Vehicle Electronic Control Unit, Vehicle System and Software
The electronic control unit addresses the challenge of abrupt failures in vehicles by transitioning to a safe state with controlled torque reduction, ensuring driver safety and controllability while reducing costs and complexity.
Patent Information
- Authority / Receiving Office
- BR · BR
- Patent Type
- Applications
- Current Assignee / Owner
- MARELLI EURO SPA
- Filing Date
- 2024-03-13
- Publication Date
- 2026-07-14
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
1 / 16 Vehicle Electronic Control Unit, Vehicle System and Software Cross-referencing related requests
[001] This patent application claims priority over Italian Patent Application No. 102023000004803, filed on March 14, 2023, the full disclosure of which is incorporated herein by reference. Technical field of the invention
[002] The present invention relates, in general, to the field of functional safety of vehicles, in particular in emergency situations, such as failures in electronic control units (ECUs) of a vehicle, for example, engine electronic control units.
[003] The present invention, in particular, refers to an electronic control unit, in particular for the vehicle engine, designed to perform one or more vehicle control functions for the operation of a vehicle system with a given level of functional safety integrity of the vehicle.
[004] The present invention finds application in any type of two- or four-wheeled road vehicle, whether used for the transport of people or goods. State of the art
[005] As is well known, safety is a major issue, especially in the automotive market. The integration of electrical and electronic systems in vehicles requires safety development processes and content, as well as the ability to provide evidence that all reasonable safety targets are met.
[006] New technologies, based on resources distributed across various electronic control units, typically developed by different vendors, increase complexity, software content and mechatronic implementation and, consequently, the risks of systematic and random hardware failures.
[007] The increasing integration of electrical and electronic equipment (including programmable devices as well as electromechanical components) into vehicle systems led to the introduction of the international standard ISO 26262, derived from the standard of Petition 870250082401, dated 12 / 09 / 2025, pp. 76 / 99 2 / 16 Functional safety standard IEC 61508 for industrial electrical / electronic systems.
[008] The ISO 26262 standard provides process and product requirements to mitigate the effects of systematic and random hardware failures. This standard covers functional safety concepts applied to the automotive sector, seeking the absence of unacceptable risks related to the malfunction of electrical / electronic and programmable systems.
[009] The ISO 26262 standard defines four Automotive Safety Integrity Levels (ASILs), specifying risks and risk reduction needs. For safety-related functions, the ASIL can assume four different values, indicated by letters, from the highest, indicated by the letter D, which represents the most critical level in terms of safety integrity, to the lowest level, indicated by the letter A, which represents the least stringent in terms of safety integrity. In addition, the ISO 26262 standard defines four Motorcycle Safety Integrity Levels (MSILs), where D indicates the highest level of integrity and A the lowest level of integrity; there is a standardized correspondence between ASIL and MSIL. The ISO 26262 standard also indicates QM (Quality Management) as the class assigned to functions that do not impose any functional safety requirements, for which development according to quality standards is sufficient. Objective and summary of the invention
[0010] To ensure driver safety while driving in the event of a dangerous failure in one or more of the vehicle's electronic control units, i.e., in the event that one or more electronic control units fail, resulting in a breach of a safety target set by the associated automotive safety integrity level, the electronic control unit is designed to execute an automatic fault detection strategy and a response strategy corresponding to the detected fault.
[0011] According to a first known solution, hereinafter also called a fail-safe solution, the electronic control unit affected by the fault is configured to suddenly interrupt the automatic control function that presents the fault; however, such a reaction may startle the driver and compromise the Petition 870250082401, dated 12 / 09 / 2025, pp. 77 / 99 3 / 16 vehicle controllability, as it may lead to a possible reduction in the user's ability to control the vehicle.
