Apparatus, system, and method for avoiding failure propagation in a safety system
By introducing an isolation component between the control unit and the safety component, the problem of fault propagation in the safety component is solved, ensuring that the system operates normally under fault conditions and meets high safety level requirements.
Patent Information
- Application Number
- CN202011381891.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-12-18
- Filing Date
- 2020-12-01
- Publication Date
- 2026-02-06
- Estimated Expiration
- 2040-12-01
AI Technical Summary
Existing technologies have failed to effectively address the propagation of faults and the factors that induce faults in safety components, resulting in safety systems that cannot meet high safety level requirements.
By introducing isolation components, including current isolation and voltage isolation, between the control unit and the safety components, fault signals are prevented from propagating between the safety components, and the isolation components are used to form a voltage divider circuit to reduce the impact of faults.
It effectively prevents the propagation of faults between safety components, ensures that the system can still operate normally under fault conditions, meets high safety level requirements, and reduces the impact on safety functions and mechanisms.
Smart Images

Figure CN112987680B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The technology described herein generally relates to devices, systems, and methods for avoiding propagation of faults in safety systems. More specifically, the technology described herein generally relates to automotive and other functional safety standards and devices and systems to comply with such standards. Even more specifically, the technology described herein relates to avoiding propagation of fault conditions between two or more safety functions and / or safety mechanisms used in motor vehicles, other vehicles, and the like. The technology described herein also generally relates to devices, systems, and methods for avoiding propagation of faults that occur with respect to induced fault initiators in safety systems. BACKGROUND
[0002] Automotive systems today are required to comply with various functional safety standards. Such standards include the International Organization for Standardization (ISO) ISO 26262-1:2018 standard and its earlier versions. Similarly, other standards apply to other forms of vehicles, including the SIL standards for aircraft. Various embodiments of this specification relate to automotive standards, but can also apply to other standards.
[0003] The ISO 26262 standard (herein, referred to as the “standard”) generally applies to electrical / electronic / programmable electronic (“E / E / PE”) components (herein, such E / E / PE components are referred to individually and collectively as “vehicle systems” or “modules”) in generally available passenger vehicles. The standard addresses possible dangers that can arise from vehicle system faults and interactions between two or more of such vehicle systems.
[0004] As is known, the standard is a risk-based safety standard. The standard provides for safety of the vehicle, its passengers, and others such as pedestrians by relying on automatic protection that operates correctly in response to error or fault conditions (herein, referred to as “faults”) in / with vehicle systems and whether such faults can lead to dangerous events and / or are otherwise addressed if the faults are uncontrollable. Examples of dangerous events include, but are not limited to, motor vehicle accidents (herein, referred to as “hazards”). To address, prevent, and minimize the risks created by faults and hazards as much as possible, vehicle systems are evaluated and assigned one or more safety goals (such evaluation and assignment of safety goals is identified herein as “hazard analysis”).
[0005] As Figure 1 shown, hazard analysis includes classifying potential faults according to the probability of injury that can result if the fault occurs, and classifying potential faults according to controllability of the fault if it occurs. As shown, one or more “measures” can reduce the ratio of unacceptable injury to acceptable injury.
[0006] As shown in Table 1 below, the probability of injury can occur in a range from low to high probability, and is also often denoted as“exposure” (as shown in the“Exposure E” column provided in the included table). The severity of injury can occur in a range from low to high severity, with higher severity injuries being potentially life threatening (as shown in the“Severity S” column provided in the included table). The controllability of injury can occur in a range from high C1 to low C3 controllability (as shown in the“Controllability C” column provided in the included table). A high controllability rating C1 generally indicates that a response to such a failure is“controllable” when the given failure occurs. In contrast, a low controllability rating C3 indicates that recovery from the failure is uncontrollable if it occurs. Or, simply put, a C3 failure can result in significant injury to the car’s driver or other people, including potentially fatal. Figure 1 Figure 1 Figure 1
[0007] Table 1
[0008]
[0009] In short, hazard analysis involves the creation of safety goals and safety measures, both of which are designed to reduce hazards to an acceptable risk level. Safety measures are implemented by“safety components” that include one or more“safety functions” that are monitored by one or more“safety mechanisms.” A safety mechanism is essentially one or more verification and / or confirmation measures that are provided to ensure that a given safety goal is achieved by a given safety function(s). Each safety function provides a predetermined response that is executed when a fault is detected in the vehicle system. When a fault is detected in one or more safety functions, the safety mechanism typically results in the vehicle being configured into a“safe state” (also referred to as a“fail-safe” state) and / or a functional state that is performed at a different operational level (often referred to as a“fail-function” state). For example, a“fail-safe” state can result in the vehicle becoming inoperable, and often requiring a tow service. A“fail-function” state can result in the vehicle being operable despite being at a reduced functionality, such as prohibiting the vehicle speed from exceeding a certain speed (until the fault is resolved), disabling components (such as airbag deployment mechanisms being powered off), or other cases.
[0010] To further define such safety goals, safety functions, and the safety mechanisms required for any given single point failure, one or more Automotive Safety Integrity Levels (each being an“ASIL”) can be assigned to one or more of the various vehicle systems. As Figure 1 As shown, the ASIL classification provides a range of safety targets from ASIL A to ASIL D (where A is the least stringent and D is the most stringent). More specifically, each of these ASIL safety targets specifies a single point failure metric (SPFM) - the percentage (%) of failures that are covered by safety mechanisms or do not impact the safety target, as follows: ASIL B = 90%, ASIL C = 97%, and ASIL D = 99%. No percentage is specified for ASIL. As Figure 1 As shown in the table provided, ASIL D failures occur with respect to those failures that have the highest severity rating, the highest exposure rating, and are uncontrollable (i.e., they have a C3 controllability rating - indicating that the driver lacks controllability if a failure occurs).
[0011] More specifically, an ASIL D hazard event is an event that has a reasonable probability of causing life-threatening harm, where the harm is physically possible in most operating conditions, and the driver has little, if any, opportunity to prevent the harm with respect to the event. An example of an ASIL D event is an uncontrolled / random airbag deployment while driving a vehicle and the vehicle is not in an accident. Uncontrolled airbag deployment while the vehicle is moving can cause severe physical harm, if not death, to one or more occupants of the vehicle or other occupants.
