Component switching for vehicle

WO2026200246A1PCT designated stage Publication Date: 2026-10-01ZHEJIANG GEELY HLDG GRP CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2026/074173
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-26
Filing Date
2026-01-22
Publication Date
2026-10-01

Smart Images

  • Figure CN2026074173_01102026_PF_FP_ABST
    Figure CN2026074173_01102026_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the present application are a component switching method for a vehicle, a computer-readable storage medium and a program product. A primary system and a backup system are deployed on a vehicle, wherein the primary system comprises one or more primary components, the backup system comprises one or more backup components, and for any primary component in the primary system, the primary component and / or a backup component in the backup system that has the same function as the primary component maintain / maintains a mapping relationship between the primary component and the backup component that has the same function as the primary component. The method comprises: when it is determined that the operating state of any primary component is abnormal, determining, on the basis of a mapping relationship, a target backup component in a backup system that corresponds to the primary component; and switching the primary component to the target backup component, so that the target backup component operates in place of the primary component.
Need to check novelty before this filing date? Find Prior Art

Description

Vehicle component switching Cross-references to related applications This application claims priority to Chinese Patent Application No. 202510362545.5, filed with the Chinese Patent Office on March 26, 2025, the entire contents of which are incorporated herein by reference. Technical Field

[0001] The embodiments of this application relate to, but are not limited to, the field of vehicle control technology, and particularly to, but are not limited to, a method for switching vehicle components, a computer-readable storage medium, and a program product. Background Technology

[0002] In autonomous driving scenarios, a redundant system refers to a technical architecture that uses multiple backup components to replace the corresponding main component in order to maintain the safe operation of the vehicle. Its role is to eliminate the risk of single point of failure and ensure minimum safe operation capability. Summary of the Invention

[0003] The following is an overview of the subject matter described in detail herein. This overview is not intended to limit the scope of the claims.

[0004] According to a first aspect of this application, a component switching method for a vehicle is provided. The vehicle is equipped with a main system and a backup system. The main system includes one or more main components, and the backup system includes one or more backup components. For any main component in the main system, the main component and / or the backup component in the backup system that has the same function as the main component maintain a mapping relationship between the main component and the backup component that has the same function as the main component. The method includes: when it is determined that the working state of the main component is abnormal, determining a target backup component in the backup system corresponding to the main component according to the mapping relationship; and switching the main component to the target backup component so that the target backup component replaces the main component in operation.

[0005] According to a second aspect of this application, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps of the method described in the first aspect.

[0006] According to a third aspect of this application, a computer program product is provided, comprising a computer program / instructions that, when executed by a processor, implement the steps of the method described in the first aspect.

[0007] According to a fourth aspect of this application, a component switching device for a vehicle is provided. The vehicle is equipped with a main system and a backup system. The main system includes one or more main components, and the backup system includes one or more backup components. For any main component in the main system, the main component and / or the backup system maintain a mapping relationship between the main component and the backup component having the same function as the main component. The device includes: a target backup component determination unit, configured to determine a target backup component in the backup system corresponding to the main component according to the mapping relationship when it is determined that the working state of any main component is abnormal; and a target backup component switching unit, configured to switch the main component to the target backup component, so that the target backup component replaces the main component in operation.

[0008] The vehicle described in this application can be equipped with a main system and a backup system. The main system includes one or more main components, and the backup system includes one or more backup components. For any main component in the main system, the main component and / or the backup component in the backup system that has the same function as the main component can maintain a mapping relationship between the main component and the backup component with the same function. If the working state of any main component becomes abnormal, a target backup component corresponding to the abnormal main component can be quickly located from the backup system according to the mapping relationship. Then, the abnormal main component and the target backup component are switched so that the target backup component can replace the abnormal main component and continue to work normally. The above mapping relationship is created based on the decomposition results of preset functional safety objectives. In other words, which components in the vehicle are main components and which are corresponding backup components can be uniformly determined by the predetermined functional safety objectives. A complete architectural standard is then formulated around these functional safety objectives to cover the blind spots in scenarios caused by the lack of systematic architectural design in traditional solutions and to avoid the risk of failure under complex operating conditions.

[0009] After reading and understanding the accompanying diagrams and detailed descriptions, the other aspects can be understood. Attached Figure Description

[0010] The accompanying drawings are used to provide a further understanding of the technical solutions of this application and constitute a part of the specification. They are used together with the embodiments of this application to explain the technical solutions of this application and do not constitute a limitation on the technical solutions of this application.

[0011] To more clearly illustrate the technical solutions of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are merely some embodiments of this application. For those skilled in the art, other drawings can be obtained from these drawings without any creative effort.

[0012] Figure 1 is a schematic diagram of the architecture of a vehicle component switching system according to an embodiment disclosed in this application.

[0013] Figure 2 is a flowchart illustrating a vehicle component switching method according to an embodiment of this application.

[0014] Figures 3A to 3C are schematic diagrams illustrating the architecture of a communication system between redundant vehicle components according to embodiments disclosed in this application.

[0015] Figure 4 is a schematic diagram of the architecture of a vehicle redundancy component as shown in an embodiment of this application.

[0016] Figure 5 is a schematic structural diagram of an electronic device according to an embodiment of this application.

[0017] Figure 6 is a block diagram of a vehicle component switching device according to an embodiment of this application. Detailed Implementation

[0018] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application.

[0019] The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The singular forms “a,” “the,” and “the” used in this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any or all possible combinations of one or more of the associated listed items.

[0020] It should be understood that although the terms first, second, third, etc., may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to determination."

[0021] In autonomous driving scenarios, a redundant system refers to a technical architecture that uses multiple backup components to replace the corresponding primary component in order to maintain the safe operation of the vehicle. Its function is to eliminate the risk of single-point failure and ensure minimum safe operational capability. Taking the current mainstream autonomous driving levels L3 and L4 as examples, the former basically only implements basic redundancy such as braking and steering, while the latter, due to the safety requirements of highly automated driving, lists power redundancy as an essential redundancy. However, the industry currently lacks a complete architectural standard for vehicle redundancy systems, resulting in blind spots in safety scenario coverage and difficulty in effectively dealing with failure risks under complex operating conditions. The following detailed description, with reference to the accompanying drawings, describes an embodiment of the vehicle component switching method of this application.

[0022] Figure 1 is a schematic diagram of the architecture of a vehicle component switching system according to an embodiment of this application. As shown in Figure 1, the system may include a vehicle 10, a main system 11, and a backup system 12.