[0012] According to a second known solution, hereinafter also referred to as the fault-operating solution, the fault-affected electronic control unit is designed to execute an automatic fault detection strategy, which allows the faulty electronic control unit system to switch to a degraded operating mode in order to avoid violating safety targets. In particular, the degraded operating mode allows, in accordance with ISO 26262, ensuring safety in response to a fault without the sudden stoppage of one or more key vehicle functions (e.g., propulsion, if the fault-affected electronic control unit is the vehicle's engine electronic control unit). For example, the faulty engine electronic control unit, in the case of a fault-operating architecture, is configured to limit the target torque value and allow the driver to complete the run without the vehicle becoming uncontrollable.
[0013] The Applicant noted that the fail-safe solution does not allow for a smooth transition to a safe state, since achieving a safe state is generally abrupt and difficult for a driver to control. Furthermore, fail-safe operational solutions are generally expensive, since implementing the aforementioned functions, particularly the monitoring and operational response functions in case of failure, requires implementing several redundant systems and components, which increases the number of components involved and, consequently, the associated costs.
[0014] The objective of the present invention is to provide an electronic control unit designed to perform one or more vehicle control functions for the operation of a vehicle system with a given level of vehicle safety integrity, which allows the disadvantages of the prior art to be at least partially overcome.
[0015] According to the present invention, an electronic control unit designed to perform one or more vehicle control functions for the operation of a vehicle system with a given level of vehicle safety integrity is Petition 870250082401, dated 12 / 09 / 2025, pp. 78 / 99 4 / 16 supplied as defined in the attached claims. Brief description of the figures
[0016] Figure 1 shows a functional block diagram of an electronic control unit designed to perform vehicle control functions relating to the operation of a vehicle system with a level of vehicle safety integrity in accordance with the invention.
[0017] Figure 2 shows a block diagram of the emergency operational mode function monitoring operations implemented by an electronic control unit designed to perform one or more vehicle control functions related to the operation of a vehicle system with a given level of vehicle safety integrity according to the present invention.
[0018] Figure 3 shows a logic diagram of an emergency switch of an electronic control unit designed to perform one or more vehicle control functions relating to the operation of a vehicle system with a given level of vehicle safety integrity according to the present invention. Description of preferred configurations of the invention
[0019] The present invention will now be described in detail with reference to the accompanying figures, in order to enable a skilled person to implement and use it. Various modifications to the configurations described will be readily apparent to those skilled in the art, and the general principles described may be applied to other configurations and applications without, however, departing from the scope of protection of the present invention, as defined in the appended claims. Therefore, the present invention should not be considered limited to the configurations described and illustrated herein, but rather to have the broader scope of protection consistent with the features described and claimed herein.
[0020] Unless otherwise defined, all technical and scientific terms used herein have the same meaning commonly understood by a person skilled in the art to which the invention pertains. In case of conflict, the present description, including the definitions provided, shall prevail. Furthermore, examples are provided for illustrative purposes only and, as such, should not be construed as limiting. Petition 870250082401, dated 12 / 09 / 2025, pp. 79 / 99 5 / 16
[0021] In particular, the block diagrams included in the attached figures and described below should not be understood as a representation of structural characteristics, i.e., construction constraints, but rather as a representation of functional characteristics, i.e., intrinsic properties of the devices defined by the effects obtained, i.e., functional constraints, which can be implemented in different ways in order to protect their functionalities (operational capacity).
[0022] To facilitate understanding of the configurations described herein, reference will be made to some specific configurations and specific language will be used to describe them. The terminology used herein is used only to describe particular configurations and is not intended to limit the scope of the present invention.
[0023] As also better described below, the present invention relates to an electronic control unit configured to reduce torque from an initial value to zero, following a ramp, or to limit the target torque value to a filtered value in case of failure. In this way, the time during which the vehicle remains in the degraded operating mode (i.e., within an emergency operating period) is sufficient for the driver to place the vehicle in a state free from excessive risks, i.e., a safe state, for example, on the side of the road or in a parking lot, thus preserving the driver's controllability of the vehicle.Furthermore, the electronic control unit affected by the failure is configured to supervise operations in emergency operating mode through related monitoring functions, implemented in the same electronic control unit and developed in accordance with the safety standards required for the same monitoring functions.
