Braking system and method of designing the same

CN117901831BActive Publication Date: 2026-09-18FAW CAR CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202410212433.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-02-27
Publication Date
2026-09-18
Estimated Expiration
2044-02-27

AI Technical Summary

Technical Problem

但是仅针对行车制动系统的功能安全开发方案还存在一些不足,如经济性差、方案复杂、成本高等问题

Benefits of technology

[0036] This invention introduces a dual-control EPB redundant braking scheme. Starting from the functional definition, it performs hazard analysis and risk assessment based on the functional failure modes, derives functional safety objectives, and finally transforms them into executable functional safety mechanisms and measures. At the same time, it improves development economy and vehicle safety, solves braking safety and regulatory compliance issues, and reduces enterprise costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117901831B_ABST
    Figure CN117901831B_ABST
Patent Text Reader

Abstract

The application is a kind of brake system and its design method. It includes double control EPB system; double control EPB system includes first EPB, second EPB, third EPB and fourth EPB; first EPB, second EPB are installed on the left front wheel and right front wheel of vehicle respectively; third EPB and fourth EPB are installed on the left rear wheel and right rear wheel of vehicle respectively; A1 executor is arranged on the first EPB; A2 executor is arranged on the fourth EPB; B1 executor is arranged on the second EPB; B2 executor is arranged on the third EPB; A1 executor and A2 executor are controlled by M1 controller; B1 executor and B2 executor are controlled by M2 controller; the application designs double control EPB redundancy brake scheme, starting from function definition, according to function failure mode, carries out hazard analysis and risk assessment, derives function safety target, finally transforms into function safety mechanism and measures in the executable level, improves development economy, vehicle safety, and solves brake safety and regulation compliance problem, reduces enterprise cost.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of braking technology, specifically a braking system and its design method. Background Technology

[0002] With the continuous development of automotive technology, electronic and intelligent vehicle braking systems have become a trend in the automotive industry. Among them, the electronic parking brake system, replacing the handbrake as a new standard braking system, offers advantages such as ease of use and strong braking capability, and is widely used in modern vehicles. In actual driving, the safety of vehicle braking systems has become a focus of public attention. To ensure the reliability and safety of braking systems, functional safety development and testing verification are necessary to guarantee the overall vehicle braking safety. However, functional safety development solutions focusing solely on the service braking system have some shortcomings, such as poor economic efficiency, complex solutions, and high costs.

[0003] Therefore, in order to ensure the braking safety of passenger vehicles, developing redundant functional safety for the braking system can effectively protect the lives and property of passengers and other traffic participants, save enterprise development costs, and is of great significance. Summary of the Invention

[0004] This invention provides a braking system and its design method, which designs a dual-control EPB redundant braking scheme. Starting from the functional definition, hazard analysis and risk assessment are performed based on the functional failure modes to derive functional safety objectives. Finally, these objectives are transformed into executable functional safety mechanisms and measures, while improving development economy and vehicle safety. The invention also solves braking safety and regulatory compliance issues and reduces enterprise costs.

[0005] The technical solution of this invention is described below in conjunction with the accompanying drawings:

[0006] A braking system includes a dual-control EPB system; the dual-control EPB system includes a first EPB, a second EPB, a third EPB, and a fourth EPB; the first EPB and the second EPB are respectively mounted on the left front wheel and the right front wheel of a vehicle; the third EPB and the fourth EPB are respectively mounted on the left rear wheel and the right rear wheel of the vehicle; an actuator A1 is provided on the first EPB; an actuator A2 is provided on the fourth EPB; an actuator B1 is provided on the second EPB; an actuator B2 is provided on the third EPB; the A1... Actuators A1 and B2 are controlled by controller M1; actuators B1 and B2 are controlled by controller M2; when the service brake fails, actuators A1 and A2 apply the service brake; when the service brake fails and actuators A1 and A2 also fail, actuators B1 and B2 apply the service brake; controllers M1 and M2 are mounted on the chassis; actuators A1, A2, B1, and B2 are connected to sensors S1, S2, S3, and S4, respectively.

[0007] Furthermore, the first EPB and the fourth EPB constitute the SY1 parking brake system; the second EPB and the third EPB constitute the SY2 parking brake system.

[0008] Furthermore, a design method for a braking system includes the following steps:

[0009] Step 1: Perform a vehicle function analysis on the dual-control EPB system and the service braking system, determine the function list, identify the main operating scenarios of the vehicle, and analyze the failure modes and the most severe vehicle hazard events caused by different scenarios.

[0010] Step 2: Based on the severity (S), exposure rate (E), and controllability (C) level, conduct hazard analysis and risk assessment for the hazard event, and then formulate functional safety objectives based on this.

[0011] Step 3: Derive functional security requirements through system security analysis;

[0012] Step 4: Test the safety of the designed braking system.