[0012] To address ASIL risks, the standard provides that a given safety target can be met by “decomposing” (or dispersing) the risk into subordinate vehicle systems, each of which has a lower ASIL rating. The corresponding safety function can be implemented by providing failover to redundant functions, using two independent functions to determine the same parameter (e.g., using a speed sensor and a drive shaft RPM sensor to determine the current speed characteristic of the vehicle), or other ways.
[0013] That is, the safety target can be met by decomposing the safety function (and its safety mechanism monitoring) into one or more safety requirements that are assigned to multiple vehicle systems, each of which has a low risk rating, thereby avoiding the single point failure risk.
[0014] For example, as Figure 2 shown, an ASIL D event can be “decomposed” into subordinate vehicle systems that operate below the critical level, including operating at a quality management (QM) level - a level that does not require safety measures because the risk of the hazard event is not unreasonable. QM standards are defined in ISO 26262-03:2018, Annex 2 and Section 5.4.5.1. Figure 2An example of ASIL decomposition is provided. The bold "D" indicates that each slave vehicle system has a lower ASIL level, such as an ASIL C rated component combined with an ASIL A rated component, or two ASIL B rated components (such as redundant ASIL B components), or an ASIL D rated component combined with a QM rated component, before decomposition into an excellent ASIL level, such as ASIL D, capable of being satisfied by two or more slave vehicle systems.
[0015] In Figure 3 , an exemplary representation of a relationship that can be provided between a vehicle system, such as airbag system 300, a safety function 302, and a safety mechanism 304 is shown. As shown, safety function 302 can include one or more circuits, such as accelerometer 306, gain stage 308, and analog-to-digital (A / D) converter 310. Safety mechanism 304 can monitor the proper operation of one or more of such circuits. It should be appreciated that accelerometer 306 can be used to determine whether an airbag should be deployed (as evidenced by a sudden, severe deceleration of the vehicle), and safety mechanism 304 can be used to verify that accelerometer 306 is operating properly and that the safety function of, for example, operating the airbag system correctly without an unintended deployment is ensured. If any of these circuits fails, as indicated, for example, due to a "fault" on the accelerometer 306 itself or the connection between accelerometer 306 and gain stage 308, the given safety requirements can be violated (as shown by the dashed line). For ASIL D requirements, 99% of such faults must be detected and resolved by appropriate corrective action (such a corrective action is a "response") in order for the vehicle system to be compliant with the standard. It should be appreciated that the response can vary based on the fault detected and other factors.
[0016] It should also be appreciated that a vehicle system, such as a hardware module provided by an integrated circuit ("IC"), can also typically be affected based on the ASIL level associated with the components used to provide that IC, such as the die and the "package" used with such die. The ASIL level of an IC can thus depend on the SPFM associated with each of the die and the package (or other individually identifiable components). Such SPFM can be mathematically represented in accordance with Equations 1 and 2 below, where λ is the probability of a time fault ("FIT"), expressed as one fault in ten (10) billion hours of vehicle system use, "SPF" is a single point failure, and "SR" is a safety related circuit. SPF is a value representing the probability of the number of faults that violate the safety requirements and are still undetected in ten (10) billion hours. λ SRis a value that represents the probability of a single fault in a safety-related component of an electronic system within ten (10) billion hours. It should be understood that not all faults in a safety-related circuit will result in a violation of a safety requirement. Moreover, some implementations generally expect to be consistent with Equations 1 and 2 for both dies and packages.
[0017] Equation 1
[0018]
[0019] Equation 2
[0020]
[0021] It should also be understood that a package (or other component) can fail based on a failure of a single element thereof, such as a single bond wire (BW) provided with and / or used by the package. Such single point failures can inhibit compliance with one or more AISL ratings. For example, when a package is provided with sixteen (16) BWs, a failure of a single BW can result in a violation of requirements for both ASIL C and ASIL D. As shown, ASIL decomposition can thus require the use of ASIL B redundant ICs or other combinations of components; such combinations can be cost and complexity prohibitive. Figure 2
[0022] Moreover, system designers often seek to avoid induced faults. Induced faults are essentially faults that appear with respect to one vehicle system that can be common to another vehicle system. Induced faults can be identified as common cause faults, cascading faults, and the like. To address induced faults and meet ASIL requirements, system designers often seek to avoid the causative factors of such induced faults, induced fault initiators (DFIs).
[0023] However, DFIs are not limited to vehicle systems and can exist in the safety components themselves. That is, a single point failure of a signal provided to each of a safety function and a safety mechanism can result in a DFI that renders one or more of the safety function and the safety mechanism ineffective or otherwise causes an undesirable response in one or more of the safety function and the safety mechanism. For example, a propagating fault in a control input signal, such as a clock, reset, power, reference voltage, bias current, or other, provided to each of a safety function and a safety mechanism can result in a DFI in one or more safety components for one or more vehicle systems (according to Figure 3 However, currently available devices, systems, and methods still do not address the problem of avoiding such propagating DFIs in safety components. Accordingly, various embodiments of the present disclosure need and provide devices, systems, and methods that avoid fault propagation and propagating DFIs in safety components. SUMMARY
[0024] Various embodiments of the present disclosure describe apparatuses, systems, and methods for avoiding fault propagation and induced fault initiation in safety systems.
[0025] According to at least one embodiment of the present disclosure, a system for avoiding fault propagation to a safety component can include a control unit outputting an input signal; a first component electrically coupled to receive the input signal from the control unit; a safety component electrically coupled to receive the input signal from the control unit; and a first isolation component electrically disposed between and coupling the control unit and the first component. For at least one embodiment, each of the first component and the safety component can be electrically coupled to the control unit at least through a common lead. For at least one embodiment, the first isolation component can be configured to prevent a first IC fault generated with respect to the first component from propagating to the safety component via the input signal.
[0026] For at least one embodiment, a system for avoiding fault propagation to a safety component can include using a first component configured to provide a first safety function and a safety component configured to provide a first safety mechanism.
[0027] For at least one embodiment, a system for avoiding fault propagation to a safety component can include using a first component configured to provide a first safety function and a safety component configured to provide a second safety function.
[0028] For at least one embodiment, a system for avoiding fault propagation to a safety component can include using a first component configured to provide a first safety mechanism and a safety component configured to provide a second safety mechanism.
