016] FIG. 2 is a block diagram of a second controller according to some embodiments;
[0017] FIG. 3 is a block diagram of a first controller according to some embodiments;
[0018] FIG. 4 is a flowchart of a control method of a vehicle according to some embodiments;
[0019] FIG. 5 is another flowchart of a control method of a vehicle, according to some embodiments;
[0020] FIG. 6 is a block diagram of an electronic device, according to some embodiments;
[0021] FIG. 7 is a block diagram of a vehicle, according to some embodiments; and
[0022] FIG. 8 is a block diagram of another vehicle, according to some embodiments. DETAILED DESCRIPTION
[0023] The technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of protection of the present disclosure.
[0024] Unless otherwise required by context, the term "comprise" and other forms of the term "comprise", such as "comprises" and "comprising", and the like, are used in an open, inclusive sense, that is, as "including, but not limited to". In the description of the specification, the terms "one embodiment", "some embodiments", "exemplary embodiments", "example", "specific example", or "some examples" are intended to indicate that the specific features, structures, materials, or characteristics associated with that embodiment or example are included in at least one embodiment or example of the present disclosure. The illustrative representations of the above terms do not necessarily indicate a consistent or collective dependence on that embodiment or example. In addition, the specific features, structures, materials, or characteristics described can be included in any appropriate manner in any one or more embodiments or examples.
[0025] The terms "first", "second", etc. are used only for the purpose of description and should not be understood as indicating or implying relative importance or implying that the indicated technical features are limited to a certain number. Therefore, the features defined with "first", "second" can explicitly or implicitly include one or more of the features. In the description of the present disclosure, unless otherwise stated, the meaning of "a plurality of" is two or more.
[0026] In the present disclosure, the word "exemplary" or "for example" is used to mean "an example of" or "an example, only. Any implementation or design solution described as "exemplary" or "for example" in the present disclosure should not be construed as being more suitable, advantageous, or any superior to other implementation or design solutions. In fact, a word or phrase, such as "exemplary" or "for example", is used only to present one or more related concepts in a concrete manner.
[0027] In addition, the use of "based on" means open and inclusive, because the process, step, calculation or other action "based on" one or more described conditions or values can be based on additional conditions or values beyond those described in practice.
[0028] Generally, when the vehicle control function fails, the vehicle will not be able to travel normally. In this case, for the vehicle that is driving, it will undoubtedly pose a threat to the life safety of the driver or passenger in the vehicle.
[0029] Therefore, how to improve the reliability of vehicle control is a technical problem to be solved.
[0030] To this end, some embodiments of the present disclosure provide an electronic and electrical system of a vehicle, the electronic and electrical system of the vehicle comprising a first controller and a second controller, the first controller and the second controller being connected. The control function of the first controller comprises a safety control function. The second controller is configured to perform zone control, and the second controller is further configured to implement the safety control function in the event of failure of the first controller.
[0031] The electronic and electrical system of the vehicle provided by some embodiments of the present disclosure can, on the one hand, implement the safety control function of the vehicle through the first controller, and on the other hand, continue to implement the safety control function through the second controller instead of the first controller in the event of failure of the first controller, so as to ensure that the vehicle control will not be interrupted in the event of failure of the first controller, and improve the safety and reliability of the vehicle control.
[0032] On the other hand, the electronic and electrical system of the vehicle provided by some embodiments of the present disclosure can support or integrate more types of safety control functions, such as but not limited to a single electric parking brake (EPB) or vehicle control unit (VCU) safety function, thereby improving the safety of the vehicle control. On the other hand, the detection focus of the fault is placed on the second controller, so that even if the first controller cannot accurately convey its own fault condition, the second controller can accurately determine whether the first controller fails, and implement the safety control function in the event of failure of the first controller.
[0033] In another aspect, considering that multiple domain controllers are usually provided in an electronic and electrical architecture, the method provided by some embodiments of the present disclosure can redundantly implement a safety control function on the basis of the original controller of the vehicle, thereby improving the safety and reliability of the vehicle without adding a new controller, saving cost and storage space.
[0034] For ease of understanding, first, an electronic and electrical system of a vehicle provided by some embodiments of the present disclosure is introduced.
[0035] As shown in FIG. 1, the electronic and electrical system 10 of the vehicle includes a first controller 110 and a second controller 120, and the second controller 120 is connected to the first controller 110. In some embodiments, the electronic and electrical system 10 of the vehicle can further include a reset device 130.
[0036] The first controller 110 is configured to implement vehicle control of the vehicle, and the control function of the first controller 110 includes a safety control function. The safety control function can also be referred to as a basic safety function, and the safety control function includes but is not limited to at least one of the following: an electric power steering (EPS) function, an integrated powertrain brake (IPB) function, a vehicle control unit (VCU) function, and a body control module (BCM) function. In some embodiments, the first controller 110 can also send control signaling to the second controller 120 to control the second controller 120.
[0037] The second controller 120 is configured to perform regional control. The vehicle is divided into multiple regions according to position, and the second controller 120 can be configured to perform regional control on a region. For example, the second controller 120 can be arranged in or near the region, so that the devices in the region are connected to the second controller 120 nearby to shorten the length of the connection harness. The second controller 120 can also have control functions of part of the functional domain. The second controller 120 is also configured to implement the safety control function in the case of failure of the first controller 110. In some embodiments, the second controller 120 is also configured to monitor the state of the first controller 110. It should be noted that in the case where the first controller 110 is not failed, the second controller 120 can also implement its own control function, such as a power management function.
[0038] In some embodiments, the first controller 110 is further configured to send an indication message to the second controller 120 to indicate the status of the first controller 110. For example, the indication message comprises one or more of a pulse width modulation (PWM) message or a heartbeat message. The PWM message can also be referred to as a hardwire PWM, a PWM signal or a PWM waveform. Correspondingly, the second controller 120 determines whether the status of the first controller 110 is the failure status according to the reception of the indication message.