[0023] Vehicle 10 serves as the carrier for implementing the component switching function in this application. It constructs a redundant architecture through its own deployed main system 11 and backup system 12 to ensure the achievement of the vehicle's functional safety goal. Specifically, vehicle 10 is actually equipped with a main component in the main system that performs preset functions and a corresponding backup component in the backup system 12. The components form switchable logical links based on the mapping relationship established after the functional safety goal is disassembled. When the main component in the main system malfunctions, vehicle 10 can execute a corresponding switching mechanism to call upon the backup component in the backup system 12 for functional replacement, thereby ensuring the continuity and reliability of vehicle operation. Vehicle 10 can be a gasoline vehicle, a hybrid vehicle, an electric vehicle, or other vehicles based on different power types and possessing autonomous driving capabilities; this application does not impose any restrictions on this.

[0024] The main system 11 is the core execution unit for realizing vehicle functions. It can contain m main components, where m is a positive integer. Specifically, the main components can store mapping relationship data of backup components with the same function according to the actual situation. This allows the corresponding target backup component in the backup system 12 to be quickly located based on the preset mapping relationship data when the working state of any main component is abnormal. The abnormal main component and the backup component can be switched to achieve seamless replacement of the faulty component.

[0025] The backup system 12 serves as a redundant backup unit for the main system 11. It may contain n backup components that have the same function as the main components in the main system 11, where n is a positive integer greater than or equal to m. Each backup component forms a one-to-one or many-to-one logical association with the main component through a predefined mapping relationship. For example, backup component A corresponds only to main component B, while backup components C and D correspond to main component E.

[0026] It is worth mentioning that in addition to the main components, there may be other components in the main system. There are no backup components with the same function in the backup system. Of course, other components can be regarded as having met the functional safety objectives, so there is no need to adopt the redundancy design of backup components.

[0027] To facilitate the subsequent introduction, this application provides a preliminary explanation of the relevant technologies surrounding the concept of functional safety objectives.

[0028] Functional safety objectives, as core safety principles based on systematic risk assessment and hazard analysis, aim to ensure that vehicle electronic and electrical systems maintain an acceptable level of safety even in the event of a failure. Specifically, taking the international standard ISO 26262 as an example, after designing and defining the functional boundaries, operating environment, and interactions with other systems of a system or component, automakers can list possible failure modes and their resulting hazardous events based on Hazard Analysis and Risk Assessment (HARA). For example, steering system failure may lead to loss of vehicle control. These hazardous events are then quantified and scored from three dimensions: Severity (S), Exposure (E), and Controllability (C). Based on the scores for each dimension, a corresponding Automotive Safety Integrity Level (ASIL) is obtained. ASIL levels are specifically divided into Quality Management (QM), A, B, C, and D, with the stringency of safety requirements increasing in that order. For example, if brake failure leads to a fatal accident and is difficult to control, an ASIL level must be assigned. If the failure of the interior lighting system or window control has a minor impact on safety, then ASIL A can be assigned.

[0029] After determining the ASIL level of a hazardous event, corresponding quantitative indicators such as fault tolerance, failure probability, and response time can be formulated to form a true functional safety objective, such as "preventing unexpected braking failure, ensuring parking braking force ≥500 N·m, and switching time ≤300 ms". However, functional safety objectives such as "preventing unexpected braking failure" and "avoiding unexpected loss of lateral motion control" are too abstract and cannot directly guide the vehicle's engineering design. Therefore, they can be broken down step by step until the smallest concrete functional safety objective is reached. For ease of description, this will be referred to as the decomposition result of the functional safety objective, such as the redundancy requirements at the chip level of the circuit board. Of course, the embodiments in this application focus on the redundancy architecture design of the Bill of Materials (BOM) level of the whole vehicle, mainly considering whether the selection, layout, and interface of parts meet the safety requirements of the whole vehicle, without needing to delve into the specific design details inside the chip. For example, if an original functional safety objective is "when the main controller of the braking system fails, it must switch to the backup controller within 10ms to maintain ≥50% braking force, ASIL D", then the main controller and the backup controller can be designed as independent heterogeneous units. Although the ASIL level of the functional safety objective corresponding to each controller is downgraded to ASIL C, the two controllers working together can meet the ASIL D requirement, ultimately achieving the effect of decomposing ASIL D into ASIL C + ASIL C. Based on this, the main controller, which is the result of the decomposition of the original functional safety objective in the above example, can be regarded as the main component in the main system and the backup controller as the backup component in the backup system. A mapping relationship can be established between the two, so that the main component and the backup component can achieve the original functional safety objective according to the mapping relationship.

[0030] Those skilled in the art will understand that, from the perspective of functional redundancy, although the primary and backup components with a mapping relationship have the same function, the performance of each component in performing the same function can be set according to actual needs. For example, in Level 3 autonomous driving, the backup system is required to take over driving only in specific scenarios such as highways, but the driver still needs to manually take over within a certain response time. Therefore, the backup component used to replace the primary component only needs to provide the minimum safe operating capability, such as maintaining vehicle stability until the driver takes over. The backup component does not need to achieve the same performance as the primary component. Similarly, in Level 4 autonomous driving, the system is required to independently handle all faults in specific scenarios such as urban roads without human intervention. Therefore, the aforementioned backup component must completely reproduce the performance of the primary component to ensure that the system can still operate as originally designed after a fault switch. In some embodiments, when the performance of the primary and backup components in performing the same function is consistent, they can be used interchangeably, that is, there is no need to distinguish between the primary and backup systems. For ease of explanation, this application uses Level 3 as the default autonomous driving level followed by the vehicle, which allows the backup component to achieve the same function as the primary component with lower performance.

[0031] In this application, based on functional safety objectives, the originally abstract safety requirements can be transformed into executable technical specifications, thereby enabling the vehicle redundancy system designed based on the above functional safety objectives to fully cover different safety scenarios and avoid the risk of vehicle function failure under complex operating conditions.

[0032] Figure 2 is a flowchart illustrating a component switching method for a vehicle according to an exemplary embodiment. The vehicle is equipped with a main system and a backup system. The main system includes multiple main components, and the backup system includes multiple backup components. For any main component, the main component and / or the backup component with the same function as the main component maintain a mapping relationship between the main component and the backup component with the same function. The mapping relationship is created based on the disassembly results of a preset functional safety target. The method may include steps 202 to 204.

[0033] Step S202: If it is determined that the working state of any main component is abnormal, the target backup component corresponding to the main component in the backup system is determined according to the mapping relationship.

[0034] Based on the mapping relationship that represents the correspondence between primary components and backup components with the same function, once an abnormality is determined in the working state of any primary component in the primary system, the corresponding backup component in the backup system can be determined according to the mapping relationship for functional replacement in subsequent steps. The abnormality in the working state can be further categorized into hardware physical failures, such as a hydraulic valve's pressure sensor detecting actual pressure exceeding a preset pressure threshold, leading to abnormal braking force output; software logic failures, such as an autonomous driving path planning algorithm continuously generating erroneous trajectories with offsets exceeding a preset value within a preset time period due to memory overflow; and performance degradation, such as lens damage to a vehicle camera causing a decrease in the signal-to-noise ratio of the captured image and reducing the target detection confidence of objects identified based on the image to a preset confidence level. Of course, regardless of the type of abnormality, the operation of determining the target backup component based on the mapping relationship can be triggered.

