Systems and methods for storing critical data in electronic control modules
By using FRAM and a corresponding circuit detection system in the engine control module, the problem of data loss caused by unexpected power failure was solved, enabling rapid and reliable storage and recovery of critical data.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CUMMINS INC
- Filing Date
- 2021-07-07
- Publication Date
- 2026-04-21
AI Technical Summary
In the event of an unexpected power failure, critical data in the engine control module is easily lost, and existing technologies cannot effectively preserve it.
Ferroelectric random access memory (FRAM) is used to store critical data. When a power failure is detected, the data is immediately written to the FRAM through system monitoring circuit and data storage circuit. Combined with battery detection and key switch detection circuit, the integrity of the data is ensured.
In the event of a power outage, it can quickly and reliably save critical data, reduce the risk of data loss, and ensure that the data can be recovered when power is restored.
Smart Images

Figure CN115956158B_ABST
Abstract
Description
[0001] Cross-references to related applications
[0002] This application claims priority and benefit to Indian Patent Application No. 202041036295, filed on August 24, 2020, the entire contents of which are incorporated herein by reference. Technical Field
[0003] This disclosure relates to systems and methods for storing critical data in an engine control module.
[0004] background
[0005] Engine-driven systems and devices (e.g., automotive systems) may include a power source and / or battery controlled by a key switch. In an automotive system, the automotive battery is a rechargeable battery that provides power to start the engine. The power source and / or battery controlled by the automotive key switch supplies power to the vehicle's engine throughout the vehicle's operation. In engine-driven and battery-driven systems and devices with electronic control components (e.g., in vehicles with an engine control module (ECM), engine control unit (ECU), or similar electronic components), an unexpected power-down event may result in the loss of critical ECM data. When an unexpected power outage occurs, such as when the battery is removed before allowing the ECM to shut down properly, the ECM may not have sufficient time to perform data saving operations.
[0006] Overview
[0007] Example embodiments relate to controllers (e.g., vehicle controllers). A controller for a vehicle includes at least one processor and at least one memory storing instructions that, when executed by the processor, cause the controller to perform various operations. Operations include determining that a power outage has occurred to the controller, and, in response to this determination, saving operational data to ferroelectric random access memory (FRAM). According to various arrangements, the FRAM is included in and / or coupled to the controller (e.g., as a component on a circuit board of the controller, as a component on a separate circuit board that is communicatively coupled to the controller, etc.). In some arrangements, determining that a power outage has occurred includes determining that a power supply configured to provide power to the controller is not operating. In some arrangements, the power supply includes a battery. In some arrangements, the power supply includes a capacitor. In some arrangements, saving operational data to the FRAM includes comparing the operational data with a previous version of operational data previously stored in the FRAM, and, if it is determined that the operational data differs from the previous version, overwriting the previous version previously stored in the FRAM with the operational data. In some configurations, operational data includes vehicle speed, engine speed, engine throttle power, acceleration, or accelerator pedal status. In some configurations, the controller is configured to periodically save operational data to the FRAM before a power failure is detected. In some configurations, the FRAM is a double-buffered FRAM.
[0008] Another example embodiment relates to a method for storing critical operational data of an engine control module (ECM), the method comprising determining that a power outage to the ECM has occurred, including determining that a power source configured to supply power to the ECM is not operating, and in response to the determination, storing the operational data to a ferroelectric random access memory (FRAM). According to various arrangements, the FRAM is included in and / or coupled to the controller (e.g., as a component on a circuit board of the controller, as a component on a separate circuit board communicatively coupled to the controller, etc.). In some arrangements, the power source includes at least one of a battery and a capacitor. In some arrangements, storing the operational data to the FRAM includes comparing the operational data with a previous version of operational data previously stored in the FRAM, and if it is determined that the operational data differs from the previous version, overwriting the previous version stored in the FRAM with the operational data. In some arrangements, the operational data includes vehicle speed, engine speed, engine throttle power, acceleration, or accelerator pedal status. In some arrangements, the ECM is configured to perform the operation of periodically storing operational data to the FRAM before a power outage is determined to have occurred. In some configurations, the FRAM is a double-buffered FRAM.
[0009] Another example embodiment relates to a non-transitory computer-readable medium including computer-executable instructions stored on the medium, which, when executed by one or more processors, perform operations including: determining that a power outage to the ECM has occurred, including determining that a power source configured to supply power to the ECM is not operating; and, in response to the determination, saving operational data to ferroelectric random access memory (FRAM). According to various arrangements, the FRAM is included in and / or coupled to the controller (e.g., as a component on a circuit board of the controller, as a component on another circuit board separate from and communicatively coupled to the controller, etc.). In some arrangements, the power source includes at least one of a battery and a capacitor. In some arrangements, the operation of saving operational data to the FRAM includes comparing the operational data with a previous version of operational data previously stored in the FRAM, and if it is determined that the operational data is different from the previous version, overwriting the previous version previously stored in the FRAM with the operational data. In some arrangements, the operational data includes vehicle speed, engine speed, engine throttle power, acceleration, or accelerator pedal status. In some configurations, the ECM is configured to periodically save operational data to the FRAM before a power outage is detected. In some configurations, the FRAM is a double-buffered FRAM.
[0010] These and other features, as well as the organization and manner of their operation, will become apparent from the following detailed description taken in conjunction with the accompanying drawings. Brief description of the attached diagram
[0012] Figure 1 This is a schematic diagram of a vehicle having an engine and a controller coupled to an exhaust aftertreatment system according to an example embodiment.
[0013] Figure 2 It is according to the example embodiment for use by Figure 1 A schematic representation of the system architecture in which the controller stores critical data.
[0014] Figure 3 This is an example embodiment of saving critical data to a file during the initial shutdown event, performed according to the example embodiment. Figure 1 A flowchart of a method for using a controller associated with non-volatile memory.
[0015] Figure 4 This refers to the recovery of previously saved critical data and the saving of critical data to a database during subsequent shutdown events, according to the example embodiment. Figure 1 A flowchart of a method for using a controller associated with non-volatile memory.
[0016] Detailed description
[0017] The following is a more detailed description of various concepts and implementations related to methods, devices, and systems for storing critical data in the engine control module. Because the concepts described are not limited to any particular implementation, the various concepts presented herein can be implemented in any number of ways. Examples of specific implementations and applications are provided primarily for illustrative purposes.