[0024] The electronic control unit according to the present invention, comprising functions implemented in emergency operation mode and its monitoring, is developed, as a whole, in accordance with the functional safety standards required by the application, thus ensuring compliance with safety targets; in particular, the functions that implement fault detection and emergency mode monitoring in case of faults are developed in accordance with the required level of functional safety integrity. The implementation of the emergency operation mode in accordance with a quality or safety standard lower than that of its Petition 870250082401, dated 12 / 09 / 2025, pages 80 / 99 The 6 / 16 monitoring functions ensure lower implementation costs without compromising compliance with functional safety requirements, since the implementation of the emergency mode is periodically monitored by functions developed according to appropriate safety standards.
[0025] If the emergency functions are not performed correctly or within a predefined time interval, the electronic control unit is designed to perform fail-safe, i.e., error-proof, reaction functions to ensure safety within a tolerance time interval for operation in emergency operating mode, which is defined as the specified time period during which operation in emergency operating mode can be maintained without an excessive level of risk, in particular in accordance with ISO 26262. In particular, when implementing fail-safe reaction functions, the electronic control unit is configured to determine and execute an independent shutdown path to achieve the safe state (e.g., motor shutdown) only when operation in emergency operating mode fails.
[0026] To verify that operation in emergency operating mode was successful, the electronic control unit is configured to receive and process one or more feedback signals to implement monitoring functions of operation in emergency operating mode and, therefore, any fail-safe reaction functions, to assess whether, for example, the vehicle is reducing speed in the event of failure of the engine's electronic control unit. In this way, the electronic control unit is configured to extend the time interval of operation in emergency operating mode, as it is performing operations to achieve a safer and more controllable operating state, in which there is no violation of the predefined safety target.
[0027] The electronic control unit is also configured to implement an alert strategy to warn the driver about reduced functionality due to the emergency operating mode and to prevent the driver from losing control of the vehicle. In particular, the electronic control unit is configured to generate notifications, such as tactile, audible and / or visual notifications, and transmit them so that they can be made available on a network, such as a Controller Area Network (CAN), so that Petition 870250082401, dated 12 / 09 / 2025, pp. 81 / 99 7 / 16 may be received by other electronic control units, for example, to ensure that they adapt their control laws to the vehicle's new situation.
[0028] Figure 1 shows an electronic control unit 1 designed to perform one or more vehicle control functions for the operation of a vehicle system (not shown) with a given level of vehicle safety integrity. Hereafter, and without any loss of generality, the electronic control unit 1 is an electronic control unit for a vehicle's engine.
[0029] In particular, a vehicle control function of the electronic control unit 1 is configured to cause the vehicle system to operate in a nominal operating mode, in which the vehicle system is forced to operate at nominal performance. Note that, hereinafter, the term nominal indicates values, targets or modes requested by a user after a specific action, detected by the sensor system 2 (for example, the equivalent torque value requested by the user, for example, during acceleration, taking into account torque losses and the presence of any additional loads), in non-problematic situations, i.e., in which there is no fault.