[0035] In this application, the entity responsible for identifying anomalies and the target backup component can be adjusted according to actual circumstances. Therefore, the primary and backup components can be further refined. The primary component can include a main control component and a first controlled component controlled by it, while the backup component can include a secondary control component and a second controlled component controlled by it. The secondary control component can be used to control the second controlled component of the backup system. In the context of autonomous driving, the primary control component can specifically refer to the Highly Automated Driving (HAD) controller in the vehicle. It is responsible for collecting data from various sensors in the vehicle, performing complex calculations and processing, and then sending commands to actuators in the vehicle, such as steering, braking, and power systems, according to preset algorithms and strategies to achieve autonomous driving operations such as automatic following, lane keeping, and automatic lane changing. Sensors and actuators can both be considered as first controlled components. The secondary control component and the primary control component, as well as the first controlled component and the second controlled component, are essentially the same in implementation, except for the different systems they belong to; therefore, this application will not elaborate further.

[0036] In one embodiment, when the master control component determines that the first controlled component meets the component abnormality conditions, the master control component can determine that the working state of the first controlled component is abnormal, that is, the working state of the master component is abnormal. Specifically, the master control component establishes a communication connection with the first controlled component to determine the working state of the first controlled component through active monitoring or passive reception. Specifically, the master control component can actively poll the status register in the first controlled component using communication protocols such as Controller Area Network with Flexible Data Rate (CAN FD) / Controller Area Network eXtended Large Frames (CAN XL), or receive self-test status reports from the first controlled component at fixed intervals. The component anomaly conditions can be a preset multi-dimensional set of judgment rules used to determine whether the working state of the first controlled component is abnormal. For example, if the first controlled component is a current sensor for a motor, and the current exceeds the maximum current threshold set in the component anomaly conditions, then it can be determined that the working state of the current sensor (first controlled component) is abnormal, and thus the working state of the main component is abnormal. Similarly, if the communication between the main control component and the first controlled component times out, it can also be determined that the working state of the first controlled component is abnormal, and thus the working state of the main component is abnormal. Likewise, a communication connection can be established between the secondary control component and the second controlled component in the backup component to achieve the same effect as the main control component and the first controlled component mentioned above; this will not be elaborated further in this application.

[0037] In another embodiment, if the secondary control component determines that the primary control component meets the component abnormality conditions, the secondary control component can determine that the operating state of the primary control component has become abnormal, that is, determine that the operating state of the primary component has become abnormal. In this embodiment, the secondary control component can act as the executing entity for determining that the primary component has become abnormal, in order to solve the special situation in the previous embodiment where the primary control component itself is abnormal, resulting in the inability to promptly determine that the first controlled component or the primary control component has become abnormal. Specifically, a communication connection can be established between the secondary control component and the primary control component, thereby realizing communication between the primary system and the backup system.

[0038] Those skilled in the art will understand that the above two embodiments can be implemented simultaneously to ensure that both the main control component and the first controlled component in the main system can be detected in a timely manner, thereby improving the accuracy of anomaly determination for the main component.

[0039] If an anomaly is detected in the operating status of any primary component, the execution entity of the corresponding target backup component can be further classified. This allows for dynamic selection of the path to the target backup component, accelerating the efficiency of subsequent switchover operations. The classification criteria can be associated with the maintenance location of the mapping relationship.

[0040] In one embodiment, when it is determined that the working state of the first controlled component has become abnormal, and either the main control component or the sub-control component maintains a mapping relationship, either the main control component or the sub-control component can determine the second controlled component corresponding to the first controlled component as the target backup component based on the mapping relationship. In this embodiment, for the first controlled component, there are two scenarios: First, the main control component can determine the target backup component directly after determining that the first controlled component has become abnormal. Second, the main control component can synchronize the determined abnormal result to the sub-control component, and then the sub-control component can determine the target backup component corresponding to the first controlled component. The execution of these two scenarios depends on the location of the mapping relationship. When only the main control component maintains the mapping relationship, the first scenario is implemented; when only the sub-control component maintains the mapping relationship, the second scenario is implemented; when both the main control component and the sub-control component maintain the mapping relationship, either scenario can be implemented. The difference is that the first scenario eliminates the synchronization process of the abnormal result compared to the second scenario, thus having higher efficiency in determining the target backup component.

[0041] In another embodiment, if it is determined that the operating state of the main control component is abnormal, and the secondary control component maintains a mapping relationship, the secondary control component determines itself as the target backup component based on the mapping relationship. Since the abnormality occurs in the main control component itself, even if the main control component maintains a mapping relationship, it cannot guarantee that the main control component will successfully identify the corresponding secondary control component in the backup system as the target backup component. Therefore, it needs to rely on the secondary control component and the mapping relationship maintained within it to identify itself as the target backup component.

[0042] It is worth mentioning that the secondary control unit and the second controlled unit can reduce the probability of common cause failure through heterogeneous design and physical isolation, making the probability of synchronous anomalies between the primary control unit and the secondary control unit, and between the first controlled unit and the second controlled unit, corresponding to the same mapping relationship, extremely low. Of course, even in extreme cases where the primary control unit and the secondary control unit, or the first controlled unit and the second controlled unit, malfunction simultaneously, triggering a full redundancy link failure, the system can force entry into a static safety mode based on the underlying hardware and preset failure safety logic, performing basic safety operations such as electronic parking and hazard warning lights.

[0043] Physical isolation, in this context, refers to isolating the main power supply component from the main power supply component in a primary system, and the backup power supply component from the backup power supply component in a backup system. This isolates the main power supply component from the backup power supply component, ensuring that other main components in the primary system depend on it, and vice versa. Specifically, the purpose of isolation is to establish independent power distribution networks and grounding loops for the primary and backup systems. For example, if the main power supply component uses a 12V lead-acid battery with its negative terminal grounded to the vehicle body, and the backup power supply component uses a 48V lithium battery with an independent negative terminal loop, electrical decoupling can be achieved using devices such as optocouplers. This prevents the failure of both power supplies from causing both the main and backup components to malfunction. Furthermore, heterogeneous design can be understood from both software and hardware perspectives. First, the software for the main and backup components adopts a heterogeneous architecture design, avoiding the use of system code in the design of the main and backup components. This prevents identical architectures from having the same software anomalies that could cause both the main and backup components to fail simultaneously. Secondly, the hardware platforms of the main component and the backup component adopt heterogeneous deployment, that is, avoid using the same underlying chip to prevent the main component and the corresponding backup component from failing together due to quality and manufacturing process defects in hardware with the same circuit architecture or the same production batch.