[0029] For at least one embodiment, a system for avoiding fault propagation to a safety component can include using a first isolation component that includes a galvanic isolation component.
[0030] For at least one embodiment, a system for avoiding fault propagation to a safety component can include using a first isolation component that includes a voltage isolation component.
[0031] For at least one embodiment, a system for avoiding propagation of a fault to a safety component can include using a second isolation component electrically disposed between the control unit and the safety component and also coupling the control unit with the safety component. For at least one embodiment, the second isolation component can be configured to prevent a second IC fault generated with respect to the safety component from propagating to the first component via the input signal. As described below and used herein, a“first IC fault” is used to identify a fault generated with respect to the first IC or first non-safety component and a“second IC fault” is used to identify a fault generated with respect to the second IC or second non-safety component.
[0032] For at least one embodiment, a system for avoiding propagation of a fault to a safety component can include using a first isolation component and a second isolation component configured as galvanic isolation components having substantially the same impedance.
[0033] For at least one embodiment, a system for avoiding propagation of a fault to a safety component can be configured to operate such that a first IC fault results in a non-substantial change to the input signal provided to the safety component and a second IC fault results in a non-substantial change to the input signal provided to the first component.
[0034] For at least one embodiment, a system for avoiding propagation of a fault to a safety component can be configured to operate such that when at least one of the first IC fault and the second IC fault includes a short circuit fault, during the short circuit fault, a voltage potential of the input signal provided to the non-faulty safety component is between seventy-five percent (75%) and one hundred percent (100%) of an output voltage potential of the input signal generated by the control unit during a non-faulty operating state.
[0035] For at least one embodiment, a system for avoiding propagation of a fault between two or more safety components can be configured to operate when one of the first IC fault and the second IC fault includes an open circuit fault. In this case, the fault can propagate when, under fault-free conditions, an input impedance of the currently faulting first IC is used at least in part to convert a current of the input signal provided to the second non-faulty IC to a required input voltage of the second IC. Thus, according to at least one embodiment of the present disclosure, a voltage potential of the input signal provided to the non-faulty safety component is between twenty-five percent (25%) and one hundred percent (100%) of an output voltage potential of the input signal generated by the control unit during a non-faulty operating state.
[0036] For at least one embodiment, the system for avoiding propagation of a fault between two or more safety components can be configured for use with a motor vehicle safety system, a vehicle airbag system, a self-driving vehicle system, a vehicle lane-keeping assist system, and a vehicle automated braking system.
[0037] For at least one embodiment, the system for avoiding propagation of a fault to a safety component can be configured to prevent a second IC fault generated with respect to a second safety component from propagating to a first safety component via an input signal, such that the vehicle system is facilitated to continue operating in a fault-function operating mode.
[0038] For at least one embodiment, the system for avoiding propagation of a fault to a safety component can be configured for use in a vehicle system that is at least one of a motor vehicle system, a vehicle airbag system, a self-driving vehicle system, a vehicle lane-keeping assist system, and a vehicle automated braking system.
[0039] For at least one embodiment, the system for avoiding propagation of a fault between two or more safety components can be configured for use in an aircraft system.
[0040] According to at least one embodiment of the present disclosure, a package for avoiding propagation of a fault in a safety system can include a receptacle configured to receive a die pin. The die can include a control unit integrated circuit. The package can further include a first output pin and a second output pin, the first output pin first electrically coupling the die pin to a first safety component via the receptacle, and the second output pin second electrically coupling the die pin to a second safety component via the receptacle. For at least one embodiment, each of the first safety component and the second safety component can be configured to receive a control signal from the control unit via the die pin and the first output pin and the second output pin, respectively.
[0041] According to at least one embodiment of the present disclosure, the package for avoiding propagation of a fault in a safety system can further include an isolation member configured to electrically isolate the first output pin from the second output pin. The isolation member can be configured to prevent a fault generated with respect to one of the first safety component and the second safety component from propagating to the other safety component via the receptacle provided in the package.
[0042] According to at least one embodiment of the present disclosure, the package for avoiding propagation of a fault in a safety system can include an isolation member that is a galvanic isolation member.
[0043] According to at least one embodiment of the present disclosure, a package for avoiding propagation of faults in a safety system can include an isolation member configured as a single isolation member configured to provide an impedance that is at least three times a common impedance that is produced between a die pin and each of a first output pin and a second output pin without use of the single isolation member.
[0044] According to at least one embodiment of the present disclosure, a package for avoiding propagation of faults in a safety system can include a jack configured to split a control signal into a first control signal and a second control signal, the first control signal provided to a first safety component via a first control signal connection, and the second control signal provided to a second safety component via a second control signal connection.
[0045] According to at least one embodiment of the present disclosure, a package for avoiding propagation of faults in a safety system can include an isolation member configured to prevent propagation of a fault produced with respect to a first control signal connection used with a first safety component to a second safety component. For at least one embodiment, the isolation member can be configured to prevent propagation of a fault produced with respect to a second control signal connection used with a second safety component to the first safety component.
[0046] According to at least one embodiment of the present disclosure, a method for mitigating propagation of a fault from a first safety component to a second safety component can include isolating at least one of a first input signal and a second input signal. For at least one embodiment, each of the first input signal and the second input signal can be produced from a common input signal electrically output by a control unit for respective use by each of the first safety component and the second safety component. For at least one embodiment, the first input signal can be electrically provided to the first safety component, and the second input signal can be electrically provided to the second safety component.
[0047] According to at least one embodiment of the present disclosure, a method for mitigating propagation of a fault from a first safety component to a second safety component can include isolating a first current provided in a first input signal from a second current provided in a second input signal by use of a first impedance.
[0048] According to at least one embodiment of the present disclosure, a method for mitigating propagation of a fault from a first safety component to a second safety component can include isolating a first voltage provided in a first input signal from a second voltage provided in a second input signal by use of a diode. BRIEF DESCRIPTION OF DRAWINGS
[0049] Features, aspects, advantages, functions, modules, and components of the devices, systems, and methods provided by various embodiments of the present disclosure are further disclosed herein in relation to at least one of the following descriptions and drawings. In the drawings, like elements or components can have the same reference label. Additionally, components of the same type can be distinguished by following the reference label by a dash and a second label that distinguishes among the gears of same-type components. If only the first reference label is used in the text, the description is applicable to any one of the similar components having the same first reference label irrespective of the second reference label, if there is any.
