Device for executing a functionality in an automotive communication network
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- CONTINENTAL AUTOMOTIVE TECHNOLOGIES GMBH
- Filing Date
- 2025-11-24
- Publication Date
- 2026-06-11
Smart Images

Figure EP2025084000_11062026_PF_FP_ABST
Abstract
Description
[0001] 202406765
[0002] 1
[0003] DEVICE FOR EXECUTING A FUNCTIONALITY IN AN AUTOMOTIVE COMMUNICATION NETWORK
[0004] Field of Invention
[0005] This invention relates to vehicle networking and control systems. In particular, this invention discloses devices for executing a functionality in an automotive communication network, integrating remote-control protocol functionality with time and / or safety-critical processes. This invention further discloses a respective automotive communication network and vehicle.
[0006] Technical Background and Problem
[0007] Vehicle networking and control systems have become a cornerstone of modem automotive design, revolutionizing how cars operate and interact with their environment. This field has seen rapid advancements in recent years, driven by the increasing demand for connectivity, safety, and autonomous capabilities in vehicles.
[0008] At the heart of these systems are in-vehicle networks (IVNs), which facilitate communication between the numerous electronic control units (ECUs), sensors, and actuators found in today's cars. A typical modern vehicle may contain between 100 to 150 ECUs, managing everything from the powertrain and braking systems to advanced driver assistance features and infotainment.
[0009] The need for reducing the weight of network wiring by implementation advanced functionalities including remote-controlled devices executing time and / or safety-critical processes require stable high-bandwidth, low-latency networks to process vast amounts of sensor data in real-time. However, existing networks face several challenges when dealing with these critical operations, driving the need for even more sophisticated networking solutions.
[0010] The Controller Area Network (CAN) protocol has long been a staple in automotive applications, known for its reliability and cost-effectiveness. However, as vehicles become more complex, the limitations of CAN, particularly in terms of data rate, are 202406765
[0011] 2 becoming apparent. The bandwidth of CAN is often insufficient for the high data throughput required by modern safety-critical systems, especially those involving real-time sensor data or video streams. Also, CAN'S broadcast nature and lack of built-in authentication or encryption make it vulnerable to various attacks. This is particularly concerning for remote-controlled safety-critical processes, as unauthorized access could lead to catastrophic consequences. Additionally, CAN'S arbitration mechanism potentially lead to message delays in high-traffic scenarios.
[0012] This has led to the rise of Automotive Ethernet, which offers significantly higher data transfer rates. However, also Automotive Ethernet poses challenges when implementing time and / or safety-critical processes due to, e.g., latency concerns. Additionally, the implementation of newer technologies like Automotive Ethernet can be more complex and costly compared to established systems like CAN.
[0013] Protocols like FlexRay have been developed to address the need for high-bandwidth, fault-tolerant communication in time-sensitive applications. While FlexRay offers advantages in terms of data payload and network flexibility, its adoption has been limited compared to CAN and Ethernet, partly due to its complexity and higher implementation costs.
[0014] In recently suggested implementations of remote-controlled functionality in automotive communication network, especially if they involve safety-critical processes, the ECUs rely on elaborate software code execution on a microcontroller (MCU) and heavy data exchange to a central ECU to orchestrate said functionality. But an additional MCU in each ECU is a disadvantage from a cost and update perspective.
[0015] The challenges in remote-controlled safety-critical processes are also addressed in various ongoing standardization efforts, such as IEEE 802.3, Open Alliance TC18, CAN in Automation (CiA), or ISO 11898-1 .
[0016] The object of this invention is to provide a device which provides a secure and fast way to execute time and / or safety critical functions in an automotive communication 202406765
[0017] 3 network. It is a further object of this invention to provide a respective network and vehicle.
[0018] Summary of the Invention
[0019] The object is met by the subject-matter of the independent claims. Advantageous embodiments of the invention are subject-matter of the dependent claims.