[0018] Referring generally to the accompanying drawings, the various embodiments disclosed herein relate to systems, apparatus, and methods for storing critical data in an engine control module of a vehicle. A controller for a vehicle (e.g., an engine control module (ECM), engine control unit (ECU), etc.) includes at least one processor and at least one memory storing instructions that, when executed by the processor, cause the controller to perform various operations. Operations include determining that a power outage has occurred to the controller. The controller may be powered by an onboard battery and / or capacitors (or other power sources, such as an alternator). In response to determining that a power outage has occurred, the operation includes determining whether a key switch associated with the vehicle's engine is engaged; and, when the key switch is engaged, storing operational data in a ferroelectric random access memory (FRAM) coupled to the controller.
[0019] Now for reference Figure 1 The illustration depicts a vehicle 100 having an engine and controller coupled to an example exhaust aftertreatment system according to an example embodiment. The vehicle 100 may be a highway or off-road vehicle, including but not limited to long-haul trucks, medium-duty trucks (e.g., pickups), tanks, aircraft, locomotives, various types of industrial equipment (excavators, bulldozers, tractors, lawnmowers, etc.). In other embodiments, the vehicle 100 may be or include stationary equipment, such as a generator set. The vehicle 100 typically includes an engine system 10, which includes an internal combustion engine 14, an exhaust aftertreatment system 18 in exhaust gas receiving communication with the engine 14, a driveline 50 including a transmission 52, operator input / output (I / O) devices 122, and a controller 38 coupled to various components. Each of these components is described in more detail below.
[0020] According to one embodiment and as shown in the figure, engine 14 is configured as a compression-ignition internal combustion engine utilizing diesel fuel. The size / displacement of engine 14 may vary depending on the application (e.g., 30L to 120L). Furthermore, the configuration of engine 14 may also vary (e.g., V6 engine, V8, inline, etc.). In various alternative embodiments, engine 14 may be configured as a variety of other types of engines. Other examples of engine 14 include, but are not limited to, other internal combustion engines (e.g., gasoline, natural gas), hybrid engines (e.g., a combination of an internal combustion engine and an electric motor), etc. In the example shown, engine 14 includes a plurality of cylinders 23. The plurality of cylinders 23 may be arranged as one or more cylinder banks 25. In one example embodiment, the cylinders of the plurality of cylinders 23 are oriented in a V-shaped configuration (e.g., two cylinder banks 25 as shown).
[0021] The exhaust aftertreatment system 18 is in exhaust gas receiving communication with some or each cylinder bank 25. As shown in the example embodiment, the exhaust aftertreatment system 18 includes a diesel particulate filter (DPF) 54, a diesel oxidation catalyst (DOC) 58, a selective catalytic reduction (SCR) system 62 with an SCR catalyst 66, and an ammonia oxidation (AMOx) catalyst 70. The SCR system 62 may also include a reductant delivery system having a diesel exhaust fluid (DEF) source that supplies DEF to a DEF doser via a DEF line. Those skilled in the art will understand that exemplary embodiments have been discussed herein, and various components of the aftertreatment system 18 may be rearranged, combined, and / or omitted.
[0022] In operation, and according to the example embodiment, combustion air enters the engine 14 through the engine intake manifold 34 and flows to multiple cylinders 23. The engine 14 combusts air and fuel to generate power to propel the vehicle 100. The combustion gases (i.e., exhaust gases) are then discharged from the cylinders 23. In the exhaust flow direction indicated by the directional arrow 84, the exhaust gases flow from the engine 14 into the inlet pipe 86 of the exhaust aftertreatment system 18. The exhaust gases flow from the inlet pipe 86 into the DOC 58 and exit the DOC 58 into the first exhaust pipe 90A. The exhaust gases flow from the first exhaust pipe 90A into the DPF 54 and exit the DPF 54 into the second exhaust pipe 90B. The exhaust gases flow from the second exhaust pipe 90B into the SCR catalytic converter 66 and exit the SCR catalytic converter 66 into the third exhaust pipe 90C. As the exhaust gases flow through the second exhaust pipe 90B, DEF can be periodically metered into it via a DEF metering device. Therefore, the second exhaust duct 90B can also be used as a decomposition chamber or pipe to facilitate the decomposition of DEF or other reducing agents into ammonia. Exhaust gas flows into the AMOx catalytic converter 70 from the third exhaust duct 90C and exits the AMOx catalytic converter 70 into the outlet duct 94 before being discharged from the exhaust aftertreatment system 18. Based on the above, in the illustrated embodiment, the DOC 58 is positioned upstream of the DPF 54 and the SCR catalytic converter 66, which is positioned downstream of the DPF 54 and upstream of the AMOx catalytic converter 70. However, in alternative embodiments, other arrangements of the components of the exhaust aftertreatment system 18 are possible (e.g., the AMOx catalytic converter 70 may be excluded from the exhaust aftertreatment system 18, the relative positioning of components may differ, etc.).
[0023] DOC 58 can be any of a variety of flow-through designs. Typically, DOC 58 is configured to oxidize at least some of the particulate matter in the exhaust gas (e.g., the soluble organic portion of soot) and reduce unburned hydrocarbons and CO in the exhaust gas into compounds less harmful to the environment. DPF 54 can be any of a variety of flow-through designs and is configured to reduce the concentration of particulate matter (e.g., soot and ash) in the exhaust gas to, for example, compliance with one or more required emission standards.
[0024] As described above and in this example configuration, the SCR system 62 may include a reductant delivery system having a DEF source, a pump, and a metering dispenser (not shown). The SCR catalyst 66 may be any of a variety of known catalysts. For example, in some implementations, the SCR catalyst 66 is a vanadium-based catalyst, while in others, it is a zeolite-based catalyst, such as a Cu zeolite or Fe zeolite catalyst. The AMOx catalyst 70 may be any of a variety of flow-through catalysts configured to react with ammonia to primarily produce nitrogen. As briefly described above, the AMOx catalyst 70 is configured to remove ammonia that has escaped or left the SCR catalyst 66 and has not reacted with NOx in the exhaust gas. In certain cases, the exhaust aftertreatment system 18 may operate with or without an AMOx catalyst. Furthermore, although the AMOx catalyst 70 is shown as... Figure 1 The SCR catalyst 66 is a separate unit, but in some implementations, the AMOx catalyst 70 can be integrated with the SCR catalyst 66. For example, the AMOx catalyst 70 and the SCR catalyst 66 can be located in the same housing.