[0050] Figure 1 is a graph showing a known representation of injury probability versus injury severity that can be used to assess a dangerous risk associated with a vehicle system.
[0051] Figure 2 is a graphical representation of a known ASIL decomposition that can be used to reduce a dangerous risk associated with a vehicle system.
[0052] Figure 3 is an exemplary representation of relationships between a vehicle system, safety functions, and safety mechanisms.
[0053] Figure 4A is a schematic representation of a first system for preventing a fault from propagating between two or more safety components according to at least one embodiment of the present disclosure.
[0054] Figure 4B is a schematic representation of a second system for preventing a fault from propagating between two or more safety components according to at least one embodiment of the present disclosure.
[0055] Figure 4C is a schematic representation of a third system for preventing a fault from propagating between two or more safety components according to at least one embodiment of the present disclosure.
[0056] Figure 5 is a schematic representation of a fourth system for preventing a fault from propagating between two or more safety components while also providing ASIL decomposition according to at least one embodiment of the present disclosure.
[0057] Figure 6 is a schematic representation of a fifth system for preventing a fault from propagating between two or more safety components according to at least one embodiment of the present disclosure.
[0058] Figure 7 This is a schematic representation of a sixth system for preventing the propagation of faults between two or more safety components according to at least one embodiment of the present disclosure.
[0059] Figure 8 This is a flowchart of a method for preventing the propagation of a fault between two or more safety components according to at least one embodiment of the present disclosure. Detailed Implementation
[0060] The various implementation schemes described herein relate to devices, systems, and methods for preventing the propagation of faults and the induction of faults in security systems.
[0061] like Figures 4A-4C As shown, for at least one embodiment of this disclosure, a system 400 for preventing DFI between two or more security components includes a control unit 402 electrically coupled via a common lead 403 to each of a security function provided by a first IC 404 and a security mechanism provided by a second IC 406. Hereinafter, the term "control unit" includes any electronic circuitry or device that provides input signals to the security components. Non-limiting examples of a "control unit" include devices that provide bias current, LVDS transmitters, and main control units. Hereinafter, the terms "security function" and "first IC" are used interchangeably to refer to one or more components that provide a desired security function to facilitate the fulfillment of a security objective. Similarly, the terms "security mechanism" and "second IC" are used interchangeably to refer to one or more components that provide monitoring of one or more security functions. As shown, the security function provided by the first IC 404 and the security mechanism provided by the second IC 406 are electrically coupled and / or communicatively coupled via a monitoring link 407 to facilitate monitoring of the security function provided by the first IC 404, etc., by the security mechanism provided by the second IC 406.
[0062] Safety functions provided by the first IC 404 and safety mechanisms provided by the second IC 406 can be provided to monitor one or more vehicle systems / modules 408 and to provide compliance with safety objectives, such as ASIL safety objectives specified for one or more vehicle systems / modules 408. Any desired configuration of the first IC 404 and the second IC 406 relative to the common lead provided by the control unit 402 can be utilized.
[0063] The common lead 403 can be used to provide a common input, power, and / or control signal (herein, individually and collectively each “input signal” 405) to each of the first IC 404 and the second IC 406. For at least one embodiment, the input signal 405 is provided using the common lead 403. The common lead 403 is split into a first common lead 403a and a second common lead 403b that are coupled to each of the first IC 404 and the second IC 406, respectively. As a result, the input signal 405 is provided as a first input signal 405a and a second input signal 405b. Non-limiting examples of the input signal 405 include an enable signal, a clock signal, a reset signal, power, a reference voltage, a bias current, a data signal, and the like.
[0064] For at least one embodiment, a common impedance 412 is created between the common lead 403 and the control unit 402. The common impedance 412 can be used to regulate the current in the input signal 405 as provided by the control unit 402 to each of the safety functions provided by the first IC 404 and the safety mechanisms provided by the second IC 406.
[0065] As further discussed herein, the common impedance 412 can be coupled with one or more isolation components, such as a first isolation component 410a and a second isolation component 410b Figure 4B to avoid the first IC fault 416a from propagating to the second IC 406 and to avoid the second IC fault 416b from propagating to the first IC 404. When an isolation component is present in the system 400, an isolation lead 414 couples a given safety component with the isolation component. More specifically, in Figure 4A and Figure 4C , a first isolation lead 414a couples the first IC 404 with the first isolation component 410a, and in Figure 4B and Figure 4C , a second isolation lead 414b couples the second IC 406 with the second isolation component 410b.
[0066] For at least one embodiment where the input signal 405 is typically provided in the range of 0.1 V to 1 V, the common impedance 412 can be an impedance of 100 ohms to 300 ohms, and the isolation impedance of each of the first isolation component 410a and the second isolation component 410b is three times (3x) the common impedance. For at least one embodiment where a short to ground generates a given fault, the isolation impedance of the given faulted safety component results in an input voltage to the non-faulted safety components that is within 75%-100% of the output voltage from the control unit 402. Similarly, for another embodiment where a short to power supply generates a given fault, the isolation impedance of the given faulted safety component results in an input voltage to the non-faulted safety components that is within 0%-25% of the output voltage from the control unit 402.
[0067] As Figure 4A shown and for at least one embodiment, the system 400 can also include a first isolation component 410a. As Figure 4B shown and for at least one embodiment, the system can include using a second isolation component 410b. As Figure 4C shown and for at least one embodiment, each of the first isolation component 410a and the second isolation component 410b can be used.
[0068] For at least one embodiment, failure of the isolation component does not affect the SPFM associated with a given safety goal. For at least one embodiment, failure on the first isolation component 410a and / or the second isolation component 410b can result in minimal potential failure impact, if any. The lower impact of adding an isolator on safety metrics can be understood by studying the possible failure of the isolation element itself, such as forming a short or open circuit, a short failure can have negligible impact on the safety element, and an open failure will be easily detected. More specifically, for the short case, the safety component will operate in the same manner as if the isolator was not present. For the open case, the normal operation of the safety component associated with the failed isolation component will be affected. However, the failure of this isolation component is detectable, so the system can detect, and enter into an appropriate safety state, where any impact on the SPF or LFM, if any, can also be negligible. In addition to this, depending on the total impedance of the given circuit connection under faultless conditions, the addition of an isolator has no impact on the faultless functional operation, as the additional impedance of the isolation element is at a minimum. For example, when no fault condition is present, the common impedance 412 can be, for example, three hundred ohms (300 Ω), the first isolation component 410a can provide an impedance of one kilo-ohm (1 KΩ), and the input impedance of the safety function 404 can be ten kilo-ohms (10 KΩ). This results in an additional impedance due to the use of the first isolation component 410a that is less than ten percent (10%) of the total impedance of the circuit formed by the common lead 403 and the first common lead 403a.