[0013] Furthermore, the specific function list of the dual-control EPB system and the service braking system in step one is as follows:

[0014] When the braking system functions normally, the service braking system is responsible for the service braking function, the SY1 parking braking system is responsible for the parking braking function, and the SY2 parking braking system is in a dormant state and does not work.

[0015] When the service brake system fails, the service brake system controller sends a failure signal to the SY1 parking brake system. At this time, the service brake system stops working, and the brake pedal signal will be forwarded to the SY1 parking brake system. With the help of the algorithm, intermittent braking is achieved to ensure that the driver's expected braking effect is achieved. At the same time, an alarm prompt is sent to the driver. At this time, the SY2 parking brake system remains in a dormant state and awaits wake-up.

[0016] When the SY1 parking brake system fails, a failure signal is sent to the SY2 parking brake system to wake it up. The parking brake system stops working, and all functions are transferred to the SY2 parking brake system, including the redundant service brake function. At the same time, an alarm is sent to the driver.

[0017] Furthermore, the specific methods for step one, which involves determining the main operating scenarios of the vehicle and analyzing the failure modes and the most severe vehicle-wide hazard events resulting from different scenarios, are as follows:

[0018] For high-adhesion road surfaces, when the braking system fails, a hazard analysis is performed on the system, as detailed below:

[0019] For severity S, when a vehicle is traveling at 100 km / h on a dry highway and a failure occurs, it will rear-end the vehicle in front. Due to the high deceleration of the vehicle, it will cause serious injury, i.e., a high-speed collision. The probability of AIS5-6 and disability is greater than 10%. Therefore, severity S is set as S3, i.e., the third severity level.

[0020] For exposure rate E, it is assumed that the time spent driving on highways is greater than 10% and occurs in every drive, so the exposure rate level is E4, which is the fourth level of exposure rate.

[0021] For controllability C, for unintended longitudinal movement, the driver has difficulty controlling it, meaning less than 90% of drivers can usually avoid the hazard. The controllability level is C3, which is the third level of controllability.

[0022] Analysis of hazardous events caused by other failure modes ultimately determined that the highest functional safety integrity level for braking system failure is ASIL D, which is the highest functional safety integrity level for automobiles.

[0023] Furthermore, in step two, the functional safety objective is as follows:

[0024] Unintended deceleration of the vehicle should meet the safety requirements of ISO / DIS 6597, not less than 5.8 m / s². 2 ;

[0025] Unexpected reduction in a vehicle's deceleration capability should meet the safety metric for unexpected reduction in deceleration capability.

[0026] Unintended longitudinal displacement of the vehicle should meet the safety metric for unintended longitudinal motion.

[0027] Unintended lateral movement of the vehicle should meet the safety metric for unintended lateral movement.

[0028] Furthermore, in step three, the functional security requirements are derived through security analysis of the system as follows:

[0029] Implement a self-inspection mechanism, with each subsystem performing periodic self-inspections to check the system's working status, whether there are delays in signal transmission, and to interactively confirm each other's status.

[0030] The signal transmission protection mechanism implements E2E and CRC protection verification to ensure the accuracy of signal transmission and avoid information errors.

[0031] The system includes a failure alarm mechanism that immediately sends audible and visual alarms to the driver when a malfunction occurs.

[0032] Furthermore, step four, which involves testing the safety of the designed braking system, is as follows:

[0033] Conduct functional safety testing, derive test cases based on functional safety goals and requirements, and carry out targeted testing, including virtual simulation testing and real vehicle fault injection testing, to confirm that each safety goal has been achieved;

[0034] Extreme tests are conducted, including long-term tests, back-to-back tests, and robustness tests, to ensure that the braking system maintains functionally safe and qualified braking performance even under extreme conditions.

[0035] The beneficial effects of this invention are as follows:

[0036] This invention introduces a dual-control EPB redundant braking scheme. Starting from the functional definition, it performs hazard analysis and risk assessment based on the functional failure modes, derives functional safety objectives, and finally transforms them into executable functional safety mechanisms and measures. At the same time, it improves development economy and vehicle safety, solves braking safety and regulatory compliance issues, and reduces enterprise costs. Attached Figure Description

[0037] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0038] Figure 1 This is a design flowchart of the present invention;

[0039] Figure 2 This is a schematic diagram of the dual-control EPB system. Detailed Implementation

[0040] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0041] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this invention, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0042] Example 1

[0043] See Figure 2 This embodiment provides a braking system including a dual-control EPB system; the dual-control EPB system includes a first EPB, a second EPB, a third EPB, and a fourth EPB.