[0030] The electronic control unit of vehicle 1 is configured to: - Monitor the execution of vehicle control functions to detect failures in the execution of vehicle control functions that result in a violation of a safety target established by the vehicle's safety integrity level; - If a fault is detected in the execution of a vehicle control function, trigger an emergency response to the detected fault, which involves executing an emergency function to cause the vehicle system to operate in an emergency operating mode, aimed at preventing a violation of the safety target established by the vehicle's safety integrity level and in which the vehicle system is forced to operate with degraded performance; - Monitor the vehicle's system operation in emergency operating mode to determine whether the emergency function is achieving its objective or not; and - If the emergency function fails to achieve its objective, trigger a safety reaction (also called a failsafe reaction), which involves executing a safety function designed to bring the vehicle system to a safe state. Petition 870250082401, dated 12 / 09 / 2025, pp. 82 / 99 8 / 16
[0031] In particular, as foreseen above, the emergency function and related monitoring functions are developed in accordance with the functional safety standards required by the application, thus ensuring compliance with the corresponding safety targets; in particular, the functions that implement fault detection and emergency mode monitoring in case of faults are developed in accordance with the level of functional safety integrity required by the application. Furthermore, the implementation of the emergency operating mode occurs in accordance with a quality or safety standard lower than that of its monitoring functions; in addition, the functions that implement the emergency mode are periodically monitored by functions developed in accordance with the appropriate safety standards.
[0032] Therefore, the emergency function is designed in accordance with quality standards, in particular in accordance with the QM quality level (specifically, ISO 26262-3:2018, in particular as specified in Provision 6.4.3.10, Note 2 of the text of the same ISO, https: / / www.iso.Org / obp / ui / #iso:std:iso:26262:-3:ed-2:vl:en), or in accordance with a safety standard with a certain level of vehicle safety integrity lower than that of the emergency function monitoring functions, and the operation of the vehicle system in emergency operating mode is monitored by the implementation of one or more fault detection functions developed in accordance with a level of vehicle safety integrity higher than that of the emergency function and predetermined based on the highest risk of failure associated with the vehicle's electronic control unit 1.
[0033] The electronic control unit of vehicle 1 also comprises: - a main controller 5 designed to communicate with a vehicle sensor system 2 and with a vehicle communication network 3 to receive input data indicative of the vehicle system operation and calculate, based on the input data, and generate, as output, a nominal target for the vehicle system, so that it operates in the nominal operating mode; - a fault detector 6 designed to communicate with a vehicle sensor system 2 and with a vehicle communication network 3 to receive input data indicative of the vehicle system operation and detect, based on the input data, Petition 870250082401, dated 12 / 09 / 2025, pp. 83 / 99 9 / 16 and generate, as well as issue, an emergency switching command in the presence of a failure in the execution of a vehicle control function; - an emergency controller 7 designed to communicate with the fault detector 6 to receive notifications about the existence of faults in the execution of the vehicle's control function, which result in the violation of a safety target established by the vehicle's safety integrity level, and to calculate, as well as issue, an emergency target for the vehicle system, so that it operates in emergency operating mode; and - an emergency switch 8 designed to communicate with the main controller 5 to receive the nominal target from the latter, with the emergency controller 7 to receive the emergency target from the latter, and with the fault detector 6 to receive the emergency switching command from the latter and provide the vehicle system with the nominal target in the absence of the emergency switching command and the emergency target in the presence of the emergency switching command.
[0034] Electronic control unit 1 further comprises: - an input driver 9 designed to communicate with the vehicle's sensor system 2 to receive input data indicative of the vehicle's system operation; - a vehicle communication network receiver driver 10 designed to communicate with vehicle communication network 3 to receive input notifications indicative of vehicle operation; - an output driver 11 designed to communicate with one or more actuators 4 to issue commands relating to the nominal target or the emergency target to the vehicle system, so that it operates in nominal operating mode or emergency operating mode; and - a vehicle communication network transmitter driver 12 designed to communicate with the vehicle communication network 16 to transmit output notifications relating to the operation of the vehicle system.
[0035] It is observed that the input driver 9, the fault detector 6 and the emergency controller 7 are designed to implement monitoring functions, developed according to pre-determined safety standards. On the other hand, the Petition 870250082401, dated 12 / 09 / 2025, pp. 84 / 99 10 / 16 vehicle communication network receiver driver 10, output driver 11, vehicle communication network transmitter driver 12, controller 5 and emergency switch 8 are designed to implement nominal and emergency functions and, in general, functions developed according to a lower integrity level than monitoring functions.