[0025] As described above, although the illustrated exhaust aftertreatment system 18 includes one of the DOC 58, DPF 54, SCR catalyst 66, and AMOx catalyst 70 positioned relative to each other along the exhaust flow path, in other embodiments, the exhaust aftertreatment system 18 may include any one or fewer of a variety of catalysts, and / or their relative positioning may differ. Furthermore, although the DOC 58 and AMOx catalyst 70 are non-selective catalysts, in some embodiments, the DOC 58 and AMOx catalyst 70 may be selective catalysts.
[0026] The vehicle 100 is also shown to include a drivetrain 50, which includes a transmission 52. The drivetrain 50 may include various additional components (not shown), including drive shafts, axles, wheels, etc. The transmission 52 receives power from the engine 14 and provides rotational power to the final drive (e.g., wheels) of the vehicle 100. In some embodiments, the transmission 52 is a continuously variable transmission (CVT). In other embodiments, the transmission 52 is a geared transmission including multiple gears. The transmission 52 may be an automatic, manual, or auto-manual type transmission. The transmission 52 may include one or more sensors (virtual or real sensors) coupled to the controller 38 and providing information or data about the operation of the transmission 52 (e.g., current gear or operating mode, temperature in the transmission, etc.).
[0027] The operator I / O device 122 is coupled to the controller 38, enabling information to be exchanged between the controller 38 and the operator I / O device 122, wherein the information may involve Figure 1 The operator I / O device 122 enables the operator (or another passenger) of the vehicle 100 to communicate with the controller 38 of the vehicle 100 and one or more components or (described below) the determination / command / instruction, etc. The operator I / O device 122 enables the operator of the vehicle 100 (or another passenger) to communicate with the controller 38 of the vehicle 100 and one or more components. Figure 1 The operator I / O device 122 may include a steering wheel, joystick, accelerator pedal, brake pedal, etc. Furthermore, the operator I / O device 122 may include an interactive display, touchscreen device, one or more buttons and switches, voice command receiver, etc. Through the operator I / O device 122, the controller 38 can receive and provide various commands, data, and information regarding the operations described herein.
[0028] The vehicle 100 is also shown to include a variety of sensors. These sensors can be strategically arranged throughout the vehicle 100. For example, an engine intake manifold temperature sensor 106 may be located at or near the engine intake manifold 34 of the engine system 10 to detect the temperature of the air entering the engine system 10. An engine coolant temperature sensor 110 may be strategically located to determine the temperature of the engine coolant in the engine 14.
[0029] Sensors can also be strategically positioned throughout the exhaust aftertreatment system 18 and in or near the external environment. Sensors can communicate with the controller 38 to monitor the operating conditions of the engine system 10 and various environmental conditions. Sensors associated with the aftertreatment system may include a NOx sensor 98 and a temperature sensor 102 located within the exhaust aftertreatment system 18, an engine intake manifold temperature sensor 106, and an ambient (e.g., outside) temperature sensor 114. In this respect, the controller 38 can receive data from one or more sensors. As shown, the temperature sensor 102 is associated with the SCR catalyst 66, exhaust manifold 68, DOC 58, and DPF 54. Therefore, temperature data indicating the temperature of each of these components can be tracked and monitored. For example, with respect to the SCR catalyst 66, the temperature sensor 102 is strategically positioned to detect the temperature of the exhaust gases flowing into and out of the SCR catalyst 66.
[0030] As mentioned above regarding transmission 52, sensors can be strategically arranged throughout the drivetrain 50. Sensors coupled to the drivetrain 50 may include a ground speed sensor 55 configured to determine the ground speed of vehicle 100, a vehicle weight sensor 56 configured to determine the weight of vehicle 100, and / or a transmission position sensor 59 configured to determine the transmission state of vehicle 100 (e.g., forward, reverse, neutral, selected gear, etc.). Sensors can also be strategically arranged throughout the operator input / output (I / O) device 122. For example, operator I / O device 122 may include an accelerator pedal and may be associated with an accelerator pedal position sensor 60. Sensors may also include pressure sensors, accelerometers, etc.
[0031] The controller 38 is configured to at least partially control the operation of the engine system 10 and associated subsystems, such as the internal combustion engine 14, exhaust aftertreatment system 18, transmission system 50, and / or operator I / O devices 122. Communication between and within components can be via any number of wired or wireless connections. For example, wired connections may include serial cables, fiber optic cables, CAT5 cables, or any other form of wired connection. In contrast, wireless connections may include the Internet, Wi-Fi, cellular, radio, etc. In one embodiment, a controller local area network (“CAN”) bus provides the exchange of signals, information, and / or data. The CAN bus includes any number of wired and wireless connections. Because the controller 38 is communicatively coupled to… Figure 1 The system and components, so the controller 38 is configured to... Figure 1 and / or Figure 2 One or more components shown receive data. For example, the data may include vehicle operation data (e.g., accelerator pedal position, required torque, engine speed, vehicle speed, engine temperature, etc.) received via one or more sensors and / or determined by the controller based on information received from the sensors. Regarding... Figure 2 The structure and function of controller 38 are further described.
[0032] Now for reference Figure 2 This illustrates a method for using an example embodiment of a device... Figure 1This is a schematic representation of a system architecture 200 for storing critical data by controller 38. System architecture 200 allows for operations to store, restore, and / or manage critical data and corresponding fast-access non-volatile memory (e.g., one or more ferroelectric random access memory modules (FRAM) 208). According to various embodiments, operations may include initial data storage operations, such as detecting a power-off event (e.g., battery removal, key switch off, etc.), triggering data transfer to store data to the fast-access non-volatile medium (e.g., FRAM 208), and / or causing controller 38 to release a power-off signal. Operations may also include subsequent data and memory management operations, including, for example, restoring data from the fast-access non-volatile medium (e.g., FRAM 208), preparing the fast-access non-volatile medium (e.g., FRAM 208) for subsequent read / write operations, battery detection and key switch operation, monitoring operating conditions associated with the vehicle to determine if the vehicle is running, and / or performing periodic data storage / updates in the fast-access non-volatile medium (e.g., FRAM 208).
