A fault degradation testing system and method
By injecting fault simulation signals through external testing equipment, vehicle faults are simulated and degradation strategies are triggered. This overcomes the limitations of high-cost hardware-in-the-loop testing, achieves the authenticity and comprehensiveness of real vehicle fault degradation testing, and evaluates the reliability and stability of the vehicle control system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SAIC GM WULING AUTOMOBILE CO LTD
- Filing Date
- 2023-05-04
- Publication Date
- 2026-04-24
AI Technical Summary
In existing technologies, vehicle fault degradation simulation testing requires high-cost hardware-in-the-loop equipment and can only be performed in a static environment. This fails to accurately reflect the fault conditions of vehicles in dynamic driving environments, resulting in a limited testing environment and poor data accuracy.
By connecting the domain under test controller and the vehicle electronic control module with an external testing device, a fault simulation signal is injected to simulate the fault and trigger the degradation strategy, thereby realizing the real vehicle fault degradation test, maintaining the normal transmission of vehicle signals, and reducing testing costs.
It enables real-vehicle fault degradation testing without vehicle modification, improving the realism and comprehensiveness of the test, expanding the test scope, and enabling the evaluation of the reliability and stability of the vehicle control system in the event of a fault.
Smart Images

Figure CN116483057B_ABST
Abstract
Description
[Technical Field]
[0001] This application relates to the field of vehicle fault testing technology, and in particular to a fault degradation testing system and testing method. [Background Technology]
[0002] With the increasing level of vehicle electrification, Domain Controllers (DCs) and the Electronic Control Units (ECUs) they manage are playing a central role in intelligent control across various vehicle body electronic control modules and lower-level devices. Before a vehicle leaves the factory, DCs and ECUs undergo fault degradation simulation testing. This test simulates a fault in a body electronic control module, observing whether the DC and ECU can employ preset degradation strategies to limit or disable the faulty function, or activate redundant devices to temporarily take over the function. This assesses whether the DC and ECU's degradation strategies can minimize the impact of the fault on vehicle system performance.
[0003] Currently, fault degradation simulation testing of DC and ECU often requires the use of Hardware-in-the-Loop (HIL) methods. However, this method requires the use of simulation hardware or test benches to statically build a simulation environment for performing fault degradation simulation tests. The simulation hardware or test benches used in HIL are often expensive, and the way they test specific areas of the vehicle by disconnecting the vehicle wiring harness and building virtual nodes will cause the vehicle system signal transmission to be interrupted. This means that fault degradation testing can only be performed in a static environment, which inevitably leads to a limited testing environment and cannot reflect the fault degradation situation under real driving conditions. [Summary of the Invention]
[0004] This application provides a fault degradation testing system and method that allows testers to connect the relevant wiring harnesses of the domain controller and the vehicle electronic control module under test using only one set of external testing equipment. This reduces the cost of testing equipment while enabling real-vehicle fault degradation testing and improving the realism of the test.
[0005] In a first aspect, embodiments of this application provide a fault degradation testing system, the system comprising: a domain controller under test, a vehicle electronic control module under test, and external testing equipment electrically connected to the domain controller under test and the vehicle electronic control module under test, respectively;
[0006] The external testing equipment is used to receive the first fault type that the user needs to test; according to the preset mapping relationship between fault type and fault simulation signal, it generates a first fault simulation signal corresponding to the first fault type, and injects the first fault simulation signal into the electronic control module of the vehicle body under test.
[0007] The vehicle electronic control module under test is used to generate a first fault code based on the first fault simulation signal and forward it to the domain controller under test through the external test equipment.
[0008] The domain controller under test is used to execute the first degradation strategy corresponding to the first fault code according to the preset mapping relationship between fault codes and degradation strategies.
[0009] In this embodiment, an external testing device is connected to the corresponding wiring harness of the vehicle, and a first fault simulation signal is injected into the electronic control module under test (ECU). This simulates the first fault type that the user needs to test, namely the internal component fault of the ECU. This triggers the ECU to output a fault code based on the first fault type, and the fault code causes the domain controller under test to execute a first degradation strategy. This tests whether the fault degradation measures adopted by the domain controller under test can be executed normally and whether the execution effect meets expectations. This allows fault degradation simulation testing to be carried out through real vehicle testing without large-scale vehicle modifications, reducing testing difficulty and cost. At the same time, only one set of external testing equipment is used to connect the relevant wiring harnesses of the domain controller under test and the ECU, ensuring that the normal transmission of vehicle signals can be maintained throughout the testing process. Fault simulation is only performed on specific signals as needed for testing, thus enabling the vehicle to undergo better real-vehicle fault degradation testing and improving the authenticity of the test results.
[0010] Optionally, the system further includes: other vehicle body electronic control modules, and the external testing equipment is electrically connected to the other vehicle body electronic control modules;
[0011] The other vehicle body electronic control modules are used to send interactive signals to the external test equipment;
[0012] The external testing equipment is also used to receive the second fault type that the user needs to test; according to the preset network fault rules, the interactive signal is processed into the second fault simulation signal corresponding to the second fault type, and the second fault simulation signal is injected into the domain controller under test;
[0013] The domain controller under test is further configured to generate a second fault code based on the second fault simulation signal, and execute the second degradation strategy corresponding to the second fault code according to the preset mapping relationship between the fault code and the degradation strategy.