[0036] Therefore, in view of the above, the electronic control unit 1, in particular the controller 5, is configured to receive and process data and / or information from components external to it, for example, from the sensor system 2 and the vehicle communication network 3, in order to control the operation of one or more actuators 4 and provide information to the vehicle communication network 16.
[0037] The fault detector 6 is therefore designed to implement nominal function monitoring, in particular by implementing one or more of the following monitoring strategies: - integrity checks of the input data (i.e., both in a wired connection, for example, connecting the vehicle parts to which the electronic control unit 1 is connected, for example, the sensor system 2, and in the connection with the vehicle's communication network 3) received by the electronic control unit 1; - detection of a violation of one or more predefined security targets for electronic control unit 1; - a request to activate a secure state; and - Integrity checks of critical safety functions of the electronic control unit 1.
[0038] As mentioned above, when fault detector 6 detects a fault in the execution of the vehicle's control functions, the same fault detector 6 is designed to generate an emergency alert to the emergency controller 7; consequently, the emergency controller 7 is designed to transmit the emergency target to the emergency switch 8, and fault detector 6 is designed to control the emergency switch 8 to provide emergency commands to allow the vehicle system to operate in emergency operating mode, specifically to control one or more actuators 4. By way of example, commands of Petition 870250082401, dated 12 / 09 / 2025, pages 85 / 99 11 / 16 emergency related emergency values are values that can be assumed by quantities implemented by the actuators 4 that decrease over time, according to some configurations of the invention, even reaching zero, from nominal values assumed by the quantities implemented by the actuators 4.
[0039] In addition, the fault detector 6 is designed to monitor the operation of the vehicle system in emergency operating mode to determine whether the emergency function is hitting its target or not, or to monitor whether the execution of emergency functions has occurred by reading feedback data and / or notifications 17 entered into the electronic control unit 1.
[0040] Some modes of operation of the present electronic control unit 1 are now described, in particular with reference to Figure 2.
[0041] Under nominal conditions, the controller 5 is designed to calculate a nominal value of quantities, for example, torque, to be issued as nominal commands to allow the vehicle system to operate in a nominal operating mode, in particular to control one or more actuators 4, taking into account various vehicle conditions and parameters (e.g., driver requests, torque requests from external systems, friction braking torque and the like). The fault detector 6 is therefore designed to monitor the vehicle's control functions, in particular by reading data and notifications sent to the electronic control unit 1 to detect faults in the execution of the vehicle's control functions.In the absence of faults, the fault detector 6 is designed to adjust the emergency switch 8 to the nominal target and thus allow the vehicle system to operate in nominal operating mode, i.e., to transmit nominal commands associated with nominal values assumed by the quantities implemented by the actuators 4.
[0042] In the event of a request to perform emergency functions, i.e., in the event of a failure, the fault detector 6 is designed to adjust the emergency switch 8 to the emergency target and signal the presence of a fault to the emergency controller 7, thus initiating an emergency response to the fault; considering the vehicle's conditions and parameters, in particular knowing the last valid value of the nominal target before fault detection, the emergency controller 7 is designed to Petition 870250082401, dated 12 / 09 / 2025, pp. 86 / 99 12 / 16 calculate an emergency target for the quantities implemented by the actuators 4 and transmit it to the emergency switch 8 so that the electronic control unit 1 issues the emergency commands, causing the vehicle system to operate in emergency operating mode. In particular, the emergency controller 7 is designed to determine, as emergency values, alternatively: - a target value that decreases over time after ramping down to zero; and - a target value for operational quantities, for example, torque, limited to a filtered value.
[0043] In both cases, according to the present invention, special attention is given to the definition of the target to avoid abrupt discontinuities in the target delivered to the control chain, which includes the emergency switch 8, the output driver 11 and the actuators 4.
