Boot management circuit and method for domain controller, and MCU, domain controller and vehicle

By introducing high ASIL-level control modules and power management circuits into the ADAS domain controller, the system can ensure that the SOC is powered on according to a preset timing sequence and detect anomalies, thus solving the problems of high cost and low efficiency in SOC control and improving the safety and stability of the domain controller.

WO2026091274A1PCT designated stage Publication Date: 2026-05-07HUNAN XINGBIDA NETLINK TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
HUNAN XINGBIDA NETLINK TECH CO LTD
Filing Date
2024-12-24
Publication Date
2026-05-07

AI Technical Summary

Technical Problem

Existing SOC control is costly and inefficient, affecting the safety and stability of ADAS domain controllers.

Method used

The power-on and boot phases of the SOC are controlled by the control module. The ASIL level of the control module is higher than that of the SOC. It generates power supply commands for multiple phases and detects the power supply status. The power management circuit performs voltage conversion to ensure that the functional modules are powered according to the preset timing and restarts the SOC in case of abnormality.

Benefits of technology

It reduces control costs and improves the security and stability of domain controller startup management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024141820_07052026_PF_FP_ABST
    Figure CN2024141820_07052026_PF_FP_ABST
Patent Text Reader

Abstract

A boot management circuit for a domain controller. A control module sequentially generates power supply instructions for a plurality of stages on the basis of a preset time sequence requirement, and detects power supply states of functional modules on the basis of power supply state signals; a power management circuit converts a power voltage on the basis of the power supply instructions for the plurality of stages, so as to sequentially obtain a plurality of power supply voltages, and generates the plurality of power supply state signals; and when an SOC is normally powered on, the control module generates a mode selection instruction for controlling the SOC to run a boot stage, detects a running state of the SOC in the boot stage, and generates an SOC reboot instruction when the running state in the boot stage is abnormal. Further disclosed are a management method used by the management circuit, and an MCU, a domain controller, and a vehicle having the circuit or the MCU. The powering-on and a boot stage of an SOC are controlled by means of a control module, and an ASIL of the control module is higher than an ASIL of the SOC, such that the control cost is low and the efficiency is high, thereby improving the safety and stability of boot management of a domain controller.
Need to check novelty before this filing date? Find Prior Art

Description

Domain controller startup management circuitry, methods, MCU, domain controller, and vehicle

[0001] This application claims priority to Chinese Patent Application No. 202411556961.0, filed on November 4, 2024, entitled “Domain Controller Startup Management Circuit, Method, MCU, Domain Controller and Vehicle”, the entire contents of which are incorporated herein by reference. Technical Field

[0002] This application relates to the field of vehicle control technology, and in particular to a domain controller startup management circuit, method, MCU, domain controller, and vehicle. Background Technology

[0003] With the continuous development of electric vehicle control technology, Advanced Driving Assistance System (ADAS) domain controllers are now able to handle key tasks in intelligent and autonomous driving processes, including perceiving the environment, planning driving paths, determining location, and making decisions, while controlling the vehicle in real time, significantly improving driving comfort and safety.

[0004] In the design of ADAS domain controllers, the system-on-chip (SOC) is usually the core component, providing the necessary computing power. However, due to the multi-core structure and complex power system design of the SOC, the control cost is high and the efficiency is low, which affects the security and stability of the domain controller. Summary of the Invention

[0005] This application provides a domain controller startup management circuit, method, MCU, domain controller, and vehicle to address the shortcomings of existing SOC control technologies, such as high cost, low efficiency, and negative impacts on the security and stability of the domain controller. This application controls the power-on and boot phases of the SOC through a control module. The ASIL level of the control module is higher than that of the SOC, resulting in low control cost and high efficiency, thus improving the security and stability of domain controller startup management.

[0006] This application provides a domain controller startup management circuit. The domain controller includes a System-on-Chip (SOC). The SOC includes multiple functional modules. The SOC powers on normally when all functional modules are powered on. The power supply of the multiple functional modules meets preset timing requirements. The domain controller startup management circuit includes a control module and a power management circuit. The ASIL level of the control module is higher than that of the SOC. The control module is used to generate multiple stages of power supply commands according to the preset timing requirements and detect the power supply status of the functional modules based on power supply status signals. The power management circuit is used to perform voltage conversion on the power supply voltage based on the multiple stages of power supply commands, obtaining multiple power supply voltages in sequence, and corresponding to... The control module generates multiple power supply status signals; the power supply commands for multiple stages correspond one-to-one with multiple power supply voltages; the multiple power supply voltages correspond one-to-one with the power supply of multiple functional modules; the power supply command for the next stage is generated based on the power supply status signals of the current stage; the control module is further configured to generate a mode selection command to control the SOC to run the Boot stage when the SOC is normally powered on, and to detect the running status of the SOC in the Boot stage; the mode selection command is a command to control the storage mode of the Boot stage; and generate a SOC restart command when the running status of the Boot stage is abnormal; the SOC restart command is a command to control the SOC to power on again.