[0014] In this embodiment, the external test equipment processes the interactive signals sent from other vehicle electronic control modules to the domain controller under test (DUT) into a second fault simulation signal through built-in network fault rules. This signal is then sent to the DUT to simulate network faults such as packet loss and garbled signals that occur when the DUT transmits interactive signals with other vehicle electronic control modules. This causes the DUT to generate a fault code and adopt a corresponding second degradation strategy based on the fault code. This tests whether the second degradation strategy for repairing communication transmission between the DUT and other vehicle electronic control modules under network faults is available and reasonable. This expands the testing scope of vehicle fault degradation simulation testing beyond the traditional method of directly generating fault signals for fault simulation, allowing users to more comprehensively evaluate the reliability and stability of the vehicle control system under fault conditions.
[0015] Optionally, the external testing equipment is also used for:
[0016] Receive multiple pre-compiled fault-generating codes, which are used to modify the content of the interaction signal to simulate all fault types of the interaction signal;
[0017] In response to the first configuration operation for the multiple fault-causing codes, the mapping relationship between all fault types and the multiple fault-causing codes is determined to obtain the network fault rules.
[0018] In this embodiment, by inputting multiple pre-compiled fault-generating codes into an external test device and establishing the relationship between all fault types of the interactive signal and the multiple fault-generating codes, the external test device can use the pre-set fault-generating codes to intercept the interactive signal, modify the signal content to generate a second fault simulation signal, and resend it when it receives an interactive signal that matches the second fault type specified by the user. This allows the fault simulation to be updated or modified according to the user's test needs, improving the scalability of the test.
[0019] Optionally, the system further includes: a backup domain controller, which is electrically connected to the external test equipment;
[0020] The external testing equipment is also used to receive the third fault type that the user needs to test; generate the third fault simulation signal corresponding to the third fault type according to the preset mapping relationship between the fault type and the fault simulation signal, and inject the third fault simulation signal into the domain controller under test.
[0021] The domain controller under test is further configured to generate a third fault code based on the third fault simulation signal, and forward the third fault code to the backup domain controller through the external test equipment;
[0022] The backup domain controller is used to determine and execute the third degradation strategy corresponding to the third fault code based on the preset mapping relationship between fault codes and degradation strategies.
[0023] In this embodiment, the external test equipment sends a third fault simulation signal to the domain controller under test (DUT), causing the DUT to exhibit a third fault type and output a third fault code. Upon receiving the corresponding fault code, the backup domain controller executes the corresponding third degradation strategy to take over the functions of the DUT. This allows the fault degradation simulation test to go beyond evaluating the preset degradation strategy within the DUT; it can also simulate the process of the backup domain controller initiating degradation when the DUT itself experiences a functional failure, thus enhancing the comprehensiveness of the vehicle control system degradation test.
[0024] Optionally, the external testing equipment is also used for:
[0025] Receive the pre-compiled first fault simulation signal and the third fault simulation signal;
[0026] In response to a second configuration operation for the first fault simulation signal and the third fault simulation signal, the mapping relationship between the first fault simulation signal and the first fault type, and the mapping relationship between the third fault simulation signal and the third fault type are determined.
[0027] In this embodiment, by editing the contents of the first fault simulation signal and the third fault simulation signal and their mapping relationship with the first fault type and the third fault type before the test begins, a signal transmission mechanism is established during the fault degradation simulation test process. This enables the sending of a specified fault simulation signal to the vehicle control system according to the test type specified by the user to simulate the test effect of the corresponding fault. This improves test efficiency and also facilitates targeted configuration and modification of the test content.
[0028] Secondly, embodiments of this application provide a simulation testing method for fault degradation, applied to the fault degradation simulation testing system described in the first aspect, the method comprising:
[0029] The external testing equipment receives the first type of fault that the user needs to test;
[0030] The external testing equipment generates a first fault simulation signal corresponding to the first fault type according to a preset mapping relationship between fault types and fault simulation signals.
[0031] The external testing equipment sends the first fault simulation signal to the vehicle electronic control module under test, and the vehicle electronic control module under test generates a first fault code based on the first fault simulation signal.
[0032] The external test device receives the first fault code and forwards it to the domain controller under test. The domain controller under test determines and executes the first degradation strategy corresponding to the first fault code based on a preset mapping relationship between fault codes and degradation strategies.
[0033] Optionally, the method further includes:
[0034] The external testing equipment receives interactive signals sent by other vehicle body electronic control modules and processes the interactive signals into a second fault simulation signal according to preset network fault rules.
[0035] The external test equipment forwards the second fault simulation signal to the domain under test controller. The domain under test controller generates a second fault code based on the second fault simulation signal and executes the second degradation strategy corresponding to the second fault code according to the preset mapping relationship between fault codes and degradation strategies.
[0036] Optionally, the method further includes:
[0037] The external testing equipment receives multiple pre-compiled fault-causing codes, which are used to modify the content of the interactive signal to simulate all fault types of the interactive signal.
[0038] The external testing device responds to the first configuration operation for the multiple fault-causing codes, determines the mapping relationship between all fault types and the multiple fault-causing codes, and obtains the network fault rules.
[0039] Optionally, the method further includes:
[0040] The external testing equipment receives the third type of fault that the user needs to test;
[0041] The external test device generates a third fault simulation signal corresponding to the third fault type according to a preset mapping relationship between fault types and fault simulation signals, and injects the third fault simulation signal into the domain under test controller. The domain under test controller is used to generate and send a third fault code to the external test device based on the third fault simulation signal.