[0033] System architecture 200 may be part of the on-board electronic control system of vehicle 100. As shown, system architecture 200 includes engine 14, battery 16, converter 19, key switch 20, sensor 22, actuator 24, and controller 38. In some embodiments, controller 38 is an engine control module (ECM), sometimes also referred to as engine control unit (ECU).
[0034] As shown, system architecture 200 includes a battery 16 and a converter 19. In an example embodiment, battery 16 is a rechargeable automotive battery configured to power various components of system architecture 200, including controller 38. According to various embodiments, battery 16 may be a lithium-ion battery, a lithium-air battery, a lithium-sulfur battery, etc. As shown, battery 16 may be a 12-volt battery. In some embodiments, multiple low-voltage batteries (e.g., two 12-volt batteries) are connected in series to provide a 24-volt power supply. Battery 16 may be arranged in battery terminals electrically coupled to converter 19 via a suitable connector. As shown, converter 19 is a power converter configured to convert the power supply voltage (e.g., 12 volts, 24 volts, etc.) generated by battery 16 into a circuit power supply voltage (e.g., 3.3 volts, 5 volts, etc.) suitable for powering controller 38 and / or its various components.
[0035] As shown in the figure, system architecture 200 includes a key switch 20. In an example embodiment, key switch 20 is an energizing switch for engine 14. For example, an operator can insert a key and turn it to complete the circuit, causing an alternator or other powered source (battery) to crank the starter motor and start the engine. In other embodiments, a push-button starter may be used, where a user presses a button to start the engine.
[0036] As shown in the figure, system architecture 200 includes a controller 38. The controller 38 is configured to control at least some operations of one or more systems of the vehicle, such as controlling some operations of the engine 14, battery 16, converter 19, key switch 20, sensor 22, actuator 24, etc. The controller 38 may be, or may be coupled to, an engine control unit or various other types of electronic control units for the vehicle. In some embodiments, the controller 38 is a specific unit. In other embodiments, the vehicle 100 includes multiple vehicle controllers 38. In this regard, the various circuits of the controllers 38 discussed below may be distributed in separate physical locations within the vehicle.
[0037] As shown in the figure, the controller 38 includes processing circuitry 202. Processing circuitry 202 includes a processor 204, a main memory device 206, a Fast Access Non-Volatile Memory (FRAM) 208, a system monitoring circuit 210, a data storage circuit 212, an SPI / QSPI chipset 216, and a communication interface 220. The FRAM 208, system monitoring circuitry 210, data storage circuitry 212, and SPI / QSPI chipset 216 include battery detection and key switch detection circuitry 214.
[0038] Processing circuitry 202 may be constructed or configured to execute or implement the instructions, commands, and / or control processes described herein with respect to various circuits (e.g., system monitoring circuitry 210, data storage circuitry 212, and / or battery detection and key switch detection circuitry 214). Therefore, the depicted configurations indicate that these circuits are implemented as machine- or computer-readable media that may be stored by main memory device 206. However, this illustration is not intended to be limiting, as other embodiments in which at least one circuit is configured as a hardware unit are contemplated. All such combinations and variations are considered to fall within the scope of this disclosure.
[0039] Processor 204 may be implemented as a single-chip or multi-chip processor, digital signal processor (DSP), application-specific integrated circuit (ASIC), field-programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof, designed to perform the functions described herein. The processor may be a microprocessor or any conventional processor or state machine. Processor 204 may also be implemented as a combination of computing devices, such as a combination of a digital signal processor (DSP) and a microprocessor, multiple microprocessors, one or more microprocessors combined with a DSP core, or any other such configuration. In some embodiments, one or more processors may be shared by multiple circuits that may include or otherwise share the same processor, which in some example embodiments may execute instructions stored or otherwise accessed via different regions of main memory device 206 and / or FRAM 208. Alternatively or additionally, the one or more processors may be configured to perform or otherwise perform a particular operation independently of one or more coprocessors. In other example embodiments, two or more processors may be coupled via a bus to enable independent, parallel, piped, or multithreaded instruction execution. All of these variations are considered to fall within the scope of this disclosure.
[0040] Main memory device 206 (e.g., memory, memory cell, storage device) may include one or more devices (e.g., RAM, ROM, flash memory, hard disk storage) for storing data and / or computer code that performs or facilitates the various processes, layers, and modules described herein. Main memory device 206 may be coupled to processor 204 to provide processor 204 with computer code or instructions for performing at least some of the processes described herein. Furthermore, main memory device 206 may be or include tangible, non-transient volatile memory or non-volatile memory. Therefore, main memory device 206 may include database components, object code components, scripting components, or any other type of information structure for supporting the various activities and information structures described herein.
[0041] FRAM 208 may include one or more fast-access non-volatile memory cells, such as one or more ferroelectric random access memory cells. Advantageously, FRAM 208 supports fast read / write operations and is configured to retain saved data under power-off conditions. In example embodiments, the FRAM 208 memory cells may include a ferroelectric semiconductor layer and / or a ferroelectric insulator layer (e.g., lead zirconate titanate, etc.) disposed on a silicon substrate. According to various embodiments, FRAM 208 may be configured to interface with various circuits (such as system monitoring circuitry 210, data retention circuitry 212, and / or battery detection and key switch detection circuitry 214) via SPI / QSPI chipset 216. System monitoring circuitry 210, data retention circuitry 212, and / or battery detection and key switch detection circuitry 214 may initiate read / write operations on FRAM 208 to retain critical data (e.g., vehicle operating parameters, etc.) when powered off. System monitoring circuit 210, data storage circuit 212, and / or battery detection and key switch detection circuit 214 may include one or more memory devices for storing instructions executable by processor 204. For example, battery detection and key switch detection circuit 214 may include FRAM 208 and SPI / QSPI chipset 216. The structure and operation of these circuits are described in further detail herein.