[0044] Regarding the process by which the main control component determines that the working state of the first controlled component has become abnormal, this application can be implemented based on different communication systems between the components shown in Figures 3A to 3C, thereby supporting multiple anomaly detection methods.

[0045] In one embodiment, the master control unit determines that the operating state of the first controlled component is abnormal based on the first connection between the master control unit and the first controlled component. In this case, the first connection can correspond to the centralized communication connection between the master control unit and x first controlled components in Figure 3A, and can also correspond to the communication connection between the sub-control unit and x second controlled components. When the master control unit communicates with any first controlled component through the first connection, the communication content can carry control information from the master control unit, status information from the first controlled component, and other information such as handshake information. This allows the master control unit to quickly locate the abnormal first controlled component based on the status information and instruct the switching operation of the target backup component in subsequent steps by sending corresponding control information to the abnormal first controlled component and the sub-control unit.

[0046] In the main system, a special first connection, as shown in Figure 3A, can also be established between the main power supply component and the main control component. The communication content of this connection only needs to include battery status information. This is because the core control of the vehicle's power supply is usually held by a dedicated power management module. For example, main control components such as HAD (H-infinity Adaptive Decoupling) controllers cannot directly control the power supply's on / off state or voltage regulation. Therefore, the main control component cannot carry control information for the main power supply component in its communication with it. Of course, the main control component can interact with the power management system through communication protocols to indirectly influence the power supply strategy, such as adjusting the load priority of different first controlled components. This satisfies the flexibility requirements of the autonomous driving system while ensuring the safety and reliability of power management. The same principle applies between the secondary control component and the backup power supply component in the backup system, which will not be elaborated upon here.

[0047] In another embodiment, the master control unit can determine that the working state of the first controlled component is abnormal based on the second connection between the master control unit and other first controlled components. These other first controlled components are controlled components of the master control unit that are different from the first controlled component, such as first controlled components 2 to y in Figure 3B. These other first controlled components establish a third connection with the first controlled component, such as the connection between first controlled component 1 and each of the first controlled components 2 to y in Figure 3B. In this case, the second connection can correspond to the communication connection of the distributed architecture between the master control unit and the first controlled component 1 in Figure 3B. The first controlled component 1 can independently process the information of the first controlled components 2 to y through the third connection, and finally feed the processing results back to the master control unit in a unified manner, thereby distributing and reducing the computational pressure on the master control unit and improving the overall efficiency of identifying abnormal components. Taking the braking component, brake light component, and wheel speed sensing module in the vehicle chassis domain as examples, the braking component can establish a third connection with the brake light component and wheel speed sensing module, thereby managing and controlling the brake light component and wheel speed sensing module. Simultaneously, the braking component establishes a second connection with the main control component to feed back its own status information and the control results for the brake light component and wheel speed sensing module. Furthermore, the same principle applies to the sub-controller and the y second controlled components in Figure 3B, which will not be elaborated upon further in this application.

[0048] Specifically, based on the second and third connections, a special communication structure as shown in Figure 3C can be derived. In this structure, although the first controlled component 1 establishes a third connection with other first controlled components 3, the first controlled component 3 further establishes a communication connection with the first controlled component 2 (for ease of distinction, this connection is called the fourth connection). This creates a hierarchical nested communication link between the three components and the main control component: "Main control component → (second connection) → first controlled component 1 → (third connection) → first controlled component 3 → (fourth connection) → first controlled component 2". That is, the first controlled component 3 can independently process the information of the first controlled component 2 through the fourth connection. The processing result, along with the state information of the first controlled component 3, is then sent to the first controlled component 1 for independent processing through the third connection. The processing result, along with the state information of the first controlled component 1, is then sent to the main control component 1 for processing through the second connection. This further distributes and reduces the computational burden on the main control component, thereby improving the overall efficiency of identifying abnormal components.

[0049] Furthermore, the first controlled component 3 in Figure 3C, which has already established a third connection with the first controlled component 1, can also establish a special connection with the main control component (referred to as the fifth connection for ease of distinction) to reduce the communication links between the main control component and the corresponding first controlled component 3. Specifically, for security reasons, the time required for the main component to detect an anomaly, determine the target backup component, and then perform the switching operation in subsequent steps needs to be controlled within a relatively short fixed time, such as 100 milliseconds. Therefore, simply performing layered communication with the first controlled component can easily lead to excessive time consumption. Thus, a fifth connection can be established between the first controlled component 3 in these "inner layers" and the main control component. The key messages proving that the corresponding first controlled component 3 has an anomaly can be quickly obtained by the main control component through the fifth connection, while other non-key messages can be handled by the original layered communication relationship and analyzed by the first controlled component 1 in the outer layer. This design effectively compresses the time consumption for key anomaly determination and optimizes bandwidth resources through heterogeneous communication links. In the embodiments of this application, each first controlled component is a single physical unit. For example, the single physical unit can refer to the smallest or basic hardware component that exists as an independent physical entity.

[0050] The following example uses a configuration where the driver intervention module is the first controlled component 1, the vehicle driving angle module is the first controlled component 2, the steering component is the first controlled component 3, and the HAD main controller is the main control component. The driver intervention module (first controlled component 1) receives real-time torque data from the steering component (first controlled component 3) via a third connection, and simultaneously obtains yaw rate information from the vehicle driving angle module (first controlled component 2) via a fourth connection. When the steering component (first controlled component 3) detects a deviation of >15% between the angle command and the actual wheel angle for 20ms, it can directly send a corresponding emergency fault code to the HAD main controller via a fifth connection. The HAD main controller triggers redundancy switching within 5ms. Simultaneously, the steering component (first controlled component 3) still uploads detailed diagnostic logs (such as temperature and current waveforms) through the hierarchical link (component 3 → component 1 → main controller). This example ensures that in the event of a single point of failure in the steering system, the main control component can make rapid decisions while retaining in-depth analysis capabilities, and the load on the main control component can be reduced through local preprocessing by the driver intervention module.

[0051] Step S204: Switch the main component to the target backup component so that the target backup component can replace the main component in operation.

[0052] Once the target backup component is identified, the main component that is currently executing the target task can be stopped, and the target backup component can continue to execute the target task, thereby achieving the effect of the target backup component replacing the main component.

[0053] The specific execution method between the main component and the target backup component can be adaptively adjusted according to the execution relationship between the two and the target task before the switch, thereby expanding the application scenarios of the solution in this application.