[0039] For example, the first controller 110 is determined to be failed in a case that at least one of the PWM message meets a first failure condition or the heartbeat message meets a second failure condition. The first failure condition and the second failure condition can be referred to the description in the method embodiments below.
[0040] In some embodiments, the second controller 120 implements a handshake process with the first controller 110 in a case that no communication connection is established between the first controller 110 and the second controller 120. The first controller 110 is determined to be failed in a case that a handshake time in the handshake process exceeds a preset time threshold.
[0041] In some embodiments, the first controller 110 is further configured to send an auxiliary control request message to the second controller 120 in a case of failure, the auxiliary control request message being configured to request the second controller 120 to implement a safety control function. Correspondingly, the second controller 120 determines that the first controller 110 is failed in a case that the auxiliary control request message is received. In addition, the second controller 120 implements the safety control function after determining that the first controller 110 is failed.
[0042] In some embodiments, the first controller 110 and the second controller 120 are both connected with a bus and obtain vehicle operation parameters from the bus, so as to determine a control instruction suitable for the vehicle based on the vehicle operation parameters. The vehicle operation parameters comprise at least one of a start button signal, a brake signal, an accelerator pedal depth signal, a brake pedal depth signal, an ethernet (ETH) signal and the like.
[0043] It should be noted that, in a case that the first controller 110 is not failed, the second controller 120 can always determine the control instruction based on the vehicle operation parameters, but does not perform the external sending operation. In a case that the first controller 110 is failed, the second controller 120 implements the safety control function based on the determined control instruction. In this way, the safety control function can be smoothly transitioned, the instruction delay caused by the switching of the first controller 110 and the second controller 120 is reduced, and the safety and reliability of the vehicle control are improved.
[0044] In some embodiments, the electronic and electrical system 10 comprises a plurality of zone controllers, the first controller 110 being a first zone controller of the plurality of zone controllers, and the second controller 120 being a second zone controller of the plurality of zone controllers. In some embodiments, the first zone controller is deployed with the function of a central domain controller.
[0045] In some embodiments, the first controller 110 is a central domain controller of the electronic and electrical system 10.
[0046] In some embodiments, the second controller 120 is a zone controller of the electronic and electrical system 10.
[0047] In some embodiments, one of the first controller 110 and the second controller 120 is a left domain controller of the electronic and electrical system 10, and the other is a right domain controller of the electronic and electrical system 10.
[0048] In some embodiments, the reset device 130 is connected with the first controller 110, and the reset device 130 is configured to output a reset signal to the first controller 110 to reset the first controller 110 in case that the first controller 110 is detected to be failed.
[0049] In some embodiments, a reset number threshold, also referred to as a maximum reset number, is set in the reset device 130. In case that the reset device 130 fails to reset for N times continuously, and N reaches the reset number threshold, the reset device 130 no longer outputs the reset signal, so as to avoid the problem that the reset device 130 still frequently resets the first controller 110 in case that the second controller 120 has successfully implemented the safety control function. It should be noted that the above-mentioned N is a positive integer.
[0050] In some embodiments, the second controller 120 comprises a plurality of cores, one of the plurality of cores being configured to implement the safety control function in case that the first controller 110 is failed, and the other of the plurality of cores being configured to implement the control function of the second controller 120 itself. For example, a first core of the plurality of cores is configured to implement the safety control function in case that the first controller 110 is failed, and a second core of the plurality of cores is configured to implement the control function of the second controller 120 itself. Based on this, the safety control function can be deployed on the second controller 120 by means of core redundancy. Compared with directly deploying the safety control function on the second controller 120, the function redundancy is implemented by means of core redundancy, so that the safety control function can be migrated in case that the first controller 110 is failed, and the implementation of the control function of the second controller 120 itself is not affected.
[0051] As shown in FIG. 2, the second controller 120 includes a first core 210, a second core 220, and a third core 230. The first core 210 is configured to implement a safety control function. The second core 220 is configured to deploy a single-domain safety function and a single-domain vehicle body system control function. The single-domain safety function is a control function for the second controller 120 itself, and the single-domain safety function includes, but is not limited to, at least one of a power management function or an electronic parking brake (EPB) function. In a case where the second controller 120 is a right-domain vehicle body controller, the single-domain vehicle body system control function deployed by the second core 220 is configured to control a right-domain vehicle body system. In a case where the second controller 120 is a left-domain vehicle body controller, the single-domain vehicle body system control function deployed by the second core 220 is configured to control a left-domain vehicle body system. The third core 230 is configured to deploy a network function.
[0052] In some embodiments, in a case where the first controller 110 fails, the second controller 120 implements the safety control function through the first core 210. For example, the second controller 120 invokes the first core 210, and implements the safety control function and a hard-wired output based on a vehicle operating parameter. Meanwhile, the second core 220 and the third core 230 remain running.
[0053] It should be noted that the cores can also be referred to as cores, kernels, or modules, and each core can be understood as a basic unit of executing instructions and processing data.
[0054] In some embodiments, the multiple cores in the second controller 120 are integrated on the same hardware device with processing capability. For example, the multiple cores in the second controller 120 can be deployed in the same chip or the same central processing unit (CPU). With the development of technology, they can also be deployed in the same other form of hardware device, such as an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), and a digital signal processor (DSP), etc. Of course, the multiple cores in the second controller 120 can also be deployed on different chips.
[0055] In some embodiments, the hardware device used by each of the plurality of cores in the second controller 120 is independent of each other. For example, the second controller 120 includes a plurality of hardware devices, and each of the plurality of hardware devices is deployed with one core of the second controller 120. For example, the first core 210, the second core 220, and the third core 230 are deployed on different chips, respectively. It can be understood that the hardware device can also have other forms, which can be referred to the description above.
