System and method for determining the status of a second ECU using a shared sensor in a dual ECU system

By using shared sensor signals in a dual ECU system to monitor the pin state and protocol data of the communication terminals, the problem of difficulty in determining the second ECU state under IMC failure is solved, and accurate state judgment is achieved when the IMC is unavailable.

CN115195634BActive Publication Date: 2025-08-12STEERING SOLUTIONS IP HOLDING CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210368994.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-04-09
Filing Date
2022-04-08
Publication Date
2025-08-12
Estimated Expiration
2042-04-08

AI Technical Summary

Technical Problem

In a dual ECU system, it is difficult to accurately determine the status of the second ECU when the inter-microcontroller communication (IMC) fails because the IMC signal cannot distinguish between communication failure and ECU failure.

Method used

By sharing the sensor signal, the pin state of the communication terminal is monitored by the first ECU, and the status of the second ECU is determined in combination with the sensor signal protocol data.

Benefits of technology

Even in the case of an IMC failure, the power-on, power-off or operating state of the second ECU can be accurately judged, providing a state determination method when the IMC is not available.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115195634B_ABST
    Figure CN115195634B_ABST
Patent Text Reader

Abstract

The present application discloses a system and method for determining the state of a second ECU using a shared sensor in a dual ECU system. A technical solution of a system and method for determining the state of an electronic control unit (ECU) in a dual ECU system is described. The method includes: determining, by a first ECU, a pin state of a communication terminal connected to a sensor; powering the sensor by a second ECU; and determining, by the first ECU, the state of the second ECU based on the pin state of the communication terminal. The first ECU may determine the second ECU as unresponsive via a communication interface, and the first ECU may determine the state of the second ECU in response to determining that the second ECU is unresponsive via the communication interface. The first ECU may determine the state of the second ECU as one of powered and unresponsive, powered and running, or powered off based on the pin state of the communication terminal.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This patent application claims priority to U.S. Provisional Patent Application Serial No. 63 / 172,958, filed on April 9, 2021, the entire contents of which are incorporated herein by reference. Technical Field

[0003] The present application generally relates to methods and systems for determining a status of a secondary electronic control unit (ECU) in a dual-ECU system. Background Art

[0004] In a dual-ECU system, one ECU typically uses inter-microcontroller communication (IMC) to determine the status of the other. If the second ECU in a dual-ECU system stops functioning, the IMC signal will reflect a fault condition on the first ECU, indicating that the second ECU may have stopped functioning. However, the IMC itself may have failed while the second ECU is still functioning. In this case, the first ECU will have difficulty determining the status of the second ECU because the IMC failure does not provide sufficient information to distinguish between a communication failure and an ECU failure.

[0005] In some dual ECU systems, one or more sensor signals can be shared between the two ECUs. The sensor signals can be powered by the second ECU and read by both the primary ECU and the second ECU. Summary of the Invention

[0006] One aspect of the disclosed embodiment includes a method for determining the status of an electronic control unit (ECU) in a dual-ECU system. The method includes: determining, by a first ECU, a pin status of a communication terminal connected to a sensor; powering the sensor by a second ECU; and determining, by the first ECU, the status of the second ECU based on the pin status of the communication terminal.

[0007] One aspect of the disclosed embodiment includes a method for determining a state of an electronic control unit (ECU) in a dual-ECU system. The method includes: powering a sensor by a second ECU; determining, by a first ECU via a communication interface, that the second ECU is unresponsive; in response to determining that the second ECU is unresponsive, determining, by the first ECU, sensor signal protocol data based on a communication terminal connected to the sensor; determining, by the first ECU, whether the sensor signal protocol data passes a protocol check; in response to determining that the sensor signal protocol data fails the protocol check, determining, by the first ECU, a pin state of the communication terminal; and in response to determining that the sensor signal protocol data fails the protocol check, determining, by the first ECU, a state of the second ECU based on the pin state of the communication terminal. The pin state includes at least one of: the communication terminal remaining in a given logic level state for a predetermined period of time, or the communication terminal toggling between a logic high state and a logic low state rather than remaining in a given state, either a logic high state or a logic low state, for a predetermined period of time. Determining the state of the second ECU includes: determining, in response to determining the pin state of the communication terminal toggling between a logic high state and a logic low state, that the second ECU is powered on and operational. Determining the state of the second ECU includes: in response to determining that the pin state of the communication terminal remains in a logic high state for a first predetermined time period, determining that the state of the second ECU is powered on and unresponsive. Each of the first ECU and the second ECU is configured to communicate with the sensor using a Single Edge Nibble Transmission (SENT) protocol. Determining the state of the second ECU includes: in response to determining that the pin state of the communication terminal remains in a logic low state for a second predetermined time period, determining that the state of the second ECU is powered off. The method also includes: in response to determining that the state of the second ECU is powered on and unresponsive, the first ECU executing a first control action, the first control action at least including initializing communication with the sensor; and in response to determining that the state of the second ECU is powered off, the first ECU executing a second control action, wherein the second control action at least includes providing power to the sensor and initializing communication with the sensor.

[0008] One aspect of the disclosed embodiment includes a system for determining the state of an electronic control unit (ECU) in a dual ECU system. The system includes: a sensor having a sensor output pin; and a first ECU having a first communication terminal in electrical communication with the sensor output pin. The first ECU is configured to read sensor data from the sensor based on the pin state of the first communication terminal. The system also includes a second ECU having a second communication terminal in electrical communication with the sensor output pin. The second ECU is configured to read sensor data from the sensor based on the pin state of the second communication terminal. The second ECU provides power to the sensor power rail and biases the voltage of the first communication terminal and the second communication terminal to a logic level high condition. The first ECU is configured to determine the state of the second ECU based on the pin state of the first communication terminal.