[0054] In one embodiment, when the primary component and the target backup component operate independently, the primary component is switched to the target backup component, allowing the target backup component to completely replace the primary component. The primary component performs the target task based on an independent operating mode, while the corresponding target backup component performs diagnostic monitoring and data transmission under normal conditions, without participating in real-time control. Only when the primary component fails will the backup component fully take over all its functions. For example, in a vehicle's hydraulic braking system, the primary braking component independently responds to pressure boosting demands and controls the ABS (Antilock Brake System), while the backup braking component normally only monitors pressure and fault status. If the primary braking component fails, the backup braking component immediately takes over brake pressure boosting and ABS control, and the primary braking component ceases operation.

[0055] In another embodiment, when the primary component and the target backup component work collaboratively, the primary component is switched to the target backup component so that the target backup component synchronously takes over the work of the primary component. The primary component and the backup component work together in a collaborative mode under normal circumstances to execute tasks. These tasks can refer to the same task or different related tasks under the same task. The primary component dominates control decisions; when the primary component fails, the backup component increases its control weight to maintain the integrity of the system. For example, in a vehicle's steering system, the primary steering component controls 50% of the torque output of the motor assist, and the backup steering component synchronously executes the remaining 50%. If the primary steering component fails, the backup steering component automatically increases the output to 100% and takes over the parsing function of the HAD primary controller's steering commands.

[0056] This application provides different switching strategies for abnormal situations of special main components in order to maintain the integrity of vehicle functions and normal operation.

[0057] In one embodiment, if the main control component or main power supply component malfunctions, each main component in the main system can be switched to a corresponding backup component in the backup system. In some embodiments, if the main control component malfunctions, the main component corresponding to that main control component and the first controlled component controlled by that main control component in the main system can be switched to corresponding backup components in the backup system; or, if the main power supply component malfunctions, the main component in the main system that relies on that main power supply component for power can be switched to a backup component in the backup system that relies on the backup power supply component for power. Unlike other main components, the main control component and main power supply component are the core components of the main system. The former controls the functions and behaviors of other first controlled components, while the latter provides power support for all main components. Therefore, even if other first controlled components are functioning normally, the backup components used to replace the main components or main power supply component may not meet the normal operation requirements of all main components in the main system. For example, when the main power supply fails, the backup power supply only supports some critical first controlled components such as braking and steering. Non-critical modules (such as the entertainment system) will lose power, resulting in abnormalities in related functions. Therefore, it is necessary to switch each main component in the main system to a corresponding backup component in the backup system. Of course, this embodiment is applicable to L3, where the performance of the main component and the backup component does not need to be consistent. In the case of L4 autonomous driving level, the vehicle does not actually need to perform a complete switch of the main control component or the main power supply component; it only needs to be replaced with the corresponding backup component.

[0058] The following section, with reference to Figure 4, provides a detailed explanation of the architecture design of the vehicle's redundant components. As shown in Figure 4, the main components include a drive power module 1, main brake 1, brake light 1, wheel speed sensing module 1, parking brake 1, data recording 1, turn signal module 1, driver intervention module 1, vehicle travel angle module 1, main steering 1, vehicle attitude information 1, rear vehicle visible warning light 1, HMI (Human-Machine Interface) alarm reminder 1, vehicle lighting 1, navigation / positioning 1, perception redundancy 1, HAD main controller 1, and main power supply 1. These components can sequentially establish one-to-one mapping relationships with the backup components: drive power module 2, auxiliary brake 2, brake light 2, wheel speed sensing module 2, parking brake 2, data recording 2, turn signal module 2, driver intervention module 2, vehicle travel angle module 2, auxiliary steering 2, vehicle attitude information 2, rear vehicle visible warning light 2, HMI alarm reminder 2, vehicle lighting 2, navigation / positioning 2, perception redundancy 2, HAD secondary controller 2, and backup power supply 2. These mapping relationships are based on ISO... The functional safety objectives under standard 26262 are derived from the breakdown of these objectives. For example, the functional safety objective of "avoiding unexpected loss of lateral motion control" belongs to ASIL D, so the risk of single-point failure can be reduced through redundant design. That is, the main steering 1 (ASIL B) and the auxiliary steering 2 (ASIL B) are designed independently to ensure that they do not fail due to a common cause. Another example is the functional safety objective of "avoiding unexpected loss of deceleration capability," which also belongs to ASIL D. Therefore, a braking redundancy system can be designed, where the main brake 1 (ASIL B) and the auxiliary brake 2 (ASIL B) control different hydraulic circuits. For example, the main brake 1 uses conventional hydraulic control, while the auxiliary brake 2 integrates electromechanical braking. The process of creating the mapping relationship between other main components and backup components is basically the same, so it will not be elaborated on in this application.

[0059] Specifically, the functional safety objective of "avoiding unexpected loss of vehicle's external lighting and indications during autonomous driving operation" is ASIL A when viewed independently. Considering the whole vehicle level, a non-redundant design is feasible. However, based on the breakdown of functional safety requirements, when the HAD main controller 1 is in control, if the vehicle's autonomous driving technology uses a pure vision solution, then after the lighting fails, the duration for which the vehicle maintains its lane at night will inevitably be unsustainable. Therefore, a complementary redundancy design for the vehicle lighting is necessary. This meets the ASIL B level backup link design requirements of the perception link. In other words, the lighting system must at least meet the overall decomposed functional safety requirements of ASIL B and a redundancy scheme needs to be designed, namely the vehicle lighting 1 and vehicle lighting 2 components in Figure 4.

[0060] Furthermore, if the vehicle corresponds to Level 3 autonomous driving, the redundant design of the drive power module 2 can be omitted to save on vehicle production costs and interior space without affecting minimum safety requirements.

[0061] The following explanation of an embodiment of Figure 4 illustrates the minimum safety requirements corresponding to the primary and backup components associated with each mapping relationship, wherein the minimum safety requirements are obtained from the breakdown of preset functional safety objectives.

[0062] 1. Drive Power Module 1 and Drive Power Module 2: Drive Power Module 2 must provide ≥8% of the peak torque output, corresponding to an acceleration of 0.15g (i.e., 1.47 m / s²), in the event of failure of Drive Power Module 1. 2 It supports the full speed range of 0-150km / h and curve conditions with a radius of curvature ≥30m, ensuring power continuity and switching delay ≤50ms.

[0063] 2. Main brake 1 and auxiliary brake 2: Auxiliary brake 2 must achieve a deceleration of ≥0.6g (i.e., -5.88 m / s) when main brake 1 fails. 2 For example, in a scenario with an initial vehicle speed of 80 km / h on a dry road surface, the Antilock Braking System (ABS) is activated, with wheel speed fluctuation control ≤ ±5% and response time ≤ 100 ms.

[0064] 3. Brake light 1 and brake light 2: Brake light 2 must activate the dual-lamp synchronous lighting mode within 50ms when brake light 1 fails (brightness ≥ 200 cd / m²). 2 It covers the entire speed range braking scenario (including AEB emergency braking) and ensures that the following vehicle recognition delay is ≤300ms.