[0042] In an example embodiment, controller 38 may be configured to electronically monitor and control various subsystems within a vehicle. As shown, system architecture 200 includes sensor 22 and actuator 24. Controller 38 is coupled to sensor 22, and particularly electrically coupled to sensor 22, and is configured to receive data collected by sensor 22. In an example embodiment, sensor 22 is a physical or virtual (e.g., composite or multi-factor) sensor configured to collect information about vehicle operation, including rail pressure (e.g., common rail fuel injection pressure in a direct injection engine), vehicle speed, engine speed, engine throttle power, acceleration, accelerator pedal state, etc. Controller 38 is also electrically coupled to actuator 24 and configured to generate electronic commands to cause actuator 24 to perform various operations. Actuator 24 may include a vehicle control actuator configured to convert electrical signals generated or transmitted by controller 38 into physical actions in braking systems, steering systems, engine control systems, etc. In an example embodiment, controller 38 is communicatively coupled to battery detection and key switch detection circuit 214 and is configured to exchange data and electronic commands with it. In some embodiments, controller 38 may be configured to propagate (i.e., to appropriate actuators 22, etc.) electronic commands generated by battery detection and key switch detection circuit 214 according to shutdown and data retention logic implemented by battery detection and key switch detection circuit 214.
[0043] The battery detection and key switch detection circuit 214 is configured to manage data save and restore operations. These operations may include initial data save operations, such as detecting power failure events (e.g., battery removal, key switch off, etc.), triggering data transfer to save data to FRAM 208 via SPI / QSPI chipset 216, and / or causing controller 38 to release the power-down signal. Operations may also include subsequent data and memory management operations, including, for example, restoring data from FRAM 208 and transferring data to main memory device 206, preparing FRAM 208 for subsequent read / write operations, activating battery detection and key switch operations, monitoring operating conditions associated with the vehicle (e.g., by using data provided by various sensors) to determine that the vehicle is running, and / or performing periodic data save / updates in FRAM 208.
[0044] According to various embodiments, the above operations can be performed by system monitoring circuitry 210 and / or data storage circuitry 212. In some embodiments, system monitoring circuitry 210 is configured to detect power outage events associated with a power source configured to power controller 38. The power source may include a battery, capacitor, etc. In some embodiments, system monitoring circuitry 210 is configured to determine the state of key switch 20 associated with engine 14, such that various FRAM 208 management and data storage operations can be performed based on its state. In some embodiments, system monitoring circuitry 210 is configured to receive various operating parameters associated with the operation of the vehicle and initiate specific FRAM 208 management and / or data storage operations based on the values of these parameters, as further described herein. In some embodiments, data storage circuitry 212 is configured to perform media management operations of FRAM 208, save data to FRAM 208, retrieve data from FRAM 208, and / or verify data previously saved to FRAM 208 during a previous shutdown event, as further described herein.
[0045] In one configuration, system monitoring circuitry 210, data storage circuitry 212, and / or battery detection and key switch detection circuitry 214 are implemented as machine- or computer-readable media storing instructions executable by a processor (e.g., processor 204). As described herein and in other uses, machine-readable media facilitate the performance of specific operations to achieve the reception and transmission of data. For example, machine-readable media may store and provide instructions (e.g., commands, etc.) for, for example, acquiring data. In this regard, machine-readable media may include programmable logic defining the frequency of data acquisition (or data transmission). Computer-readable media may include code written in any programming language, including but not limited to Java and any conventional procedural programming language, such as the "C" programming language or similar programming languages. Computer-readable program code may be executed on one or more processors. In the latter case, processors may be interconnected via a suitable type of network (e.g., CAN bus, etc.).
[0046] In another configuration, the system monitoring circuit 210, data storage circuit 212, and / or battery detection and key switch detection circuit 214 are implemented as hardware units, such as electronic control units. Therefore, some or all of these circuits can be embodied as one or more circuit components, including but not limited to processing circuitry, network interfaces, peripherals, input devices, output devices, sensors, etc. In some embodiments, the system monitoring circuit 210, data storage circuit 212, and / or battery detection and key switch detection circuit 214 can take the form of one or more analog circuits, electronic circuits (e.g., integrated circuits (ICs), discrete circuits, system-on-a-chip (SOC) circuits, microcontrollers, etc.), telecommunications circuits, hybrid circuits, and any other type of "circuit". In this regard, the controller 38, system monitoring circuit 210, data storage circuit 212, and / or battery detection and key switch detection circuit 214 can include any type of component for performing or facilitating the implementation of the operations described herein. For example, the circuits described herein may include one or more transistors, logic gates (e.g., NAND, AND, NOR, OR, XOR, NOT, XNOR, etc.), resistors, multiplexers, registers, capacitors, inductors, diodes, wiring, etc. The system monitoring circuit 210, data storage circuit 212, and / or battery detection and key switch detection circuit 214 may also include programmable hardware devices, such as field-programmable gate arrays, programmable array logic, programmable logic devices, etc.
[0047] Communication interface 220 is configured to enable controller 38 to communicate with onboard components such as fuel injectors and external systems such as remote systems as part of a mobile telematics system. Communication interface 220 may include wired and / or wireless interfaces (e.g., jacks, antennas, transmitters, receivers, transceivers, wired terminals, etc.) for data communication with / through these various systems, devices, or networks. For example, communication interface 220 may include a Wi-Fi transceiver for communication via a wireless communication network. Communication interface 220 may be configured to communicate via a local area network or a wide area network (e.g., the Internet, etc.) and may use various communication protocols (e.g., TCP / IP, Local Operation Network (LON), Controller Area Network (CAN), J1939, Local Interconnect Network (LIN), Bluetooth, ZigBee, radio, cellular, near field communication, etc.).
[0048] Now for reference Figure 3 This illustrates the process of saving critical data to a database during the initial shutdown event, according to an example embodiment. Figure 1 A flowchart of method 300 for using non-volatile memory associated with a controller. Method 300 can be provided by... Figure 2 The components are executed in a manner that allows reference to these components to aid in the interpretation of method 300. At a high level and according to an example embodiment, method 300 includes detecting a power-off event (e.g., battery removal, key switch closure, etc.), triggering data transmission to save data to a fast-access non-volatile medium (e.g., ...). Figure 2 The method 300 allows the vehicle to retain critical data even if power is interrupted. For example, although power from battery power 16 to controller 38 may be interrupted, the circuit can still remain operational for a short period of time through a keep-alive procedure (e.g., by drawing power from a backup battery, capacitor, or other onboard power source).