[0056] In yet some embodiments, some of the plurality of cores in the second controller 120 are deployed on independent hardware devices, and some of the plurality of cores are integrated deployed on the same hardware device. For example, the first core 210 can be deployed on one chip alone, and the second core 220 and the third core 230 can be integrated deployed on another chip.
[0057] In some embodiments, the first controller 110 also includes a plurality of cores, one of the plurality of cores is configured to implement a safety control function, and the other cores are configured to implement control functions other than the safety control function.
[0058] As shown in FIG. 3, the first controller 110 includes a fourth core 310, a fifth core 320, and a sixth core 330. The fourth core 310 is configured to implement a safety control function. The fifth core 320 is configured to deploy a single-domain vehicle body system control function, a chassis function, and a network driver function. In the case that the first controller 110 is a right-domain vehicle body controller, the single-domain vehicle body system control function deployed by the fifth core 320 is configured to control a right-domain vehicle body system. In the case that the first controller 110 is a left-domain vehicle body controller, the single-domain vehicle body system control function deployed by the fifth core 320 is configured to control a left-domain vehicle body system. The sixth core 330 is configured to deploy a network function.
[0059] Similarly, the plurality of cores in the first controller 110 are integrated on the same hardware device with processing capability. Alternatively, the hardware device used by each of the plurality of cores in the first controller 110 is independent of each other. Alternatively, some of the plurality of cores in the first controller 110 are deployed on independent hardware devices, and some of the plurality of cores are integrated deployed on the same hardware device. For example, the integrated deployment of the plurality of cores in the first controller 110 can be referred to the description above of the integrated deployment of the plurality of cores in the second controller 120.
[0060] It should be noted that, in the case where the first controller 110 and the second controller 120 each include a kernel configured to implement the safety control function, on the one hand, it is beneficial to update or maintain the safety control function, for example, only the corresponding kernel in the first controller 110 and the second controller 120 needs to be updated or maintained, thereby improving the efficiency and reliability of maintaining the safety control function. On the other hand, it is convenient to implement the redundancy of the safety control function in the second controller 120, so that when the redundant safety control function is implemented, only the content of the fourth kernel 310 in the first controller 110 needs to be copied through the first kernel 210, without affecting the use of other kernels.
[0061] In some embodiments, in the case where the first controller 110 fails, the safety control function is always implemented by the second controller 120, and no function migration is performed. After receiving the restart instruction, for example, after the vehicle is powered on again, the first controller 110 is enabled by default to implement the safety control function.
[0062] It can be understood that the above-mentioned terminal embodiments are only for more clearly illustrating the technical solutions of the present disclosure, and do not constitute a limitation on the present disclosure. Those skilled in the art can know that, with the evolution of network architecture and the appearance of new business scenarios, the technical solutions provided by the present disclosure are also applicable to similar technical problems.
[0063] In order to more clearly illustrate the control method of the vehicle provided by the present disclosure, the window transmission method provided by the present disclosure is introduced below in combination with the drawings. It should be pointed out that the embodiments of the present disclosure can be mutually borrowed or referred to, for example, the same or similar steps, method embodiments and device embodiments can be mutually referred to, and the present disclosure does not limit this.
[0064] As shown in FIG. 4, some embodiments of the present disclosure provide a control method of a vehicle, applied to the electronic and electrical system 10 of the vehicle, and the method includes S101 to S102.
[0065] S101, the second controller confirms that the first controller fails.
[0066] The control function of the first controller includes a safety control function. In addition, the first controller can also implement vehicle control.
[0067] The safety control function can also be referred to as a basic safety function, and the safety control function is a function related to a basic safety requirement of vehicle operation. For example, the safety control function includes at least one of an electric power steering (EPS) function, an integrated power brake (IPB) function, a vehicle control unit (VCU) function, and a body control module (BCM) function. The EPS function is configured to assist a driver in steering a steering wheel by an electric motor. The IPB function integrates an engine, a generator, an electric motor, and a brake system together to improve efficiency and reduce emissions. The VCU function is configured to monitor and manage various functions of the vehicle. The BCM function is configured to control body system functions of the vehicle.
[0068] The safety control function is deployed on the first controller, and the safety control function is also deployed on the second controller. That is, the safety control function of the first controller is redundant on the second controller. Based on this, a redundancy domain is introduced in the controllers of the vehicle, and the safety control function is provided in the multiple controllers without adding new controllers, so that the multiple controllers are redundant to each other. In this way, in the case of failure of a single controller, the basic control of the whole vehicle can still be reliably operated, and the safety and reliability of the vehicle operation are improved.
[0069] In some embodiments, in addition to the safety control function, the first controller can also integrate a single-domain body system function and a network function. In addition to the safety control function, the second controller can also integrate its own control function, such as a single-domain safety function. It can be understood that the structure and function of the first controller and the structure and function of the second controller can also refer to the description of the electronic and electrical system of the vehicle above.
[0070] In some embodiments, the second controller can also monitor the state of the first controller during the implementation of the safety control function by the first controller.
[0071] In some embodiments, the first controller can also initialize an Ethernet protocol to determine whether the first controller fails. For example, in the case that the first controller fails to initialize and still fails after 3 attempts, it is determined that the first controller fails.
[0072] In some embodiments, the first controller is also connected with a reset device, and in the case that the first controller fails, the reset device sends a reset signal. In response to the reset signal, the second controller is reset. It should be noted that the reset device includes at least one of a hardware reset device or a software reset device.
[0073] In order to more clearly illustrate the vehicle control method provided by some embodiments of the present disclosure, the way in which the second controller monitors the state of the first controller is briefly introduced below.
[0074] In some embodiments, the control method further comprises: the second controller receiving an indication message sent by the first controller. The state of the first controller is determined according to the reception of the indication message. In this way, the second controller can monitor the state of the first controller according to the reception of the indication message.
[0075] In some embodiments, the indication message comprises at least one of a pulse width modulation (PWM) message or a heartbeat message. It can be understood that other possible indication messages can also exist, which are not limited in the present disclosure.