[0065] 4. Wheel Speed ​​Sensing Module 1 and Wheel Speed ​​Sensing Module 2: Although ABS for the braking system requires feedback on the status of each wheel, some applications of the Operational Design Domain (ODD) can consider not redundant four-wheel sensors and only redundancy for two front wheels. However, considering that if a single wheel speed sensing module 1 fails, relying solely on the estimation of the rear wheel speed by the Inertial Measurement Unit (IMU) and the status of each wheel obtained by wheel speed sensing module 2 based on the redundancy of the two front wheels is unreliable, wheel speed sensing module 2 must be designed with independent redundancy for all four wheels. The IMU estimation error compensation threshold should be ≤2km / h. If wheel speed sensing module 1 fails, wheel speed sensing module 2 can provide four-wheel speed data (accuracy ±0.5km / h) within 20ms, meeting the full functional requirements of ABS / ESP.

[0066] 5. Parking 1 and Parking 2: In the event of failure of the main control of Parking 1, Parking 2 is required to have an auxiliary control capable of maintaining a parking slope of no less than 8% under the condition of maintaining pressure until the vehicle is stationary, with a hydraulic pressure holding leakage rate of ≤0.5 bar / min and an electronic parking command response time of ≤200 ms.

[0067] 6. HAD Main Controller 1 and HAD Sub-Controller 2: In the event of failure of HAD Main Controller 1, for L3 systems, HAD Sub-Controller 2 needs to maintain a 10-second control window, provided that the vehicle speed is ≤60km / h. Simultaneously, it triggers driver takeover prompts through methods such as "audio-visual + tactile warning". For L4 systems, HAD Sub-Controller 2, in conjunction with power redundancy, can perform sidewalk control or lane-keeping control in non-high-speed situations, relying on high-precision map positioning error ≤30cm.

[0068] 7. Data Record 1 and Data Record 2: These can be recorded in two ways. In the event of Data Record 1 failure, Data Record 2 must support dual-channel synchronous writing in both cloud and local storage. The data loss rate in case of single-channel failure must be ≤0.1%, the recording frequency ≥100Hz, and the pre-caching time for critical events (such as AEB (Automatic Emergency Braking) triggering) ≥30s. Data can be recorded and retrieved for accident scenario reproduction or data verification.

[0069] 8. Turn Signal Module 1 and Turn Signal Module 2: In the L3 design, if Turn Signal Module 1 malfunctions, the vehicle can directly brake to a stop within the lane without turning, thus eliminating the need for redundancy in Turn Signal Module 2. However, during the application of the turning function, a malfunction in the Turn Signal Module 1 results in the loss of turn signal indication, creating a risk that other vehicles cannot controllably avoid. The left and right turn signals can be handled by Turn Signal Module 1 and Turn Signal Module 2 respectively (both modules can be considered primary components). If either module (let's say Turn Signal Module 1) malfunctions, Turn Signal Module 2 can be designated as a backup component, which uses rapid flashing (flash frequency 2Hz, brightness ≥150cd / m²). 2 This achieves the same effect as a warning light. For L4, turn signal module 1 can be designed with dual redundancy, meaning turn signal module 2 has independent redundancy for the left and right turn signals respectively. In case of failure, the lighting logic can be switched via CAN signal remapping.

[0070] 9. Driver Intervention Module 1 and Driver Intervention Module 2: To achieve the functional safety objective of smooth driver takeover of autonomous driving mode and overtaking control in emergency situations, the torque sensor of the steering wheel (torque detection sensitivity ±0.5Nm) can be redundantly designed as part of the driver intervention module, without using a switch combination method; or it can be combined with the ASILB-compliant autonomous driving function switch (switch response time ≤50ms) and the torque sensor to form an ASILD design, which can meet the safety objective.

[0071] 10. Vehicle driving angle module 1 and vehicle driving angle module 2: Regarding the vehicle steering angle, vehicle driving angle module 2 needs to provide redundant detection of steering wheel angle, with an angle resolution error ≤0.5°, a data fusion period with yaw rate ≤10ms, and support for closed-loop correction of steering control. The vehicle driving angle is essentially derived from the raw data collected by the steering wheel angle sensor (e.g., dual potentiometer + Hall sensor) and the algorithmic conversion of the vehicle steering system. The result can be combined with vehicle attitude information, and the algorithm is calculated by the HAD main controller.

[0072] 11. Main Steering 1 and Secondary Steering 2: In the event of failure of Main Steering 1, Secondary Steering 2 is required to maintain steering assistance at a vehicle speed of ≥5km / h, i.e., output torque ≥30Nm, steering angle tracking error ≤2°, and support minimum turning radius ≤6m.

[0073] 12. Vehicle Attitude Information 1 and Vehicle Attitude Information 2: First, the component corresponding to either vehicle attitude information must be used to analyze the collected chassis dynamics information using a chassis dynamics algorithm to obtain vehicle state characteristics, such as longitudinal acceleration ax, lateral acceleration ay, yaw rate, roll angle, slip ratio, stability status, and slope. These information are then processed as the results of Vehicle Attitude Information 1 or Vehicle Attitude Information 2. Subsequent control and management rely on the HAD main controller and HAD sub-controller, respectively. The longitudinal / lateral acceleration detection accuracy is ±0.05g, the yaw rate accuracy is ±0.1° / s, and the data output frequency is ≥100Hz.

[0074] 13. Rear Visible Warning Light 1 and Rear Visible Warning Light 2: Similar to the turn signal module, they can be designed based on left and right lights. In the event of an abnormality in Rear Visible Warning Light 1, Rear Visible Warning Light 2 will flash rapidly (4Hz, brightness ≥300cd / m²). 2 (With a nighttime visibility distance of ≥200m, it achieves the same effect as hazard lights.)

[0075] 14. HMI Alarm Reminder 1 and HMI Alarm Reminder 2: HMI Alarm Reminder 1 can be presented in a voice + text manner; HMI Alarm Reminder 2 can adopt design schemes such as vibrating seat (5-15Hz) + interior lighting (red gradient warning of interior RGB ambient light) + intermittent braking reminder (1Hz, deceleration ≤0.1g), that is, to complement each other through diversified combination methods. Among them, voice backup broadcast can be provided between HMI Alarm Reminder 1 and HMI Alarm Reminder 2, requiring voice alarm delay ≤200ms.