[0044] As the fault detector 6 commands the emergency switch 8 to switch to the emergency value, the nominal value provided by the controller 5 is not selected and therefore the output driver 11 receives the indicative data of the first emergency value for the operating quantities, so that it can transmit them to one or more actuators 4.
[0045] Once emergency functions are requested to be executed, fault detector 6 is designed to monitor the vehicle system operation in emergency operating mode to determine whether the emergency function is achieving its target or not, or to monitor whether the execution of emergency functions has occurred by reading feedback data and / or notifications 17 entered into the electronic control unit 1. In this case, fault detector 6 is designed to verify, alternatively, that: - the indicative values of the vehicle's system operation, for example, speed, a decrease over time that can be associated with a specific known characteristic, depending on the vehicle's conditions; and - The parameters indicative of the vehicle's system operation, for example, engine speed, are below a limit that can be associated with the vehicle's condition.
[0046] If fault detector 6 detects that there is an undesirable evolution of Petition 870250082401, dated 12 / 09 / 2025, pp. 87 / 99 13 / 16 Vehicle system operation, the same fault detector 6 is designed to trigger a safety reaction involving the execution of a safety function intended to bring the vehicle system to a safe state, i.e., to request a safety reaction to implement an independent shutdown path to bring the vehicle to a safe state. If the emergency operation is requested while the vehicle is descending, monitoring the emergency operation may not be reliable depending on the type of feedback used: therefore, the safety reaction is requested in all cases; in fact, loss of propulsion on descent is acceptable as long as the vehicle does not stop suddenly, provided that a non-zero traction value remains and provided that the general safety conditions of the vehicle, such as braking capability, are guaranteed.
[0047] It should be noted that the role played by fault detector 6 is of particular importance, since the integrity level of the control chain for emergency operation mode is lower than the integrity level of fault detector 6.
[0048] With reference to Figure 3 and as partially anticipated in the preceding paragraphs, the emergency switch 8 is designed, by default, to output magnitude values to control one or more actuators 4 according to commands received from the fault detector 6.
[0049] Emergency switch 8 comprises: - a first and a second input switch 13, 14 designed to receive the nominal target from the main controller 5, the emergency target from the emergency controller 7 and the emergency switching command from the fault detector 6 to generate respective first and second outputs A, B, indicating, alternately, the nominal target in the absence of the emergency switching command and the emergency target in the presence of the emergency switching command; and - an output switch 15 designed to receive the first and second outputs A, B from the first and second input switches 13, 14 and to provide the vehicle system with the nominal target in the absence of the emergency switching command and the emergency target in the presence of the emergency switching command.
[0050] How can emergency switch 8 be affected by dependent faults? Petition 870250082401, dated 12 / 09 / 2025, pages 88 / 99 14 / 16 of the control functions, according to one aspect of the present invention, the electronic control unit 1 is configured to check the integrity of the emergency switch 8 to ensure its correct operation; therefore, the electronic control unit 1 is configured to periodically test the emergency switch 8 to assess its integrity and correct operation.
[0051] In particular, the electronic control unit 1 is designed to perform a safety function to control switches 13, 14 and 15 and to determine, through periodic verification, whether one of them fails to switch correctly as expected. The above periodic test can be performed under suitable vehicle conditions and repeated periodically, as output C is indicative of the nominal values in the absence of a fault. In detail, outputs A, B and C are indicative of the presence of possible faults, i.e., they indicate the presence of a malfunction of the emergency switch 8, in one or more of switches 13, 14 and 15, and allow the electronic control unit 1 to detect which of switches 13, 14 and 15 is faulty and trigger the activation of the remaining switches 13, 14 and 15 or, alternatively, request a safety reaction or an alarm strategy.If any of the switches 13, 14, or 15 are defective or malfunctioning, the test duration is short enough to minimize any disruptive effect. Furthermore, if emergency switch 8 is not affected by any fault, there will be no disruption.