[0042] The external test device receives the third fault code and forwards it to the backup domain controller. The backup domain controller determines and executes the third degradation strategy corresponding to the third fault code based on the preset mapping relationship between fault codes and degradation strategies.
[0043] Optionally, the method further includes:
[0044] The external test equipment receives the pre-compiled first fault simulation signal and the third fault simulation signal;
[0045] The external test equipment responds to a second configuration operation for the first fault simulation signal and the third fault simulation signal to determine the mapping relationship between the first fault simulation signal and the first fault type, and the mapping relationship between the third fault simulation signal and the third fault type.
[0046] It should be understood that the second aspect of the embodiments of this application is consistent with the technical solution of the first aspect of the embodiments of this application, and the beneficial effects achieved by each aspect and the corresponding feasible implementation are similar, and will not be described again. [Attached Image Description]
[0047] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0048] Figure 1 An architecture diagram of a fault degradation test system for testing a first fault type is provided in an embodiment of this application;
[0049] Figure 2 An architecture diagram of a fault degradation test system for testing a second fault type is provided in an embodiment of this application.
[0050] Figure 3 An architecture diagram of a fault degradation test system for testing a third fault type is provided in an embodiment of this application;
[0051] Figure 4 An architecture diagram of a fault degradation test system provided in this application for testing the overall failure of the electronic control module of the vehicle under test;
[0052] Figure 5 A flowchart illustrating a fault degradation test method for a first fault type provided in an embodiment of this application;
[0053] Figure 6 A flowchart illustrating a fault degradation test method for a second fault type provided in an embodiment of this application;
[0054] Figure 7 A flowchart illustrating a method for generating network fault rules provided in an embodiment of this application;
[0055] Figure 8 A flowchart illustrating a fault degradation test method for a third fault type provided in an embodiment of this application;
[0056] Figure 9This is a flowchart illustrating a method for configuring a first fault simulation signal and a third fault simulation signal, as provided in an embodiment of this application.
Detailed Implementation Methods
[0057] To better understand the technical solutions in this specification, the embodiments of this application will be described in detail below with reference to the accompanying drawings.
[0058] It should be understood that the described embodiments are merely some, not all, of the embodiments in this specification. All other embodiments obtained by those skilled in the art based on the embodiments in this specification without inventive effort are within the scope of protection of this specification.
[0059] The terminology used in the embodiments of this application is for the purpose of describing particular embodiments only and is not intended to be limiting of this specification. The singular forms “a,” “the,” and “the” used in the embodiments of this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise.
[0060] With the increasing level of vehicle electrification, Domain Controllers (DCs) and the Electronic Control Units (ECUs) they manage have begun to play a central role in intelligent control across various vehicle body electronic control modules and lower-level devices. Before a vehicle leaves the factory, fault degradation simulation tests are required on the DCs and ECUs within the vehicle control system. This test simulates a fault in the body electronic control module, observing whether the DC and ECU can adopt preset degradation strategies to limit or disable the faulty function, or activate redundant devices to temporarily take over the function, thereby minimizing the impact of the fault on vehicle system performance.
[0061] The inventors of this application have discovered that fault degradation simulation testing of DC and ECU often requires a hardware-in-the-loop (HIL) approach. However, this requires the use of simulation hardware or test benches to statically build a simulation environment for fault degradation simulation testing. The simulation hardware or test benches used in HIL are often expensive, and the method of testing specific areas of the vehicle by disconnecting the vehicle wiring harness and building virtual nodes will cause the vehicle system signal transmission to be interrupted. This means that fault degradation testing can only be performed in a static environment, which may lead to potential problems such as a limited testing environment. It is impossible to fully test the fault degradation of DC and ECU under various real-world driving conditions, resulting in poor reliability of the test data.
[0062] In view of this, the present application provides a fault degradation test system that allows testers to connect the wiring harness of the domain controller under test and the electronic control module of the vehicle under test using only one set of external test equipment. The external test equipment generates fault simulation signals and injects them into the system and devices under test, thereby reducing the cost of test equipment while maintaining the normal transmission of vehicle signals. This enables the vehicle to undergo real-vehicle fault degradation testing and improves the realism of the test.
[0063] It should be understood that the "vehicle electronic control module" mentioned in this application refers to an important component of the vehicle control system, mainly including sensors, ECUs, and actuators. Its function is to be responsible for a specific function of the vehicle, such as window operation, air conditioning, anti-lock braking system, and engine speed control, through the preset control program inside the ECU. Due to the intelligent and integrated development of vehicle control systems, the vehicle electronic control module has also been divided into multiple "functional domains" according to its functional type. DC is a high-level controller that highly integrates and manages these functional domains, and is responsible for making decisions or regulating one or more vehicle electronic control modules according to the current state of the vehicle.
[0064] Since the aforementioned electronic components all have a certain failure rate, vehicle design often incorporates a certain degree of redundancy in the control system. This redundancy allows the vehicle to maintain a minimum level of stable operation when a malfunction occurs. For example, if a vehicle's steering control system malfunctions, causing difficulty or even loss of steering, some models will activate a pre-programmed sequence to actively limit speed or reduce the vehicle's steering angle to ensure safe driving even in the event of a malfunction. This is what is referred to as "fault degradation" in this application.
[0065] The technical solutions provided in the embodiments of this application will now be described in conjunction with the accompanying drawings.