[0049] At 302, method 300 is shown for detecting a power failure event. In some embodiments, Figure 2 The system monitoring circuit 210 is configured to include computer-executable instructions to continuously or periodically (e.g., at predetermined time intervals) monitor... Figure 2 The state of battery 16 and / or key switch 20 is shown. When the vehicle is running, [the following is observed]... Figure 2 The power to the controller 38 may be interrupted, causing the vehicle to stop. Therefore, the system monitoring circuit 210 can detect that the key switch 20 is in the "off" state. In this case, Figure 2The controller 38 can receive power from an alternative power source, such as battery 16, and power can flow from battery 16 to various components of the controller 38 via converter 19. However, the power flow from the alternative power source may also be interrupted. For example, battery 16 may have failed or may have been removed. In some embodiments, system monitoring circuitry 210 receives and / or generates fault codes based on information received from one or more sensors, and determines, based on the received information and / or fault codes, that battery 16 is in a “off” state and therefore a power outage event has occurred. Conventionally, when this occurs (i.e., when both key switch 20 and battery 16 are in a “off” state), critical data may not be saved to any type of fast-access non-volatile memory. However, as described below, in an embodiment of method 300, at 304, system monitoring circuitry 210 continues to save data.
[0050] If a power failure event is detected at 302, then at 304, Figure 2 The data storage circuit 212 can trigger data storage operations to fast-access non-volatile memory such as FRAM 208. For example, the data storage circuit 212 can recognize data storage operations to fast-access non-volatile memory such as FRAM 208. Figure 2 The system retrieves the current operating parameters associated with engine 14, sensor 22, actuator 24, or controller 38, and saves all or some of these operating parameter data values to FRAM 208. The data values may include information provided by engine 14, sensor 22, and / or actuator 24. For example, data values may include track pressure, vehicle speed, engine speed, engine throttle power, acceleration, accelerator pedal status, etc. FRAM 208 can be accessed, and read / write operations on FRAM 208 can be performed via... Figure 2 The SPI / QSPI chipset 216 shown is used to perform this function to store data values. Advantageously, due to the use of FRAM208, the power-down data retention time is reduced to sub-millisecond levels.
[0051] At 306, method 300 is shown as including releasing a power-off signal to the controller 38 or its components once the data has been saved to FRAM 208. For example, in some embodiments, system monitoring circuitry 210 may determine at 304 that the data saving operation has been completed. System monitoring circuitry 210 may transmit electronic commands to various components of the vehicle (e.g., engine 14) to initiate their respective shutdown procedures.
[0052] Now for reference Figure 4 This illustrates the recovery of previously saved critical data and the saving of critical data to a record during a subsequent shutdown event, according to an example embodiment. Figure 1 A flowchart of method 400 for using non-volatile memory associated with a controller. Method 400 can be provided by... Figure 2 The components are executed so that these components can be referenced to help explain method 400.
[0053] At a high level and according to an example embodiment, method 400 includes methods for managing saves to Figure 2 The operation of critical data in FRAM 208, such as track pressure, vehicle speed, engine speed, engine throttle power, acceleration, and accelerator pedal status, is described. In summary, method 400 includes the following operations: transferring any previously saved data from FRAM 208 to main memory 206; preparing FRAM 208 for subsequent write operations; and periodically saving updated data to FRAM 208 as long as battery 16 is in the "on" state. Advantageously, this allows for the creation of a snapshot of operational data that can be retrieved later in the event of an unexpected power outage. The operation also includes various data management operations performed based on the states of battery 16 and key switch 20, which are monitored throughout the operation of method 400. If battery 16 is "on" and key switch 20 is "on," updated critical data continues to be periodically saved to FRAM 208. If battery 16 is "on" and key switch 20 is "off," the latest available copy of the critical data is saved to FRAM 208, and the system is shut down. If battery 16 is "off" and key switch 20 is "on", then if it is determined that the latest data value has changed from the data previously saved to FRAM 208, the latest available copy of the critical data is saved to FRAM 208, and the system is shut down. If battery 16 is "off" and key switch 20 is "off", the system is shut down, and FRAM 208 retains data that is periodically saved and updated during system operation. These operations are described in more detail below with reference to an example embodiment.
[0054] At 402, method 400 is shown to include a computer-executable operation of determining whether previously valid data during the last power-down cycle has been saved to FRAM 208. The operation at 402 is performed by data storage circuitry 212, which may be configured to access FRAM 208, retrieve previously saved data, and perform data integrity and / or verification operations on the previously saved data. If the determination is affirmative, method 400 proceeds to the operation at 404. If the determination is negative (i.e., invalid data was found upon power-up), method 400 proceeds to the operation at 408.
[0055] At 404, method 400 is shown as including computer-executable operations for saving power-down data determined to be valid. The operations at 404 are performed by data storage circuitry 212. In some embodiments, data storage circuitry 212 may be configured to read data from FRAM 208 and save the data to... Figure 2 The main memory 206 shown may include flash memory. In other embodiments, such as when FRAM 208 implements a dual buffer, the operation of transferring data to main memory 206 may be omitted, so that two copies of critical data from two recent shutdown events are available in the next power-on event.
[0056] At 406, method 400 is shown as including a computer-executable operation of preparing FRAM 208 for read / write operations. The operation at 406 is performed by data storage circuitry 212, which may be configured to prepare FRAM 208 by clearing specific areas within FRAM 208 (e.g., by erasing data corresponding to a specific buffer or by erasing all data in FRAM 208).
[0057] At 408, method 400 is shown as including computer-executable operations for performing battery detection and key switch detection operations. The operations at 408 are performed by system monitoring circuit 210 of battery detection and key switch detection circuit 214, which can be configured to receive data and / or electrical signals from various components of the vehicle (e.g., engine 14, sensor 22, actuator 24, etc.). The operations at 408 may include monitoring vehicle operating parameters, monitoring the state of battery 16, monitoring the state of key switch 20, etc.
[0058] Method 400 may include operations at 410 and 412. Typically, these operations allow the system to periodically monitor vehicle operating parameters and periodically save critical data to FRAM 208 until a power failure event is detected, so that the latest data is available if the key switch 20 is turned off and battery power has been lost.