[0076] In some embodiments, the method for the second controller to confirm the failure of the first controller comprises at least one of:
[0077] The indication message comprises a pulse width modulation (PWM) message, and the first controller is determined to fail when the PWM message meets a first failure condition. The first failure condition comprises at least one of: the PWM message is not received within a first preset time length, or a target parameter of the received PWM message is out of a preset parameter range, the target parameter comprising at least one of a frequency or a duty cycle.
[0078] The indication message comprises a heartbeat message, and the first controller is determined to fail when the heartbeat message meets a second failure condition. The second failure condition comprises at least one of: the heartbeat message is not received within a second preset time length, or a handshake time in a handshake process with the first controller before the heartbeat message is received exceeds a preset time threshold.
[0079] It can be understood that when the PWM message meets the first failure condition, it can be considered that the PWM message is not received successfully. When the heartbeat message meets the second failure condition, it can be considered that the heartbeat message is not received successfully.
[0080] Alternatively, the above method can also be understood as: the first controller is determined to fail when at least one of the following conditions is met: the PWM message meets the first failure condition, or the heartbeat message meets the second failure condition.
[0081] Some embodiments of the state determination method for the first controller are described below.
[0082] (1) The indication message comprises a pulse width modulation (PWM) message, and the first controller is determined to fail when the PWM message meets a first failure condition.
[0083] In some embodiments, the first preset time length is 1 second. It can be understood that the first preset time length can also have other possible values. The time length set by the first preset time length can be shortened, for example, the first preset time length is set to 0.1 seconds, 0.5 seconds, etc., to improve the failure judgment efficiency, so that the second controller can quickly take over when the first controller fails. For example, the time length set by the first preset time length can be extended, for example, the first preset time length is set to 1.1 seconds, 1.2 seconds, etc., to reduce the possibility of failure misjudgment, thereby improving the failure judgment reliability.
[0084] In some embodiments, the target parameter of the received PWM message exceeding the preset parameter range includes: the target parameter of the received PWM message continuously exceeding the preset parameter range within the first preset time length. For example, in the case of receiving a PWM message and the target parameter of the PWM message not being within the preset parameter range, the second controller accumulates the first timeout time. In the case where the first timeout time exceeds the first preset time length, it is determined that the PWM message meets the first failure condition or that the PWM message reception fails.
[0085] In some embodiments, not receiving the PWM message includes: not receiving the PWM message within the first preset time length. For example, in the case of not receiving the PWM message, the second controller accumulates the first timeout time. In the case where the first timeout time exceeds the first preset time length, it is determined that the PWM message meets the first failure condition or that the PWM message reception fails.
[0086] In some embodiments, in the case of receiving the PWM message and the target parameter of the PWM message being within the preset parameter range, the above-mentioned first timeout time can be cleared.
[0087] Based on this, in the case of PWM message reception failure, other judgments are not made and the second controller is directly switched to implement the safety control function, reducing the judgment steps. Especially in the case where the first controller of the vehicle is indeed failed, the other controller can be more quickly and safely controlled, improving the safety and reliability of the vehicle driving.
[0088] (2) The indication message includes a heartbeat message, and in the case where the heartbeat message meets the second failure condition, it is determined that the first controller fails.
[0089] In some embodiments, the second preset time length is 1 second. It can be understood that the second preset time length can also have other possible values. The time length set by the second preset time length can be shortened, for example, the second preset time length is set to 0.1 seconds, 0.5 seconds, etc., to improve the failure judgment efficiency, so that the second controller can quickly take over when the first controller fails. For example, the time length set by the second preset time length can be extended, for example, the second preset time length is set to 1.1 seconds, 1.2 seconds, etc., to reduce the possibility of failure misjudgment, thereby improving the failure judgment reliability.
[0090] In some embodiments, not receiving the heartbeat packet includes not receiving the heartbeat packet within the second preset time length. For example, in the case of not receiving the heartbeat packet, the second controller accumulates the second timeout time. In the case that the second timeout time exceeds the second preset time length, it is determined that the heartbeat packet meets the first failure condition or it is determined that the heartbeat packet receiving fails.
[0091] In some embodiments, in the case of receiving the heartbeat packet, the above-mentioned second timeout time can be cleared.
[0092] Based on this, in the case of heartbeat packet receiving failure, the second controller can be directly switched to implement the safety control function without other judgments, reducing the judgment steps. Especially in the case that the first controller of the vehicle indeed fails, the safety control can be performed more quickly and to other controllers, improving the safety and reliability of vehicle driving.
[0093] (3) The indication packet includes a pulse width modulation (PWM) packet and a heartbeat packet, and the first controller is determined to fail in the case that the PWM packet meets the first failure condition and the heartbeat packet meets the second failure condition.
[0094] The related content that the PWM packet meets the first failure condition can refer to the corresponding description in the above embodiments, and the related content that the heartbeat packet meets the second failure condition can refer to the corresponding description in the above embodiments.
[0095] Compared with determining the state of the first controller based on only the reception of the PWM message or only the reception of the heartbeat message, the state of the first controller can be more accurately determined by comprehensively considering the reception of the PWM message and the reception of the heartbeat message. For example, in a case where the heartbeat message is not received but the PWM message is received, it does not necessarily mean that the first controller is failed, for example, there can be other problems such as a configuration error of a message flag or signal interference. In a case where the PWM message is not received but the heartbeat message is received, it also does not necessarily mean that the first controller is failed, for example, there can be other problems such as the first controller selecting a PWM waveform of a different data format from the second controller, line noise interference, or poor hard-wire contact. Therefore, only in a case where the PWM message is not received and the heartbeat message is not received, it is determined that the first controller is failed, and the accuracy of failure determination can be improved.