[0069] For at least one embodiment, the first isolation component 410a and / or the second isolation component 410b can comprise one or more current isolation components. For at least one embodiment, the current isolation component can comprise a resistor. For at least one embodiment, the resistor used in the first isolation component 410a and / or the second isolation component 410b provides a respective first impedance and second impedance. For at least one embodiment, the first impedance and the second impedance are substantially the same. For at least one embodiment, the first impedance and the second impedance are different. For at least one embodiment, the first impedance and the second impedance each provide an impedance that is at least three times (3x) greater than the common impedance.
[0070] For at least one embodiment, the one or more first isolation components 410a and second isolation components 410b are voltage isolation components. For at least one embodiment, the voltage isolation components include diodes. For at least one embodiment, the one or more voltage isolation components inhibit the propagation of an overvoltage or undervoltage fault condition generated in a first one of the first IC 404 and second IC 406 to the other. For at least one embodiment, the one or more voltage isolation components inhibit voltage changes in the input signal 405 greater than 0% to 50% of an expected voltage (overvoltage condition) and / or less than 0% to 50% of an expected voltage (undervoltage condition).
[0071] For at least one embodiment and when no fault condition is present, each of the first input signal 405A on the first common lead 403a and the second input signal 405b on the second common lead 403b has substantially the same voltage and current. Thus, it should be appreciated that the use of the first isolation component 410a and / or second isolation component 410b prevents a fault generated, for example, at the first IC 404 from propagating to the second IC 406 through the first common lead 403a and second common lead 403b, and vice versa.
[0072] For at least one embodiment, by including one or more of the first isolation component 410a and / or second isolation component 410b in the system 400, a fault generated at either the first IC 404 or second IC 406 will not propagate to the respective other non-fault IC. It should be appreciated that the use of one or more of the first isolation component 410a and second isolation component 410b in combination with the common impedance 412 effectively forms a voltage divider circuit. Thus, the voltage provided to the safety component under fault and non-fault conditions can be readily calculated by one of ordinary skill in the art using known principles. For example and with reference to Figure 4A, the goal can be to provide the given input signal 405 to both the first IC 404 and the second IC 406 at a first given level such as a "high level" (e.g., when the IO provides a 3V signal). When a fault condition (e.g., short to ground) is created at the second IC 406, the voltage divider circuit formed by the common impedance 412 and the second isolation component 410b causes the voltage provided to the first IC 404 to decrease by only 25% (when the first isolation component is three times (3x) the common impedance and the short to ground impedance is 0 Ohms). This reduced voltage provided to the first IC 404 is advantageously sufficient for the first IC 404 to interpret the first input signal 405A as being at the high level that is expected for the first IC 404's intended use. Similarly, the goal can be to provide the given input signal 405 to both the first IC 404 and the second IC 406 at a second given level such as a "LOW level" (e.g., when the IO provides a 0V signal). When a fault condition (e.g., short to supply) is created at the second IC 406, the voltage divider circuit formed by the common impedance 412 and the second isolation component 410b causes the voltage provided to the first IC 404 to be limited to increase by twenty-five percent (25%) and thus be provided at a voltage that will be interpreted by the first IC 404 as being at the LOW level.
[0073] As Figure 5 shown and for at least one embodiment of the present disclosure, the system 500 can include the use of a third isolation component 504 that provides isolation between one or more monitoring links 502 or other links (such as power links) electrically coupling the first IC 404 and the second IC 406. It should be appreciated that a combination of the third isolation component 504 with one or more of the first isolation component 410a and the second isolation component 410b can facilitate decomposition of the safety component. For example, when the first IC 404 has a QM(D) rating and the second IC 406 has an ASIL D(D), the combined safety component meets the standard through the use of decomposition since the first IC 404 and the second IC 406 are independently provided and isolated by the first isolation component 410a / second isolation component 410b / third isolation component 504.
[0074] Furthermore, it should be appreciated that because the second input signal 405b as received by the non-faulty, secure component of the second IC 406 is not significantly affected by the first IC fault 416a, the first IC fault 416a will not affect the operation provided by the second secure component. More specifically, the voltage divider principle discussed above can also be used to avoid the first IC fault, e.g., with respect to a safety function, from propagating to a second IC that provides, e.g., a safety mechanism. The first isolation component 410a enables the second IC 406 / safety mechanism to continue to operate correctly, detect a fault of the safety function, and output a corresponding error signal to the appropriate system controller. When providing a redundant system, it should be appreciated that the use of one or more isolation components can be used to make the “fail functional” operation principle easier according to embodiments of the present disclosure. Thus and for at least one embodiment, a fault generated with respect to a safety function in the first safety system A will not affect whether the vehicle system detects such a fault and will not transfer to the fully redundant second safety system B, thereby providing a fail functional operation method.
[0075] Thus, according to Figures 4A-4C and Figure 5 one or more of the systems shown, a fault in the first secure component will not propagate to the second secure component and can provide a standard compatible secure component without disassembly (according to Figures 4A-4C ) or disassembly (according to Figure 5 ). Thus, one or more embodiments of the present disclosure also limit the “fail safe” and “fail functional” operation principles of the vehicle system.
[0076] As shown in Figure 6 , a non-limiting example of an implementation of an embodiment of the present disclosure is provided. For this non-limiting example, the secure component can include a master control unit (MCU) 602 electrically coupled to two or more of a sequencer 604, a regulator 606, and a voltage monitor 608. One or more isolation components 610a-610d, such as a first isolator (ISO) 610a, a second isolator 610b, a third isolator 610c, and a fourth isolator 610d, can be used to provide galvanic and / or voltage isolation between two or more of the sequencer 604, the regulator 606, and the voltage monitor 608.