[0009] These and other advantages and features will become more apparent from the following description taken in conjunction with the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] The subject matter of the present disclosure is particularly pointed out and distinctly claimed in the claims at the conclusion of the specification. The foregoing and other features and advantages of the present disclosure are apparent from the following detailed description when taken in conjunction with the accompanying drawings, in which:

[0011] Figure 1 A vehicle according to the principles of the present disclosure is generally shown.

[0012] Figure 2 A block diagram generally illustrating a dual electronic control unit (ECU) configuration according to the principles of the present disclosure is shown.

[0013] Figure 3 Generally shown is a schematic wiring diagram between two ECUs and sensors according to the principles of the present disclosure.

[0014] Figure 4 A graph showing voltage over time on a communication line between a sensor and an ECU according to the principles of the present disclosure is shown.

[0015] Figure 5 is a flow chart generally illustrating a first method of determining ECU status in a dual ECU system according to the principles of the present disclosure.

[0016] Figure 6 is a flow chart generally illustrating a second method of determining ECU status in a dual ECU system according to the principles of the present disclosure. DETAILED DESCRIPTION

[0017] Reference will now be made to the accompanying drawings, in which the present disclosure will be described with reference to specific embodiments, but not limiting thereof, it being understood that the disclosed embodiments are merely illustrative of the present disclosure, which may be embodied in various forms and alternatives. The figures are not necessarily drawn to scale; certain features may be exaggerated or minimized to illustrate details of particular components. Therefore, the specific structural and functional details disclosed herein should not be construed as limiting, but merely as a representative basis for teaching one skilled in the art to employ the present disclosure in various ways.

[0018] A system and method are provided for determining the health status of a secondary ECU using shared sensor signals between the primary and secondary ECUs. The disclosed system and method can provide information about the health status of the secondary ECU even when inter-microcontroller communication (IMC) between the primary and secondary ECUs fails or becomes unavailable.

[0019] The disclosed system and method can determine the health status of a second ECU based on sensor signals shared between the two ECUs. This provides a way to determine the health of the other ECU in the event of an IMC failure, when IMC data cannot be used to determine the status of the other ECU. Based on the signature of the protocol used by the sensor signals, various ECU operating states can be determined.

[0020] As used herein, the terms module and submodule refer to one or more processing circuits (e.g., application-specific integrated circuits (ASICs), electronic circuits), processors and memories (shared, dedicated, or grouped) that execute one or more software or firmware programs, combinatorial logic circuits, and / or other suitable components that provide the functionality described. It will be understood that the submodules described below can be combined and / or further divided.

[0021] As previously mentioned, vehicles such as cars, trucks, sport utility vehicles, crossovers, minivans, speedboats, aircraft, all-terrain vehicles, recreational vehicles, or other suitable vehicles typically include one or more electronic control units (ECUs). For example, a vehicle may include one or more ECUs to control various aspects of the vehicle's steering system. One or more systems within the vehicle may utilize a dual ECU system comprising two ECUs for redundancy.

[0022] Now, with reference to the accompanying drawings, the technical solution will be described in conjunction with specific embodiments, but is not limited thereto. Figure 1A vehicle 10 is generally shown in accordance with the principles of the present disclosure. Vehicle 10 may include any suitable vehicle, such as a car, truck, sport utility vehicle, minivan, crossover, any other passenger vehicle, any suitable commercial vehicle, or any other suitable vehicle. Although vehicle 10 is illustrated as a passenger vehicle having wheels and used on a road, the principles of the present disclosure may be applied to other vehicles, such as airplanes, ships, trains, drones, or other suitable vehicles.

[0023] Vehicle 10 includes a body 12 and a hood 14. A passenger compartment 18 is at least partially defined by body 12. Another portion of body 12 defines an engine compartment 20. Hood 14 is movably attached to a portion of body 12 such that hood 14 provides access to engine compartment 20 when in a first, or open, position and covers engine compartment 20 when in a second, or closed, position. In some embodiments, engine compartment 20 may be located at a rear portion of vehicle 10 (compared to what is generally shown).

[0024] The passenger compartment 18 may be positioned rearward of the engine compartment 20, but in embodiments where the engine compartment 20 is positioned at a rear portion of the vehicle 10, the passenger compartment 18 may be positioned forward of the engine compartment 20. The vehicle 10 may include any suitable propulsion system, including an internal combustion engine, one or more electric motors (e.g., an electric vehicle), one or more fuel cells, a hybrid (e.g., a hybrid vehicle) propulsion system including a combination of an internal combustion engine, one or more electric motors, and / or any other suitable propulsion system.

[0025] In some embodiments, vehicle 10 can include a gasoline fuel engine, such as a spark ignition engine. In some embodiments, vehicle 10 can include a diesel fuel engine, such as a compression ignition engine. The engine compartment 20 houses and / or surrounds at least some components of the propulsion system of vehicle 10. Additionally or alternatively, propulsion control devices (e.g., an accelerator actuator (e.g., an accelerator pedal), a brake actuator (e.g., a brake pedal), a steering wheel, and other such components) are disposed in the passenger compartment 18 of vehicle 10. The propulsion control devices can be actuated or controlled by the driver of vehicle 10 and can be directly connected to corresponding components of the propulsion system, such as a throttle, brakes, axles, and a vehicle transmission, respectively. In some embodiments, the propulsion control devices can transmit signals to a vehicle computer (e.g., drive-by-wire), which in turn can control corresponding propulsion components of the propulsion system. Thus, in some embodiments, vehicle 10 can be an autonomous vehicle.

