Multicore Control Unit Watchdog Segmentation for Fault Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional control units for motor vehicles lack scalability and reliability, particularly in heterogeneous architectures, and struggle to maintain high availability and computing power while managing complex monitoring and fault detection across multiple processor cores.
Innovation Solution
Implementing a hierarchical watchdog structure across multiple processor cores, where self-testing units generate test results that are combined by monitoring units to ensure fault detection and tolerance, allowing for temporal decoupling of communication and task execution, and utilizing lockstep methods and hardware components for enhanced reliability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single computing element performs both control and monitoring, then device complexity is reduced, but reliability deteriorates due to lack of separation between control and monitoring functions
Solution Approach 1:
The control unit is segmented into multiple processor cores with distinct roles: first processor core for control tasks, second processor core for monitoring tasks, first self-testing unit for control monitoring, and second self-testing unit for monitoring function monitoring. This segmentation separates control and monitoring functions while maintaining manageable complexity through modular architecture.
Solution Approach 2:
Self-testing units act as intermediaries between processor cores and the watchdog unit. The first self-testing unit monitors the first processor core, and the second self-testing unit monitors the second processor core, creating an intermediate monitoring layer that enhances reliability without directly complicating the control-monitoring interface.
2Reliability
If monitoring and regulation are implemented in control-unit-wide software frame, then reliability improves through comprehensive monitoring, but device complexity increases due to software complexity
Solution Approach 1:
The patent replaces software-based monitoring with hardware-based self-testing units that are integrated into the processor cores. These hardware units automatically perform monitoring and generate test results, eliminating the need for complex software monitoring frames while maintaining comprehensive reliability coverage.
Solution Approach 2:
The processor cores include integrated self-testing units that autonomously monitor their respective cores without requiring external software intervention. The first self-testing unit self-monitors the first processor core, and the second self-testing unit self-monitors the second processor core, reducing software complexity while enhancing reliability.
3Device complexity
If data transmission is secured over a single connection between control units, then device complexity is reduced, but reliability deteriorates due to single point of failure
Solution Approach 1:
The monitoring function is segmented across multiple independent components: first self-testing unit on first processor core, second self-testing unit on second processor core, and second monitoring unit that receives results from both. This segmentation creates redundant monitoring paths that improve reliability without requiring complex multi-connection architectures between control units.
4Productivity
If multiple processor cores are used to increase computing power, then productivity improves, but device complexity increases due to coordination and monitoring requirements
Solution Approach 1:
The multicore processor is segmented into specialized cores: first processor core for control, second processor core for monitoring, with corresponding self-testing units for each. This functional segmentation allows multiple cores to operate independently with clear responsibilities, reducing coordination complexity while maintaining high computing power.
Solution Approach 2:
Self-testing units serve as intermediaries that simplify multicore coordination by automatically monitoring each core's operation and generating standardized test results. The second monitoring unit receives these results and determines the status response, reducing the complexity of direct core-to-core communication and coordination.
Data Source
AI summary
A method for operating a control unit of a motor vehicle. A status inquiry is transmitted by a watchdog unit to a first monitoring unit, which is implemented on a first processor core of a multicore processor. A status response is ascertained by the first monitoring unit as a function of the status inquiry. A fault is ascertained by the watchdog unit as a function of the status response.