[0020] The invention is based on the realization of the inventors that a small extra hardware in an electronic control unit (ECU) instead of a full microcontroller (MCU) can provide a kind of minimal intelligence necessary to execute time and / or safety critical processes, reducing the need for elaborate software code execution on the ECU and data traffic to a central ECU or high-performance computer (HPC).
[0021] A first aspect of the invention provides a device for executing a functionality in an automotive communication network, the device being a node in the automotive communication network, the functionality comprising basic processes and time and / or safety critical processes. The device comprises a remote-control protocol (RCP) chip communicatively coupled to the automotive communication network via a first communication means while using a remote-control protocol. The RCP chip executes the basic processes using input channels and / or output channels. The device further comprises a calculation unit communicatively coupled to the automotive communication network or the remote-control chip via a second communication means. The calculation unit is formed to execute at least in part the time and / or safety critical processes.
[0022] The functionality may be any function or process which requires exchange of data over the automotive communication network. Usually, multiple components like sensors, switches, or actuators interact to execute the functionality. Examples for functionalities include anti-pinch protection for window lifters, central locking systems, powertrain and airbag control, or interior lighting. Also, low-level tasks such as crash-detection as part of an airbag control functionality is considered a functionality. 202406765
[0023] 4
[0024] The functionality is comprised of processes which be characterized by at least two classes: basic processes that are not subject to time and / or safety critical requirements, and those that are. Basic processes might include the ability to read out sensor signals, signal / data and address encoding, voltage and current control as well as phase or pulse modulation. Even adhering to a certain communication protocol like Local Interconnect Network (LIN) or Controller Area Network (CAN) is considered to be a basic process.
[0025] On the other hand, time and / or safety critical processes include analysis of sensor data, fault detection, or fail-operation mechanisms. Processes that require conditional validation (if / then statements) are considered beyond basic processes and thus might be characterized as time and / or safety critical processes.
[0026] Some processes are time critical but do not require a closed loop, such as a turn indicator, in which the time criticality requires a responsiveness of about 100ms. However, security critical processes such as anti-pinch protection for a window lifter typically require a close loop and a responsiveness in the range of 5ms. That is, some processes are just time critical, others may be time and safety critical.
[0027] The automotive communication network consists of nodes, one of which is the device itself. The device therefore comprises a first communication means which enables communication between the device and the network. The first communication means might be a CAN or Ethernet transceiver and controller (CAN or Ethernet node).
[0028] The network usually comprises further nodes, such as edge nodes or a central ECU or HPC. Edge nodes might be embodied as sensors (such as a pressure or temperature sensor, Radar, or Lidar), actuators, or transmitters (for example lighting components such as light emitting diodes (LEDs)). While all nodes feature a communication interface such as CAN or Ethernet, only some nodes comprise further components depending on their type, such as sensors, actuators, System-on-Chip (SoC), MCUs, a central processing unit (CPU), graphic processing units (GPUs), or memory such as random-access memory (RAM). 202406765
[0029] 5
[0030] The device comprises an RCP chip which features specialized integrated circuits (ICs) designed to handle standardized methods of communication enabling the device being controlled from another device in the network. Usual RCPs in automotive applications include LIN, CAN, or Ethernet (such as 10BASE-T1 S). The specialized ICs are designed to handle the encoding, transmission, reception, and decoding of remote-control signals.
[0031] The RCP chip exclusively executes the basic processes of the functionality. In particular, the RCP chip is not formed to execute time and / or safety critical processes. Any input or output channels required for a specific functionality are part of the device. For example, the functionality of airbag control requires analysis of acceleration sensor data to detect a crash. Therefore, a data input channel from said acceleration sensor is required.
[0032] The device further comprises a calculation unit which is communicatively coupled either to the automotive communication network directly or the remote-control chip (and therefore indirectly coupled to the automotive communication network). The coupling is established via a second communication means, which might be a Serial Peripheral Interface (SPI) or LIN.