[0026] In some embodiments, vehicle 10 includes a transmission that communicates with the crankshaft via a flywheel, a clutch, or a fluid coupling. In some embodiments, the transmission comprises a manual transmission. In some embodiments, the transmission comprises an automatic transmission. In the case of an internal combustion engine or a hybrid vehicle, vehicle 10 may include one or more pistons that cooperate with the crankshaft to generate force that is transmitted through the transmission to one or more shafts to rotate wheels 22. When vehicle 10 includes one or more electric motors, the vehicle battery and / or fuel cell provides energy to the electric motors to rotate wheels 22.

[0027] Vehicle 10 may include an automated vehicle propulsion system, such as cruise control, adaptive cruise control, automatic braking control, other automated vehicle propulsion systems, or combinations thereof. Vehicle 10 may be an autonomous vehicle or a semi-autonomous vehicle, or another suitable type of vehicle. Vehicle 10 may include additional or fewer features than generally shown and / or disclosed herein.

[0028] In some embodiments, the vehicle 10 may include an Ethernet component 24, a controller area network (CAN) bus 26, a media oriented system transport component (MOST) 28, a FlexRay component 30 (e.g., a brake-by-wire system, etc.), and a local interconnect network component (LIN) 32. The vehicle 10 may use the CAN bus 26, MOST 28, FlexRay component 30, LIN 32, other suitable networks or communication systems, or a combination thereof to transmit various information from, for example, sensors inside or outside the vehicle to, for example, various processors or controllers inside or outside the vehicle. The vehicle 10 may include additional or fewer features than generally shown and / or disclosed herein.

[0029] In some embodiments, the vehicle 10 may include one or more controllers or electronic control units (ECUs). An ECU may also be referred to as a controller. Figure 2 As generally shown, the control system 50 within the vehicle includes a first ECU 100 and a second ECU 110, each connected to a sensor 120. The sensor 120 may be referred to as a common sensor or a shared sensor due to being connected to two or more ECUs 100, 110. Each of the first ECU 100 and the second ECU 110 may include any suitable controller. The first ECU 100 may be referred to as a primary ECU or a primary controller, and the second ECU 110 may be referred to as a secondary ECU or a secondary controller. The control system 50 may be configured to control, for example, various aspects of the vehicle 10 (e.g., various aspects of the electric power steering system) and / or other features or components of the vehicle 10. The first ECU 100 may include a first processor 102 and a first memory 104. The second ECU 110 may include a second processor 112 and a second memory 114.

[0030] Each of the processors 102, 112 may include any suitable processor, such as those described herein. Additionally or alternatively, either or both of the first ECU 100 and / or the second ECU 110 may include any suitable number of processors in addition to or in addition to the first and second processors 102, 112. Each of the memories 104, 114 may include a single disk or multiple disks (e.g., hard drives) and a storage management module that manages one or more partitions within the memories 104, 114. In some embodiments, one or both of the memories 104, 114 may include flash memory, semiconductor (solid-state) memory, or the like. Either or both of the memories 104, 114 may include random access memory (RAM), read-only memory (ROM), or a combination thereof. Either or both of the memories 104, 114 may include instructions that, when executed by the corresponding processor 102, 112, cause the corresponding processor 102, 112 to control at least various functions of the vehicle 10.

[0031] Likewise Figure 2 As shown, the control system 50 includes a communication interface 130 between the first ECU 100 and the second ECU 110. The communication interface 130 provides inter-microcontroller communication (IMC) between the first ECU 100 and the second ECU 110. In some embodiments, the communication interface 130 may include a serial peripheral interface (SPI) and / or an inter-integrated circuit (I2C) interface. However, any type of communication protocol and / or interface may be used. In some embodiments, one or more other controllers (not shown) may also be connected to the communication interface 130. For example, the communication interface 130 may include a portion of a communication network. Such a communication network may include, for example, a controller area network (CAN), a local interconnect network (LIN), Ethernet, etc., although other types of communication protocols and / or interfaces may be used.

[0032] The present disclosure provides an example of an electric power steering (EPS) system having dual ECUs, including a first ECU 100 and a second ECU 110. Each of the first ECU 100 and the second ECU 110 is configured to use information from a sensor 20. This is merely an example, and the systems and methods of the present disclosure can be applied to any number of sensors or any type of control system having two or more ECUs, as long as both ECUs are connected to a shared sensor or other data source.

[0033] In some embodiments, the sensor 120 is configured to communicate with the first ECU 100 and / or the second ECU 110 using a point-to-point communication interface. In some embodiments, the point-to-point communication interface includes a voltage interface that transmits data based on voltage changes. In some embodiments, the point-to-point communication interface includes an asynchronous voltage interface, such as the Single Edge Nibble Transmission (SENT) protocol described in SAE International Standard J2716. However, other communication interfaces and / or protocols may be used.