[0059] At 410, method 400 is shown as including a computer-executable operation that determines current values of at least some system parameters. The operation at 410 is performed by system monitoring circuitry 210, which may be configured to receive various operating parameters directly from its source components (e.g., engine 14, sensor 22, actuator 24). The data may include various parameters such as track pressure, vehicle speed, engine speed, engine throttle power, acceleration, accelerator pedal state, etc. As shown, in one embodiment, at 410, if it is determined that a particular operating parameter meets a specific threshold, method 400 proceeds to the operation at 412. As shown, if system monitoring circuitry 210 determines that the vehicle speed is 0 mph, the accelerator pedal position is 0%, and / or the engine speed is below a low idle threshold, method 400 may proceed to 412 to save the data to FRAM 208. In an example embodiment, the low idle threshold is 800 rpm for highway vehicles and 900 rpm for off-highway vehicles. In some embodiments, the determination at 410 is omitted, such that critical data is saved at predetermined time intervals. According to various embodiments, each data saving operation occurs within 1 millisecond (equal to or less than 1 millisecond).
[0060] At 412, method 400 is shown as including a computer-executable operation for saving operational data to FRAM 208. The operation at 412 is performed by data storage circuitry 212, which can overwrite previously saved values corresponding to specific operational parameters.
[0061] At 414, method 400 is shown as including a computer-executable operation that determines whether battery 16 is in a “shutdown” state—for example, whether battery 16 has been removed. The operation at 414 is performed by system monitoring circuitry 210, which may be configured to receive and / or generate a fault code and determine, based on the fault code, that battery 16 is in a “shutdown” state and therefore a power outage event has occurred. If the determination is negative, method 400 proceeds to the operation at 416. If the determination is positive, method 400 proceeds to the operation at 420.
[0062] At 416, method 400 is shown to include a computer-executable operation performed if it is determined at 414 that battery 16 is in an "on" state. The operation at 416 is performed by system monitoring circuitry 210, which may be configured to determine whether key switch 20 is in an "on" state. In some embodiments, system monitoring circuitry 210 may receive key switch data. If it is determined that the key switch is "on," method 400 proceeds to the operation at 412 to save operation data to FRAM 208, and then proceeds to the operations at 408 and 414 to continue monitoring the state of battery 16. If it is determined that the key switch is "off," method 400 proceeds to the operation at 418.
[0063] At 418, method 400 is shown as including a computer-executable operation of saving critical data to FRAM 208. The operation at 402 is performed by data saving circuitry 212, which can be configured to trigger a data saving operation to FRAM 208. For example, data saving circuitry 212 can recognize... Figure 2 The system retrieves the current operating parameters associated with engine 14, sensor 22, actuator 24, or controller 38, and saves all or some of these operating parameter data values to FRAM 208. The data values may include information provided by engine 14, sensor 22, and / or actuator 24. For example, data values may include track pressure, vehicle speed, engine speed, engine throttle power, acceleration, accelerator pedal status, etc. FRAM 208 can be accessed, and read / write operations on FRAM 208 can be performed via... Figure 2 The SPI / QSPI chipset 216 shown is used to perform the function of storing data values.
[0064] At 420, method 400 is shown as including a computer-executable operation performed if it is determined at 414 that battery 16 is in an "off" state. The operation at 420 is performed by system monitoring circuitry 210, which can be configured to determine whether key switch 20 is in an "on" state. If it is determined that the key switch is "on," method 400 proceeds to the operation at 422. If it is determined that the key switch is "off," method 400 continues to cause controller 38 to release the power-off signal.
[0065] At 422, method 400 is shown as including a computer-executable operation to determine whether data previously stored in FRAM 208 has been altered. The operation at 422 is performed by data storage circuitry 212, which can be configured to retrieve the most recently stored data from FRAM 208 and compare that data with a current snapshot of the operational data. For example, data values may include track pressure, vehicle speed, engine speed, engine throttle power, acceleration, accelerator pedal status, etc. FRAM 208 can be accessed, and read / write operations on FRAM 208 can be performed via… Figure 2 The SPI / QSPI chipset 216 shown is used to perform this operation to save the latest data value, as shown in 418. Once these operations are performed, method 400 proceeds to causing the controller 38 to release the power-down signal.
[0066] For the purposes of this disclosure, the term "coupled" refers to two components being directly or indirectly connected or linked to each other. Such a connection can be fixed or movable in nature. For example, the "coupled" driveshaft of an engine to a transmission represents a movable coupling. Such a connection can be achieved by two components or two components and any additional advanced components. For example, circuit A being communicatively "coupled" to circuit B can mean that circuit A communicates directly with circuit B (i.e., without intermediaries) or indirectly with circuit B (e.g., through one or more intermediaries).
[0067] Despite Figure 2 Various circuits with specific functions are illustrated herein; however, it should be understood that controller 38 may include any number of circuits for performing the functions described herein. For example, the activities and functions of the circuits may be combined into multiple circuits or as a single circuit. Additional circuits with additional functions may also be included. Furthermore, controller 38 may control other activities beyond the scope of this disclosure.
[0068] As described above, and in one configuration, a “circuit” can be implemented in a machine-readable medium for execution by various types of processors. The identified circuitry of executable code can, for example, comprise one or more physical or logical blocks of computer instructions, which can be organized, for example, into objects, processes, or functions. However, the executable files of the identified circuitry are not necessarily physically located together, but can include different instructions stored in different locations that, when logically connected, comprise the circuitry and achieve the circuitry’s stated purpose. In practice, the circuitry of computer-readable program code can be a single instruction or multiple instructions, and can even be distributed across multiple different code segments, between different programs, and across multiple memory devices. Similarly, operational data may be identified and illustrated herein in the form of a circuit, and can be embodied in any suitable form and organized in any suitable type of data structure. Operational data can be collected as a single dataset, or it can be distributed across different locations, including different storage devices, and can exist at least partially as electronic signals within a system or network.
[0069] While the term "processor" has been briefly defined above, the terms "processor" and "processing circuit" are intended to be interpreted broadly. In this respect, as stated above, a "processor" can be implemented as one or more general-purpose processors, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), or other suitable electronic data processing components configured to execute instructions provided by memory. One or more processors can take the form of a single-core processor, a multi-core processor (e.g., a dual-core processor, a triple-core processor, a quad-core processor, etc.), a microprocessor, etc. In some embodiments, one or more processors can be external to the device; for example, one or more processors can be remote processors (e.g., cloud-based processors). Alternatively or additionally, one or more processors can be internal to the device and / or local. In this regard, a given circuit or its components can be arranged locally (e.g., as part of a local server, a local computing system, etc.) or remotely (e.g., as part of a remote server such as a cloud-based server). Therefore, the "circuit" described herein can include components distributed in one or more locations.