[0033] The calculation unit is formed to execute at least in part the time and / or safety critical processes, establishing a division for the execution of basic and time and / or safety critical processes between the calculation unit and the RCP chip. This division ensures that time and / or safety critical processes are always handled appropriately even during network failure situations such as high latency, bandwidth limitations, or connection loss.
[0034] Advantageously, the calculation unit is communicatively coupled to the output channels of the remote-control protocol chip. Then, the calculation unit is able to control the output channels in case of a failure of the RCP chip (for example a damaged RCP chip) or the network (for example when data from the RCP chip cannot be received by a central ECU due to a low bandwidth). 202406765
[0035] 6
[0036] Advantageously, the second communication means is one of:
[0037] - A Serial Peripheral Interface (SPI), Inter-Integrated Circuit (l2C), Pulse Width Modulation (PWM), General Purpose Input / Output (GPIO), Local Interconnect Network (LIN), Universal Asynchronous Receiver / Transmitter (UART), Peripheral Sensor Interface 5 (PSI5), or Single Edge Nibble Transmission (SENT), directly connecting the remote-control protocol chip and the calculation unit,
[0038] - A bus directly connecting the calculation unit and the automotive communication network or a further communication network different from the automotive communication network.
[0039] The second communication means is therefore either directly connecting the calculation unit and the RCP chip, or the calculation unit to a network, or both (introducing redundancy). In the latter case, the network might be the same network to which the RCP chip is connected or a different, further network. The calculation unit being connected to the automotive communication network might introduce a redundant communication channel to deal with failure situations. The calculation unit being connected to a further communication network allows for a backup communication channel detached from the automotive communication network.
[0040] The further communication network might comprise components inside and outside of the vehicle to allow harnessing of cloud services.
[0041] Advantageously, the remote-control protocol chip operates completely or partially as a gateway for the calculation unit. The gateway is an intermediary between different nodes or networks, allowing data to flow between them. The gateway converts data from one network protocol to another or between different networks (even if they conform to the same protocol), allowing nodes or networks that would otherwise be incompatible to exchange information seamlessly. Converting might imply packaging of data. A gateway might incorporate security features such as firewalls and authentication mechanisms.
[0042] Advantageously, a watchdog is generated by the remote-control protocol chip and transmitted to the calculation unit via the second communication means. In general, 202406765
[0043] 7 a watchdog is a monitoring mechanism used to detect and / or recover from failures or malfunctions. It serves as a safeguard to ensure the continuous and proper operation of network devices, nodes, and connections. For this purpose, the watchdog might monitor processes, detect failures or unresponsive processes, and trigger recovery actions. The watchdog might be implemented as a software or a hardware. Typical watchdogs include the monitoring of clocks, high / low signal levels, or byte transfers. For example, the watchdog might be a clock indicating that specific sensor data are received at the RCP chip.
[0044] Advantageously, the calculation unit disables at least parts of the basic processes executed by the remote-control chip in case a failure is indicated during monitoring of the watchdog by the calculation unit.
[0045] In other words, the watchdog is continually monitored by the calculation unit. In case the watchdog is a clock which counts down from a preset value and under normal operation and resets before the preset value reaches zero, a failure is detected when the preset value has reached zero. In that case, the calculation unit disables at least parts of the basic processes to ensure safe operation of the functionality.
[0046] In case the functionality is given by a window lifter control with anti-pinch protection, the RCP chip handles the basic processes connected to that functionality, including receiving current data from a sensor. A spike in the current would suggest a pinching event has occurred. In reality, identifying a pinch event is more complicated, because a spike on the current also appears when the window reaches a completely closed state for example. However, to illustrate the concepts of the invention, the simplified assumption should suffice.