[0034] Figure 3 A schematic wiring diagram 200 is shown between the first ECU 100, the second ECU 110, and the sensor 120. A sensor power rail 202 has a voltage Vcc secondary and is powered by the second ECU 110. The sensor 120 has a sensor input / output (I / O) terminal 122 connected to the sensor power rail 202 via a pull-up resistor 204, which pulls the sensor I / O terminal 122 to the Vcc secondary voltage provided by the second ECU 110. The sensor I / O terminal 122 is also connected to the first communication terminal 106 of the first ECU 100 via a first current-limiting resistor 206. The pulled-up voltage of the sensor I / O terminal 122 can be registered by the first ECU 100 as a logic-level high condition on the first communication terminal 106. The sensor I / O terminal 122 is also connected to the second communication terminal 116 of the second ECU 110 via a second current-limiting resistor 216. The pulled-up voltage at the sensor I / O terminal 122 may be registered by the second ECU 110 as a logic level high condition on the second communication terminal 116 .

[0035] The first communication terminal 106 of the first ECU 100 may include input hardware configured for read-only communication. In other words, the first communication terminal 106 of the first ECU 100 may be configured as an input device that only reads or measures signals thereon and cannot write or change the value of voltage or other signals thereon. Alternatively, the first communication terminal 106 of the first ECU 100 may include input / output hardware configured for bidirectional communication.

[0036] The second ECU 110 may include input / output hardware that is connected to the second communication terminal 116 to provide two-way communication thereon. In other words, the second ECU 110 may be configured to both read from and write to the second communication terminal 116. For example, the second ECU 110 may read the voltage level on the second communication terminal 116 and also adjust the voltage level on the second communication terminal 116. The second ECU 110 may include one or more switching devices (e.g., transistors) that are configured to selectively connect the second communication terminal 116 to a ground or reference voltage in order to reduce or pull down the voltage on the second communication terminal 116. This varying voltage on the second communication terminal 116 may be received by the sensor 120 as a voltage variation on its sensor I / O terminal 122. This is merely an example, and other types of signaling may be used.

[0037] The sensor 120 may include input / output hardware connected to the sensor I / O terminals 122 to provide bidirectional communication thereon. In other words, the sensor 120 may be configured to both read signals from the sensor I / O terminals 122 and change the electrical state of the sensor I / O terminals 122 to write data thereto. For example, the sensor 120 may include one or more switching devices configured to selectively connect the sensor I / O terminals 122 to ground or a reference voltage in order to reduce or pull down the voltage on the sensor I / O terminals 122.

[0038] As long as Vcc secondary remains high, the sensor signal on the sensor I / O terminal 122 is pulled high. When the sensor 120 is communicating, it pulls the sensor I / O terminal 122 low, thereby generating a switching pattern on the sensor I / O terminal 122. The pulled-down voltage of the sensor I / O terminal 122 can be registered by the first ECU 100 as a logic level low condition on the first communication terminal 106. The pulled-down voltage of the sensor I / O terminal 122 can also be registered by the second ECU 110 as a logic level low condition on the second communication terminal 116.

[0039] When the second ECU 110 is turned on, Vcc secondary maintains the signal on the first communication terminal 106 of the first ECU 100 at a high level. The first communication terminal 106 of the first ECU 100 will read a high or switched state. When the second ECU 110 is turned off, Vcc secondary will also be turned off. The first communication terminal 106 of the first ECU 100 will remain in a logic low state, which the first ECU 100 can interpret as determining the shutdown state of the second ECU 110.

[0040] Figure 4A graph 250 is shown comprising a graph 252 of the voltage over time on a communication line between the sensor 122 and the second ECU 110. This may be the voltage at the sensor I / O terminal 122, for example.

[0041] Graph 252 shows a long pulse between time t0 and time t1, where the voltage on the communication line drops to a low voltage state. This long pulse may be generated by the second ECU 110 and may represent a command to the sensor 120, requesting that the sensor 120 provide data. Subsequently, and between time t2 and time t3, graph 252 shows a series of shorter low-voltage pulses, with varying intervals between pulses. These pulses between time t2 and t3 represent digital data transmitted from the sensor 120 via its sensor I / O terminal 122.

[0042] The first ECU 100 may be configured to monitor the communication line between the sensor 122 and the second ECU 110 and determine the status of the second ECU 110. Alternatively or additionally, the first ECU 100 may be configured to monitor data transmitted by the sensor 120 to independently monitor sensor data from the sensor 120.

[0043] The second ECU 110 can be configured to periodically transmit a command (i.e., a long pulse) to the sensor 120. If the first ECU 100 does not detect the command (i.e., the long pulse) within a predetermined period of time, the first ECU 110 can determine that the second ECU 110 is faulty. The first ECU 100 can use the logic level of the first communication terminal 106 to determine the state of the second ECU 110. The first ECU 100 can interpret the first communication terminal 106 as being in a maintained logic level low state (e.g., a voltage below a predetermined value) to determine that the second ECU 110 is in a closed state. Similarly, the first ECU 100 can interpret the first communication terminal 106 as being in a maintained logic level high state (e.g., a voltage above a predetermined value) to determine that the second ECU 110 is in an open state.

[0044] Figure 5 1 is a flow chart generally illustrating a first method 300 for determining ECU status in a dual-ECU system. The first method 300 may be implemented in software (e.g., a program executed by the first ECU 100). At 302, the first method 300 checks sensor signal protocol data. For example, the first processor 102 may check the status of data received on the first communication terminal 106 connected to the sensor 120.

[0045] At 304, the first method 300 determines whether the protocol check passes. For example, the first processor 102 may determine whether the sensor signal data is valid. This step 304 may include, for example, checking the parity of the sensor data, using a cyclic redundancy check (CRC), or any other technique used to verify protocol data. If the sensor signal is determined to be valid, the method 300 proceeds to 306; if the sensor signal is determined to be invalid, the first method 300 proceeds to 308.