[0096] In some embodiments, the method for the second controller to confirm the failure of the first controller includes: in a case where the handshake time of the handshake process between the first controller and the second controller exceeds a preset time threshold, the second controller determines that the first controller is failed. For example, the handshake between the first controller and the second controller occurs in a case where no communication connection is established between the first controller and the second controller.
[0097] In some embodiments, the method for the second controller to confirm the failure of the first controller includes: in a case where the second controller receives an auxiliary control request message sent by the first controller, the second controller determines that the first controller is failed, and the auxiliary control request message is configured to request the second controller to implement a safety control function. Based on this, the second controller can be directly informed of the state of the first controller through the auxiliary control request, and the monitoring workload of the second controller is reduced, so that the second controller can be quickly called to implement the safety control function.
[0098] In order to more clearly illustrate the control method of the vehicle provided by some embodiments of the present disclosure, please refer to FIG. 5. The second controller can determine whether the first controller is failed by the following steps S201 to S212. That is, S101 can include the following steps S201 to S212.
[0099] S201, receiving a PWM message sent by the first controller.
[0100] S202, determining whether the PWM message is received. In a case where the PWM message is received, step S203 is performed, and in a case where the PWM message is not received, step S204 is performed.
[0101] S203, determining whether the target parameter of the received PWM message belongs to a preset parameter range. In a case where the target parameter belongs to the preset parameter range, step S206 is performed, and in a case where the target parameter does not belong to the preset parameter range, step S204 is performed.
[0102] S204, accumulate the first timeout time, and perform step S205.
[0103] S205, determine whether the first timeout time exceeds a first preset time length. In the case that the first timeout time exceeds the first preset time length, it is determined that the PWM packet reception fails, and step S212 is performed. In the case that the first timeout time does not exceed the first preset time length, step S201 is returned.
[0104] S206, clear the first timeout time, and return to step S201.
[0105] S207, determine whether the first controller has been successfully handshaked. If yes, step S209 is performed, and if no, step S208 is performed.
[0106] S208, determine whether the handshaking time exceeds a preset time threshold. If yes, step S212 is performed, and if no, step S207 is returned.
[0107] S209, determine whether the heartbeat packet sent by the first controller is received. In the case that the heartbeat packet is received, step S209 is repeatedly performed, and in the case that the heartbeat packet is not received, step S210 is performed.
[0108] S210, accumulate the second timeout time, and perform step S211.
[0109] S211, determine whether the second timeout time exceeds a second preset time length. In the case that the second timeout time exceeds the second preset time length, it is determined that the heartbeat packet reception fails, and step S212 is performed. In the case that the second timeout time does not exceed the second preset time length, step S209 is returned.
[0110] S212, in the case that the handshaking time exceeds the preset time threshold, or in the case that the PWM packet reception fails and the heartbeat packet reception fails, it is determined that the first controller is invalid. It can be understood that the PWM packet reception failure can also be understood as that the PWM packet satisfies the first invalidation condition. The heartbeat packet reception failure can also be understood as that the heartbeat packet satisfies the second invalidation condition.
[0111] In some embodiments, step S212 further comprises: determining that the first controller is invalid in the case that the handshaking time exceeds the preset time threshold and the PWM packet reception fails. It can be understood that, based on the embodiment shown in FIG. 5, in the case that the handshaking time exceeds the preset time threshold, it means that the heartbeat packet will fail to be received.
[0112] It should be noted that the steps S201 to S206 described above can be executed simultaneously with the steps S207 to S211, or can be executed before the steps S207 to S211, or can be executed after the steps S207 to S211. In addition, the steps S207 and S208 are optional steps, for example, in the case where the first controller and the second controller have successfully established a connection, the steps S207 and S208 can not be executed. It can be understood that the present disclosure does not limit this.
[0113] S102, the second controller implements a safety control function.
[0114] That is, the second controller implements the safety control function in the case where the first controller is confirmed to be failed.
[0115] In some embodiments, after the second controller is powered on for the first time or wakes up from hibernation, the second controller determines the control instruction related to the safety control function, but does not issue the control instruction. That is, in the case where the first controller is not failed, the second controller and the first controller simultaneously implement the application logic of the safety control function, but the second controller does not issue the control instruction related to the safety control function, and only in the case where the first controller is failed, the control instruction is issued.
[0116] Based on this, in the case where the first controller is failed, the second controller can quickly issue the determined control instruction, reduce the instruction delay caused by the switching of the first controller and the second controller, so as to be able to realize the smooth migration of the safety control function, and improve the reliability of vehicle control.
[0117] The control method of the vehicle provided by some embodiments of the present disclosure can realize the safety control function of the vehicle through the first controller, and in the case where the first controller is failed, the second controller can continue to realize the safety control function instead of the first controller. In this way, it can be ensured that the vehicle control will not be interrupted in the case where the first controller is failed, and the safety and reliability of vehicle control are improved.
[0118] On the other hand, more types of safety control functions can be supported or integrated, which are not limited to a single safety function such as electric parking brake EPB or vehicle control unit VCU, and the safety of vehicle control is improved. On the other hand, the detection focus of the fault is placed on the second controller, so that even if the first controller cannot accurately convey its own fault condition, the second controller can accurately determine whether the first controller is failed, and implement the safety control function in the case where the first controller is failed.
[0119] In another aspect, considering that a central domain controller and several area controllers are usually arranged in an electronic and electrical architecture, the method provided by the present disclosure redundantly implements a safety control function on the basis of the original controller of the vehicle (e.g., deploying a safety control function on a second controller), thereby improving the safety and reliability of the vehicle without adding a new controller, saving cost and storage space.
[0120] In addition, some embodiments of the present disclosure also provide a control method of a vehicle, applied to an electronic and electrical system of the vehicle, the electronic and electrical system of the vehicle comprising a first controller and a second controller connected to the first controller, the second controller being configured to implement a safety control function of the vehicle in the case of failure of the first controller, the method comprising: in the case that the first controller is able to work, the first controller implements the safety control function.