[0047] The current data is then provided to the calculation unit, which monitors these values and acts when a threshold is exceeded. Once the watchdog indicates a failure such as missing incoming current data, the calculation unit disables the basic processes. The calculation unit could, for example, overwrite an output channel of the RCP chip which controls an actuator that opens or closes the window. In particular, the output channel could be set by the calculation unit to open the window 202406765
[0048] 8 so as to prevent any possible pinching. It is noted that the RCP chip itself will not assume the monitoring.
[0049] Advantageously, the disabling involves one of:
[0050] - Pull-up and / or pull-down resistors,
[0051] - Logic gates.
[0052] These options are easily available solutions to ensure a well-defined logical state for the input and / or output channels (pins) of the RCP chip (or any integrated circuit). Logic gates might be fundamental building blocks of digital circuits that perform basic logical operations. However, also a gate of a low-side and high-side driver of a power or output stage qualifies as a logic gate.
[0053] Advantageously, the device comprises a further calculation unit with further communication means to support a majority vote process for the disabling.
[0054] A majority voting improves reliability and fault tolerance. For that purpose, the further calculation unit will implement a redundant monitoring of the RCP chip. Then, the disabling might only be implemented when both calculation units detected a failure. In general, it is also possible to add any number of additional calculation units to implement a majority voting functionality.
[0055] Advantageously, the calculation unit is an Application-Specific Integrated Circuit which implements the time and / or safety critical processes with logic gates.
[0056] Advantageously, the calculation unit is a microprocessor which implements the time and / or safety critical processes with simple control loops, the simple control loops not implementing any processes other than the time and / or safety critical processes.
[0057] Simple control loops might be implemented as software, but with very limited capability. For example, a simple control loop might implement a sensor measurement and a subsequent comparison with a set point. Also, the calculation of a difference between current value and set point and a calculation of a necessary 202406765
[0058] 9 adjustment qualifies as a simple control loop. As does sending a signal to adjust operations to reduce the difference (i.e. control the component which is measured). However, more elaborate strategies such as predictive or adaptive control, advanced real-time optimization, or over-the-air updates (OTAs) cannot be realized with simple control loops.
[0059] Advantageously, the calculation unit does not redundantly implement functionalities of the remote-control chip.
[0060] Advantageously, the remote-control chip and the calculation unit are integrated on a single chip or a multi chip module.
[0061] Advantageously, the calculation unit comprises dedicated input channels and / or dedicated output channels which are used to execute the time and / or safety critical processes. This way, the calculation unit utilizes input and output channels dedicated to monitor and disable the time and / or safety critical processes. Alternatively, the dedicated input channels and dedicated output channels redundantly provide communication means to sensors, actuators, and the like, necessary for executing basic and / or time and / or safety critical processes.
[0062] Advantageously, the input channels and output channels and / or the dedicated input channels and dedicated output channels are one of: sensors, actuators, and / or controllable components.
[0063] Advantageously, the basic processes are at least one of: Receiving sensor signals, Signal encoding, Signal transmission, Address encoding, Data encoding, Signal modulation, Phase control, Current control, 202406765
[0064] 10
[0065] Voltage level control,
[0066] Pulse width modulation control.
[0067] A second aspect of the invention provides an automotive communication network comprising at least one afore-described device.
[0068] A third aspect of the invention provides a vehicle comprising an afore-described automotive communication network.
[0069] The invention provides means (devices, network, vehicle) to implement time and / or safety critical processes of a functionality in a fail-save way.
[0070] Brief Description of the Drawings
[0071] The disclosed invention will be further discussed in the following based on preferred embodiments presented in the attached drawings. However, the disclosed invention may be embodied in many different forms and should not be construed as limited to said preferred embodiments. Rather, said preferred embodiments are provided for thoroughness and completeness, and fully convey the scope of the invention to the skilled person. The following detailed description refers to the attached drawings, in which:
[0072] Figure 1 depicts a top view of a vehicle with a state-of-the-art communication network and an automotive communication network;
[0073] Figure 2 depicts a schematic of a state-of-the-art communication network from Fig. 1 ;
[0074] Figure 3 depicts an automotive communication network including a device;
[0075] Figure 4 depicts a first embodiment of the device;
[0076] Figure 5 depicts a second embodiment of the device; 202406765
[0077] 11
[0078] Figure 6 depicts a third embodiment of the device; and
[0079] Figure 7 depicts a fourth embodiment of the device.