[0046] At 306, the first method 300 increments or decrements the pin fault counter by 1 every 2 ms (milliseconds) until the pin fault counter reaches ten (10). When the pin fault counter reaches ten, the first method 300 proceeds to 316. It should be understood that 2 ms is an example, and step 306 may include incrementing or decrementing the pin fault counter by different values and / or at different rates.

[0047] At 308 , the first method 300 obtains a pin status. For example, the first processor 102 may determine whether the first communication terminal 106 connected to the sensor 120 is at a high logic level or a low logic level.

[0048] At 310, the first method 300 makes a determination based on the pin state. In response to determining that the pin (e.g., the first communication terminal 106) has a logic level high condition, the first method 300 proceeds to step 312. In response to determining that the pin (e.g., the first communication terminal 106) has a logic level low condition, the first method 300 proceeds to step 314.

[0049] At 312, the first method 300 decrements the pin fault counter by 1 every 2 ms (milliseconds) until the pin fault counter reaches zero (0). When the pin fault counter reaches zero, the first method 300 proceeds to 316. It should be understood that 2 ms is an example and that step 312 may include decrementing the pin fault counter by a different value and / or at a different rate.

[0050] At 314, the first method 300 increments the pin fault counter by 1 every 2 ms (milliseconds) until the pin fault counter reaches twenty (20). When the pin fault counter reaches 20, the first method 300 proceeds to 316. It should be understood that 2 ms is an example, and step 314 may include incrementing the pin fault counter by a different value and / or at a different rate.

[0051] At 316, the first method 300 makes a decision based on the value of the pin fault counter. In response to determining that the value of the pin fault counter is zero (0), the first method 300 proceeds to 318. In response to determining that the value of the pin fault counter is ten (10), the first method 300 proceeds to 320. In response to determining that the value of the pin fault counter is twenty (20), the first method 300 proceeds to 322.

[0052] At 318 , the first method 300 determines that a pin (eg, the first communication terminal 106 ) is stuck in a logic level high condition. Therefore, the first method 300 may determine that the second ECU 110 is powered but not functioning.

[0053] At 320 , the first method 300 determines that the pin (eg, the first communication terminal 106 ) is switched between a logic level high state and a logic level low state. Therefore, the first method 300 may determine that the second ECU 110 is powered on and operating.

[0054] At 322 , the first method 300 determines that the pin (eg, the first communication terminal 106 ) is stuck in a logic level low condition. Therefore, the first method 300 may determine that the second ECU 110 is powered off.

[0055] The software component that reads from this sensor uses a built-in protocol check to indicate whether the sensor signal is valid. As long as the first ECU 100 reads a valid signal, the sensor signal protocol check will pass. This indicates that both the sensor and the second ECU are communicating.

[0056] When the protocol check fails for the first ECU 100, this indicates that the sensor signal was not received as expected. In this case, the logic level of the pin is read on the first ECU 100. If it remains at a logic high or logic low for longer than a threshold timer (20ms CBE), the pin status is set to "stuck high" or "stuck low," respectively. This pin status can be used to determine the health status of the second ECU 110. The threshold timer can have any suitable value, and 20ms is merely an example.

[0057] The correlation shown in Table 1 below can be established between the pin status and the ECU status based on the protocol signature of the sensor signal. This correlation forms the basis for determining the health status of the second ECU 110.

[0058] Table 1

[0059]

[0060] All of the above logic is independent of the state of the IMC signal and the IMC communication channel. Therefore, the above logic can be used to determine the health state of the second ECU 110 even in the presence of an IMC fault.

[0061] The systems and methods of the present disclosure may use shared sensor signals from the sensor 120, which may include a torque sensor in an electric power steering system. Alternatively or additionally, the systems and methods of the present disclosure may use other types of shared sensors / protocols to determine the health status of the second ECU 110. The systems and methods of the present disclosure may utilize existing hardware and determine the health status of the second ECU 110 with minimal software updates, regardless of the IMC status.

[0062] According to one aspect of the present disclosure, even in the event of an IMC failure, an alternative method for determining the health status of an ECU is to route the battery voltage signal of one ECU to another ECU to check the ECU's status by monitoring the battery voltage signal. However, this may require additional hardware and / or modifications to existing system hardware.

[0063] Figure 6 4 is a flow chart generally illustrating a second method 400 for determining ECU status in a dual ECU system. The second method 400 may be implemented in software (e.g., a program executed by the first ECU 100). At 402, the second method 400 provides power to a sensor by the second ECU. For example, the second ECU 110 may provide power to the sensor 120 via the sensor power rail 202.

[0064] At 404 , the second method 400 determines, by the first ECU via the communication interface, that the second ECU is unresponsive.

[0065] At 406 , the second method 400 determines, by the first ECU, sensor signal protocol data based on a communication terminal connected to the sensor in response to determining that the second ECU is unresponsive.

[0066] At 408 , the second method 400 determines, by the first ECU, whether the sensor signal protocol data passes the protocol check.

[0067] At 410 , the second method 400 determines, by the first ECU, a pin status of a communication terminal in response to determining that the sensor signal protocol data fails a protocol check.

[0068] At 412, in response to determining that the sensor signal protocol data has failed the protocol check, the second method 400 determines, by the first ECU, a state of the second ECU based on a pin state of the communication terminal. The pin state may include at least one of: the communication terminal remaining in a given logic level state for a predetermined period of time, or the communication terminal switching between a logic level high state and a logic level low state instead of remaining in a given one of the logic level high state and the logic level low state for a predetermined period of time.

