In-Vehicle ECU Domain Failover via Hypervisor Virtual Network

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional in-vehicle systems face challenges in smoothly continuing essential functions when an ECU failure occurs, especially if the failure is in an ECU with low failure probability, and there is a high burden of communication processing for transferring functions between ECUs.

Innovation Solution

The system incorporates an extended domain unit, a basic domain unit, a management domain unit, and a hypervisor unit, operating under different operating systems, which allows for smooth continuation of functions by halting affected units and redirecting operations through an independent virtual network to substitute units on separate ECUs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If function transfer is based on failure probability, then preparation for failure is simplified, but function continuation fails when low-probability failures occur and communication burden increases

Engineering Contradiction:
Improvefunction continuation capabilityVSAvoidcommunication processing burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments ECUs into basic domain units and extended domain units, with basic units handling essential functions and extended units handling non-essential functions. This segmentation allows the system to maintain critical functions through basic units while reducing communication burden by isolating extended unit failures from affecting core operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A management domain unit acts as an intermediary between basic domain units and extended domain units. It monitors the operational status of extended units and automatically transfers functions from failed extended units to standby basic units, eliminating the need for complex peer-to-peer communication and function transfer protocols among all ECUs.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If function transfer is implemented across all ECUs, then function availability is improved, but communication processing burden becomes excessively large

Engineering Contradiction:
Improvefunction availabilityVSAvoidcommunication processing energy
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system divides the ECU network into distinct domains (basic domain and extended domain) with clear functional boundaries. This segmentation limits the scope of function transfer to specific domain transitions, reducing the overall communication load compared to universal function transfer across all ECUs.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The management domain unit serves as a centralized intermediary that handles all function transfer decisions and communications. By consolidating transfer logic in this intermediary, the system avoids the exponential growth of communication overhead that would result from direct peer-to-peer transfer protocols among all ECU pairs.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If basic domain unit fails, then essential function continuation is compromised, but system complexity increases with substitute units

Engineering Contradiction:
Improveessential function continuationVSAvoidsubstitute unit configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system pre-configures standby basic domain units within the same ECU that can immediately assume essential functions if the primary basic unit fails. This preliminary preparation of substitute units eliminates the need for complex real-time selection and configuration processes, as the takeover is pre-arranged and automatic.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system merges the primary basic domain unit and standby substitute unit into a single ECU, allowing them to share hardware resources and communication interfaces. This merging reduces overall system complexity compared to requiring separate dedicated substitute ECUs, while still providing essential function continuation capability.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12139152B2In-vehicle electronic control unit and computer readable medium
Publication Date: 2024.11.12 MITSUBISHI ELECTRIC CORP
  • US12139152B2 patent drawing
  • US12139152B2 patent drawing
  • US12139152B2 patent drawing

AI summary

A management domain unit is connected, via an independent virtual network (95) using a hypervisor unit, to a separate management domain unit (B) (10B) of a separate electronic control unit ECU (B) (1) having the separate management domain unit (B) (10B) and a separate basic domain unit (A) (50B) which substitutes for a basic domain unit. When an abnormality of the basic domain unit is detected, the management domain unit halts operation of the basic domain unit, and causes the separate management domain unit (B) (10B) possessed by the separate electronic control unit ECU (B) (1) to start operation of the separate basic domain unit (A) (50B).