[0121] In some embodiments, the second controller is further configured to monitor the state of the first controller.
[0122] In some embodiments, the first controller further implements the following steps: sending an indication message to the second controller, so that the second controller can monitor the state of the first controller according to the reception of the indication message, thereby determining whether the state of the first controller is a failure state. For example, the indication message comprises one or more of a PWM message and a heartbeat message.
[0123] In some embodiments, the above-mentioned sending of the indication message to the second controller comprises: after the first controller is powered on for the first time or wakes up from hibernation, initialization is performed. In the case that the initialization is successful, the first controller implements the safety control function of the vehicle and sends a PWM message and a heartbeat message to the second controller. In the case that the initialization fails, the first controller continues to attempt initialization.
[0124] In some embodiments, the first controller sends the heartbeat message to the second controller only after the initialization of the Ethernet chip of the first controller is successful.
[0125] In some embodiments, the target parameter of the PWM message sent by the first controller is within a preset parameter range. For example, the first controller sends a PWM message with a fixed frequency and a fixed duty cycle to the second controller.
[0126] In some embodiments, the above-mentioned method further comprises: in the case of a fault, the first controller sends an auxiliary control request message to the second controller, the auxiliary control request message being configured to request the second controller to implement the safety control function.
[0127] For example, in a case where a controller area network (CAN) transceiver of the safety function system in the first controller is detected to be faulty, the auxiliary control request message is sent to the second controller.
[0128] For example, the auxiliary control request message can also be sent to the second controller in a case where the first controller is faulty and the first controller fails to reset. Based on this, the accuracy of failure judgment can be improved.
[0129] In some embodiments, the first controller is connected with a reset device, and the method further includes: in a case where the first controller receives a reset signal sent by the reset device, resetting the first controller. It should be noted that the reset device includes at least one of a hardware reset device or a software reset device. It should be noted that the first controller and the second controller can each be equipped with different reset devices to ensure that the first controller and the second controller can be independently reset.
[0130] For example, taking a hardware watchdog as the reset device, in a case where the first controller is not faulty, the first controller performs a feeding operation on the hardware watchdog every preset time, for example, the first controller clears a timer built in the hardware watchdog every preset time. In response to the first controller not performing the feeding operation within the preset time, the hardware watchdog determines that the first controller is faulty, and sends a reset signal to the first controller to make the first controller reset based on the reset signal.
[0131] For example, the maximum number of resets of the first controller can also be set to avoid the case where the first controller is frequently reset.
[0132] The control method of the vehicle provided by some embodiments of the present disclosure has the following advantages. On the one hand, the safety control function of the vehicle can be realized by the first controller, and in a case where the first controller is faulty, the safety control function can be continued to be realized by the second controller instead of the first controller. In this way, the vehicle control will not be interrupted in a case where the first controller is faulty, and the safety and reliability of the vehicle control are improved. On the other hand, more types of safety control functions can be supported or integrated, and the safety control functions are not limited to a single safety function such as an electric parking brake (EPB) or a vehicle control unit (VCU), and the safety of the vehicle control is improved. On the other hand, the detection focus of the fault is placed on the second controller, so that even if the first controller cannot accurately convey its own fault condition, the second controller can accurately monitor whether the first controller is faulty, and realize the safety control function in a case where the first controller is faulty.
[0133] It can be understood that, in order to realize the above functions, the above device comprises at least one of the hardware structure or the software module corresponding to the execution of each function. Those skilled in the art should easily realize that, in combination with the algorithm steps of each embodiment described in the embodiments disclosed in the present text, the present disclosure can be realized in the form of hardware or the combination of hardware and computer software. Whether a certain function is executed in the form of hardware or computer software driven hardware depends on the specific application and design constraints of the technical solution. The skilled person can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present disclosure.
[0134] Some embodiments of the present disclosure also provide a second controller configured to implement the control method of the vehicle. The second controller comprises a state monitoring module and a redundant safety module.
[0135] The state monitoring module is configured to monitor the state of the first controller during the implementation of the safety control function by the first controller, the first controller being configured to implement the safety control function of the vehicle.
[0136] The redundant safety module is configured to implement the safety control function in the case of failure of the first controller.
[0137] In some embodiments, the safety control function comprises at least one of the following: electric power steering EPS function, integrated powertrain brake IPB function, vehicle control unit VCU function, body control module BCM function.
[0138] In some embodiments, the state monitoring module is configured to receive an indication message sent by the first controller. According to the reception of the indication message, the state of the first controller is determined.
[0139] In some embodiments, the indication message comprises one or more of a pulse width modulation PWM message and a heartbeat message.
[0140] In some embodiments, the indication message comprises a pulse width modulation PWM message, and the state monitoring module is configured to determine that the first controller fails in the case that the PWM message meets a first failure condition.
[0141] In some embodiments, the indication message comprises a heartbeat message, and the state monitoring module is configured to determine that the first controller fails in the case that the heartbeat message meets a second failure condition.
[0142] In some embodiments, the indication message comprises a pulse width modulation (PWM) message and a heartbeat message, and the state monitoring module is configured to determine that the first controller fails when the PWM message meets a first failure condition and the heartbeat message meets a second failure condition. Here, the first failure condition and the second failure condition can refer to the descriptions above.
[0143] In some embodiments, the state monitoring module is configured to determine that the first controller fails when a handshake time of a handshake process between the first controller and the second controller exceeds a preset time threshold.
[0144] In some embodiments, the state monitoring module is configured to determine that the first controller fails when an auxiliary control request message sent by the first controller is received, and the auxiliary control request message is configured to request the second controller to implement the safety control function.
[0145] In some embodiments, the second controller comprises a plurality of cores, a first core of the plurality of cores is configured to implement the safety control function when the first controller fails, and a second core of the plurality of cores is configured to implement a control function of the second controller itself. In some embodiments, the redundant safety module is for the core responsible for implementing the safety control function, or the redundant safety module can be integrated on the core responsible for implementing the safety control function.