[0076] 15. Vehicle Lighting 1 and Vehicle Lighting 2: Vehicle Lighting 1 and Vehicle Lighting 2 can be complementary high beam and low beam headlights, respectively. For example, Vehicle Lighting 1 can be the high beam headlight, and Vehicle Lighting 2 can be the low beam headlight. The specific design can be tailored to different visual perception recognition capabilities. For instance, in autonomous driving scenarios, the minimum requirement is whether forward objects and lane lines can be accurately identified. Furthermore, the maximum vehicle speed is a key factor. For example, if the vehicle speed is too high, the illumination distance of Vehicle Lighting 2 (as the low beam headlight) will not match the perception processing time, making it unsuitable for prolonged use. In short, complementary high beam or low beam headlights, with the high beam automatically reducing power to 50% to maintain basic illumination (illumination distance ≥60m) when the low beam fails, can achieve a low-cost solution. For higher requirements, a redundant dual high beam design can be implemented, maintaining a brightness of ≥800 lumens when a single headlight fails, with a beam deflection compensation angle of ±1.5°.

[0077] 16. Navigation / Positioning 1 and Navigation / Positioning 2: Navigation / Positioning 1 can integrate positioning with electronic maps and IMU + Global Navigation Satellite System (GNSS), while Navigation / Positioning 2 can ensure safe operation of Advanced Driving Assistance System (ADAS) maps and self-built perception maps. The positioning data update frequency is ≥10Hz, and the time synchronization error with the main system (i.e., GNSS + IMU) is ≤10ms.

[0078] 17. Perception Redundancy 1 and Perception Redundancy 2: These refer to a series of sensor devices used by a vehicle to perceive its surrounding environment. Considering their large number and variety, they are collectively referred to as perception redundancy. In the event of the failure of Perception Redundancy 1, Perception Redundancy 2 is required to maintain at least 80% of the original perception coverage, such as a 120° horizontal field of view, and key target detection capabilities, such as obstacle recognition accuracy ≥95% within 50 meters. This is achieved by using heterogeneous sensor combinations, such as LiDAR + millimeter-wave radar in Perception Redundancy 2, to replace the failed vision module in Perception Redundancy 2, ensuring the continuity of multi-source data fusion, while meeting the fault response time requirements of ASIL B functional safety.

[0079] Figure 5 is a schematic structural diagram of an electronic device in an exemplary embodiment. Referring to Figure 5, at the hardware level, the electronic device includes a processor 502, an internal bus 510, a network interface 504, a memory 506, and a non-volatile memory 508, and may also include other necessary hardware. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it, forming a risk code detection device at the logical level. Of course, in addition to software implementation, this application does not exclude other implementation methods, such as logic devices or a combination of hardware and software, etc. That is to say, the execution subject of the following processing flow is not limited to individual logic units, but can also be hardware or logic devices.

[0080] Figure 6 is a block diagram of a vehicle component switching device according to an embodiment of this application. As shown in Figure 6, in this device, the vehicle is equipped with a main system and a backup system. The main system includes one or more main components, and the backup system includes one or more backup components. For any main component in the main system, the main component and / or the backup component in the backup system that has the same function as the main component maintain a mapping relationship between the main component and the backup component that has the same function as the main component. The device may include: a target backup component determination unit 602, configured to determine a target backup component in the backup system corresponding to the main component according to the mapping relationship when it is determined that the working state of any main component is abnormal; and a target backup component switching unit 604, configured to switch the main component to the target backup component, so that the target backup component replaces the main component in operation.

[0081] In some embodiments, for any primary component in the main system, the primary component includes a primary control component and a first controlled component controlled by the primary control component; for any backup component in the backup system, the backup component includes a secondary control component; the device further includes: a first anomaly determination unit, wherein if the primary control component determines that the first controlled component meets the component anomaly conditions, the primary control component determines that the working state of the first controlled component is abnormal; and a second anomaly determination unit, wherein if the secondary control component determines that the primary control component meets the component anomaly conditions, the secondary control component determines that the working state of the primary control component is abnormal.

[0082] In some embodiments, the backup component further includes a second controlled component controlled by the secondary control component; the target backup component determining unit 602 is configured to: when it is determined that the working state of the first controlled component is abnormal, and either the primary control component or the secondary control component maintains the mapping relationship, the primary control component or the secondary control component determines the second controlled component corresponding to the first controlled component in the backup system as the target backup component according to the mapping relationship; when it is determined that the working state of the primary control component is abnormal, and the secondary control component maintains the mapping relationship, the secondary control component determines the secondary control component as the target backup component according to the mapping relationship.

[0083] In some embodiments, the first anomaly determination unit is configured such that: the main control component determines that the working state of the first controlled component is abnormal based on a first connection between the main control component and the first controlled component; or, the main control component determines that the working state of the first controlled component is abnormal based on a second connection between the main control component and other first controlled components, wherein the other first controlled components are controlled components in the main control component that are different from the first controlled component, and the other first controlled components have established a third connection with the first controlled component.

[0084] In some embodiments, the apparatus further includes a power isolation unit for isolating the main power component from the backup power component when one or more main components include a main power component and one or more backup components include a backup power component.

[0085] In some embodiments, the main component includes a main control component, and the device further includes: a full component switching unit, configured to switch each main component in the main system to a corresponding backup component in the backup system when the working state of the main control component or the main power supply component is abnormal.

[0086] In some embodiments, the target backup component switching unit 604 is configured to: switch the main component to the target backup component when the main component and the target backup component work independently, so that the target backup component completely replaces the main component in operation; and switch the main component to the target backup component when the main component and the target backup component work together, so that the target backup component synchronously takes over the work of the main component.

[0087] The specific implementation process of the functions and roles of each unit in the device can be found in the implementation process of the corresponding steps in the method, and will not be repeated here.

[0088] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to in the description of the method embodiments. The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this application according to actual needs. Those skilled in the art can understand and implement this without creative effort.

[0089] Based on the same concept as the method, this application also provides an electronic device, including: a processor; a memory for storing processor-executable instructions; wherein the processor implements the steps of the method as described in any embodiment by executing the executable instructions.

[0090] Based on the same concept as the method, this application also provides a computer-readable storage medium having computer instructions stored thereon that, when executed by a processor, implement the steps of the method as described in any embodiment.

[0091] Based on the same concept as the method, this application also provides a computer program product, including a computer program / instructions that, when executed by a processor, implement the steps of the method as described in any embodiment.

[0092] The embodiments of the subject matter and functional operation described in this application can be implemented in: digital electronic circuits, tangibly embodied computer software or firmware, computer hardware including the structures disclosed in this application and their structural equivalents, or combinations thereof. Embodiments of the subject matter described in this application can be implemented as one or more computer programs, i.e., one or more modules of computer program instructions encoded on a tangible, non-transitory program carrier for execution by a data processing apparatus or for controlling the operation of a data processing apparatus. Alternatively or additionally, the program instructions may be encoded on artificially generated propagation signals, such as machine-generated electrical, optical, or electromagnetic signals, which are generated to encode information and transmit it to a suitable receiving device for execution by the data processing apparatus. The computer storage medium may be a machine-readable storage device, a machine-readable storage substrate, a random or serial access memory device, or combinations thereof.