[0077] More specifically, one or more of the first isolator 610a and the second isolator 610b can be provided to prevent a fault from propagating between the sequencer 604 and the voltage monitor 608 through a sleep (“SLP”) enable connection 612, which is provided in parallel with each of the sequencer 604 and the voltage monitor 608 using a first SLP enable connection 612a and a second SLP enable connection 612b. For at least one embodiment and when a fault condition is not present, the enable signal on each of the first SLP enable connection 612a and the second SLP enable connection 612b can have substantially the same voltage and current - this is generally due to the large input impedance (e.g., > 10K ohms) created at each component as compared to the impedance associated with a given control signal (e.g., ~ 300 ohms). Thus, it should be appreciated that the use of the first isolator 610a prevents a fault created, for example, at the sequencer 604 from propagating to the voltage monitor 608 through the first and second enable connections 612a / 612b. Likewise, the second isolator 610b prevents a fault created, for example, at the voltage monitor 608 from propagating to the sequencer 604 through the second and first enable connections 612b / 612a. It should be appreciated that the SLP enable connection 612 and its sub-elements 612a / 612b can be used to provide any desired signal or signals. It should also be appreciated that, Figures 4A-4C Any of the embodiments of FIG. 6 can be used to provide one or more of the first isolator 610a and / or the second isolator 610b.
[0078] Similarly and as Figure 6 Also shown, one or more of a third isolator 610c and a fourth isolator 610d can be provided to prevent a fault from propagating between the sequencer 604 and the voltage monitor 608 through a power enable connection 614, which is provided in parallel with each of the sequencer 604 and the voltage monitor 608 using a first power enable connection 614a and a second power enable connection 614b. For at least one embodiment and when a fault condition is not present, the power enable signal on each of the first power enable connection 614a and the second power enable connection 614b can have substantially the same voltage and current - this is generally due to the large input impedance (e.g., > 10K ohms) created at each component as compared to the impedance associated with a given control signal (e.g., ~ 300 ohms). Thus, it should be appreciated that the use of the third isolator 610c and / or the fourth isolator 610d prevents a fault created, for example, at the sequencer 604 from propagating to the voltage monitor 608 through the first and second power enable connections 614a / 614b, and vice versa. It should be appreciated that the power enable connection 614 and its sub-elements 614a / 614b can be used to provide any desired signal or signals. It should also be appreciated that, Figures 4A-4CAny of the implementation schemes may be used to provide one or more of the third isolator 610c and / or the fourth isolator 610d.
[0079] like Figure 6 It is also shown that one or more third connections 616 may be provided between MCU 602 and one or more of sequencer 604, regulator 606, and voltage monitor 608. For at least one embodiment, such one or more third connections 616a-616b may not need to be fault isolated due to the voltage and / or current provided between such third connections 616a-616b, such as communication lines or buses, the use of redundancy checks such as cyclic redundancy checks, fail-safe components, etc. Therefore, it should be understood that isolators may be used relative to those common connections subject to fault propagation risk according to at least one embodiment of this disclosure, and may not be used relative to other common connections not subject to fault propagation, and / or may not be used where the system is configured to continue operating even when a fault propagates through the system (fault functionality).
[0080] For at least one implementation, one or more of the MCU 602, sequencer 604, regulator 606, voltage monitor 608, and isolators 610a-d may be components supplied by ON Semiconductor of Phoenix, Arizona, USA, or one of its affiliates.
[0081] like Figure 7 As shown, another embodiment of system 700 for preventing fault-inducing factors from propagating faults between two or more safety components includes an MCU 702 electrically connected to safety function 704 and safety mechanism 706. Safety function 704 and safety mechanism 706 jointly provide a safety component. The safety component is provided for use with one or more vehicle systems / modules 708. As shown, MCU 702 also includes a die 710 and a package 712. The die includes at least one pin 714 (or other known connector) for outputting at least one signal such as control signal 716. Control signal 716 is provided to safety function 704 and safety mechanism 706 as the same first control signal 716a and second control signal 716b via first control signal connection 718 and second control signal connection 719, respectively. It should be understood that "control signal" can be any signal, and the use of "control" herein is for identification purposes only.
[0082] like Figure 7As shown, the package 712 includes a receptacle 720 that has been configured to include a first output pin 722 and a second output pin 724, in accordance with embodiments of the present application. That is, rather than using a single pin to connect the MCU 702 with both safety components, two pins (the first output pin 722 and the second output pin 724) are used and coupled to the first control signal connection 718 and the second control signal connection 719, respectively. It should be appreciated that each of the first output pin 722 and the second output pin 724 can be configured such that the package 712 provides galvanic and / or voltage isolation between such pins and such that a fault generated with respect to the safety function 704 does not propagate to the second output pin 724, the second control signal connection 719, and to the safety mechanism 706 through the first control signal connection 718, the first output pin 722, and the receptacle 720, and vice versa. With such embodiments, it should be appreciated that a single isolation member (such as a galvanic and / or voltage isolation component) (not shown) can be used at the receptacle 720 to provide isolation between the first output pin 722 and the second output pin 724 with respect to the signals provided to both safety components at least with respect to the common ground, thereby providing isolation between the two safety components.
[0083] It should also be appreciated that, as described herein with respect to embodiments of the Figure 5 , ASIL decomposition can also be provided by replicating the redundant pin embodiments of the Figure 7 with respect to each connection that is commonly shared by two or more safety components with another vehicle component, such as an MCU or other.
[0084] It should also be appreciated that, by facilitating ASIL decomposition using modified or unmodified embodiments of the Figure 7 , existing configurations of safety components, for example, disposed on one or more system-on-a-chip, circuit boards, or other manners (herein, collectively referred to as “circuitry”), need not be modified to include additional components, such as resistors, diodes, and the like, to provide galvanic and / or voltage isolation between safety components. Rather, only those other single connections that are commonly shared by two or more safety components (such connections are subject to the fault propagation problem) need to be modified to include one or more second partitioned connections with respect to such circuitry. As such, the second partitioned connections are configured for coupling with modified packages to include redundant pins for the other singularly shared connections of prior art embodiments. Rather, any galvanic and / or voltage isolation components are provided by the modified package, such as the package 712 of Figure 7 .