[0080] Detailed Description of the Drawings
[0081] Figure 1 depicts a top view of a vehicle 100 with a state-of-the-art communication network and an automotive communication network 120,121.
[0082] The vehicle 100 comprises several nodes 110, such as sensors, actuators, controllers, electronic control units (ECUs), or the like. The vehicle 100 further comprises a high-performance computer 105 (HPC) which acts a central ECU. The nodes 110 and the HPC 105 are connected via a first communication means 115, which take the form of a Controller Area Network (CAN) bus 115 in the example of Fig. 1 . Together, the CAN bus 115, the nodes 110, and the HPC 105 form a state-of-the-art network 120.
[0083] The HPC 105 performs several critical functions to enable advanced capabilities in the vehicle 100, for example data processing and integration, object detection and classification for advanced driver assistance systems (ADAS), body and vehicle control functions, or distributing over-the-air (OTA) software updates.
[0084] However, some functionality remains decentralized and thus needs to be executed by the nodes 110. This includes interfacing with sensors and actuators, managing engine operations such as fuel injection, ignition timing, and emissions control, or managing the deployment of airbags and other supplemental restraint systems. These functionalities often remain decentralized because a takeover from the HPC 105 would require to exchange massive amount of data over the network 120, which imposes security issues for time and / or safety critical processes such as airbag control.
[0085] Figure 2 depicts a schematic of the state-of-the-art communication network 120 from Fig. 1 . The CAN 115 connects the HPC 105 and the nodes 110. The HPC 105 comprises a CAN interface 130 and a System-on-Chip 125 (SoC). The SoC 125 can 202406765
[0086] 12 execute a broad range of functionalities while the CAN interface 130 allows the HPC 105 to send and receive CAN messages from and into the state-of-the-art communication network 120. The HPC 105 might be replaced with a central ECU, allowing for similar functionalities.
[0087] Nodes 110 itself comprise a CAN interface 130, allowing to receive and transmit CAN messages from and into the state-of-the-art communication network 120. The nodes 110 further comprise a microcontroller 135 (MCU), which executes instructions related to messages received at the CAN interface 130.
[0088] In one embodiment, the node 110 comprises an input channel 140, which connects the node 110 with a sensor 145. Further, the node comprises an output channel 150, which connects the node 110 with an actuator 155. In a further embodiment, the sensor 145 and the actuator 155 are part of the node 110. It is understood that the node 110 might comprise many more input channels 140 and output channels 150, for example, to connect multiple sensor 145, actuators 155, or other controllable components.
[0089] In the example of Fig. 2, the HPC 105 acts as a remote controller. Based on an analysis of sensor data received via CAN messages, it deduces instructions on how to act accordingly. For example, camera images taken by a sensor 145 are first compressed within the node 110 by the MCU 135, then transmitted via the CAN bus 115 to the HPC 105. The SoC 125 inside the HPC 105 decompresses the images, performs an object calculation method on said images, and determines a security risk, for example, whether or not human beings are captured within the image.
[0090] Additionally, the SoC 125 might combine additionally received sensor data such as Lidar or Radar data in order to come to a decision, whether or not a human being is in the vicinity of the vehicle 100. Further, the SoC 125 will determine, what actions are required to reduce the security risk, for example, by slowing down the vehicle 100. 202406765
[0091] 13
[0092] For this purpose, the SoC 125 might generate a CAN message for a node 110 with a corresponding actuator 155 attached, for example, a brake control ECU. This node 110 receives the CAN message and actuates a brake of the vehicle 100.
