WO2023232401A1 - Procédé de fonctionnement d'un dispositif de commande d'un véhicule - Google Patents
Procédé de fonctionnement d'un dispositif de commande d'un véhicule Download PDFInfo
- Publication number
- WO2023232401A1 WO2023232401A1 PCT/EP2023/062263 EP2023062263W WO2023232401A1 WO 2023232401 A1 WO2023232401 A1 WO 2023232401A1 EP 2023062263 W EP2023062263 W EP 2023062263W WO 2023232401 A1 WO2023232401 A1 WO 2023232401A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- error
- scheduling
- functional components
- functional component
- real
- Prior art date
Links
- 238000000034 method Methods 0.000 title claims abstract description 37
- 238000012544 monitoring process Methods 0.000 claims abstract description 20
- 230000000977 initiatory effect Effects 0.000 claims abstract description 11
- 238000001514 detection method Methods 0.000 claims description 20
- 238000004590 computer program Methods 0.000 claims description 19
- 230000004807 localization Effects 0.000 claims description 14
- 230000000694 effects Effects 0.000 claims description 4
- 230000006870 function Effects 0.000 description 70
- 230000008901 benefit Effects 0.000 description 4
- 230000008859 change Effects 0.000 description 4
- 230000015556 catabolic process Effects 0.000 description 3
- 238000006243 chemical reaction Methods 0.000 description 3
- 238000006731 degradation reaction Methods 0.000 description 3
- 230000003993 interaction Effects 0.000 description 3
- 230000008569 process Effects 0.000 description 3
- 230000004044 response Effects 0.000 description 3
- 230000001960 triggered effect Effects 0.000 description 3
- 230000001364 causal effect Effects 0.000 description 2
- 239000000725 suspension Substances 0.000 description 2
- 230000003213 activating effect Effects 0.000 description 1
- 230000006399 behavior Effects 0.000 description 1
- 125000004122 cyclic group Chemical group 0.000 description 1
- 238000013500 data storage Methods 0.000 description 1
- 230000001629 suppression Effects 0.000 description 1
- 230000007704 transition Effects 0.000 description 1
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F11/00—Error detection; Error correction; Monitoring
- G06F11/07—Responding to the occurrence of a fault, e.g. fault tolerance
- G06F11/0703—Error or fault processing not based on redundancy, i.e. by taking additional measures to deal with the error or fault not making use of redundancy in operation, in hardware, or in data representation
- G06F11/0751—Error or fault detection not based on redundancy
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F11/00—Error detection; Error correction; Monitoring
- G06F11/07—Responding to the occurrence of a fault, e.g. fault tolerance
- G06F11/0703—Error or fault processing not based on redundancy, i.e. by taking additional measures to deal with the error or fault not making use of redundancy in operation, in hardware, or in data representation
- G06F11/0706—Error or fault processing not based on redundancy, i.e. by taking additional measures to deal with the error or fault not making use of redundancy in operation, in hardware, or in data representation the processing taking place on a specific hardware platform or in a specific software environment
- G06F11/0736—Error or fault processing not based on redundancy, i.e. by taking additional measures to deal with the error or fault not making use of redundancy in operation, in hardware, or in data representation the processing taking place on a specific hardware platform or in a specific software environment in functional embedded systems, i.e. in a data processing system designed as a combination of hardware and software dedicated to performing a certain function
- G06F11/0739—Error or fault processing not based on redundancy, i.e. by taking additional measures to deal with the error or fault not making use of redundancy in operation, in hardware, or in data representation the processing taking place on a specific hardware platform or in a specific software environment in functional embedded systems, i.e. in a data processing system designed as a combination of hardware and software dedicated to performing a certain function in a data processing system embedded in automotive or aircraft systems
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F11/00—Error detection; Error correction; Monitoring
- G06F11/07—Responding to the occurrence of a fault, e.g. fault tolerance
- G06F11/0796—Safety measures, i.e. ensuring safe condition in the event of error, e.g. for controlling element
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2201/00—Indexing scheme relating to error detection, to error correction, and to monitoring
- G06F2201/805—Real-time
Definitions
- a control device can have at least one microcontroller, which, after initialization, cyclically runs through a predetermined list of software components in a specific order.
- the processing of this list possibly also the list itself - is generally known as “scheduling”.