[0007] According to the domain controller startup management circuit provided in this application, the SOC includes a core functional module, an additional functional module, and a peripheral transmission functional module; the preset timing requirement is to sequentially power the core functional module, the additional functional module, and the peripheral transmission functional module; the control module is an MCU; the MCU is specifically used to generate a first-stage power supply command, a second-stage power supply command, and a third-stage power supply command in a timing sequence, and to detect the power supply status of the core functional module based on the first-stage power supply status signal, the power supply status of the additional functional module based on the second-stage power supply status signal, and the power supply status of the peripheral transmission functional module based on the third-stage power supply status signal; the power management circuit includes an integrated voltage conversion module and a voltage regulation conversion module; the integrated voltage conversion module is used to adjust the power supply status of the core functional module based on the first-stage power supply command. The power supply voltage is converted to obtain a first-stage power supply voltage, and a first-stage power supply status signal is generated; the first-stage power supply voltage is the voltage supplying power to the core functional module; the second-stage power supply command is generated based on the first-stage power supply status signal; the voltage regulation and conversion module is used to convert the power supply voltage based on the second-stage power supply command to obtain a second-stage power supply voltage, and generate a second-stage power supply status signal; the second-stage power supply voltage is the voltage supplying power to the additional functional module; the third-stage power supply command is generated based on the second-stage power supply status signal; the power supply voltage is converted based on the third-stage power supply command to obtain a third-stage power supply voltage, and a third-stage power supply status signal is generated; the third-stage power supply voltage is the voltage supplying power to the peripheral transmission functional module.

[0008] According to the domain controller startup management circuit provided in this application, it further includes a first PMIC module; the first PMIC module is used to perform voltage conversion on the power supply voltage based on the vehicle power-on signal to obtain the MCU power supply voltage; the MCU power supply voltage is the voltage that supplies power to the MCU.

[0009] According to a domain controller startup management circuit provided in this application, the integrated voltage conversion module is a second PMIC module; the voltage regulation conversion module includes a first DC-DC module, a second DC-DC module, and a third DC-DC module; the first DC-DC module is used to convert the power supply voltage based on the vehicle power-on signal to obtain a converted voltage; the second DC-DC module is used to convert the converted voltage based on the second stage power supply command to obtain the second stage power supply voltage, and generate the second stage power supply status signal; the third DC-DC module is used to convert the converted voltage based on the third stage power supply command to obtain the third stage power supply voltage, and generate the third stage power supply status signal.

[0010] According to a domain controller boot management circuit provided in this application, the MCU is further configured to: generate a FLASH mode selection instruction to control the SOC to run the Boot phase when the SOC is powered on normally, and detect the running status of the SOC in FLASH mode; the FLASH mode selection instruction is an instruction to select the FLASH mode; generate a first restart SOC instruction when the running status of the FLASH mode is abnormal; generate an eMMC mode selection instruction to control the SOC to run the Boot phase when the SOC is powered on normally based on the first restart SOC instruction, and detect the running status of the SOC in eMMC mode; the eMMC mode selection instruction is an instruction to select the eMMC mode; generate a second restart SOC instruction when the running status of the eMMC mode is abnormal; generate an SSD mode selection instruction to control the SOC to run the Boot phase when the SOC is powered on normally based on the second restart SOC instruction, and detect the running status of the SOC in SSD mode; the SSD mode selection instruction is an instruction to select the SSD mode.

[0011] According to a domain controller boot management circuit provided in this application, the control module is further configured to detect the state of the SOC booting the Linux operating system when the SOC is running normally in the Boot phase.

[0012] This application also provides a domain controller startup management method, wherein the domain controller includes a System-on-Chip (SOC); the SOC includes multiple functional modules; the SOC powers on normally when all of the multiple functional modules have been powered on; the power supply of the multiple functional modules meets preset timing requirements; the method includes: generating multiple stages of power supply commands according to the preset timing requirements and detecting the power supply status of the functional modules based on power supply status signals; controlling a power management circuit to perform voltage conversion on the power supply voltage based on the multiple stages of power supply commands, obtaining multiple power supply voltages in sequence, and causing the power management circuit to generate multiple power supply status signals accordingly; the multiple stages of power supply commands... Each of the power supply commands corresponds to one of the multiple power supply voltages; each of the multiple power supply voltages corresponds to one of the power supply to the multiple functional modules; the power supply command for the next stage is generated based on the power supply status signal of the current stage; when the SOC is powered on normally, a mode selection command is generated to control the SOC to run the Boot stage, and the running status of the SOC in the Boot stage is detected; the mode selection command is a command to control the storage mode of the Boot stage; when the running status of the Boot stage is abnormal, a SOC restart command is generated; the SOC restart command is a command to control the SOC to power on again.

[0013] This application also provides an MCU, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the domain controller startup management method as described above.

[0014] This application also provides a domain controller, including a System-on-a-Chip (SOC), and further including the aforementioned domain controller startup management circuitry.

[0015] This application also provides a vehicle, including the aforementioned domain controller or the aforementioned domain controller startup management circuit or the aforementioned MCU.