[0044] The first EPB and the second EPB are respectively installed on the left front wheel and the right front wheel of the vehicle; the third EPB and the fourth EPB are respectively installed on the left rear wheel and the right rear wheel of the vehicle; the first EPB is equipped with an A1 actuator; the fourth EPB is equipped with an A2 actuator; the second EPB is equipped with a B1 actuator; the third EPB is equipped with a B2 actuator; the A1 actuator and the A2 actuator are controlled by an M1 controller; the B1 actuator and the B2 actuator are controlled by an M2 controller; when the service brake fails, the A1 actuator and the A2 actuator perform the service brake; when the service brake fails and the A1 actuator and the A2 actuator also fail, the B1 actuator and the B2 actuator perform the service brake; the M1 controller and the M2 controller are installed on the chassis; the A1 actuator, the A2 actuator, the B1 actuator, and the B2 actuator are respectively connected to the S1 sensor, the S2 sensor, the S3 sensor, and the S4 sensor.

[0045] Among them, sensors S1, S2, S3 and S4 are used to detect the status and position information of the parking brake system and send relevant information signals to the controller.

[0046] The M1 and M2 controllers are used to receive signals from the braking system and control the actuators to clamp and release.

[0047] Actuators A1, A2, A3, and A4 are used to receive controller signals and release and clamp the brake.

[0048] In addition, the first EPB and the fourth EPB constitute the SY1 parking brake system; the second EPB and the third EPB constitute the SY2 parking brake system.

[0049] When the braking system functions normally, the service brake system is responsible for the service braking function, the SY1 parking brake system is responsible for the parking braking function, and the SY2 parking brake system is in a dormant state and does not operate. When the service brake system fails, the service brake system controller sends a failure signal to the SY1 parking brake system. At this time, the service brake system stops working, and the brake pedal signal is forwarded to the SY1 parking brake system. With the assistance of existing algorithms, intermittent braking is achieved to ensure that the driver's expected braking effect is achieved. At the same time, an alarm is sent to the driver. In this case, the SY2 parking brake system remains in a dormant state. Alternatively, when the SY1 parking brake system fails, a failure signal is sent to the SY2 parking brake system to wake it up. The SY1 parking brake system stops working, and all functions are performed by the SY2 parking brake system, including redundant service brake functions. At the same time, an alarm is sent to the driver.

[0050] The M1 and M2 controllers are independently backed up. When the service brake fails, the A1 / A2 actuators will perform the service brake. When the A1 / A2 actuators also fail, the B1 / B2 actuators will perform the service brake, which can further ensure the safety of the vehicle's braking function.

[0051] Example 2

[0052] See Figure 1 This embodiment provides a design method for a braking system, characterized by the following steps:

[0053] Step 1: Perform a vehicle function analysis on the dual-control EPB system and the service braking system, determine the function list, identify the main operating scenarios of the vehicle, and analyze the failure modes and the most severe vehicle hazard events caused by different scenarios.

[0054] The specific functions of the dual-control EPB system and the service braking system are as follows:

[0055] When the braking system functions normally, the service braking system is responsible for the service braking function, the SY1 parking braking system is responsible for the parking braking function, and the SY2 parking braking system is in a dormant state and does not work.

[0056] When the service brake system fails, the service brake system controller sends a failure signal to the SY1 parking brake system. At this time, the service brake system stops working, and the brake pedal signal will be forwarded to the SY1 parking brake system. With the help of the algorithm, intermittent braking is achieved to ensure that the driver's expected braking effect is achieved. At the same time, an alarm prompt is sent to the driver. At this time, the SY2 parking brake system remains in a dormant state and awaits wake-up.

[0057] When the SY1 parking brake system fails, a failure signal is sent to the SY2 parking brake system to wake it up. The parking brake system stops working, and all functions are transferred to the SY2 parking brake system, including the redundant service brake function. At the same time, an alarm is sent to the driver.

[0058] The specific methods for identifying the main operating scenarios of the vehicle and analyzing the failure modes and the most severe vehicle-wide hazard events resulting from different scenarios are as follows:

[0059] For high-adhesion road surfaces, a hazard analysis is performed on the braking system in the event of a malfunction:

[0060] For severity S, when a vehicle is traveling at 100 km / h on a dry highway and a failure occurs, it will rear-end the vehicle in front. Due to the high deceleration of the vehicle, it will cause serious injury, i.e., a high-speed collision. The probability of AIS5-6 and disability is greater than 10%. Therefore, severity S is set as S3, i.e., the third severity level.

[0061] For exposure rate E, it is assumed that the time spent driving on highways is greater than 10% and occurs in every drive, so the exposure rate level is E4, which is the fourth level of exposure rate.

[0062] For controllability C, for unintended longitudinal movement, the driver has difficulty controlling it, meaning less than 90% of drivers can usually avoid the hazard. The controllability level is C3, which is the third level of controllability.