[0066] Please see Figure 1 This application provides an architecture diagram of a test system for testing a first type of fault degradation. The system includes a domain controller under test 101, a vehicle electronic control module under test 102, and an external test device 103 electrically connected to the domain controller under test 101 and the vehicle electronic control module under test 102, respectively.
[0067] The external testing device 103 is used to receive the first fault type that the user needs to test; according to the preset mapping relationship between the fault type and the fault simulation signal, it generates the first fault simulation signal corresponding to the first fault type and injects the first fault simulation signal into the electronic control module 102 of the vehicle body under test.
[0068] The vehicle electronic control module 102 under test is used to generate a first fault code based on a first fault simulation signal and forward it to the domain controller 101 under test through an external test device 103.
[0069] The domain controller 101 under test is used to execute the first degradation strategy corresponding to the first fault code according to the preset mapping relationship between fault codes and degradation strategies.
[0070] In this embodiment of the application, a preferred wiring harness connection scheme for fault degradation testing of the vehicle control system is to connect the domain controller under test 101, the vehicle electronic control module under test 102, and the external test equipment 103 through a set of special signal lines. The special signal lines include a male interface, a female interface, and a device interface.
[0071] The male connector of the specially designed signal cable connects to the connector of the domain controller under test (DUT) 101 to carry the output signals of DUT 101. The female connector connects to the signal input harness of one or more vehicle electronic control modules (VEMs) under test (VEMs) 102, thereby forwarding the signals to the VEMs 102 (which are normally installed on the connector of DUT 101). In this connection scheme, the male and female connectors can be OBD-II interfaces (a 16-pin port) to adapt to DUT 101 and VEMs 102. However, depending on the vehicle model, the specially designed signal cable can also use a VAG COM port, J1939 port, JDM port, ISO9141-2 port, CANBUS port, or other port types.
[0072] The device port of the specially designed signal cable is responsible for connecting to the ports (such as USB port, DB9 port, etc.) of the external test device 103 to intercept and forward specified signals. In this connection scheme, the device port can use a DB9 serial port interface, a standard RS-232 serial port interface for data transmission between a computer and external devices. It has a 9-pin D-shaped connector interface and is used for transmitting serial data communication. It is typically used to connect computers to external devices such as monitors, modems, printers, etc., thus enabling signal transmission to the external test device 103. However, using other ports with signal transmission capabilities can also achieve the expected effect of fault degradation testing.
[0073] Similar to the type of special signal line, the external test equipment 103 here can also be implemented by properly configuring any device with vehicle signal simulation capabilities. The types include, but are not limited to: multi-channel vehicle board, devices with signal simulation capabilities such as Peak-System series, Vector series, Vehicle Spy series, or other devices or apparatus equipped with simulation environments such as CANoe, so as to achieve the effect of forwarding preset signals to the domain controller under test 101 and the vehicle electronic control module under test 102.
[0074] Once the external test equipment 103 is connected to the domain controller under test 101 and the vehicle electronic control module under test 102 according to the above scheme, fault degradation testing of the vehicle can begin. In the specific testing process, the external test equipment 103 is mainly used to inject a first fault simulation signal into the vehicle electronic control module under test 102, causing the built-in diagnostic function of the vehicle electronic control module under test 102 to mistakenly identify an internal component failure, and generate and output fault codes corresponding to the first fault type according to a preset program. Specifically, the external test equipment 103 generates fault simulation signals in the following ways:
[0075] (1) Create voltage / current abnormalities: Inject fluctuating voltage or current into the vehicle's electronic control unit to simulate faults such as poor contact of vehicle electrical components and low battery voltage.
[0076] (2) Signal interference: Inject interference signals from other signal sources into vehicle sensors or control units to simulate faults such as electromagnetic interference or signal interference.
[0077] (3) Signal distortion: The signals of vehicle sensors or control units are distorted, delayed, and have additional noise to simulate fault conditions such as poor sensor wiring and signal amplifier failure.
[0078] (4) Mechanical failure and other failure scenarios: By configuring different failure simulation strategies on the external test equipment 103, various uncommon or more complex failure scenarios can be simulated.
[0079] After the electronic control module 102 of the vehicle under test outputs a first fault code based on the first fault simulation signal, and the first fault code is forwarded to the domain controller 101 under test via the external test equipment 103, the domain controller 101 under test will activate the internally preset first degradation strategy according to the first fault code, and send control commands to the lower-level ECU, thereby causing the faulty electronic or mechanical components of the vehicle to stop working, start backup devices, or other devices that can perform similar functions. For example, temporarily turning off functions such as intelligent cruise control, ordering the engine control module to actively limit vehicle speed and throttle response speed, and ordering the vision sensor to compensate for the positioning function of the lidar, etc. The execution method varies depending on the vehicle model and system.
[0080] Furthermore, when the domain controller under test 101 determines that the electronic control module 102 under test has encountered a first fault type based on the first fault code, it will also control the instrument panel to output corresponding fault prompt information according to the first fault code, such as prompting the tester by illuminating warning lights, sounding alarms, or displaying text content on the instrument panel. At the same time, the external test equipment 103 will also directly read the first fault code and display it to the tester, allowing the tester to comprehensively judge whether the current degradation strategy has been successfully executed. Since the vehicle generates a fault code for the corresponding module's ECU or DC when each fault occurs, this mechanism is also applicable when simulating other fault types.
[0081] Please see Figure 2 This is an architecture diagram of a fault degradation test system for testing a second fault type, as described in an embodiment of this application. The system also includes other vehicle body electronic control modules 104, and an external test device 103 electrically connected to these modules.