[0016] This application provides a domain controller startup management circuit, method, MCU, domain controller, and vehicle. The control module generates multiple stages of power supply commands according to preset timing requirements and detects the power supply status of functional modules based on power supply status signals. The power management circuit performs voltage conversion on the power supply voltage based on the multiple stages of power supply commands, obtaining multiple power supply voltages in sequence and generating multiple corresponding power supply status signals. When the SOC is normally powered on, the control module generates a mode selection command to control the SOC to run the Boot stage and detects the SOC's operating status during the Boot stage. If the Boot stage operating status is abnormal, a SOC restart command is generated. This application controls the SOC's power-on and Boot stages through a control module. The ASIL level of the control module is higher than that of the SOC, resulting in low control cost and high efficiency, improving the security and stability of domain controller startup management. Attached Figure Description

[0017] To more clearly illustrate the technical solutions in this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0018] Figure 1 is a schematic diagram of the domain controller startup management circuit provided in this application.

[0019] Figure 2 is a schematic diagram of the principle of the preset timing requirements provided in this application.

[0020] Figure 3 is a schematic diagram of the SOC power-on process provided in this application.

[0021] Figure 4 is a schematic diagram of the structure of the eMMC and SSD storage space provided in this application.

[0022] Figure 5 is a schematic diagram illustrating the principle of the SOC provided in this application operating during the Boot phase.

[0023] Figure 6 is a flowchart illustrating the domain controller startup management method provided in this application.

[0024] Figure 7 is a schematic diagram of the structure of the MCU provided in this application.

[0025] Reference numerals: 1: MCU; 2: SOC; 3: First PMIC module; 4: Second PMIC module; 5: First DC-DC module; 6: Second DC-DC module; 7: Third DC-DC module. Detailed Implementation

[0026] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0027] With the continuous development of autonomous driving control technology for electric vehicles, ADAS domain controllers can perform tasks such as perception, planning, localization, and decision-making for intelligent or autonomous driving, and complete real-time vehicle control, effectively increasing driving comfort and safety. ADAS domain controllers typically use system-on-a-chip (SoC) to meet computing power requirements. However, due to the multi-core structure and complex power system design of the SoC, control costs are high and efficiency is low, affecting both the safety and stability of the domain controller.

[0028] Please refer to Figure 1, which is a schematic diagram of the domain controller startup management circuit provided in this application.

[0029] This application provides a domain controller startup management circuit. The domain controller includes a System-on-Chips (SOC2). The SOC2 includes multiple functional modules. The SOC2 powers on normally when all functional modules are powered on. The power supply of the multiple functional modules meets preset timing requirements. The domain controller startup management circuit includes a control module and a power management circuit. The ASIL level of the control module is higher than that of the SOC2. The control module is used to generate multiple stages of power supply commands according to the preset timing requirements and detect the power supply status of the functional modules based on power supply status signals. The power management circuit is used to perform voltage conversion on the power supply voltage based on the multiple stages of power supply commands, and obtain multiple power supply voltages in a timing sequence. Multiple power supply status signals are generated accordingly; the power supply commands for multiple stages correspond one-to-one with multiple power supply voltages; the multiple power supply voltages correspond one-to-one with the power supply of multiple functional modules; the power supply command for the next stage is generated based on the power supply status signal of the current stage; the control module is also used to generate a mode selection command to control the SOC2 to run the Boot stage when the SOC2 is powered on normally, and to detect the running status of the SOC2 in the Boot stage; the mode selection command is the command to control the storage mode in the Boot stage; if the running status in the Boot stage is abnormal, a restart command for the SOC2 is generated; the restart command for the SOC2 is the command to control the SOC2 to power on again.

[0030] To enhance the controller's safety performance, a control module with a higher functional safety level is required to power on and operate the SOC2 chip. The domain controller startup management circuit is designed to ensure that each functional module of the SOC2 can safely and reliably complete its power-on according to a preset timing sequence. This circuit design considers the ASIL level requirements in the automotive industry, with the control module having a higher ASIL level than the SOC2, providing enhanced safety. The control module generates multiple stages of power-on commands based on preset timing requirements. These commands are sent to the power management circuit via the control module. The control module is also responsible for monitoring the power supply status of the functional modules to ensure that the power supply at each stage meets the requirements.

[0031] The power management circuit provides the required supply voltage for different stages step by step according to the power supply commands provided by the control module. The power management circuit is also responsible for generating power supply status signals, which are fed back to the control module to monitor the power supply status of each functional module. Multiple power supply commands for each stage correspond to multiple supply voltages; multiple supply voltages correspond to the power supply of multiple functional modules; the power supply command for the next stage is generated based on the power supply status signals of the current stage.

[0032] After the SOC2 powers on normally, the control module generates a mode selection command to control the SOC2 to enter the Boot phase. During the Boot phase, the SOC2 loads the boot program from a preset storage device. The control module monitors the SOC2's operating status during the Boot phase. If an anomaly is detected, such as the boot program failing to load or encountering an error, the control module generates a restart command for the SOC2; the restart command is the command that controls the SOC2 to power on again.

[0033] In addition, the control module can be, but is not limited to, MCU1, FPGA (Field-Programmable Gate Array), or CPLD (Complex Programmable Logic Device). MCU1 can be ASIL-D grade.

[0034] The power management circuit may include a voltage conversion module, such as a PMIC (Power Management Integrated Circuit) module or a DCDC (Direct Current to Direct Current Converter) module, which is not specifically limited herein.

[0035] The domain controller startup management circuit of this application controls the power-on and boot phase of SOC2 through the control module, which can ensure that multiple functional modules are powered on safely and reliably according to the preset timing sequence, and handle faults when necessary, ensuring that the power supply and boot of SOC2 are normal. The ASIL level of the control module is higher than that of SOC2, with low control cost and high efficiency, improving the security and stability of domain controller startup management.