[0052] By way of example, in the absence of a fault and under periodic test conditions, the electronic control unit 1 is configured to provide, alternatively, as an emergency target, nominal values (i.e., nominal value NT) or emergency values (i.e., emergency value ET) for each of the input switches 13, 14 and for the output switch 15, so that the latter generates an output C indicative of the nominal values, or assumes the same value assumed by the output of outputs A and B, which assumed the nominal value NT. In the absence of a fault, outputs A and B will alternatively assume nominal values NT or emergency values ET, consistent with the emergency switching commands received, and output C will assume the nominal value NT. In this way, there will be no disturbance if there is no fault. For example, if output A assumes the nominal value NT and output B assumes the value ET, output C will assume the same Petition 870250082401, dated 12 / 09 / 2025, pp. 89 / 99 15 / 16 value that output A, that is, the nominal value NT.
[0053] Otherwise, in case of failure, at least one of the values assumed by outputs A, B, and C will be inconsistent with the emergency switching commands received, making it possible to identify the faulty switch and perform a targeted action. For example, in case of failure of the second input switch 14, this generates a second output B whose value is the opposite of what is expected (for example, instead of assuming an emergency value ET, it assumes a nominal value NT); on the other hand, the first output A assumes a value consistent with the emergency switching commands received (for example, it assumes a nominal value NT) and output C assumes a value consistent with the emergency switching commands received (for example, it assumes a nominal value NT).This situation also occurs in the event of a failure of the first input switch 13 (i.e., the first output A assumes a value different from that provided by the emergency switching commands) and in the event of a failure of the output switch 15 (i.e., output C assumes a value different from that provided by the emergency switching commands).
[0054] In view of the foregoing, the advantages of the present invention are evident.
[0055] In particular, as is also evident from the description above, the present solution allows the implementation of an emergency operation strategy with numerous advantages, including low implementation costs; in fact, when a failure occurs, emergency operation is requested and can be maintained to achieve a state free from excessive risk levels, without a sudden and intense security intervention, as occurs, for example, in the known solutions mentioned above.
[0056] Furthermore, with the aim of preventing the sudden stoppage of a key vehicle function, such as propulsion, the present solution allows safety goals to be considered, particularly with regard to the vehicle's engine, such as preventing unwanted accelerations and preventing sudden loss of propulsion, implementing strategies to achieve a gradual transition to a safe state, which therefore does not result in a sudden loss of propulsion.
[0057] Furthermore, the present solution is economical, as it has a highly testable architecture, based on security elements with lower integrity in Petition 870250082401, dated 12 / 09 / 2025, pages 90 / 99 16 / 16 comparison to that of its monitoring elements. There is no need to include hardware redundancies in the same architecture, and low-impact software changes are required. Furthermore, the present solution ensures greater controllability, as it allows a gradual transition to the safe state to improve vehicle controllability compared to that described with reference to known solutions; by way of example, the present solution allows efficient handling of a vehicle, such as a motorcycle, while propulsion is gradually reduced until the vehicle stops to prevent unintentional acceleration resulting from a failure. Petition 870250082401, dated 12 / 09 / 2025, pp. 91 / 99
Claims
1 / 4 Claims 1. Vehicle electronic control unit (1), designed to perform one or more vehicle control functions for the operation of a vehicle system with a given vehicle safety integrity level, characterized by: - a vehicle control function is configured to cause the vehicle system to operate in a nominal operating mode, wherein the vehicle system is forced to operate with nominal performance; the vehicle electronic control unit (1) is further configured to: - monitor the execution of vehicle control functions to detect failures in the execution of vehicle control functions that result in the violation of a safety target established by the vehicle safety integrity level;- If a failure in the execution of a vehicle control function is detected, trigger an emergency response to the detected failure, which involves executing an emergency function to cause the vehicle system to operate in an emergency operational mode, aimed at preventing a violation of the safety target established by the vehicle's safety integrity level and in which the vehicle system is forced to operate with degraded performance; - Monitor the operation of the vehicle system in emergency operational mode to determine whether the emergency function is achieving its target or not; and - If the emergency function does not achieve its target, trigger a safety response, which involves executing a safety function whose objective is to cause the vehicle system to reach a safe state.