- the list is the same in every cycle.
- the functional components to be executed are defined by the scheduling, the scheduling being carried out as a regular scheduling during normal operation, and in the second error mode being carried out as a fallback scheduling, with a smaller number of the (first and/or second) functional components (in particular only the first functional components) are (are) executed than in regular scheduling, and wherein the adjustment of the scheduling can include the following step:
- fallback scheduling is carried out, in which all first functional components for the real-time function or autonomous driving function continue to be executed, and in which at least one of the second functional components for the at least one further and of the real-time function or . autonomous driving function is exposed to a different function.
- the suspension can also be referred to as a form of switching off the second functional components.
- this shutdown is preferably carried out by suppressing the effect, such as an output of the functional components.
- this shutdown takes place in particular by adjusting the scheduling, through which the suspension can take place.
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Quality & Reliability (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Safety Devices In Control Systems (AREA)
Abstract
L'invention concerne un procédé (100) pour faire fonctionner un dispositif de commande (10) d'un véhicule (1), le dispositif de commande (10) comprenant au moins une unité de traitement électronique (20) pour exécuter au moins un premier composant fonctionnel (31) pour une fonction en temps réel pour le véhicule, et au moins un second composant fonctionnel (32) pour au moins une autre fonction pour le véhicule (1), et un ordre pour l'exécution des composants fonctionnels (31, 32) étant défini par planification, comprenant les étapes suivantes : la réalisation d'une surveillance (101) du ou des premiers composants fonctionnels (31) et du ou des seconds composants fonctionnels (32); la détection (102) d'une erreur dans au moins l'un des composants fonctionnels (31, 32) sur la base de la surveillance (101); l'initiation (103) d'un premier mode d'erreur (301) si l'erreur est détectée dans le ou les premiers composants fonctionnels (31) pour la fonction en temps réel ; l'initiation (104) d'un second mode d'erreur (302) si l'erreur est détectée dans le ou les seconds composants de fonction (32) pour la ou les fonctions supplémentaires, le second mode d'erreur (302) étant différent du premier mode d'erreur (301) et la planification étant adaptée dans le second mode d'erreur (302).
Applications Claiming Priority (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
DE102022205521.7A DE102022205521A1 (de) | 2022-05-31 | 2022-05-31 | Verfahren für einen Betrieb eines Steuergeräts eines Fahrzeuges |
DE102022205521.7 | 2022-05-31 |
Publications (1)
Publication Number | Publication Date |
---|---|
WO2023232401A1 true WO2023232401A1 (fr) | 2023-12-07 |
Family
ID=86497588
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/EP2023/062263 WO2023232401A1 (fr) | 2022-05-31 | 2023-05-09 | Procédé de fonctionnement d'un dispositif de commande d'un véhicule |
Country Status (2)
Country | Link |
---|---|
DE (1) | DE102022205521A1 (fr) |
WO (1) | WO2023232401A1 (fr) |
Citations (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20190196927A1 (en) * | 2017-12-26 | 2019-06-27 | Thales | Programmable electronic computer in an avionics environment for implementing at least one critical function and associated electronic device, method and computer program |
-
2022
- 2022-05-31 DE DE102022205521.7A patent/DE102022205521A1/de active Pending
-
2023
- 2023-05-09 WO PCT/EP2023/062263 patent/WO2023232401A1/fr unknown
Patent Citations (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20190196927A1 (en) * | 2017-12-26 | 2019-06-27 | Thales | Programmable electronic computer in an avionics environment for implementing at least one critical function and associated electronic device, method and computer program |
Non-Patent Citations (4)
Title |
---|