[0036] In a preferred embodiment, SOC2 includes a core functional module, an additional functional module, and a peripheral transmission functional module; the preset timing requirement is to supply power to the core functional module, the additional functional module, and the peripheral transmission functional module sequentially; the control module is MCU1; MCU1 is specifically used to generate a first-stage power supply command, a second-stage power supply command, and a third-stage power supply command, and to detect the power supply status of the core functional module based on the first-stage power supply status signal, the power supply status of the additional functional module based on the second-stage power supply status signal, and the power supply status of the peripheral transmission functional module based on the third-stage power supply status signal; the power management circuit includes an integrated voltage conversion module and a voltage regulation conversion module; the integrated voltage conversion module is used to regulate the power supply based on the first-stage power supply command. The source voltage is converted to obtain the first-stage supply voltage, and a first-stage supply status signal is generated. The first-stage supply voltage is the voltage that supplies power to the core functional modules. The second-stage supply command is generated based on the first-stage supply status signal. The voltage regulation and conversion module is used to convert the power supply voltage based on the second-stage supply command to obtain the second-stage supply voltage, and generate a second-stage supply status signal. The second-stage supply voltage is the voltage that supplies power to the additional functional modules. The third-stage supply command is generated based on the second-stage supply status signal. The power supply voltage is converted based on the third-stage supply command to obtain the third-stage supply voltage, and a third-stage supply status signal is generated. The third-stage supply voltage is the voltage that supplies power to the peripheral transmission functional modules.

[0037] In a preferred embodiment, it further includes a first PMIC module 3; the first PMIC module 3 is used to perform voltage conversion on the power supply voltage based on the vehicle power-on signal to obtain the MCU1 power supply voltage; the MCU1 power supply voltage is the voltage that supplies power to the MCU1.

[0038] In a preferred embodiment, the integrated voltage conversion module is the second PMIC module 4; the voltage regulation conversion module includes a first DC-DC module 5, a second DC-DC module 6, and a third DC-DC module 7; the first DC-DC module 5 is used to convert the power supply voltage based on the vehicle power-on signal to obtain a converted voltage; the second DC-DC module 6 is used to convert the converted voltage based on the second-stage power supply command to obtain the second-stage power supply voltage and generate a second-stage power supply status signal; the third DC-DC module 7 is used to convert the converted voltage based on the third-stage power supply command to obtain the third-stage power supply voltage and generate a third-stage power supply status signal.

[0039] Please refer to Figure 2, which is a schematic diagram of the principle of the preset timing requirements provided in this application.

[0040] Please refer to Figure 3, which is a schematic diagram of the SOC power-on process provided in this application.

[0041] The SOC2 power supply requires a specific startup sequence and multiple power rails, necessitating the power-on of three sets of power rails in a sequential order. In this embodiment, VCC is the power supply for the domain controller, providing the power voltage. K15 is the enable signal for the domain controller and also serves as the power-on signal for the electric vehicle. After the electric vehicle is ignited, K15 (the vehicle power-on signal) goes high, and the domain controller enters the startup state (SOC2 power-on). After successful startup, it enters the working state (Boot stage + Linux system stage). The control module is MCU1. The domain controller startup management circuit also includes a first PMIC module 3. The voltage input terminal of the first PMIC module 3 is connected to the power output terminal, and the output terminal of the first PMIC module 3 is connected to the voltage input terminal of MCU1. After K15 goes high, the first PMIC module 3 converts the power supply VCC into a voltage that can power MCU1. The first PMIC module 3 can also power the peripheral circuits related to MCU1.

[0042] The power management circuit includes an integrated voltage conversion module and a voltage regulation module. The integrated voltage conversion module is the second PMIC module 4; the voltage regulation module includes a first DC-DC module 5, a second DC-DC module 6, and a third DC-DC module 7. The voltage input terminal of the first DC-DC module 5 is connected to the power output terminal, and the output terminal of the first DC-DC module 5 is connected to the voltage input terminals of the second DC-DC module 6 and the third DC-DC module 7, respectively. When K15 ignites, the first DC-DC module 5 also starts working, converting the power supply VCC to voltage Vm (converted voltage). Vm can power sensors such as radar and cameras, and also serves as the power supply for the second DC-DC module 6 and the third DC-DC module 7. Due to the design of Vm, a stable input Vm allows the second DC-DC module 6 and the third DC-DC module 7 to operate within their ideal operating range. Both PMIC and DC-DC converters are power conversion chips, but PMICs have more comprehensive functions and higher integration than DC-DC converters. Therefore, the first PMIC module 3, with the same ASIL-D functional safety level, is selected for voltage conversion in the power supply of MCU1.

[0043] After MCU1 powers on and operates normally, it first sets POR_L low and then enables the EN1 signal (generating the first-stage power supply command). The voltage input terminal of the second PMIC module 4 is connected to the power output terminal, and the output terminal of the second PMIC module 4 is connected to the voltage input terminal of the core functional module (Group 1). The second PMIC module 4 performs voltage conversion on the power supply voltage based on the first-stage power supply command (EN1) to obtain the first-stage power supply voltage (Vgrp1) and generates the first-stage power supply status signal (PG1). The first-stage power supply voltage is the voltage that supplies power to the core functional module. MCU1 also simultaneously detects the Power Good pin PG1 of the second PMIC module 4.