[0069] In some embodiments, determining the state of the second ECU at step 412 includes determining that the state of the second ECU is powered on and in operation in response to determining a pin state of the communication terminal switching between a logic high state and a logic low state.

[0070] In some embodiments, determining the state of the second ECU at step 412 includes determining the state of the second ECU as powered and unresponsive in response to determining that the communication terminal remains in a logic level high state for a first predetermined period of time.

[0071] In some embodiments, each of the first ECU and the second ECU is configured to communicate with the sensor using a Single Edge Nibble Transmission (SENT) protocol.

[0072] In some embodiments, determining the state of the second ECU at step 412 includes determining the state of the second ECU as powered off in response to determining that the communication terminal remains in a logic level low condition for a second predetermined period of time.

[0073] At 414 , the second method 400 performs, by the first ECU, a first control action in response to determining that the status of the second ECU is powered on and unresponsive, the first control action including at least initializing communication with a sensor.

[0074] At 416 , the second method 400 performs a second control action by the first ECU in response to determining that the status of the second ECU is powered off, wherein the second control action includes at least providing power to the sensor and initiating communication with the sensor.

[0075] According to one aspect of the present disclosure, a method for determining the status of an electronic control unit (ECU) in a dual-ECU system is provided. The method includes: determining, by a first ECU, the pin status of a communication terminal connected to a sensor; powering the sensor by a second ECU; and determining, by the first ECU, the status of the second ECU based on the pin status of the communication terminal.

[0076] In some embodiments, the method may further include determining, by the first ECU via the communication interface, that the second ECU is unresponsive. The step of determining the status of the second ECU may be performed in response to determining, via the communication interface, that the second ECU is unresponsive.

[0077] In some embodiments, the method may further include determining a state of the second ECU based on a pin state of the communication terminal remaining in a given logic level condition for a predetermined period of time.

[0078] In some embodiments, the method may further include: verifying the sensor signal protocol data based on the pin status of the communication terminal; and determining, by the first ECU, whether the sensor signal protocol data passes the protocol check. The step of determining the status of the second ECU may be dependent on the sensor signal protocol data passing the protocol check.

[0079] In some embodiments, the method may further include: determining by the first ECU that the pin state of the communication terminal switches between a logic level high state and a logic level low state instead of maintaining a given one of the logic level high state or the logic level low state for a predetermined time period; and in response to determining that the pin state of the communication terminal switches between a logic level high state and a logic level low state, determining by the first ECU that the state of the second ECU is powered on and in operation.

[0080] In some embodiments, the method may further include: determining, by the first ECU, a pin state in which the communication terminal remains in a logic level high state for a first predetermined time period; and in response to determining that the pin state in which the communication terminal remains in a logic level high state for a first predetermined time period, determining, by the first ECU, that the state of the second ECU is powered on and unresponsive.

[0081] In some embodiments, the method may further include: in response to determining that the state of the second ECU is powered on and unresponsive, executing, by the first ECU, a first control action, the first control action at least including initializing communication with a sensor.

[0082] In some embodiments, the method may further include: determining, by the first ECU, that the pin state of the communication terminal remains in a logic-low state for a second predetermined time period; and in response to determining that the pin state of the communication terminal remains in a logic-low state for a second predetermined time period, determining, by the first ECU, that the state of the second ECU is power-off.

[0083] In some embodiments, the method may further include: in response to determining that the state of the second ECU is power-off, executing a second control action by the first ECU.

[0084] In some embodiments, the second control action may include at least powering the sensor and initiating communication with the sensor.

[0085] According to one aspect of the present disclosure, a method for determining the status of an electronic control unit (ECU) in a dual-ECU system is provided. The method includes: powering a sensor by a second ECU; determining, by a first ECU via a communication interface, that the second ECU is unresponsive; in response to determining that the second ECU is unresponsive, determining, by the first ECU, sensor signal protocol data based on a communication terminal connected to the sensor; determining, by the first ECU, whether the sensor signal protocol data passes a protocol check; in response to determining that the sensor signal protocol data fails the protocol check, determining, by the first ECU, a pin state of the communication terminal; and in response to determining that the sensor signal protocol data fails the protocol check, determining, by the first ECU, the status of the second ECU based on the pin state of the communication terminal. The pin state may include at least one of: the communication terminal remaining in a given logic level state for a predetermined period of time, or the communication terminal switching between a logic high state and a logic low state instead of remaining in a given one of the logic high state and the logic low state for a predetermined period of time. Determining the status of the second ECU includes: determining that the status of the second ECU is powered on and operational in response to determining that the pin state of the communication terminal switches between a logic high state and a logic low state. The step of determining the state of the second ECU includes: in response to determining that the pin state of the communication terminal remains in a logic level high state for a first predetermined time period, determining that the state of the second ECU is powered on and unresponsive. Each of the first ECU and the second ECU can be configured to communicate with the sensor using a single edge nibble transmission (SENT) protocol. The step of determining the state of the second ECU includes: in response to determining that the pin state of the communication terminal remains in a logic level low state for a second predetermined time period, determining that the state of the second ECU is powered off. The method may also include: in response to determining that the state of the second ECU is powered on and unresponsive, the first ECU performs a first control action, the first control action at least including initializing communication with the sensor; and in response to determining that the state of the second ECU is powered off, the first ECU performs a second control action, wherein the second control action at least includes providing power to the sensor and initializing communication with the sensor.