[0146] In addition, some embodiments of the present disclosure also provide a first controller configured to implement the control method of the vehicle described above. The first controller is configured to implement vehicle control of the vehicle, and the control function of the first controller comprises a safety control function.
[0147] The first controller comprises a safety control module. The safety control module is configured to implement the safety control function of the vehicle when the first controller is able to work.
[0148] In some embodiments, the first controller further comprises at least one of a state indication module or a function reset module.
[0149] In some embodiments, the state indication module is configured to send an indication message to the second controller.
[0150] In some embodiments, the indication message comprises at least one of a pulse width modulation (PWM) message or a heartbeat message.
[0151] In some embodiments, the state indication module is further configured to send an auxiliary control request message to the second controller when the first controller fails. The auxiliary control request message is configured to request the second controller to implement the safety control function.
[0152] In some embodiments, the function reset module is configured to reset the first controller in a case where a reset signal sent by the reset device is received.
[0153] It should be noted that the division of the modules in the first controller and the second controller described above is illustrative, and is only a logical function division. In actual implementation, another division manner can be used. For example, two or more functions can be integrated in one processing module. The integrated module can be implemented in the form of hardware or in the form of a software function module.
[0154] In a case where the functions of the integrated module are implemented in the form of hardware, some embodiments of the present disclosure further provide a possible structure of an electronic device configured to perform the control method of the vehicle provided by some embodiments of the present disclosure. Similarly, the electronic device and the control method of the vehicle described above can be correspondingly referred to each other.
[0155] As shown in FIG. 6, the electronic device includes a processor 602 and a communication interface 603. In some embodiments, the electronic device can further include at least one of a bus 604 and a memory 601.
[0156] The processor 602 can be various exemplary logical blocks, modules and circuits described in combination with some embodiments of the present disclosure. The processor 602 can be a central processing unit, a general purpose processor, a digital signal processor, an application specific integrated circuit, a field programmable gate array or other programmable logic device, a transistor logic device, a hardware component or any combination thereof. The processor 602 can implement or execute various exemplary logical blocks, modules and circuits described in combination with some embodiments of the present disclosure. The processor 602 can also be a combination of computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.
[0157] The communication interface 603 is configured to be connected with other devices through a communication network. The communication network can be an Ethernet, a wireless access network, a wireless local area network (WLAN) and the like.
[0158] The memory 601 can be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, an electrically erasable programmable read-only memory (EEPROM), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer, but is not limited thereto.
[0159] In some embodiments, the memory 601 can be independent of the processor 602, and the memory 601 can be connected to the processor 602 through the bus 604. The memory 601 is configured to store instructions or program codes executable by the processor 602, such as computer program instructions and the like. When the processor 602 invokes and executes the instructions or program codes stored in the memory 601, the control method of the vehicle provided by the embodiments of the present disclosure can be implemented.
[0160] In some embodiments, the memory 601 can also be integrated with the processor 602.
[0161] The bus 604 can be an extended industry standard architecture (EISA) bus or the like. The bus 604 can be divided into an address bus, a data bus, a control bus, and the like. For ease of representation, only one thick line is shown in FIG. 6, but it does not mean that there is only one bus or only one type of bus.
[0162] Referring to FIGS. 7 and 8, some embodiments of the present disclosure further provide a vehicle 1000, which includes the electronic and electrical system 10 described above, or the vehicle 1000 includes the first controller 110 and the second controller 120 described above.
[0163] Some embodiments of the present disclosure further provide a computer readable storage medium (for example, a non-transitory computer readable storage medium) having computer program instructions stored therein, and the computer program instructions, when executed on a computer, cause the computer to perform the control method of the vehicle as described in the above embodiments. It can be understood that the present disclosure does not limit the form of the computer.
[0164] In some embodiments, the aforementioned computer readable storage medium can include, but is not limited to, magnetic storage devices (e.g., hard disk, floppy disk, magnetic strips, etc.), optical disks (e.g., compact disk (CD), digital versatile disk (DVD), etc.), smart cards, and flash memory devices (e.g., card, stick, and key drive, etc.). The various computer readable storage media described herein can represent one or more devices and / or other machine-readable storage media configured to store instructions and / or data. The term "machine-readable storage medium" can include, without being limited to, wireless channels and various other media capable of storing, containing, and / or carrying instructions and / or data.
[0165] Some embodiments of the present disclosure provide a computer program product containing instructions which, when the computer program product runs on a computer, cause the computer to execute the control method of the vehicle described in the above embodiments.
Claims
1. An electronic and electrical system of a vehicle, comprising a first controller and a second controller, the first controller being connected with the second controller; wherein, the control function of the first controller comprises a safety control function; the second controller is configured to perform zone control, and the second controller is further configured to implement the safety control function in case of failure of the first controller.
2. The system of claim 1, wherein, the safety control function comprises at least one of: an electric power steering (EPS) function, an integrated power brake (IPB) function, a vehicle control unit (VCU) function, or a body control module (BCM) function.
3. The system of claim 1 or 2, wherein, the electronic and electrical system comprises a plurality of zone controllers, the first controller being a first zone controller of the plurality of zone controllers, and the second controller being a second zone controller of the plurality of zone controllers.
4. The system of claim 3, wherein, the first zone controller is deployed with a function of a central domain controller.
5. The system of claim 1 or 2, wherein, the first controller is a central domain controller of the electronic and electrical system.
6. The system of claim 1 or 2, wherein, one of the first controller and the second controller is a left domain controller of the electronic and electrical system, and the other is a right domain controller of the electronic and electrical system.
7. The system of any one of claims 1-6, wherein, the first controller is further configured to send an indication message to the second controller; the second controller is further configured to determine whether the first controller is in a failure state according to reception of the indication message.