[0082] Other vehicle body electronic control modules 104 are used to send interactive signals to external test equipment 103.
[0083] The external test device 103 is also used to receive the second fault type that the user needs to test; according to the preset network fault rules, the interactive signal is processed into the second fault simulation signal corresponding to the second fault type, and the second fault simulation signal is injected into the domain controller 103 under test.
[0084] The domain controller 101 under test is also used to generate a second fault code based on the second fault simulation signal, and execute the second degradation strategy corresponding to the second fault code according to the preset mapping relationship between the fault code and the degradation strategy.
[0085] In this embodiment, other vehicle electronic control modules 104 are located in other functional domains of the vehicle and do not form a direct hierarchical relationship with the domain controller 101 under test. Therefore, their connection method with the external test device 103 is different from that of the vehicle electronic control module 102 under test. They do not use special signal lines, nor do they directly connect the wiring harness to the external test device 103. Instead, after the port on the wiring harness is connected to the channel of the external test device 103 via the Controller Area Network (CAN) bus, the interaction signal is sent to the external test device 103 via the CAN line, and then forwarded to the domain controller 101 under test by the external test device 103.
[0086] After connecting the external test device 103 to other vehicle electronic control modules 104 via the CAN bus, the test domain controller and the lower-level ECU can be tested using the network fault rules built into the external test device 103.
[0087] Specifically, the network fault rules are mainly used to intercept and modify specified interactive signals received by the external test device 103. The specific type of interactive signal intercepted depends on the specific fault type selected by the user for testing. For example, when the domain controller 101 under test needs to obtain information such as vehicle speed, throttle opening, and braking status, it needs to receive interactive signals sent by other electronic control devices 104 from other functional domains. If the user selects to create a fault for this type of interactive signal before testing, the external test device 103 will detect whether this type of interactive signal is being transmitted through a special signal line, and intercept it when the signal is detected. The network fault rules are then used to add, delete, replace, or randomly shuffle the signal content to obtain a second fault simulation signal. In other words, during the testing of the second fault type, the external test device 103 plays a signal processing and forwarding role similar to a "gateway" device, except that the signal processing function is used specifically to create interactive signal faults.
[0088] It should be understood that when the domain controller under test 101 communicates with other vehicle electronic control modules 104, if the domain controller under test 101 is injected with a second fault simulation signal by the external test equipment 103, it will also generate a second fault code corresponding to the second fault type, and take a corresponding second degradation strategy based on the second fault code. The degradation actions in the second degradation strategy include, but are not limited to:
[0089] (1) Check whether the domain controller 101 under test is equipped with a backup channel (such as a backup CAN line channel) between itself and other body electronic control modules 104. If a backup channel exists, it will automatically switch and re-execute data synchronization according to the second degradation strategy, thereby temporarily restoring communication with other body electronic control modules 104.
[0090] (2) If there is no network or cable connection fault between the domain controller under test 101 and other body electronic control modules 104, the other body electronic control modules 104 are notified to restart some internal devices in accordance with the second degradation strategy in order to try to restore the interaction with the domain controller under test 101.
[0091] Since the network fault rules are a necessary mechanism for the external test device 103 to test the second degradation strategy, the network fault rules need to be configured before the test to meet the specific requirements of the current test.
[0092] As one possible implementation of pre-configured network fault rules, the external test device 103 is also used for:
[0093] Receives multiple pre-compiled fault-generating codes, which are used to modify the content of the interactive signal to simulate all fault types of the interactive signal.
[0094] The first configuration operation for multiple fault manufacturing codes is responded to, the mapping relationship between all fault types and multiple fault manufacturing codes is determined, and the network fault rules are obtained.
[0095] In this embodiment, the fault-generating code mainly generates faults such as signal loss, data packet verification failure, and invalid signal content. Its specific code form and execution effect are related to the simulation environment of the external test device 103. For example, in different external test devices 103, the form of the fault-generating code may include, but is not limited to: CAPL language supported by the CANoe environment, MATLAB language supported by the Simulink environment, or Python language that implements CAN bus communication and signal parsing by using third-party tool libraries (such as CanTools, Canlib, etc.).
[0096] The following is a code example written in CAPL language to simulate a signal loss fault when the external test device 103 uses the CANoe simulation environment:
[0097]
[0098] Here, CAN1.0x12a indicates that the external test device 103 has received a signal named CAN1 with the identifier 0x12a from the CAN bus. When the external test device 103 detects the specified signal and starts running this fault-generating code, it first determines whether the signal transmission direction is receiving (the value of the dir variable is rx) and whether the message comes from CAN bus network 2 (this.can == 2). If both conditions are met, the received signal is assigned to a variable named Msg_12a of type CAN1.0x12a, and the @ symbol is used to retrieve a variable named Msglose_12a (this variable is used to indicate whether the user needs to generate a signal loss fault for the current signal). If this variable is 0, it is considered that no fault needs to be generated and Msg_12a is output normally; otherwise, no further processing is performed on the signal, thus successfully simulating a signal packet loss fault during transmission.