[0044] When PG1 is invalid, the circuit of the second PMIC module 4 is re-enabled; when PG1 is valid, the next stage power supply is started. MCU1, according to the timing table, delays Td1 to enable EN2 (generating the second-stage power supply command). The second DC-DC module 6 performs voltage conversion on the conversion voltage based on the second-stage power supply command (EN2) to obtain the second-stage power supply voltage (Vgrp2) and generates the second-stage power supply status signal (PG2). The second-stage power supply voltage is the voltage that supplies power to the additional function module (Group2). MCU1 simultaneously detects the Power Good pin PG2 of the second DC-DC module 6.

[0045] When PG2 is invalid, the circuit of the second DC-DC module 6 is re-enabled; when PG2 is valid, the next stage power supply is started. MCU1, according to the timing table, delays Td2 to enable EN3 (generating the third-stage power supply command). The third DC-DC module 7 performs voltage conversion on the conversion voltage based on the third-stage power supply command (EN3) to obtain the third-stage power supply voltage (Vgrp3) and generates the third-stage power supply status signal (PG3). The third-stage power supply voltage is the voltage that supplies power to the peripheral transmission function module (Group3). MCU1 also detects the Power Good pin PG3 of the third DC-DC module 7.

[0046] When PG3 is invalid, the circuit of the third DC-DC module 7 is re-enabled; when PG3 is valid, it indicates that the SOC2 power supply is powered on normally.

[0047] POR_L is the control signal for SOC2 power-on. During power-on, POR_L is low. After SOC2 power-on is normal, POR_L will be high after a delay of Td3. POR_L is controlled by MCU1.

[0048] Core functional modules, such as the CPU (Central Processing Unit), GPU (Graphics Processing Unit), and DSP (Digital Signal Processor), are the main computing resources of the SOC2, responsible for executing program instructions and processing data. Additional functional modules may include storage controllers (such as memory controllers), dedicated hardware accelerators (such as encryption accelerators and AI accelerators), and other processor cores for specific tasks. These modules enhance the functionality of the SOC2, enabling it to perform more complex tasks. Peripheral transmission functional modules include various I / O (Input / Output) interfaces and communication interfaces, such as USB (Universal Serial Bus), SATA (Serial Advanced Technology Attachment), Ethernet, and wireless communication modules (Wi-Fi (Wireless Fidelity), Bluetooth, NFC (Near Field Communication), etc.). These modules enable the SOC2 to transmit and communicate with external devices; this application does not impose any specific limitations on these modules.

[0049] MCU1, SOC2, and the first PMIC module 3, the second PMIC module 4, the first DC-DC module 5, the second DC-DC module 6, and the third DC-DC module 7 can all be functionally safe at ASIL-D level.

[0050] In summary, in this embodiment, the domain controller's startup process involves first powering on and running the MCU1, and then starting the SOC2. The startup power management of the SOC2 within the domain controller is controlled by the MCU1. The MCU1 manages the power startup sequence of the SOC2 and can detect the status of each power level, providing a strong guarantee for the correct startup of the SOC2.

[0051] In a preferred embodiment, MCU1 is further configured to: generate a FLASH mode selection instruction to control SOC2 to run the Boot phase when SOC2 is powered on normally, and detect the running status of SOC2 in FLASH mode; the FLASH mode selection instruction is an instruction to select FLASH mode; if the running status of FLASH mode is abnormal, generate a first restart SOC2 instruction; if SOC2 is powered on normally based on the first restart SOC2 instruction, generate an eMMC mode selection instruction to control SOC2 to run the Boot phase, and detect the running status of SOC2 in eMMC mode; the eMMC mode selection instruction is an instruction to select eMMC mode; if the running status of eMMC mode is abnormal, generate a second restart SOC2 instruction; if SOC2 is powered on normally based on the second restart SOC2 instruction, generate an SSD mode selection instruction to control SOC2 to run the Boot phase, and detect the running status of SOC2 in SSD mode; the SSD mode selection instruction is an instruction to select SSD mode.

[0052] In a preferred embodiment, the control module is also used to detect the status of the SOC2 booting the Linux operating system during the normal Boot phase of the SOC2.

[0053] Please refer to Figure 4, which is a schematic diagram of the structure of the eMMC and SSD storage space provided in this application.

[0054] Please refer to Figure 5, which is a schematic diagram of the principle of the SOC provided in this application running in the Boot phase.

[0055] In this embodiment, after the SOC2 power-on normally, it enters the Boot stage. The SOC2 itself does not have space for storing the Boot and Linux operating systems; external storage is required. The default boot file is stored in Flash, and other external storage requires allocating a storage space—one for Boot and Linux. There are multiple Boot modes, commonly including FLASH mode, eMMC (embedded Multi Media Card) mode, and SSD (Solid State Drives) mode. Table 1 shows the Boot modes. The levels of the MCU1 control signals C1 and C2 determine the SOC2's Boot mode (external storage boot). C1' and C2' are converted to C1 and C2 through level conversion. When both signals are low, the SOC2's default Boot mode is FLASH mode; the SOC2's Boot mode is switched by setting the levels of the MCU1 output pins C1' and C2'.