[0070] Although the figures herein may illustrate a specific order and composition of method steps, the order of these steps may differ from that depicted. For example, two or more steps may be performed simultaneously or partially simultaneously. Furthermore, some method steps performed as discrete steps may be combined, steps performed as combined steps may be separated into discrete steps, the order of a particular process may be reversed or otherwise altered, and the nature or number of discrete processes may be changed or modified. According to alternative embodiments, the order or sequence of any element or device may be changed or substituted. All such modifications are considered to be included within the scope of this disclosure as defined in the appended claims. These variations will depend on the machine-readable medium and hardware system chosen, as well as the designer's choice. All such variations are within the scope of this disclosure.
[0071] For purposes of illustration and description, the foregoing description of embodiments has been presented. These descriptions are not intended to be exhaustive or to limit this disclosure to the precise forms disclosed, and modifications and variations are possible or available from this disclosure in accordance with the foregoing teachings. The embodiments were chosen and described to explain the principles of this disclosure and its practical application, enabling those skilled in the art to utilize various embodiments and modifications suitable for the particular purpose contemplated. Other substitutions, modifications, alterations, and omissions may be made in the design, operating conditions, and arrangement of the embodiments without departing from the scope of this disclosure as set forth in the appended claims.
[0072] Therefore, this disclosure may be practiced in other specific forms without departing from its spirit or essential characteristics. The described embodiments are to be considered illustrative in all respects only, and not restrictive. Therefore, the scope of this disclosure is indicated by the appended claims rather than by the foregoing description. All variations within the equivalent meaning and scope of the claims should be included within their scope.
Claims
1. A controller for a vehicle, the controller comprising at least one processor and at least one memory storing instructions, the instructions causing the controller, when executed by the processor, to: Based on the fact that the vehicle's battery is in a powered-off state, an indication of a power failure event is received for the controller; Determine the state of a switch that is associated with the electrical power required to start the engine of the vehicle; In response to the power failure event and the switch being in the ON state to enable power to start the engine of the vehicle, the operation data is saved to the ferroelectric random access memory. as well as In response to the power failure event and the switch being in the off state, a power failure signal is released to at least one component of the vehicle to initiate a shutdown procedure for the at least one component.
2. The controller according to claim 1, wherein, The battery is a power source for the controller, and the off state of the battery is based on the battery not being in operation.
3. The controller according to claim 1, wherein, The operation of saving operation data to the ferroelectric random access memory includes comparing the operation data with a previous version of the operation data previously stored in the ferroelectric random access memory, and if it is determined that the operation data is different from the previous version, then overwriting the previous version previously stored in the ferroelectric random access memory with the operation data.
4. The controller according to claim 1, wherein, The operational data includes vehicle speed, engine speed, engine throttle power, acceleration, or the status of the accelerator pedal.
5. The controller according to claim 1, wherein, Prior to receiving the indication of the power failure event, the controller is configured to perform the operation of periodically saving the operational data to the ferroelectric random access memory.
6. The controller according to claim 1, wherein, The ferroelectric random access memory is a double-buffered ferroelectric random access memory.
7. A method for storing critical operational data of an engine control module, the method comprising: Based on the fact that the power supply configured to provide power to the engine control module is not working, an indication of a power failure event to the engine control module is received. Determine the state of the switch, which is associated with the electrical power for starting the engine of a vehicle; In response to the power failure event and the switch being in the ON state so that power can start the engine of the vehicle including the engine control module, the operation data is saved to the ferroelectric random access memory. as well as In response to the power failure event and the switch being in the off state, a power failure signal is released to at least one component of the vehicle to initiate a shutdown procedure for the at least one component.
8. The method according to claim 7, wherein, The power source includes at least one of a battery and a capacitor.
9. The method according to claim 7, wherein, The operation of saving operation data to the ferroelectric random access memory includes comparing the operation data with a previous version of the operation data previously stored in the ferroelectric random access memory, and if it is determined that the operation data is different from the previous version, then overwriting the previous version previously stored in the ferroelectric random access memory with the operation data.
10. The method according to claim 7, wherein, The operational data includes vehicle speed, engine speed, engine throttle power, acceleration, or the status of the accelerator pedal.
11. The method according to claim 7, wherein, Prior to receiving the indication of the power failure event, the engine control module is configured to perform the operation of periodically saving the operation data to the ferroelectric random access memory.
12. The method according to claim 7, wherein, The ferroelectric random access memory is a double-buffered ferroelectric random access memory.
13. A non-transitory computer-readable medium comprising computer-executable instructions stored thereon, the instructions, when executed by one or more processors, performing operations including: Based on the fact that the power supply configured to provide power to the engine control module is not working, an indication of a power failure event to the engine control module is received. Determine the state of the switch, which is associated with the electrical power for starting the engine of a vehicle; In response to the power outage event and the switch being in an ON state to enable power to start the engine of the vehicle, including the engine control module, operational data is saved to a ferroelectric random access memory; and In response to the power failure event and the switch being in the off state, a power failure signal is released to at least one component of the vehicle to initiate a shutdown procedure for the at least one component.
14. The medium according to claim 13, wherein, The power source includes at least one of a battery and a capacitor.
15. The medium according to claim 13, wherein, The operation of saving operation data to the ferroelectric random access memory includes comparing the operation data with a previous version of the operation data previously stored in the ferroelectric random access memory, and if it is determined that the operation data is different from the previous version, then overwriting the previous version previously stored in the ferroelectric random access memory with the operation data.
16. The medium according to claim 13, wherein, The operational data includes vehicle speed, engine speed, engine throttle power, acceleration, or the status of the accelerator pedal.
17. The medium according to claim 13, wherein, Prior to receiving the indication of the power failure event, the engine control module is configured to perform the operation of periodically saving the operation data to the ferroelectric random access memory.
18. The medium according to claim 13, wherein, The ferroelectric random access memory is a double-buffered ferroelectric random access memory.
Citation Information
Patent Citations
Vehicle
CN104828072A
Power fail protection and recovery using low power states in a data storage device / system
CN105556416A
Vehicle-mounted storage apparatus
CN107797946A
Electronic control unit and data protection method therefor
CN110023911A
Vehicle data backup method
CN1906394A