[0086] According to one aspect of the present disclosure, a system for determining the state of an electronic control unit (ECU) in a dual ECU system is provided. The system includes: a sensor having a sensor output pin; a first ECU having a first communication terminal in electrical communication with the sensor output pin, the first ECU being configured to read sensor data from the sensor based on the pin state of the first communication terminal; and a second ECU having a second communication terminal in electrical communication with the sensor output pin, the second ECU being configured to read sensor data from the sensor based on the pin state of the second communication terminal, the second ECU providing power to a sensor power rail and biasing the voltages of the first communication terminal and the second communication terminal to a logic high state. The first ECU is configured to determine the state of the second ECU based on the pin state of the first communication terminal.

[0087] In some embodiments, the system may further include a communication interface providing communication between and between the first ECU and the second ECU.The first ECU may be configured to determine a status of the second ECU in response to determining via the communication interface that the second ECU is unresponsive.

[0088] In some embodiments, the first ECU may be configured to determine the state of the second ECU based on a pin state of the first communication terminal remaining at a given logic level condition for a predetermined period of time.

[0089] In some embodiments, each of the first ECU and the second ECU may be configured to communicate with the sensor using a Single Edge Nibble Transmission (SENT) protocol.

[0090] In some embodiments, the first ECU may be configured to determine that the pin state of the first communication terminal switches between a logic-level high state and a logic-level low state instead of remaining in a given one of the logic-level high state and the logic-level low state for a predetermined period of time. The first ECU may be configured to determine that the state of the second ECU is powered on and in operation in response to determining that the pin state of the first communication terminal switches between a logic-level high state and a logic-level low state.

[0091] In some embodiments, the first ECU may be configured to determine that the pin state of the first communication terminal remains in a logic-level high state for a first predetermined period of time. The first ECU may be configured to determine that the state of the second ECU is powered and unresponsive in response to determining that the pin state of the first communication terminal remains in a logic-level high state for the first predetermined period of time.

[0092] In some embodiments, the first ECU may be configured to, in response to determining that the status of the second ECU is powered on and unresponsive, perform a first control action, the first control action including at least initializing communication with a sensor.

[0093] In some embodiments, the first ECU may be configured to determine that the pin state of the first communication terminal remains in a logic-low state for a second predetermined period of time. The first ECU may be configured to determine that the state of the second ECU is power-off in response to determining that the pin state of the first communication terminal remains in a logic-low state for the second predetermined period of time.

[0094] In some embodiments, the first ECU is configured to, in response to determining that the second ECU is in a power-off state, execute a second control action, which may include at least providing power to the sensor and initiating communication with the sensor.

[0095] Although the present disclosure has been described in detail with reference to only a limited number of embodiments, it should be readily understood that the present disclosure is not limited to these disclosed embodiments. Rather, the present disclosure can be modified to include any number of variations, alterations, substitutions, or equivalent arrangements not heretofore described, but commensurate with the scope of the present disclosure. Additionally, although various embodiments of the present disclosure have been described, it should be understood that various aspects of the present disclosure may include only some of the described embodiments or combinations of various embodiments. Therefore, the present disclosure should not be considered limited by the foregoing description.

Claims

1. A method for determining a status of an electronic control unit (ECU) in a dual electronic control unit (ECU) system, comprising: providing a first ECU having a first communication terminal in electrical communication with a sensor and having a pin state representing data from the sensor; reading, by the first ECU, data from the sensor based on a pin state of the first communication terminal; reading data from the sensor by a second ECU through a second communication terminal that is in electrical communication with the sensor; The sensor is powered by the second ECU, thereby biasing the voltages of the first communication terminal and the second communication terminal to a logic-level high state; as well as The state of the second ECU is determined by the first ECU based on the pin state of the first communication terminal.

2. The method according to claim 1, further comprising: determining, by the first ECU via the communication interface, that the second ECU is unresponsive, and Wherein, determining the status of the second ECU is performed in response to determining, via the communication interface, that the second ECU is unresponsive.

3. The method according to claim 1, further comprising: The state of the second ECU is determined based on a pin state of the first communication terminal remaining in a given logic level condition for a predetermined period of time.

4. The method according to claim 1, further comprising: verifying sensor signal protocol data based on a pin state of the first communication terminal; as well as The first ECU determines whether the sensor signal protocol data passes the protocol check, Determining the state of the second ECU is dependent on the sensor signal protocol data failing the protocol check.

5. The method according to claim 1, further comprising: determining, by the first ECU, that the first communication terminal switches between the logic-level high state and the logic-level low state rather than remaining in a pin state of a given state, the logic-level high state or the logic-level low state, for a predetermined period of time; as well as In response to determining that the pin state of the first communication terminal switches between the logic level high state and the logic level low state, the first ECU determines that the state of the second ECU is powered on and in operation.

6. The method according to claim 1, further comprising: determining, by the first ECU, that the first communication terminal remains in a pin state of a logic level high state for a first predetermined period of time; as well as In response to determining that the first communication terminal remains in the pin state of the logic level high condition for the first predetermined period of time, the first ECU determines that the state of the second ECU is powered and unresponsive.

7. The method according to claim 6, further comprising: In response to determining that the state of the second ECU is powered on and unresponsive, the first ECU executes a first control action, the first control action including at least initializing communication with the sensor.

8. The method according to claim 1, further comprising: determining, by the first ECU, that the first communication terminal remains in a pin state at a logic level low state for a second predetermined period of time; as well as In response to determining that the first communication terminal remains in the pin state of the logic level low condition for the second predetermined period of time, the first ECU determines that the state of the second ECU is power-off.