[0056] During the Boot phase, MCU1 first delays for a period equal to the Boot+Linux startup time. Since MCU1 and SOC2 operate on different power rails, a level conversion circuit is required for signal transmission between them. The S1 signal, generated by SOC2, is a pulse signal used to indicate whether SOC2's startup is normal. When SOC2 has finished loading the Boot and is able to boot the operating system, SOC2 generates a fixed-frequency S1 pulse signal to notify MCU1 that SOC2 has started normally. When MCU1 detects a valid S1 signal, it indicates that the SOC2 system has started normally; when S1 is invalid, it indicates that SOC2 failed to boot from FLASH (abnormal operation in FLASH mode) and needs to jump to another memory area.

[0057] Set C1 high and simultaneously pull POR_L low (generating the first SOC2 restart instruction) to restart the SOC2 power-on process. After a delay of Ts, check if the S1 signal is valid. If the S1 signal is valid, it means that the SOC2 system has started normally. If the S1 signal is invalid, it means that the SOC2 failed to start in eMMC (the running state in eMMC mode is abnormal) and needs to jump to other memory areas.

[0058] C2 is set high. Since C1 was already set high previously, this corresponds to SSD mode. At the same time, POR_L is pulled low (generating the second SOC2 reboot instruction), restarting the SOC2 power-on process. After a delay of Ts, the S1 signal is checked for validity. If the S1 signal is valid, it means that the SOC2 system has started normally. If the S1 signal is invalid, it means that the SOC2 failed to boot in the SSD. This indicates that the SOC2 boot failed, and MCU1 records the corresponding fault.

[0059] Table 1 Boot Mode Table

[0060] The S2 signal is a pulse signal sent to MCU1 when the additional function module program is running normally, and is used by MCU1 to monitor the additional functions of SOC2. When the additional function module is running normally, SOC2 generates a fixed-frequency pulse signal S2 to notify MCU1 that the additional function module of SOC2 is running normally.

[0061] The operating system can also be Windows, and this application does not make any special restrictions here.

[0062] The SOC2 and FLASH can be connected via SPI (Serial Peripheral Interface), and the SOC2 and SSD can be connected via PCIe (peripheral component interconnect express, high-speed serial computer expansion bus standard). This application does not impose any special limitations on these connections.

[0063] In summary, in this embodiment, MCU1 can monitor whether SOC2 is working properly. When an internal fault occurs in SOC2, MCU1 can promptly notify MCU1 to restart the power-on sequence and reset SOC2. SOC2's startup requires booting from the Bootloader and the Linux operating system. Based on the boot guarantee mechanism, if the system fails to boot from Flash, MCU1 can redirect the boot process to other storage areas (eMMC, SSD), ensuring a successful system startup. MCU1 can monitor the operation of each functional module of SOC2.

[0064] The domain controller startup management method provided in this application is described below. The domain controller startup management method described below can be referred to in correspondence with the domain controller startup management circuit described above.

[0065] Please refer to Figure 6, which is a flowchart illustrating the domain controller startup management method provided in this application.

[0066] This application also provides a domain controller startup management method, wherein the domain controller includes a SOC2; the SOC2 includes multiple functional modules; the SOC2 powers on normally when all multiple functional modules have been powered on; the power supply of the multiple functional modules meets preset timing requirements; the method includes:

[0067] 601: Generates power supply commands for multiple stages according to preset timing requirements and detects the power supply status of the function module based on the power supply status signal;

[0068] 602: Based on power supply commands in multiple stages, the power management circuit performs voltage conversion on the power supply voltage, obtains multiple supply voltages in sequence, and causes the power management circuit to generate multiple power supply status signals accordingly; the power supply commands in multiple stages correspond one-to-one with the multiple supply voltages; the multiple supply voltages correspond one-to-one with the power supply of multiple functional modules; the power supply command for the next stage is generated based on the power supply status signal of the current stage.

[0069] 603: When SOC2 is powered on normally, generate a mode selection instruction to control SOC2 to run the Boot stage, and detect the running status of SOC2 in the Boot stage; the mode selection instruction is the instruction to control the storage mode in the Boot stage; if the running status in the Boot stage is abnormal, generate a restart instruction for SOC2; the restart instruction for SOC2 is the instruction to control SOC2 to power on again.

[0070] The domain controller provided in this application is described below. The domain controller described below can be referred to in correspondence with the domain controller startup management circuit described above.

[0071] This application also provides a domain controller, including SOC2, and further including the domain controller startup management circuit described above.

[0072] The vehicle provided in this application is described below. The vehicle described below can be referred to in correspondence with the domain controller startup management circuit described above.

[0073] This application also provides a vehicle, including the aforementioned domain controller or the aforementioned domain controller startup management circuit or the aforementioned MCU1.