[0099] For example, the following is a code example written in CAPL language for creating a signal invalidity fault in external test device 103:
[0100]
[0101]
[0102] Here, CAN1.0x128 indicates that the external test device 103 has received a signal named CAN1 with an identifier of 0x128 from the CAN bus. Upon receiving this signal, the external device stores it in a variable named Msg_128 and determines whether the message's transmission direction is receive (the dir variable value is rx) and whether the message originates from CAN bus network 2 (this.can == 2). If both conditions are met, the following operations are performed on the message:
[0103] If the value of the variable @VsELongAccv_invalid is 1, indicating that the user expects to create an invalid fault in the vehicle's long acceleration signal, then bit 4 (0x10) of byte 0 of Msg_128 is set to 1. If the value of the variable @EsPMCBrPressurev_invalid is 1, indicating that the user expects to create an invalid fault in the ESP brake pressure signal, then bit 4 of byte 2 of Msg_128 is set to 1. Then, bytes 0, 1, and 2 of the variable Msg_128 are summed and the result is stored in byte 7 of Msg_128. Finally, the value of the variable @Msglose128 (which indicates whether the user needs to create an invalid fault in the current signal) is checked to see if it is 0. If it is zero, Msg_128 is output.
[0104] By importing multi-segment fault-generating code in a format similar to the above into an external test device and establishing a mapping relationship with the corresponding fault type to obtain network fault rules, a fault simulation mechanism can be implemented that converts interactive signals into second fault simulation signals when the user specifies to test a certain network fault.
[0105] Please see Figure 3 This is an architecture diagram of the test system for fault degradation testing in this embodiment of the application, used to test a third fault type. The system also includes a backup domain controller 105, which is electrically connected to an external test device 103.
[0106] The external test device 103 is also used to receive the third fault type that the user needs to test; according to the preset mapping relationship between the fault type and the fault simulation signal, it generates the third fault simulation signal corresponding to the third fault type and injects the third fault simulation signal into the domain controller 101 under test.
[0107] The domain controller under test 101 is also used to generate a third fault code based on the third fault simulation signal, and forward the third fault code to the backup domain controller 105 through the external test device 103.
[0108] The standby domain controller 105 is used to execute the third degradation strategy corresponding to the third fault code according to the preset mapping relationship between fault codes and degradation strategies.
[0109] In this embodiment, the third fault simulation signal mainly includes two types: one is to send an erroneous signal to cause the domain controller 101 under test to execute an incorrect strategy under normal operation; the other is to send a diagnostic command to shut down the domain controller 101 under test, thereby stopping its interaction with the vehicle electronic control module 102 under test. Both methods will cause the domain controller 101 under test to exhibit a failure state and generate a corresponding third fault code in the vehicle control system. It should be understood that due to differences in different vehicle models and systems, the content of the erroneous signals and diagnostic commands will vary, therefore the third fault simulation signal also needs to be specifically configured before testing.
[0110] When the standby domain controller 105 receives a third fault code, it will confirm that the domain controller under test 101 has failed and that the failure has caused the normal function of the domain controller under test 101 to be ineffective, based on the pre-configured mapping relationship between fault codes and degradation policies. Subsequently, the standby domain controller 105 will start up and take over the operation of the domain controller under test 101 according to the preset degradation policy.
[0111] It should be understood that the faults caused by the first, second, and third fault simulation signals are all detected by devices with diagnostic functions in the vehicle control system. Depending on the vehicle model, the diagnostic function can be integrated into the code layer within the DC (Distributed Control Unit) or configured in a dedicated diagnostic module within the ECU (Electronic Control Unit). These diagnostic functions are primarily responsible for determining whether there are faults in electronic or mechanical components within each detection cycle, based on data sent by electronic devices and preset fault confirmation mechanisms (such as threshold values set for sensors and detection of abnormal value fluctuations).
[0112] When these faults are detected by the diagnostic function, the DC or ECU will generate a first fault code, a second fault code, or a third fault code based on the type of fault, to remind the relevant controller to take a degradation strategy according to the fault. The fault degradation test system in this embodiment can be fine-tuned according to the specific fault type to be tested, and configured to other connection methods or fault signal simulation forms, thereby adapting to various test requirements during real vehicle simulation testing.
[0113] As one possible implementation for configuring fault simulation signals, the external test device 103 is specifically used for:
[0114] Receive the pre-compiled first fault simulation signal and third fault simulation signal;
[0115] In response to the second configuration operation for the first fault simulation signal and the third fault simulation signal, the mapping relationship between the first fault simulation signal and the first fault type, and the mapping relationship between the third fault simulation signal and the third fault type are determined.
[0116] In this embodiment, the specific contents of the first fault simulation signal and the third fault simulation signal are configured in advance (due to the significant differences between different vehicle models and systems, this configuration operation needs to be performed with reference to the manufacturer's documentation and other materials). A mapping relationship between these first fault simulation signals, third fault simulation signals and corresponding fault types is established. This allows the external test equipment 103 to directly retrieve the corresponding first fault simulation signal or third fault simulation signal, just like retrieving network fault rules, when performing fault degradation simulation tests according to the fault type specified by the user. The signal is then transmitted to the vehicle control system for testing.
[0117] Please see Figure 4 This is an architecture diagram of a fault degradation test system for testing the overall fault of a vehicle electronic module under test, as described in this application embodiment. It should be understood that vehicle control systems often experience more than just single component failures; sometimes, unexpected events can cause the entire vehicle's functional modules to malfunction. Since such faults are also included in the fault degradation scope during the design phase, the external test device 103 can also simulate this fault, enabling the domain controller under test 101 to activate the backup vehicle electronic control module 106 for functional compensation. Specifically, when the external test device 103 simulates the overall fault of the vehicle electronic control module 102 under test, its system connection method is similar to the embodiments described above, and both require the external test device 103 to output a fault simulation signal to the domain controller under test 101 to trigger a preset degradation strategy corresponding to the overall fault of the vehicle electronic control module 102 under test.