8. The system of claim 7, wherein, the indication message comprises at least one of a pulse width modulation (PWM) message or a heartbeat message.
9. The system of claim 7, further satisfying at least one of: The indication message comprises a pulse width modulation (PWM) message, and the second controller is further configured to determine that the first controller is failed when the PWM message meets a first failure condition. the first failure condition comprises at least one of: no reception of the PWM message within a first preset time duration, or a target parameter of the received PWM message being out of a preset parameter range, the target parameter comprising at least one of a frequency or a duty cycle; or, the indication message comprises a heartbeat message, and the second controller is further configured to determine that the first controller is in failure in case that the heartbeat message meets a second failure condition, the second failure condition comprising at least one of: no reception of the heartbeat message within a second preset time duration; a handshake time in a handshake process with the first controller before reception of the heartbeat message exceeds a preset time threshold.
10. The system of any one of claims 1-9, wherein, the second controller is further configured to determine that the first controller is in failure in case that a handshake time in a handshake process between the first controller and the second controller exceeds a preset time threshold.
11. The system of any one of claims 1-10, wherein, the first controller is further configured to send an auxiliary control request message to the second controller in case of a fault, the auxiliary control request message being configured to request the second controller to implement the safety control function; the second controller is further configured to implement the safety control function in case of reception of the auxiliary control request message.
12. The system of any one of claims 1-11, wherein, The second controller comprises a plurality of cores, a first core of the plurality of cores is configured to implement the safety control function in case of failure of the first controller, and a second core of the plurality of cores is configured to implement a zone control function of the second controller.
13. The system of any one of claims 1-12, further comprising: a reset device connected with the first controller, the reset device being configured to output a reset signal to the first controller in case of detecting failure of the first controller.
14. A control method of a vehicle, applied to the electronic and electrical system of any one of claims 1-13, the method comprising: the second controller confirming failure of the first controller; the second controller implementing the safety control function.
15. The method of claim 14, wherein, The safety control function comprises at least one of: an electric power steering (EPS) function, an integrated power brake (IPB) function, a vehicle control unit (VCU) function, or a body control module (BCM) function.
16. The method of claim 14, further comprising: receiving an indication packet sent by the first controller; determining a state of the first controller based on reception of the indication packet.
17. The method of claim 16, wherein, The indication packet comprises at least one of a pulse width modulation (PWM) packet or a heartbeat packet.
18. The method of claim 16, further satisfying at least one of: The second controller confirms the failure of the first controller, including: The indication packet comprises a pulse width modulation (PWM) packet, and the first controller is determined to fail in case that the PWM packet meets a first failure condition; the first failure condition comprises at least one of: the PWM packet is not received within a first preset time length; a target parameter of the received PWM packet is out of a preset parameter range, the target parameter comprising at least one of a frequency or a duty cycle; or, The indication packet comprises a heartbeat packet, and the first controller is determined to fail in case that the heartbeat packet meets a second failure condition; the second failure condition comprises at least one of: the heartbeat packet is not received within a second preset time length; a handshake time in a handshake process with the first controller before receiving the heartbeat packet exceeds a preset time threshold.
19. The method of any one of claims 14-18, wherein, The second controller confirming failure of the first controller comprises: The second controller determines the first controller to fail in case that a handshake time in a handshake process with the first controller exceeds a preset time threshold.
20. The method of any one of claims 14-19, wherein, The second controller confirming failure of the first controller comprises: The second controller determines the first controller to fail in case that an auxiliary control request packet sent by the first controller is received, the auxiliary control request packet being configured to request the second controller to implement the safety control function.
21. The method of any one of claims 14-20, wherein, The second controller comprises a plurality of cores, a first core of the plurality of cores is configured to implement the safety control function in case of failure of the first controller, and a second core of the plurality of cores is configured to implement a zone control function of the second controller. 22.A control method of a vehicle applied to the electronic and electrical system according to any one of claims 1-13, the method comprising: in a case that the first controller is able to work, the first controller implements a safety control function of the vehicle; the first controller sends an indication message to the second controller, so that the second controller determines whether the first controller is in a failure state according to a reception of the indication message.
23. The method of claim 22, wherein, the indication message comprises at least one of a pulse width modulation (PWM) message or a heartbeat message. 24.The method of claim 22 or 23, further comprising: in a case that the first controller fails, the first controller sends an auxiliary control request message to the second controller, the auxiliary control request message is configured to request the second controller to implement the safety control function.
25. The method of any one of claims 22-24, wherein, the safety control function comprises at least one of an electric power steering (EPS) function, an integrated power brake (IPB) function, a vehicle control unit (VCU) function, or a body control module (BCM) function.
26. The method of claims 22-25, wherein, the first controller is connected with a reset device, and the method further comprises: in a case that the first controller receives a reset signal sent by the reset device, the first controller is reset.
27. A first controller comprising: a processor and a memory configured to store processor-executable instructions; wherein the processor is configured to execute the instructions such that the first controller performs the control method of the vehicle according to any one of claims 22-26.
28. A second controller comprising: a processor and a memory configured to store processor-executable instructions; wherein the processor is configured to execute the instructions such that the second controller performs the control method of the vehicle according to any one of claims 14-21. 29.A vehicle comprising the electronic and electrical system according to any one of claims 1-13; or, comprising the first controller according to claim 27 and the second controller according to claim 28. 30.A computer-readable storage medium having computer instructions stored thereon, when the computer instructions are executed on a computer, causing the computer to perform the control method of the vehicle according to any one of claims 14-26.
Citation Information
Patent Citations
Failure control method and system for remote power-on of vehicle
CN108650282A
System detection method and device, equipment, storage medium, vehicle and cloud control platform
CN114844807A
VCU redundancy control system based on function safety and application thereof
CN115179964A
Redundancy control system and method for autonomous vehicle and vehicle
CN115805964A
Nuclear power emergency diesel engine redundancy control method and system based on heartbeat monitoring
CN117555214A