9. The method according to claim 8, further comprising: In response to determining that the state of the second ECU is powered off, a second control action is executed by the first ECU.

10. The method according to claim 9, wherein: The second control action includes at least providing power to the sensor and initiating communication with the sensor.

11. A method for determining a status of an electronic control unit (ECU) in a dual electronic control unit (ECU) system, the dual ECU system having a first ECU and a second ECU, the method comprising: reading sensor data from the sensor by the first ECU through a first communication terminal that is in electrical communication with the sensor; reading sensor data from the sensor by the second ECU through a second communication terminal that is in electrical communication with the sensor; supplying power to the sensor by the second ECU, thereby biasing a voltage of each of the first communication terminal and the second communication terminal to a logic level high condition; determining, by the first ECU via the communication interface, that the second ECU is unresponsive; In response to determining that the second ECU is unresponsive, determining, by the first ECU, sensor signal protocol data based on a pin state of the first communication terminal; determining, by the first ECU, whether the sensor signal protocol data passes a protocol check; In response to determining that the sensor signal protocol data fails the protocol check, determining, by the first ECU, a pin state of the first communication terminal; In response to determining that the sensor signal protocol data fails the protocol check, determining, by the first ECU, a state of the second ECU based on a pin state of the first communication terminal, wherein the pin state includes at least one of: the first communication terminal remaining in a given logic level state for a predetermined period of time, or the first communication terminal switching between the logic level high state and the logic level low state instead of remaining in a given state of the logic level high state or the logic level low state for the predetermined period of time, The determining of the state of the second ECU includes: in response to determining that the pin state of the first communication terminal is switched between the logic level high state and the logic level low state, determining that the state of the second ECU is powered on and in operation; The determining of the state of the second ECU includes: in response to determining that the first communication terminal remains in the pin state of the logic level high state for a first predetermined time period, determining that the state of the second ECU is powered on and unresponsive; wherein each of the first ECU and the second ECU is configured to communicate with the sensor using a single edge nibble transmission (SENT) protocol; wherein determining the state of the second ECU comprises: in response to determining that the first communication terminal remains in the pin state of the logic level low condition for a second predetermined period of time, determining that the state of the second ECU is powered off; In response to determining that the state of the second ECU is powered on and unresponsive, the first ECU executes a first control action, the first control action at least including initializing communication with the sensor; and In response to determining that the state of the second ECU is power-off, the first ECU executes a second control action, wherein the second control action at least includes providing power to the sensor and initiating communication with the sensor.

12. A system for determining a status of an electronic control unit (ECU) in a dual electronic control unit (ECU) system, comprising: a sensor having a sensor output pin; a first ECU having a first communication terminal in electrical communication with the sensor output pin, the first communication terminal having a pin state representing sensor data from the sensor, the first ECU being configured to read the sensor data from the sensor based on the pin state of the first communication terminal; as well as a second ECU having a second communication terminal in electrical communication with the sensor output pin, the second ECU being configured to read the sensor data from the sensor based on a pin state of the second communication terminal, the second ECU providing power to a sensor power rail and biasing the voltages of the first communication terminal and the second communication terminal to a logic-level high condition, and The first ECU is configured to determine a state of the second ECU based on a pin state of the first communication terminal.

13. The system of claim 12, further comprising: a communication interface providing communication between the first ECU and the second ECU and between the first ECU and the second ECU, and The first ECU is configured to determine a status of the second ECU in response to determining via the communication interface that the second ECU is unresponsive.

14. The system according to claim 12, wherein: The first ECU is configured to determine a state of the second ECU based on a pin state of the first communication terminal remaining in a given logic level condition for a predetermined period of time.

15. The system according to claim 12, wherein: Each of the first ECU and the second ECU is configured to communicate with the sensor using a single edge nibble transmission (SENT) protocol.

16. The system of claim 12, wherein: The first ECU is configured to determine a pin state of the first communication terminal that switches between the logic level high state and the logic level low state instead of remaining in a given state of the logic level high state or the logic level low state for a predetermined period of time, and The first ECU is configured to determine that the state of the second ECU is powered on and in operation in response to determining that the pin state of the first communication terminal is switched between the logic level high state and the logic level low state.

17. The system of claim 12, wherein: The first ECU is configured to determine that the first communication terminal remains in a pin state of a logic level high condition for a first predetermined period of time, and The first ECU is configured to determine that the state of the second ECU is powered on and unresponsive in response to determining that the first communication terminal remains in the pin state of the logic level high state for the first predetermined time period.

18. The system according to claim 17, wherein: The first ECU is configured to, in response to determining that the status of the second ECU is powered on and unresponsive, perform a first control action, the first control action including at least initializing communication with the sensor.

19. The system of claim 12, wherein: The first ECU is configured to determine that the first communication terminal remains in a pin state of a logic level low condition for a second predetermined period of time, and The first ECU is configured to determine that the state of the second ECU is power-off in response to determining that the first communication terminal remains in the pin state of the logic level low state for the second predetermined time period.

20. The system of claim 19, wherein: The first ECU is configured to execute a second control action in response to determining that the state of the second ECU is powered off, wherein the second control action includes at least providing power to the sensor and initiating communication with the sensor.

Citation Information

Patent Citations

  • Fault diagnosis of electronic control unit (ECU)

    US10865726B2

  • Architecture for a driving assistance system with conditional automation

    US20180267535A1