[0093] This method requires a lot of data to be exchanged via the state-of-the-art communication network 120. It is also prone to failures that do not originate in the node 110 itself, such as bandwidth limitations, a broken or unresponsive CAN bus 115, or signal loss. However, relocating the method onto the MCU 135 of the node 110 creates other problems, such as complex update processes during OTAs.
[0094] Figure 3 depicts an automotive communication network 121 including a device 160. The device 160 is a special form of a node 110 that solve the limitations outlined earlier. Note that Fig. 3 also shows the node 110 for comparison.
[0095] The device 160 comprises a CAN interface 130, a remote-control protocol (RCP) chip 165, and a calculation unit 170. In other words, the MCU 135 of the node 110 has been replaced by the combination of the remote-control protocol (RCP) chip 165 and the calculation unit 170. Similar to the node 110, the device 160 comprises an input channel 140, which connects the device 160 with a sensor 145 and an output channel 150, which connects the device 160 with an actuator 155. It is understood that the device 160 might comprise many more input channels 140 and output channels 150, for example, to connect multiple sensor 145, actuators 155, or other controllable components.
[0096] The RCP chip 165 features specialized integrated circuits (ICs) designed to handle standardized methods of communication enabling the device 160 being controlled from the HPC 105. The specialized ICs are, for example, designed to handle the encoding, transmission, reception, and decoding of remote-control signals, as defined in RCP standards. Note that the CAN interface 130 might therefore be integrated into the RCP chip 165. The CAN interface 130 might comprise a transceiver and / or a controller and / or software components. 202406765
[0097] 14
[0098] Figure 4 depicts a first embodiment of the device 160. The CAN interface 130 is communicatively coupled to the RCP chip 165 via a further CAN bus 175. The RCP chip 165 is communicatively coupled to the calculation unit 170 via a second communication means 180, in the example of Fig. 4, a Serial Peripheral Interface 180 (SPI).
[0099] The calculation unit 170 comprises a first open-collector configuration connection 185 and a second open-collector configuration connection 190. These connections are formed in the example of Fig. 4 with pull-up and / or pull-down resistors which can be used to ensure a well-defined logical state for the input channel 140 and the output channel 150 of the RCP chip 165. These channels connect the RCP 165 to a sensor 145 and an actuator 155, respectively.
[0100] The example of a window lifter functionality with anti-pinch protection will now be discussed with reference to Fig. 4. Anti-pinch protection is a safety feature in power window systems designed to prevent injuries and damage when an obstruction is detected during window closure.
[0101] Any functionality can be segmented into two different processes. First, there are time and / or safety critical processes such as interrupting a window closure in case something is pinched between the window and the door frame. Second, there are basic processes not involving time and / or safety critical processes such as signal encoding or pulse width modulation. The device 160 allows to separate these processes in order to address the disadvantages discussed earlier with reference to Fig. 2.
[0102] In this example, the sensor 145 is a current sensor 145 and the actuator 155 a motor 155. The motor 155 is responsible to drive an opening or a closure of the window. If an obstruction is encountered during closing the window, the force required to move the window suddenly increases. This increase in force causes a corresponding spike in the motor's 155 current draw which can be interpreted as an obstruction if exceeding a predetermined threshold. 202406765
[0103] 15
[0104] The RCP chip 165 first generates a watchdog which is transmitted to the calculation unit 170. The watchdog is a monitoring mechanism and might be implemented as a word, clock, or byte transfer. Usually, a timer is implemented in the calculation unit 170. Once the first correct watchdog word is received in the calculation unit 170, output control pins are released and the watchdog timer of the calculation unit 170 begins counting down. During normal operation, the timer is reset or restarted at regular intervals as expected bytes or watchdog signal edges are successfully received. If the timer reaches zero, indicating that a wrong watchdog byte is received or a correct watchdog byte is received after timeout has occurred, a failure is assumed and a predefined action is triggered.