[0085] According to at least one embodiment of the present disclosure, an apparatus can be configured to practice any of the above-described embodiments of the present disclosure. Such an apparatus can be configured as a system-on-a-chip, or otherwise configured. For example,Figure 7 In embodiments, the device according to the present application can comprise a package configured to have duplicated pins (or similar connection structures) that are galvanically and / or voltage-isolated within the package itself.
[0086] According to at least one embodiment of the present disclosure, a method for avoiding propagation can comprise one or more operations including isolating an input signal provided to a first security component when a fault is generated with respect to a second security component, wherein the input signal is provided to each of the first security component and the second security component using, at least in part, a common pin coupled with a control unit. According to such a method and according to at least one embodiment of the present disclosure, a fault propagation between the first security component and the second security component can be avoided, even though they are electrically coupled with each other via the common pin, by using one or more current isolation components and / or one or more voltage isolation components. The current isolation components and / or the voltage isolation components can be located between a given security component and a junction at which the common pin is provided to each of the first security component and the second security component.
[0087] For at least one embodiment of such a method, each of the security components can be configured to receive a common input signal during a fault-free operation. When a fault is generated with respect to one of the security components, the fault can affect at least one attribute of the common input signal, such as a voltage potential and / or a current of the common input signal. Without using isolation means that provide galvanic and / or voltage isolation between the security components, one or more attributes of the common input signal as received by the non-fault security component would be affected by the fault condition.
[0088] According to at least one embodiment of the present disclosure and as shown in Figure 8 A method for avoiding fault propagation and / or inducing fault initiation can comprise identifying one or more connections that are commonly shared by a first security component and a second security component with a third component (operation 800), according to at least one embodiment of the present disclosure. If an identification is made, an evaluation of whether such a common connection is at risk of fault propagation (FPR, also referred to as “coexistence” in standards) can be performed (operation 802). If there is no FPR, the method can comprise evaluating another connection (operation 806). For at least one embodiment, the FPR of all identified connections is evaluated.
[0089] Returning again to operation 804, if a given connection has an FPR, the method can include classifying the FPR by type (operation 808). For example, the FPR can manifest as a failure resulting from a current risk (such as a risk resulting from a short or open circuit), a voltage risk (such as a risk resulting from an overvoltage or undervoltage condition), a timing risk (such as a risk resulting from one safety component driving a clock signal or other mechanism at an unexpected rate), or other risk, and / or a combination of one or more of the foregoing.
[0090] Based on the risk classification, in accordance with operation 808, the method can include determining a risk reduction method to be used (operation 810). For example, as described herein, for example, with respect to embodiments of Figures 4A-4C , a first risk reduction method can involve the use of a single isolation component or multiple isolation components. Similarly, as described herein, for example, with respect to embodiments of Figure 7 , the risk reduction method can include the use of a package configured to provide a plurality of pins for a divided connection between a common element and each of two or more safety components. It will be appreciated that various and / or many factors can be considered in identifying a given risk reduction method for reducing an identified FPR. Non-limiting examples of such factors include available circuit space, power requirements, signal delay considerations, radio frequency signal suppression considerations, and the like. It will thus be appreciated that the risk reduction method to be utilized will likely vary.
[0091] In accordance with operation 812, the method can include determining whether a resolution of the FPR is needed. It will be appreciated that, for one or more embodiments, operation 812 can be performed in conjunction with, sequentially with, and / or instead of operation 810. This relationship is illustrated by the dashed line connecting operations 810 and 812 in Figure 8 .
[0092] In accordance with operation 814, a resolution of the FPR to be used is selected. It will be appreciated that the resolution of the FPR can be made in accordance with any of the above-described or other embodiments. For example, as described above, for example, with respect to Figure 5 , the resolution can include the use of additional isolation components, by providing redundant systems / components, or otherwise.
[0093] In accordance with operation 816, the method can include determining whether a given FPR requires further classification and / or determining a risk reduction method and / or resolution method. If“yes,” the method can continue with one or more of operations 808, 810, 812, and 814. If“no,” the method can continue with operation 806.
[0094] According to operation 818, the method can include implementing the selected desired reduction and / or decomposition method. It should be appreciated that such methods can be implemented at any desired time of secure component manufacturing, assembly, testing, use, or otherwise, and can be implemented using any known or later arising manufacturing, assembly, or other manufacturing method.
[0095] According to operation 820, the method ends when those desired connections involving fault propagation and / or induced fault initiation have been addressed.
[0096] It should be appreciated that the operations depicted above and Figure 8 in the description of all embodiments of the present disclosure are merely illustrative and are not intended to occur in the order, sequence, or otherwise shown herein. One or more operations can be performed in parallel and operations can not be performed as provided for any given use of an embodiment of the present disclosure.
[0097] It should be appreciated that the principles of the various embodiments of the present disclosure described herein can be applied to non-safety related vehicle systems and components. For example, isolation can be provided between safety related components and non-safety related components. It should also be appreciated that the principles of the various embodiments are not limited to vehicle systems and can be used in conjunction with other systems requiring independence of a first component with respect to a second component. Non-limiting examples of such other systems include aircraft and rail systems, industrial objects, and the like.
[0098] While various embodiments of the claimed application have been described above with a certain level of particularity, the skilled artisan will recognize that many changes can be made to the embodiments disclosed without departing from the spirit or scope of the claimed application. The use of the term "about" or "substantially" means that a value has a parameter that is intended to be near the stated value or position. However, as is well understood by those skilled in the art, there can be minor variations in the value that do not materially affect the value. Thus, a difference such as a 10% difference is a reasonable difference that one of ordinary skill in the art would expect and appreciate, and is acceptable relative to the stated or ideal target of one or more embodiments of the present disclosure. It should also be understood that the terms "top" and "bottom," "left" and "right," "up" and "down," "first," "second," "next," "last," "before," "after," and other similar terms are used for description and ease of reference only and are not intended to be limiting to any orientation or configuration of any element of the various embodiments of the present disclosure or any sequence of operation. Furthermore, the terms "coupled," "connected," or other similar terms are not intended to limit such interaction and signal communication between two or more devices, systems, components, or otherwise direct the interaction; indirect coupling and connection can also occur. Additionally, the terms "and" and "or" are not intended to be used in a limiting or expansive nature and cover any possible range of combinations of elements and operations of embodiments of the present disclosure. Other embodiments are thus contemplated. It is intended that all matters contained in the above description and shown in the accompanying drawings be interpreted as illustrative only and not limiting. Changes in detail or structure can be made without departing from the spirit of the application as defined in the appended claims.
