WO2023232401A1 - Procédé de fonctionnement d'un dispositif de commande d'un véhicule - Google Patents

Procédé de fonctionnement d'un dispositif de commande d'un véhicule Download PDF

Info

Publication number
WO2023232401A1
WO2023232401A1 PCT/EP2023/062263 EP2023062263W WO2023232401A1 WO 2023232401 A1 WO2023232401 A1 WO 2023232401A1 EP 2023062263 W EP2023062263 W EP 2023062263W WO 2023232401 A1 WO2023232401 A1 WO 2023232401A1
Authority
WO
WIPO (PCT)
Prior art keywords
error
scheduling
functional components
functional component
real
Prior art date
Application number
PCT/EP2023/062263
Other languages
German (de)
English (en)
Inventor
Andre Vogel
Bernhard Plametzberger
Elisabeth Magerl
Georg Kuehberger
Original Assignee
Robert Bosch Gmbh
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Robert Bosch Gmbh filed Critical Robert Bosch Gmbh
Publication of WO2023232401A1 publication Critical patent/WO2023232401A1/fr

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/07Responding to the occurrence of a fault, e.g. fault tolerance
    • G06F11/0703Error or fault processing not based on redundancy, i.e. by taking additional measures to deal with the error or fault not making use of redundancy in operation, in hardware, or in data representation
    • G06F11/0751Error or fault detection not based on redundancy
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/07Responding to the occurrence of a fault, e.g. fault tolerance
    • G06F11/0703Error or fault processing not based on redundancy, i.e. by taking additional measures to deal with the error or fault not making use of redundancy in operation, in hardware, or in data representation
    • G06F11/0706Error or fault processing not based on redundancy, i.e. by taking additional measures to deal with the error or fault not making use of redundancy in operation, in hardware, or in data representation the processing taking place on a specific hardware platform or in a specific software environment
    • G06F11/0736Error or fault processing not based on redundancy, i.e. by taking additional measures to deal with the error or fault not making use of redundancy in operation, in hardware, or in data representation the processing taking place on a specific hardware platform or in a specific software environment in functional embedded systems, i.e. in a data processing system designed as a combination of hardware and software dedicated to performing a certain function
    • G06F11/0739Error or fault processing not based on redundancy, i.e. by taking additional measures to deal with the error or fault not making use of redundancy in operation, in hardware, or in data representation the processing taking place on a specific hardware platform or in a specific software environment in functional embedded systems, i.e. in a data processing system designed as a combination of hardware and software dedicated to performing a certain function in a data processing system embedded in automotive or aircraft systems
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F11/00Error detection; Error correction; Monitoring
    • G06F11/07Responding to the occurrence of a fault, e.g. fault tolerance
    • G06F11/0796Safety measures, i.e. ensuring safe condition in the event of error, e.g. for controlling element
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2201/00Indexing scheme relating to error detection, to error correction, and to monitoring
    • G06F2201/805Real-time

Definitions

  • a control device can have at least one microcontroller, which, after initialization, cyclically runs through a predetermined list of software components in a specific order.
  • the processing of this list possibly also the list itself - is generally known as “scheduling”.
  • the list is the same in every cycle.
  • the functional components to be executed are defined by the scheduling, the scheduling being carried out as a regular scheduling during normal operation, and in the second error mode being carried out as a fallback scheduling, with a smaller number of the (first and/or second) functional components (in particular only the first functional components) are (are) executed than in regular scheduling, and wherein the adjustment of the scheduling can include the following step:
  • fallback scheduling is carried out, in which all first functional components for the real-time function or autonomous driving function continue to be executed, and in which at least one of the second functional components for the at least one further and of the real-time function or . autonomous driving function is exposed to a different function.
  • the suspension can also be referred to as a form of switching off the second functional components.
  • this shutdown is preferably carried out by suppressing the effect, such as an output of the functional components.
  • this shutdown takes place in particular by adjusting the scheduling, through which the suspension can take place.

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Quality & Reliability (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Safety Devices In Control Systems (AREA)

Abstract

L'invention concerne un procédé (100) pour faire fonctionner un dispositif de commande (10) d'un véhicule (1), le dispositif de commande (10) comprenant au moins une unité de traitement électronique (20) pour exécuter au moins un premier composant fonctionnel (31) pour une fonction en temps réel pour le véhicule, et au moins un second composant fonctionnel (32) pour au moins une autre fonction pour le véhicule (1), et un ordre pour l'exécution des composants fonctionnels (31, 32) étant défini par planification, comprenant les étapes suivantes : la réalisation d'une surveillance (101) du ou des premiers composants fonctionnels (31) et du ou des seconds composants fonctionnels (32); la détection (102) d'une erreur dans au moins l'un des composants fonctionnels (31, 32) sur la base de la surveillance (101); l'initiation (103) d'un premier mode d'erreur (301) si l'erreur est détectée dans le ou les premiers composants fonctionnels (31) pour la fonction en temps réel ; l'initiation (104) d'un second mode d'erreur (302) si l'erreur est détectée dans le ou les seconds composants de fonction (32) pour la ou les fonctions supplémentaires, le second mode d'erreur (302) étant différent du premier mode d'erreur (301) et la planification étant adaptée dans le second mode d'erreur (302).
PCT/EP2023/062263 2022-05-31 2023-05-09 Procédé de fonctionnement d'un dispositif de commande d'un véhicule WO2023232401A1 (fr)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
DE102022205521.7A DE102022205521A1 (de) 2022-05-31 2022-05-31 Verfahren für einen Betrieb eines Steuergeräts eines Fahrzeuges
DE102022205521.7 2022-05-31

Publications (1)

Publication Number Publication Date
WO2023232401A1 true WO2023232401A1 (fr) 2023-12-07