[0074] Figure 7 illustrates a schematic diagram of an MCU1. As shown in Figure 7, the MCU1 may include: a processor 701, a communication interface 702, a memory 703, and a communication bus 704. The processor 701, communication interface 702, and memory 703 communicate with each other via the communication bus 704. The processor 701 can call logical instructions in the memory 703 to execute a domain controller startup management method. The domain controller includes a System-on-Chips (SOC2). The SOC2 includes multiple functional modules. The SOC2 powers on normally when all functional modules are powered. The power supply of the multiple functional modules meets preset timing requirements. The method includes: generating multiple stages of power supply instructions according to the preset timing requirements and detecting the power supply status of the functional modules based on power supply status signals; controlling the power management circuit to perform voltage conversion on the power supply voltage based on the multiple stages of power supply instructions, obtaining multiple power supply voltages in sequence, and causing the power management circuit to generate multiple power supplies accordingly. Status signals; power supply commands for multiple stages correspond one-to-one with multiple power supply voltages; multiple power supply voltages correspond one-to-one with the power supply of multiple functional modules; the power supply command for the next stage is generated based on the power supply status signal of the current stage; when SOC2 is powered on normally, a mode selection command is generated to control SOC2 to run the Boot stage, and the running status of SOC2 in the Boot stage is detected; the mode selection command is the command to control the storage mode in the Boot stage; if the running status in the Boot stage is abnormal, a restart command for SOC2 is generated; the restart command for SOC2 is the command to control SOC2 to power on again.

[0075] Furthermore, the logical instructions in the aforementioned memory 703 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0076] On the other hand, this application also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the domain controller startup management method provided by the above methods. The domain controller includes a SOC2; the SOC2 includes multiple functional modules; the SOC2 powers on normally when all multiple functional modules are powered; the power supply of the multiple functional modules meets preset timing requirements; the method includes: generating multiple stages of power supply instructions according to the preset timing requirements and detecting the power supply status of the functional modules based on power supply status signals; controlling the power management circuit to adjust the power supply voltage based on the multiple stages of power supply instructions. The system performs voltage conversion, obtains multiple supply voltages in sequence, and causes the power management circuit to generate multiple supply status signals accordingly. The power supply commands for multiple stages correspond one-to-one with the multiple supply voltages. Each of the multiple supply voltages corresponds one-to-one with the power supply of multiple functional modules. The power supply command for the next stage is generated based on the current stage's supply status signal. When SOC2 is powered on normally, a mode selection command is generated to control SOC2 to run the Boot stage, and the operating status of SOC2 in the Boot stage is detected. The mode selection command controls the storage mode in the Boot stage. If the operating status in the Boot stage is abnormal, a restart command for SOC2 is generated. The restart command for SOC2 controls SOC2 to power on again.

[0077] Furthermore, this application also provides a non-transitory computer-readable storage medium storing a computer program thereon. When executed by a processor, the computer program implements the domain controller startup management method provided by the methods described above. The domain controller includes a System-on-Chip (SOC2); the SOC2 includes multiple functional modules; the SOC2 powers on normally when all functional modules are powered; the power supply of the multiple functional modules meets preset timing requirements; the method includes: generating multiple stages of power supply instructions according to the preset timing requirements and detecting the power supply status of the functional modules based on power supply status signals; controlling the power management circuit to perform voltage conversion on the power supply voltage based on the multiple stages of power supply instructions, and obtaining multiple power supply commands in sequence. The power supply is controlled by a voltage regulator, which causes the power management circuit to generate multiple power supply status signals. The power supply commands for each stage correspond to a specific power supply voltage. Each power supply voltage corresponds to the power supply of a specific functional module. The power supply command for the next stage is generated based on the power supply status signals of the current stage. When the SOC2 is powered on normally, a mode selection command is generated to control the SOC2 to run the Boot stage, and the operating status of the SOC2 in the Boot stage is detected. The mode selection command controls the storage mode of the Boot stage. If the operating status of the Boot stage is abnormal, a restart command for the SOC2 is generated. The restart command controls the SOC2 to power on again.

[0078] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0079] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0080] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

[0081] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A domain controller startup management circuit, characterized in that, The domain controller includes a System-on-a-Chip (SOC); the SOC includes multiple functional modules; the SOC powers on normally when all of the functional modules are powered; the power supply of the multiple functional modules meets preset timing requirements; the domain controller startup management circuit includes a control module and a power management circuit; the ASIL level of the control module is higher than the ASIL level of the SOC. The control module is used to generate power supply commands for multiple stages according to the preset timing requirements and to detect the power supply status of the functional module based on the power supply status signal. The power management circuit is used to perform voltage conversion on the power supply voltage based on the power supply commands in multiple stages, obtain multiple power supply voltages in sequence, and generate multiple power supply status signals accordingly. The power supply commands at each of the multiple stages correspond one-to-one with the multiple power supply voltages; Each of the aforementioned power supply voltages corresponds one-to-one with the power supply of the aforementioned functional modules; The power supply command for the next stage is generated based on the power supply status signal of the current stage; The control module is also used to generate a mode selection instruction for controlling the SOC to run the Boot phase when the SOC is powered on normally, and to detect the running status of the SOC in the Boot phase; the mode selection instruction is an instruction for controlling the storage mode of the Boot phase. In the event of an abnormal operating state during the Boot phase, a SOC restart instruction is generated; the SOC restart instruction is an instruction that controls the SOC to power on again.