Claims
1. A system for avoiding propagation of a fault among safety components, the system comprising: a control unit that outputs an input signal to a first safety component and a second safety component via a common lead; wherein a common impedance is generated between the control unit and the common lead; the first safety component; the second safety component; a first isolation component; and an isolation lead; wherein, in the system, the common lead is divided into a first common lead and a second common lead in a parallel circuit configuration; wherein the control unit is coupled to the first isolation component through the common impedance, the common lead, and the first common lead; wherein the control unit is coupled to the second safety component through the common impedance, the common lead, and the second common lead; wherein the first isolation component is coupled to the first safety component through the isolation lead; and wherein the first isolation component prevents a first IC fault generated with respect to the first safety component from propagating to the second safety component via the first and second common leads.
2. The system of claim 1, wherein at least one of: the first safety component provides a first safety function and the second safety component provides a first safety mechanism; the first safety component provides the first safety function and the second safety component provides a second safety function; the first safety component provides the first safety mechanism and the second safety component provides a second safety mechanism; and wherein the system is used with at least one of a motor vehicle safety system, a vehicle airbag system, a self-driving vehicle system, a vehicle lane-keeping assist system, a vehicle automated braking system, and an aircraft system.
3. The system of claim 1, the system further comprising: a second isolation component electrically disposed between the control unit and the second safety component and further coupling the control unit and the second safety component; wherein the second isolation component prevents a second IC fault generated in the second safety component from propagating to the first safety component via the input signal; and wherein the first and second isolation components are galvanic isolation components having the same impedance.
4. The system of claim 3, wherein, during the first IC fault, a non-substantial change in the input signal is provided to the second safety component; wherein, during the second IC fault, a non-substantial change in the input signal is provided to the first safety component; and wherein, by preventing the second IC fault from propagating to the first safety component, a vehicle system operates to continue in a fault-function operational mode.
5. The system of claim 3, wherein when the first IC fault comprises a first short-circuit fault, a voltage potential of the input signal provided to the second safety component is between seventy-five percent and one hundred percent of an output voltage potential of the input signal generated by the control unit during a non-fault operational state; wherein, when the second IC fault comprises a second short-circuit fault, a voltage potential of the input signal provided to the first safety component is between seventy-five percent and one hundred percent of an output voltage potential of the input signal generated by the control unit during a non-fault operational state. a voltage potential of the input signal provided to the first secure component is between seventy-five percent and one hundred percent of an output voltage potential of the input signal generated by the control unit during the non-fault operating state; wherein, when the first IC fault comprises a first open circuit fault, a voltage potential of the input signal provided to the second secure component is between twenty-five percent and one hundred percent of the output voltage potential of the input signal generated by the control unit during the non-fault operating state; and wherein, when the second IC fault comprises a second open circuit fault, a voltage potential of the input signal provided to the first secure component is between twenty-five percent and one hundred percent of the output voltage potential of the input signal generated by the control unit during the non-fault operating state.
6. A package for avoiding fault propagation in a secure system, the package comprising: a receptacle operable to receive a die, the receptacle further comprising: a first output pin that first electrically couples a die pin to a first secure component via the receptacle; a second output pin that second electrically couples the die to a second secure component via the receptacle; wherein the first secure component is operable to receive a control signal via the die and the first output pin; wherein the second secure component is operable to receive the control signal via the die and the second output pin; an isolation member that electrically isolates the first output pin from the second output pin; and wherein the isolation member prevents a fault generated with respect to one of the first secure component and the second secure component from propagating to the other secure component via the receptacle.
7. The package of claim 6, wherein the isolation member is a galvanic isolation member; wherein the isolation member provides an impedance that is at least three times a common impedance generated between the die and the first output pin and the second output pin in the absence of the isolation member; and wherein the receptacle separates the control signal into a first control signal provided to the first secure component via a first control signal connection and a second control signal provided to the second secure component via a second control signal connection.
8. The package of claim 7, wherein the isolation member prevents a first IC fault generated with respect to the first control signal connection from propagating to the second secure component; and wherein the isolation member prevents a second IC fault generated with respect to the second control signal connection from propagating to the first secure component.
9. A method for mitigating propagation of a fault from a first secure component to a second secure component, the method comprising: isolating a first input signal from a second input signal; wherein the first input signal and the second input signal are generated from a common input signal electrically output by a control unit for use by a first secure component and a second secure component each; wherein the first input signal is electrically provided from the control unit to the first security component via a first output pin of the jack; wherein the second input signal is electrically provided from the control unit to the second security component via a second output pin of the jack; wherein isolating the first input signal from the second input signal includes using an isolation component that electrically isolates the first output pin from the second output pin; and wherein the isolation component prevents a fault generated with respect to one of the first security component and the second security component from propagating to the other security component via the jack.
10. The method of claim 9, wherein the isolation component further includes at least one of: isolating a first current provided in the first input signal from a second current provided in the second input signal by a first impedance; and isolating a first voltage provided in the first input signal from a second voltage provided in the second input signal by a diode.
11. A package for avoiding fault propagation in a safety system, the package comprising: a single jack configured to receive a die pin for a die; wherein the die pin is directly coupled to a security component including a safety function and a safety mechanism via the jack; and wherein the die includes a control unit integrated circuit that outputs a control signal on a die pin; the jack further comprising: a first output pin that first directly and individually electrically couples the die pin to the safety function; wherein the safety function is configured to receive the control signal from the control unit via the die pin and the first output pin; and a second output pin that second directly and individually electrically couples the die pin to the safety mechanism; wherein the safety mechanism is configured to receive the control signal from the control unit via the die pin and the second output pin; and an isolation component that electrically isolates the first output pin from the second output pin on the jack; and wherein the isolation component prevents a fault generated with respect to one of the safety function and the safety mechanism from propagating to the other of the safety function and the safety mechanism via the jack.
12. The package of claim 11, wherein the jack is configured to split the control signal into a first control signal provided to the safety function via a first control signal connection coupled to the first output pin and a second control signal provided to the safety mechanism via a second control signal connection coupled to the second output pin.
Citation Information
Patent Citations
Satellite navigation receiver designed for compatibility with aircraft automatic landing systems
US6570531B1