[0093] The processing and logic flow described in this application can be executed by one or more programmable computers that execute one or more computer programs to perform corresponding functions by operating on input data and generating output. The processing and logic flow can also be executed by dedicated logic circuitry—such as FPGA (Field-Programmable Gate Array) or ASIC (Application-Specific Integrated Circuit)—and the device can also be implemented as dedicated logic circuitry.

[0094] Suitable computers for executing computer programs include, for example, general-purpose and / or special-purpose microprocessors, or any other type of central processing unit. Typically, the central processing unit receives instructions and data from read-only memory and / or random access memory. The basic components of a computer include a central processing unit for implementing or executing instructions and one or more memory devices for storing instructions and data. Typically, a computer will also include one or more mass storage devices for storing data, such as disks, magneto-optical disks, or optical disks, or the computer will be operatively coupled to such mass storage devices to receive data from or transfer data to them, or both. However, a computer is not required to have such devices. Furthermore, a computer can be embedded in another device, such as a mobile phone, a personal digital assistant (PDA), a mobile audio or video player, a game console, a global positioning system (GPS) receiver, or a portable storage device such as a universal serial bus (USB) flash drive, to name a few.

[0095] Computer-readable media suitable for storing computer program instructions and data include all forms of non-volatile memory, media, and memory devices, such as semiconductor memory devices (e.g., EPROM, EEPROM, and flash memory devices), magnetic disks (e.g., internal hard disks or removable disks), magneto-optical disks, and CD-ROM and DVD-ROM disks. Processors and memory may be supplemented by or incorporated into dedicated logic circuitry.

[0096] While this application contains numerous specific implementation details, these should not be construed as limiting the scope of any invention or the scope of the claims, but rather are primarily used to describe features of specific embodiments of a particular invention. Certain features described in the multiple embodiments of this application may also be implemented in combination in a single embodiment. Conversely, various features described in a single embodiment may also be implemented separately in multiple embodiments or in any suitable sub-combination. Furthermore, while features may function in certain combinations as described above and even initially claimed in this way, one or more features from a claimed combination may be removed from that combination in some cases, and a claimed combination may refer to a sub-combination or a variation of a sub-combination.

[0097] Similarly, although operations are depicted in a specific order in the accompanying drawings, this should not be construed as requiring these operations to be performed in the specific order shown or sequentially, or requiring all illustrated operations to be performed to achieve the desired result. In some cases, multitasking and parallel processing may be advantageous. Furthermore, the separation of various system modules and components in the embodiments should not be construed as requiring such separation in all embodiments, and it should be understood that the described program components and systems can generally be integrated together in a single software product or packaged into multiple software products.

[0098] Therefore, specific embodiments of the subject matter have been described. Furthermore, the processes depicted in the figures are not necessarily shown in a specific order or sequence to achieve the desired result. In some implementations, multitasking and parallel processing may be advantageous.

[0099] The above description is merely some embodiments of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A component switching method for a vehicle, the vehicle being equipped with a main system and a backup system, the main system including one or more main components, the backup system including one or more backup components, wherein for any main component in the main system, the main component and / or the backup component in the backup system having the same function as the main component maintain a mapping relationship between the main component and the backup component having the same function as the main component; the method comprising: If it is determined that the working state of any main component is abnormal, the target backup component corresponding to that main component in the backup system is determined according to the mapping relationship; The main component is switched to the target backup component, so that the target backup component can replace the main component in operation.

2. The method according to claim 1, wherein, For any primary component in the main system, the primary component includes a primary control component and a first controlled component controlled by the primary control component; for any backup component in the backup system, the backup component includes a secondary control component. The determination that the working state of any main component is abnormal includes: If the main control component determines that the first controlled component meets the abnormal conditions, the main control component determines that the working state of the first controlled component has become abnormal. If the secondary control component determines that the primary control component meets the abnormal conditions, the secondary control component determines that the working state of the primary control component has become abnormal.

3. The method according to claim 2, wherein, The backup component also includes a second controlled component controlled by the secondary control component; determining the target backup component corresponding to the primary component in the backup system according to the mapping relationship includes: If it is determined that the working state of the first controlled component is abnormal, and the main control component and either the secondary control component maintain the mapping relationship, the main control component and either the secondary control component determine the second controlled component in the backup system corresponding to the first controlled component as the target backup component according to the mapping relationship. If it is determined that the working state of the main control component is abnormal and the secondary control component maintains the mapping relationship, the secondary control component determines the secondary control component as the target backup component according to the mapping relationship.

4. The method according to claim 2, wherein, The main control component determines that the working state of the first controlled component has become abnormal, including: The main control component determines that the operating state of the first controlled component is abnormal based on the first connection between the main control component and the first controlled component; or... The main control component determines that the working state of the first controlled component is abnormal based on the second connection between the main control component and other first controlled components. The other first controlled components are controlled components in the main control component that are different from the first controlled component. The other first controlled components have established a third connection with the first controlled component.

5. The method according to any one of claims 1 to 4, further comprising: In cases where one or more main components include a main power supply component and one or more backup components include a backup power supply component, the main power supply component and the backup power supply component are isolated.

6. The method according to claim 5, wherein, The main component includes a main control component, and the method further includes: In the event of an abnormal operation of the main control component or the main power supply component, each main component in the main system will be switched to the corresponding backup component in the backup system.

7. The method according to any one of claims 1 to 6, wherein, The step of switching the primary component to the target backup component includes: When the main component and the target backup component operate independently, the main component is switched to the target backup component so that the target backup component completely replaces the main component. When the main component and the target backup component work together, the main component is switched to the target backup component so that the target backup component can synchronously take over the work of the main component.

8. The method according to any one of claims 1 to 7, wherein, For any main component in the main system, the software of the main component and the backup component in the backup system that has the same function as the main component adopts a heterogeneous architecture design, and the hardware platform of the main component and the backup component in the backup system that has the same function as the main component adopts a heterogeneous deployment.

9. A computer-readable storage medium having stored thereon computer instructions that, when executed by a processor, implement the steps of the method as claimed in any one of claims 1 to 8.

10. A computer program product comprising a computer program / instructions that, when executed by a processor, implement the steps of the method as claimed in any one of claims 1 to 8.

11. A component switching device for a vehicle, the vehicle being equipped with a main system and a backup system, the main system including one or more main components, the backup system including one or more backup components, wherein for any main component in the main system, the main component and / or the backup system maintaining a mapping relationship between the main component and the backup component having the same function as the main component; The device includes: The target backup component determination unit is configured to determine, based on the mapping relationship, the target backup component in the backup system corresponding to the main component when it is determined that the working state of any main component is abnormal. The target backup component switching unit is configured to switch the main component to the target backup component, so that the target backup component can replace the main component in operation.