2. The domain controller startup management circuit according to claim 1, characterized in that, The SOC includes a core functional module, an additional functional module, and a peripheral transmission functional module; the preset timing requirement is to supply power to the core functional module, the additional functional module, and the peripheral transmission functional module in sequence; The control module is an MCU; the MCU is specifically used to generate the first stage power supply command, the second stage power supply command and the third stage power supply command in a timing sequence, and to detect the power supply status of the core functional module based on the first stage power supply status signal, detect the power supply status of the additional functional module based on the second stage power supply status signal, and detect the power supply status of the peripheral transmission functional module based on the third stage power supply status signal. The power management circuit includes an integrated voltage conversion module and a voltage regulation conversion module; The integrated voltage conversion module is used to convert the power supply voltage based on the first stage power supply command to obtain the first stage power supply voltage and generate the first stage power supply status signal; the first stage power supply voltage is the voltage that supplies power to the core functional module; The second-stage power supply command is generated based on the first-stage power supply status signal; The voltage regulation and conversion module is used to perform voltage conversion on the power supply voltage based on the second stage power supply command to obtain the second stage power supply voltage, and generate the second stage power supply status signal; the second stage power supply voltage is the voltage for supplying power to the additional functional module; The third-stage power supply command is generated based on the second-stage power supply status signal; the power supply voltage is converted based on the third-stage power supply command to obtain the third-stage power supply voltage, and a third-stage power supply status signal is generated; the third-stage power supply voltage is the voltage used to supply power to the peripheral transmission function module.

3. The domain controller startup management circuit according to claim 2, characterized in that, It also includes a first PMIC module; the first PMIC module is used to perform voltage conversion on the power supply voltage based on the vehicle power-on signal to obtain the MCU power supply voltage; the MCU power supply voltage is the voltage that supplies power to the MCU.

4. The domain controller startup management circuit according to claim 2, characterized in that, The integrated voltage conversion module is a second PMIC module; the voltage regulation conversion module includes a first DC-DC module, a second DC-DC module, and a third DC-DC module; The first DC-DC module is used to convert the power supply voltage based on the vehicle power-on signal to obtain the converted voltage; The second DC-DC module is used to perform voltage conversion on the conversion voltage based on the second stage power supply command to obtain the second stage power supply voltage and generate the second stage power supply status signal; The third DC-DC module is used to perform voltage conversion on the conversion voltage based on the third-stage power supply command to obtain the third-stage power supply voltage, and generate the third-stage power supply status signal.

5. The domain controller startup management circuit according to claim 2, characterized in that, The MCU is also specifically used for: When the SOC is powered on normally, a FLASH mode selection instruction is generated to control the SOC to run the Boot phase, and the running status of the SOC in FLASH mode is detected. The FLASH mode selection command is a command to select the FLASH mode; In the event of an abnormal running state in the FLASH mode, a first SOC restart instruction is generated; When the SOC is powered on normally based on the first restart SOC instruction, an eMMC mode selection instruction is generated to control the SOC to run the Boot phase, and the running status of the SOC in eMMC mode is detected. The eMMC mode selection command is a command to select the eMMC mode; In the event of an abnormal operating state in the eMMC mode, a second SOC restart instruction is generated; When the SOC powers on normally based on the second restart SOC instruction, an SSD mode selection instruction is generated to control the SOC to run the Boot phase, and the running status of the SOC in SSD mode is detected; the SSD mode selection instruction is an instruction to select the SSD mode.

6. The domain controller startup management circuit according to any one of claims 1 to 5, characterized in that, The control module is also used to detect the status of the SOC booting the Linux operating system when the SOC is running normally during the Boot phase.

7. A domain controller startup management method, characterized in that, The domain controller includes a System-on-Chip (SOC); the SOC includes multiple functional modules. The SOC powers on normally when all of the aforementioned functional modules are powered. The power supply to multiple functional modules meets preset timing requirements; the method includes: According to the preset timing requirements, multiple stages of power supply commands are generated and the power supply status of the functional module is detected based on the power supply status signal. The power management circuit controls the power supply voltage to perform voltage conversion based on the power supply commands in multiple stages, thereby obtaining multiple power supply voltages in sequence, and causing the power management circuit to generate multiple power supply status signals accordingly; the power supply commands in multiple stages correspond one-to-one with the multiple power supply voltages; the multiple power supply voltages correspond one-to-one with the power supply of multiple functional modules; the power supply command for the next stage is generated based on the power supply status signal of the current stage. When the SOC is powered on normally, a mode selection instruction is generated to control the SOC to run the Boot phase, and the running status of the SOC in the Boot phase is detected; the mode selection instruction is an instruction to control the storage mode in the Boot phase; if the running status in the Boot phase is abnormal, a restart SOC instruction is generated; the restart SOC instruction is an instruction to control the SOC to be powered on again.

8. An MCU, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the domain controller startup management method as described in claim 7.

9. A domain controller, characterized in that, It includes a SOC, and also includes the domain controller startup management circuitry as described in any one of claims 1 to 6.

10. A vehicle, characterized in that, Includes the domain controller of claim 7, the domain controller startup management circuit of any one of claims 1 to 6, or the MCU of claim 8.

Citation Information

Patent Citations

  • Optical module

    CN114077018A

  • Embedded SOC chip self-adaptive starting method

    CN114528557A

  • Domain controller starting management circuit and method, MCU, domain controller and vehicle

    CN119058390A

  • Power management circuit and control method therefor, and power management system

    WO2023024788A1