[0105] Once the RCP chip 165 receives a CAN message from the HPC 105 (or any other node 110 or device 160 within the automotive communication network 121 ) with an instruction to close the window, it will begin to do so by controlling the current level of the motor 155 via the output channel 150, i.e. , executing a basic process.
[0106] However, the calculation unit 170 continuously monitors the RCP chip 165 via the watchdog. In case a failure is indicated during monitoring of the watchdog, the calculation unit 170 disables at least parts of the basic processes in order to prevent harm (which is a typical example of a time and / or safety critical process). The failure might be caused by erroneous signal creation, a broken sensor, deterioration of signal channels, incorrect mutex handling, task-starvation, or the like. The calculation unit 170 might employ different strategies to disable at least parts of the basic processes. For example, it might overwrite the sensor data received by the RCP chip 165 via the input channel 140 with a value that triggers the RCP chip 165 to drive the motor 155 to open the window. For this purpose, it uses the first open-collector configuration connection 185.
[0107] Alternatively or additionally, the calculation unit 170 might set the current level to drive the motor 155 itself via the second open-collector configuration connection 190. The calculation unit 170 is formed with logic gates, that is, no software code is executed on the calculation unit 170 to perform the time and / or safety critical processes. 202406765
[0108] 16
[0109] Figure 5 depicts a second embodiment of the device 160. In this embodiment, the RCP chip 165 and the calculation unit 170 are integrated on a single chip 195.
[0110] Figure 6 depicts a third embodiment of the device 160. In this embodiment, the calculation unit 170 comprises its own Bus connection 200 to the automotive communication network 121. This way, it is possible to create the watchdog and transmit it to the calculation unit 170 via the Bus connections instead of a dedicated SP1 180. However, it is also possible to have an additional watchdog via the Bus 200 and the CAN bus 115 to either redundantly monitor the RCP chip 165 or monitor different metrics altogether.
[0111] Figure 7 depicts a fourth embodiment of the device 160. In this embodiment, the input channel 140 and the output channel 150 are distributed in terms of their communicative connection to the RCP chip 165 and the calculation unit 170, respectively.
[0112] In particular, the input channel 140 is still connected to the RCP chip 165, which then can execute basic processes such as, in this case, receiving data from the current sensor 145. A dedicated output channel 205 however is connected to the calculation unit 170. This allows the calculation unit 170 to execute time and safety critical processes such as, in this case, driving the motor 155 after having received and validated the sensor data from the RCP chip 165 via the SP1 180. Therefore, no first open-collector configuration connection 185 and second open-collector configuration connection 190 are required.
[0113] In this embodiment, the functionality is physically separated between the RCP chip 165 and the calculation unit 170. Although there is no monitoring of the current sensor 145 in this embodiment, the person skilled in the art can easily adapt such a function with regards to Figs. 4-6.
[0114] With reference to Fig. 1 , an automotive communication network 121 in a vehicle 100 comprises the HPC 105, and at least one node 110 in the form a device 160. 202406765
[0115] 17
[0116] Reference Signs
[0117] 100 Vehicle
[0118] 105 High-performance computer (HPC)
[0119] 110 Node
[0120] 115 First communication means; Controller Area Network (CAN) bus
[0121] 120 State-of-the-art communication network
[0122] 121 Automotive communication network
[0123] 125 System-on-Chip (SoC)
[0124] 130 CAN interface
[0125] 135 Microcontroller (MCU)
[0126] 140 Input channel
[0127] 145 Sensor; current sensor
[0128] 150 Output channel
[0129] 155 Actuator: motor
[0130] 160 Device
[0131] 165 Remote-control protocol (RCP) chip
[0132] 170 Calculation unit
[0133] 175 Further CAN bus
[0134] 180 Second communication means; Serial Peripheral Interface (SPI)
[0135] 185 First open-collector configuration connection
[0136] 190 Second open-collector configuration connection
[0137] 195 Chip
[0138] 200 Bus
[0139] 205 Dedicated output channel
Claims
20240676518Claims1 . A device (160) for executing a functionality in an automotive communication network (121 ), the device (160) being a node (110) in the automotive communication network (121 ), the functionality comprising basic processes and time and / or safety critical processes, the device (160) comprising: a) A remote-control protocol chip (165) communicatively coupled to the automotive communication network (121 ) via a first communication means (115) and using a remote-control protocol, the remote-control protocol chip (165) executing the basic processes using input channels (140) and / or output channels (150), and b) A calculation unit (170) communicatively coupled to the automotive communication network (121 ) or the remote-control chip (165) via a second communication means (180), the calculation unit (170) being formed to execute at least in part the time and / or safety critical processes.