[0118] For example, when the vehicle's ABS system fails, the domain controller under test 101 may attempt to transfer some functions of the ABS system to the engine control module for replacement, so that speed control can still be achieved during the ABS system failure, avoiding wheel lock-up due to braking. Alternatively, when the vehicle's main battery fails, the domain controller under test 101 may attempt to activate the vehicle's backup battery (such as a small lithium battery used in the starter motor) to temporarily supply power, preventing the vehicle from becoming immobile due to engine stall. Depending on the vehicle model, the model of the body electronic control module under test 102, and the backup body electronic control module 106, there are many similar preset degradation strategies and fault degradation test procedures, which will not be elaborated here.
[0119] Please see Figure 5 Based on the same inventive concept, embodiments of this application provide a fault degradation test method for a first fault type, applied to... Figures 1-4 The fault degradation test system in the example is described in the following flowchart:
[0120] Step 201: External test device 103 receives the first fault type that the user needs to test;
[0121] Step 202: The external test device 103 generates the first fault simulation signal corresponding to the first fault type according to the preset mapping relationship between fault type and fault simulation signal;
[0122] Step 203: The external test equipment 103 sends the first fault simulation signal to the vehicle electronic control module 102 under test, which generates the first fault code based on the first fault simulation signal.
[0123] Step 204: The external test device 103 forwards the first fault code to the domain controller under test 101. The domain controller under test 101 determines and executes the first degradation strategy corresponding to the first fault code according to the preset mapping relationship between fault codes and degradation strategies.
[0124] Figure 5 This is a flowchart illustrating a test method for fault degradation of a second fault type. As one possible implementation, the method includes:
[0125] Step 205: The external test equipment 103 receives the interactive signals sent by other vehicle body electronic control modules 104, and processes the interactive signals into a second fault simulation signal according to the preset network fault rules.
[0126] Step 206: The external test device 103 sends the second fault simulation signal to the domain under test controller 101. The domain under test controller 101 generates a second fault code based on the second fault simulation signal and executes the second degradation strategy corresponding to the second fault code according to the preset mapping relationship between the fault code and the degradation strategy.
[0127] Figure 6 This is a flowchart illustrating a method for generating network fault rules. As one possible implementation, steps 207 to 208 can be further executed before step 201.
[0128] Step 207: External test device 103 receives multiple pre-compiled fault-causing codes, which are used to modify the content of the interactive signal to simulate all fault types of the interactive signal.
[0129] Step 208: External test device 103 responds to the first configuration operation for multiple fault manufacturing codes, determines the mapping relationship between all fault types and multiple fault manufacturing codes, and obtains network fault rules.
[0130] Figure 7 This is a flowchart illustrating a fault degradation testing method for a third type of fault. As one possible implementation, the method includes:
[0131] Step 209: External test device 103 receives the third fault type that the user needs to test.
[0132] Step 210: The external test device 103 generates a third fault simulation signal corresponding to the third fault type according to the preset mapping relationship between fault type and fault simulation signal, and injects the third fault simulation signal into the domain under test controller 101. The domain under test controller 101 is used to generate and send a third fault code to the external test device 103 according to the third fault simulation signal.
[0133] Step 211: External test device 103 receives the third fault code and forwards it to standby domain controller 105. Standby domain controller 105 determines and executes the third degradation strategy corresponding to the third fault code based on the preset mapping relationship between fault codes and degradation strategies.
[0134] The external test device 103 receives the third fault type that the user needs to test; according to the preset mapping relationship between the fault type and the fault simulation signal, it injects the third fault simulation signal corresponding to the third fault type into the domain controller 101 under test.
[0135] Step 210: The external test device 103 receives the third fault code generated by the domain controller under test 101 based on the third fault simulation signal, and forwards the third fault code to the backup domain controller 105. The backup controller 105 is used to determine and execute the third degradation strategy corresponding to the third fault code based on the preset mapping relationship between fault codes and degradation strategies.
[0136] Figure 8 This is a flowchart illustrating a method for configuring a first fault simulation signal and a third fault simulation signal. As one possible implementation, steps 212 to 213 may be further executed before step 201 or step 208.
[0137] Step 212: External test equipment 103 receives the pre-compiled first fault simulation signal and third fault simulation signal;
[0138] Step 213: The external test device 103 responds to the second configuration operation for the first fault simulation signal and the third fault simulation signal, and determines the mapping relationship between the first fault simulation signal and the first fault type, and the mapping relationship between the third fault simulation signal and the third fault type.
[0139] The above description is merely a preferred embodiment of this specification and is not intended to limit this specification. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this specification should be included within the scope of protection of this specification.
Claims
1. A fault degradation testing system, characterized in that, The system includes: a domain controller under test, a vehicle electronic control module under test, and external test equipment electrically connected to the domain controller under test and the vehicle electronic control module under test respectively. The vehicle electronic control module under test includes sensors, ECUs and actuators, and is responsible for implementing specific functions. The domain controller under test is the superior controller of the vehicle electronic control module under test. The external testing equipment is used to receive the first fault type that the user needs to test; according to the preset mapping relationship between the fault type and the fault simulation signal, it generates a first fault simulation signal corresponding to the first fault type, and injects the first fault simulation signal into the electronic control module of the vehicle body under test. The first fault simulation signal is a combination of one or more of the following: voltage / current abnormal signal generated by injection, interference signal from other signal sources generated by injection, distortion signal obtained by distorting the signal of the sensor or controller, and mechanical fault signal generated by configuring different simulation strategies. The vehicle electronic control module under test is used to generate a first fault code based on the first fault simulation signal and forward it to the domain controller under test through the external test equipment. The domain controller under test is used to execute the first degradation strategy corresponding to the first fault code according to the preset mapping relationship between fault codes and degradation strategies.