2. Vehicle electronic control unit (1), according to claim 1, characterized in that the emergency function is designed in accordance with quality standards or in accordance with a safety standard with a certain level of vehicle safety integrity lower than that of the emergency function monitoring functions, and the operation of the vehicle system in emergency operation mode is monitored by the implementation of one or more fault detection functions developed in accordance with a level of vehicle safety integrity higher than that of the emergency function and predetermined based on the highest risk of failure associated with the vehicle electronic control unit (1).
3. Electronic control unit (1), according to claim 1 or 2, characterized by comprising: - a main controller (5) designed to communicate with a vehicle sensor system (2) and with a vehicle communication network (3) to receive input data indicative of the operation of the vehicle system and to calculate, based on the input data, and issue a nominal target for the vehicle system, so that it operates in the nominal operating mode; - a fault detector (6) designed to communicate with a vehicle sensor system (2) and with a vehicle communication network (3) to receive, from these, input data indicative of the operation of the vehicle system and to detect, based on the input data, generate and issue an emergency switching command in the presence of a fault in the execution of a vehicle control function;- an emergency controller (7) designed to communicate with the fault detector (6) to receive notifications about the existence of faults in the execution of the vehicle's control function, which result in the violation of a safety target established by the vehicle's safety integrity level, and to calculate and issue an emergency target for the vehicle system, so that it operates in emergency operation mode; and - an emergency switch (8) designed to communicate with the main controller (5) to receive the nominal target from it, with the emergency controller (7) to receive the emergency target from it, and with the fault detector (6) to receive the emergency switching command from it, and to provide the vehicle system with the nominal target in the absence of the emergency switching command and the emergency target in the presence of the emergency switching command.
4. Electronic control unit (1), according to claim 3, characterized in that the emergency switch (8) comprises: - a first and a second input switch (13, 14) designed to receive the nominal target of the main controller (5), the emergency target of the emergency controller (7) and the emergency switching command of the fault detector (6) to generate respective first and second outputs (A, B) indicating, alternatively, the nominal target in the absence of the emergency switching command and the emergency target in the presence of the emergency switching command; and - an output switch (15) designed to receive the first and second outputs (A, B) from the first and second input switches (13,14) and provide the vehicle system with the nominal target in the absence of the emergency switching command and the emergency target in the presence of the emergency switching command.
5. Electronic control unit (1), according to claim 3 or 4, further characterized by comprising: - an input driver (9) designed to communicate with the vehicle's sensor system (2) to receive input data indicative of the vehicle system's operation; - a vehicle communication network receiver driver (10) designed to communicate with the vehicle communication network (3) to receive input notifications indicative of the vehicle's operation; - an output driver (11) designed to communicate with one or more actuators (4) to issue commands relating to the nominal target or the emergency target of the vehicle system, so that it operates in nominal operating mode or in emergency operating mode; and - a vehicle communication network transmitter driver (12) designed to communicate with the vehicle communication network (16) to transmit output notifications relating to the vehicle system's operation.
6. Vehicle system comprising an electronic control unit (1) characterized in that it is designed to perform one or more vehicle control functions relating to the operation of a vehicle system with a given level of vehicle safety integrity, in accordance with any of the preceding claims.
7. Software, which can be loaded and executed by an electronic control unit (1) according to any one of claims 1 to 5, the software is characterized in that it is designed so that, when executed, the electronic control unit (1) is designed to perform one or more vehicle control functions of operating a vehicle system with a given level of vehicle safety integrity, as claimed in any one of claims 1 to 5.