Family

ID=86497588

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/EP2023/062263 WO2023232401A1 (fr) 2022-05-31 2023-05-09 Procédé de fonctionnement d'un dispositif de commande d'un véhicule

Country Status (2)

Country Link
DE (1) DE102022205521A1 (fr)
WO (1) WO2023232401A1 (fr)

Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20190196927A1 (en) * 2017-12-26 2019-06-27 Thales Programmable electronic computer in an avionics environment for implementing at least one critical function and associated electronic device, method and computer program

Patent Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20190196927A1 (en) * 2017-12-26 2019-06-27 Thales Programmable electronic computer in an avionics environment for implementing at least one critical function and associated electronic device, method and computer program

Non-Patent Citations (4)

* Cited by examiner, † Cited by third party
Title
"ISO 26262-8:2011 Road vehicles -- Functional safety -- Part 8: Supporting processes", 15 November 2011 (2011-11-15), pages 1 - 48, XP009501916, Retrieved from the Internet <URL:https://www.iso.org/standard/51364.html> *
AUTOSAR: "Overview of Functional Safety Measures in AUTOSAR AUTOSAR CP Release 4.3.0", AUTOSAR STANDARD RELEASES, 30 November 2016 (2016-11-30), pages 1 - 96, XP055894030, Retrieved from the Internet <URL:https://www.autosar.org/fileadmin/user_upload/standards/classic/4-3/AUTOSAR_EXP_FunctionalSafetyMeasures.pdf> [retrieved on 20220221] *
CHOI JUNCHUL HINOMK2@IRIS SNU AC KR ET AL: "Optimization of Fault-Tolerant Mixed-Criticality Multi-Core Systems with Enhanced WCRT Analysis", ACM TRANSACTIONS ON DESIGN AUTOMATION OF ELECTRONIC SYSTEMS, ACM, NEW YORK, NY, US, vol. 24, no. 1, 21 December 2018 (2018-12-21), pages 1 - 26, XP058682182, ISSN: 1084-4309, DOI: 10.1145/3275154 *
SUKUMARAN NAIR ARUN ET AL: "TaskMUSTER: a comprehensive analysis of task parameters for mixed criticality automotive systems", SADHANA, SPRINGER INDIA, NEW DELHI, vol. 47, no. 1, 31 December 2021 (2021-12-31), XP037652924, ISSN: 0256-2499, [retrieved on 20211231], DOI: 10.1007/S12046-021-01778-Y *

Also Published As

Publication number Publication date
DE102022205521A1 (de) 2023-11-30

Similar Documents

Publication Publication Date Title
DE10049441B4 (de) Verfahren zum Betrieb eines von einem Prozessor gesteuerten Systems
WO2006015945A2 (fr) Procede, systeme d&#39;exploitation et dispositif de calcul pour executer un programme informatique
WO2008040641A2 (fr) Procédé et dispositif de gestion des pannes
DE102013113296A1 (de) Redundante Rechenarchitektur
EP2207097A1 (fr) Procédé et dispositif destinés au fonctionnement d&#39;un appareil de commande
EP1810139B1 (fr) Procédé, système d&#39;exploitation et ordinateur pour l&#39;exécution d&#39;un programme informatique
EP2099667A1 (fr) Procede pour garantir ou maintenir la fonction d&#39;un systeme global complexe critique pour la securite
DE102005009813A1 (de) Elektronisches Steuerungssystem und -Verfahren mit Microcomputerüberwachungs-Unterdrückungsfunktion
DE102007056218A1 (de) Verfahren zur Behandlung von transienten Fehlern in Echtzeitsystemen, insbesondere in Steuergeräten von Kraftfahrzeugen
DE102008004206A1 (de) Anordnung und Verfahren zur Fehlererkennung und -behandlung in einem Steuergerät in einem Kraftfahrzeug
DE102011053580A1 (de) Verfahren zum betrieb einer elektrischen hilfskraftlenkung
DE102004046611A1 (de) Verfahren zur Abarbeitung eines Computerprogramms auf einem Computersystem
EP2228723B1 (fr) Procédé de gestion des erreurs d&#39;un système de calcul
WO2023232401A1 (fr) Procédé de fonctionnement d&#39;un dispositif de commande d&#39;un véhicule
DE102013202961A1 (de) Verfahren zum Überwachen eines Stackspeichers in einem Betriebssystem eines Steuergeräts eines Kraftfahrzeuges
DE102004046288A1 (de) Verfahren zur Abarbeitung eines Computerprogramms auf einem Computersystem
EP1812853A2 (fr) Procede, système d&#39;exploitation et ordinateur pour l&#39;execution d&#39;un programme informatique
WO2016206847A1 (fr) Procédé et dispositif de sécurisation d&#39;une structure de compteur de programme d&#39;un système de processeur et de surveillance du traitement d&#39;une demande d&#39;interruption
WO2007074056A2 (fr) Systemes processeur tolerants aux erreurs
EP2338111B1 (fr) Procédé et dispositif pour tester un coeur de processeur dans une unité de calcul constituée d&#39;au moins deux coeurs de processeur
DE102017212560A1 (de) Verfahren zum ausfallsicheren Durchführen einer sicherheitsgerichteten Funktion
WO2022263416A1 (fr) Système de commande pour au moins un dispositif de réception dans des applications critiques en termes de sécurité
EP1774417B1 (fr) Procede et dispositif pour surveiller le deroulement d&#39;un programme de commande dans un ordinateur
WO2017153411A1 (fr) Procédé pour faire fonctionner un appareil de commande de véhicule automobile
DE102017208872A1 (de) Elektronische Steuereinheit

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 23725693

Country of ref document: EP

Kind code of ref document: A1