2. The system according to claim 1, characterized in that, The system also includes other vehicle body electronic control modules, and the external testing equipment is electrically connected to the other vehicle body electronic control modules. The other vehicle body electronic control modules are used to send interactive signals to the external test equipment; The external testing equipment is also used to receive the second fault type that the user needs to test; according to the preset network fault rules, the interactive signal is processed into the second fault simulation signal corresponding to the second fault type, and the second fault simulation signal is injected into the domain controller under test; The domain controller under test is further configured to generate a second fault code based on the second fault simulation signal, and execute the second degradation strategy corresponding to the second fault code according to the preset mapping relationship between the fault code and the degradation strategy.
3. The system according to claim 2, characterized in that, The external testing equipment is also used for: Receive multiple pre-compiled fault-generating codes, which are used to modify the content of the interaction signal to simulate all fault types of the interaction signal; In response to the first configuration operation for the multiple fault-causing codes, the mapping relationship between all fault types and the multiple fault-causing codes is determined to obtain the network fault rules.
4. The system according to claim 1, characterized in that, The system further includes: a backup domain controller, which is electrically connected to the external test equipment; The external testing equipment is also used to receive the third fault type that the user needs to test; generate the third fault simulation signal corresponding to the third fault type according to the preset mapping relationship between the fault type and the fault simulation signal, and inject the third fault simulation signal into the domain controller under test. The domain controller under test is further configured to generate a third fault code based on the third fault simulation signal, and forward the third fault code to the backup domain controller through the external test equipment; The backup domain controller is used to execute the third degradation strategy corresponding to the third fault code according to the preset mapping relationship between fault codes and degradation strategies.
5. The system according to claim 4, characterized in that, The external testing equipment is also used for: Receive the pre-compiled first fault simulation signal and the third fault simulation signal; In response to a second configuration operation for the first fault simulation signal and the third fault simulation signal, the mapping relationship between the first fault simulation signal and the first fault type, and the mapping relationship between the third fault simulation signal and the third fault type are determined.
6. A fault degradation testing method, applied to the fault degradation testing system according to any one of claims 1-5, characterized in that, The method includes: The external testing equipment receives the first type of fault that the user needs to test; The external testing equipment generates a first fault simulation signal corresponding to the first fault type according to the preset mapping relationship between fault type and fault simulation signal. The first fault simulation signal is a combination of one or more of the following: voltage / current abnormal signal generated by injection, interference signal from other signal sources generated by injection, distortion signal obtained by distorting the signal of sensor or controller, and mechanical fault signal generated by configuring different simulation strategies. The external testing equipment sends the first fault simulation signal to the vehicle electronic control module under test, and the vehicle electronic control module under test generates and sends a first fault code to the external testing equipment based on the first fault simulation signal. The external test device receives the first fault code and forwards it to the domain controller under test. The domain controller under test determines and executes the first degradation strategy corresponding to the first fault code based on a preset mapping relationship between fault codes and degradation strategies.
7. The method according to claim 6, characterized in that, The method further includes: The external testing equipment receives interactive signals sent by other vehicle body electronic control modules and processes the interactive signals into a second fault simulation signal according to preset network fault rules. The external test device forwards the second fault simulation signal to the domain under test controller. The domain under test controller generates a second fault code based on the second fault simulation signal and determines and executes the second degradation strategy corresponding to the second fault code based on the preset mapping relationship between fault codes and degradation strategies.
8. The method according to claim 7, characterized in that, The method further includes: The external testing equipment receives multiple pre-compiled fault-causing codes, which are used to modify the content of the interactive signal to simulate all fault types of the interactive signal. The external testing device responds to the first configuration operation for the multiple fault-causing codes, determines the mapping relationship between all fault types and the multiple fault-causing codes, and obtains the network fault rules.
9. The method according to claim 6, characterized in that, The method further includes: The external testing equipment receives the third type of fault that the user needs to test; The external test device generates a third fault simulation signal corresponding to the third fault type according to a preset mapping relationship between fault types and fault simulation signals, and injects the third fault simulation signal into the domain under test controller. The domain under test controller is used to generate and send a third fault code to the external test device based on the third fault simulation signal. The external test device receives the third fault code and forwards it to the backup domain controller. The backup domain controller determines and executes the third degradation strategy corresponding to the third fault code based on the preset mapping relationship between fault codes and degradation strategies.
10. The method according to claim 9, characterized in that, The method further includes: The external test equipment receives the pre-compiled first fault simulation signal and the third fault simulation signal; The external test equipment responds to a second configuration operation for the first fault simulation signal and the third fault simulation signal to determine the mapping relationship between the first fault simulation signal and the first fault type, and the mapping relationship between the third fault simulation signal and the third fault type.
Citation Information
Patent Citations
Vehicle test method and apparatus and machine readable storage medium
CN109507981A
Real vehicle function safety fault injection test method and system
CN113467416A
Fault degradation simulation test method based on L4-level intelligent driving algorithm
CN115993811A