2. Device according to claim 1 , characterized in that the calculation unit (170) is communicatively coupled to the output channels (150) of the remote-control protocol chip (165).
3. Device according to claim 1 or 2, characterized in that the second communication (180) means is one of: a) A Serial Peripheral Interface (180), Inter-Integrated Circuit, Pulse Width Modulation, General Purpose Input / Output, Local Interconnect Network, Universal Asynchronous Receiver / Transmitter, Peripheral Sensor Interface 5, or Single Edge Nibble Transmission, directly connecting the remote-control protocol chip (165) and the calculation unit (170), b) A bus (175) directly connecting the calculation unit (170) and the automotive communication network (121 ) or a further communication network different from the automotive communication network (121 ).
4. Device according to any of the previous claims, characterized in that the remote-control protocol chip (165) operates completely or partially as a gateway and is upstream from the calculation unit (170).202406765195. Device according to any of the previous claims, characterized in that a watchdog is generated by the remote-control protocol chip (165) and transmitted to the calculation unit (170) via the second communication means (180).
6. Device according to claims 2 and 5, characterized in that the calculation unit (170) disables at least parts of the basic processes executed by the remote-control chip (165) in case a failure is indicated during monitoring of the watchdog by the calculation unit (170).
7. Device according to claim 6, characterized in that the disabling involves one of: a) Pull-up and / or pull-down resistors, b) Logic gates.
8. Device according to claim 6 or 7, characterized in that the device (160) comprises a further calculation unit with further communication means to support a majority vote process for the disabling.
9. Device according to any of the previous claims, characterized in that the calculation unit (170) is an Application-Specific Integrated Circuit which implements the time and / or safety critical processes with logic gates.
10. Device according to any of the previous claims, characterized in that the calculation unit (170) is a microprocessor which implements the time and / or safety critical processes with simple control loops, the simple control loops not implementing any processes other than the time and / or safety critical processes.11 . Device according to any of the previous claims, characterized in that calculation unit (170) does not redundantly implement functionalities of the remote-control chip (165).
12. Device according to any of the previous claims, characterized in that the remote-control chip (165) and the calculation unit (170) are integrated on a single chip (195) or a multi chip module.2024067652013. Device according to any of the previous claims, characterized in that the calculation unit (170) comprises dedicated input channels and / or dedicated output channels (205) which are used to execute the time and / or safety critical processes.
14. Device according to any of the previous claims, characterized in that the input channels (140) and output channels (150) and / or the dedicated input channels and dedicated output channels (205) are one of: sensors, actuators, and / or controllable components.
15. Device according to any of the previous claims, characterized in that the basic processes are at least one of: a) Receiving sensor signals, b) Signal encoding, c) Signal transmission, d) Address encoding, e) Data encoding, f) Signal modulation, g) Phase control, h) Current control, i) Voltage level control, j) Pulse width modulation control.
16. An automotive communication network (121 ) comprising at least one device (160) according to any of the previous claims.
17. A vehicle (100) comprising an automotive communication network (121 ) according to claim 16.
Citation Information
Patent Citations
US20120106446A1
US20210116907A1
US20240020255A1