"ISO 26262-8:2011 Road vehicles -- Functional safety -- Part 8: Supporting processes", 15 November 2011 (2011-11-15), pages 1 - 48, XP009501916, Retrieved from the Internet <URL:https://www.iso.org/standard/51364.html> * |
AUTOSAR: "Overview of Functional Safety Measures in AUTOSAR AUTOSAR CP Release 4.3.0", AUTOSAR STANDARD RELEASES, 30 November 2016 (2016-11-30), pages 1 - 96, XP055894030, Retrieved from the Internet <URL:https://www.autosar.org/fileadmin/user_upload/standards/classic/4-3/AUTOSAR_EXP_FunctionalSafetyMeasures.pdf> [retrieved on 20220221] * |
CHOI JUNCHUL HINOMK2@IRIS SNU AC KR ET AL: "Optimization of Fault-Tolerant Mixed-Criticality Multi-Core Systems with Enhanced WCRT Analysis", ACM TRANSACTIONS ON DESIGN AUTOMATION OF ELECTRONIC SYSTEMS, ACM, NEW YORK, NY, US, vol. 24, no. 1, 21 December 2018 (2018-12-21), pages 1 - 26, XP058682182, ISSN: 1084-4309, DOI: 10.1145/3275154 * |
SUKUMARAN NAIR ARUN ET AL: "TaskMUSTER: a comprehensive analysis of task parameters for mixed criticality automotive systems", SADHANA, SPRINGER INDIA, NEW DELHI, vol. 47, no. 1, 31 December 2021 (2021-12-31), XP037652924, ISSN: 0256-2499, [retrieved on 20211231], DOI: 10.1007/S12046-021-01778-Y * |
Also Published As
Publication number | Publication date |
---|---|
DE102022205521A1 (de) | 2023-11-30 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
DE10049441B4 (de) | Verfahren zum Betrieb eines von einem Prozessor gesteuerten Systems | |
WO2006015945A2 (fr) | Procede, systeme d'exploitation et dispositif de calcul pour executer un programme informatique | |
WO2008040641A2 (fr) | Procédé et dispositif de gestion des pannes | |
DE102013113296A1 (de) | Redundante Rechenarchitektur | |
EP2207097A1 (fr) | Procédé et dispositif destinés au fonctionnement d'un appareil de commande | |
EP1810139B1 (fr) | Procédé, système d'exploitation et ordinateur pour l'exécution d'un programme informatique | |
EP2099667A1 (fr) | Procede pour garantir ou maintenir la fonction d'un systeme global complexe critique pour la securite | |
DE102005009813A1 (de) | Elektronisches Steuerungssystem und -Verfahren mit Microcomputerüberwachungs-Unterdrückungsfunktion | |
DE102007056218A1 (de) | Verfahren zur Behandlung von transienten Fehlern in Echtzeitsystemen, insbesondere in Steuergeräten von Kraftfahrzeugen | |
DE102008004206A1 (de) | Anordnung und Verfahren zur Fehlererkennung und -behandlung in einem Steuergerät in einem Kraftfahrzeug | |
DE102011053580A1 (de) | Verfahren zum betrieb einer elektrischen hilfskraftlenkung | |
DE102004046611A1 (de) | Verfahren zur Abarbeitung eines Computerprogramms auf einem Computersystem | |
EP2228723B1 (fr) | Procédé de gestion des erreurs d'un système de calcul | |
WO2023232401A1 (fr) | Procédé de fonctionnement d'un dispositif de commande d'un véhicule | |
DE102013202961A1 (de) | Verfahren zum Überwachen eines Stackspeichers in einem Betriebssystem eines Steuergeräts eines Kraftfahrzeuges | |
DE102004046288A1 (de) | Verfahren zur Abarbeitung eines Computerprogramms auf einem Computersystem | |
EP1812853A2 (fr) | Procede, système d'exploitation et ordinateur pour l'execution d'un programme informatique | |
WO2016206847A1 (fr) | Procédé et dispositif de sécurisation d'une structure de compteur de programme d'un système de processeur et de surveillance du traitement d'une demande d'interruption | |
WO2007074056A2 (fr) | Systemes processeur tolerants aux erreurs | |
EP2338111B1 (fr) | Procédé et dispositif pour tester un coeur de processeur dans une unité de calcul constituée d'au moins deux coeurs de processeur | |
DE102017212560A1 (de) | Verfahren zum ausfallsicheren Durchführen einer sicherheitsgerichteten Funktion | |
WO2022263416A1 (fr) | Système de commande pour au moins un dispositif de réception dans des applications critiques en termes de sécurité | |
EP1774417B1 (fr) | Procede et dispositif pour surveiller le deroulement d'un programme de commande dans un ordinateur | |
WO2017153411A1 (fr) | Procédé pour faire fonctionner un appareil de commande de véhicule automobile | |
DE102017208872A1 (de) | Elektronische Steuereinheit |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 23725693 Country of ref document: EP Kind code of ref document: A1 |