[0063] Analysis of hazardous events caused by other failure modes ultimately determined that the highest functional safety integrity level for braking system failure is ASIL D, which is the highest functional safety integrity level for automobiles.

[0064] Step 2: Based on the severity (S), exposure rate (E), and controllability (C) level, conduct hazard analysis and risk assessment for the hazard event, and then formulate functional safety objectives based on this.

[0065] The functional safety objectives are as follows:

[0066] Unintended deceleration of the vehicle should meet the safety requirements of ISO / DIS 6597, not less than 5.8 m / s². 2 ;

[0067] Unexpected reduction in a vehicle's deceleration capability should meet the safety metric for unexpected reduction in deceleration capability.

[0068] Unintended longitudinal displacement of the vehicle should meet the safety metric for unintended longitudinal motion.

[0069] Unintended lateral movement of the vehicle should meet the safety metric for unintended lateral movement.

[0070] Step 3: Derive functional security requirements through security analysis of the system.

[0071] The specific functional security requirements derived from the system's security analysis are as follows:

[0072] Implement a self-inspection mechanism, with each subsystem performing periodic self-inspections to check the system's working status, whether there are delays in signal transmission, and to interactively confirm each other's status.

[0073] The signal transmission protection mechanism implements E2E and CRC protection checks to ensure the accuracy of signal transmission and avoid information errors. Among them, E2E stands for End to End, and CRC stands for Cyclic Redundancy Check.

[0074] The system includes a failure alarm mechanism that immediately sends audible and visual alarms to the driver when a malfunction occurs.

[0075] Step 4: Test the safety of the designed braking system.

[0076] The safety of the designed braking system was tested in the following ways:

[0077] Conduct functional safety testing, derive test cases based on functional safety goals and requirements, and carry out targeted testing, including virtual simulation testing and real vehicle fault injection testing, to confirm that each safety goal has been achieved;

[0078] Extreme tests are conducted, including long-term tests, back-to-back tests, and robustness tests, to ensure that the braking system maintains functionally safe and qualified braking performance even under extreme conditions.

[0079] In summary, this invention introduces a dual-control EPB redundant braking scheme. Starting from the functional definition, it conducts hazard analysis and risk assessment based on the functional failure modes, derives functional safety objectives, and finally transforms them into executable functional safety mechanisms and measures. At the same time, it improves development economy and vehicle safety, solves braking safety and regulatory compliance issues, and reduces enterprise costs.

[0080] Although embodiments of the present invention have been disclosed above, they are not limited to the applications listed in the specification and embodiments. It can be applied to various fields suitable for the invention. Further modifications can be readily made by those skilled in the art. Therefore, without departing from the general concept defined by the claims and their equivalents, the invention is not limited to the specific details and illustrations shown and described herein.

Claims

1. A braking system, characterized in that, The system includes a dual-control EPB system; the dual-control EPB system includes a first EPB, a second EPB, a third EPB, and a fourth EPB; the first EPB and the second EPB are respectively installed on the left front wheel and the right front wheel of the vehicle; the third EPB and the fourth EPB are respectively installed on the left rear wheel and the right rear wheel of the vehicle; the first EPB is equipped with an A1 actuator; the fourth EPB is equipped with an A2 actuator; the second EPB is equipped with an B1 actuator; the third EPB is equipped with a B2 actuator; the A1 actuator and A2 actuator is controlled by controller M1; B1 actuator and B2 actuator are controlled by controller M2; when the service brake fails, A1 actuator and A2 actuator perform the service brake; when the service brake fails and A1 actuator and A2 actuator also fail, B1 actuator and B2 actuator perform the service brake; the M1 controller and M2 controller are mounted on the chassis; A1 actuator, A2 actuator, B1 actuator and B2 actuator are respectively connected to sensors S1, S2, S3 and S4. The first EPB and the fourth EPB constitute the SY1 parking brake system; the second EPB and the third EPB constitute the SY2 parking brake system.

2. A design method for a braking system, characterized in that, Includes the following steps: Step 1: Perform a vehicle function analysis on the dual-control EPB system and the service braking system, determine the function list, identify the main operating scenarios of the vehicle, and analyze the failure modes and the most severe vehicle hazard events caused by different scenarios. Step 2: Based on the severity (S), exposure rate (E), and controllability (C) level, conduct hazard analysis and risk assessment for the hazard event, and then formulate functional safety objectives based on this. Step 3: Derive functional security requirements through system security analysis; Step 4: Test the safety of the designed braking system; The specific function list of the dual-control EPB system and the service braking system in step one is as follows: When the braking system functions normally, the service braking system is responsible for the service braking function, the SY1 parking braking system is responsible for the parking braking function, and the SY2 parking braking system is in a dormant state and does not work. When the service brake system fails, the service brake system controller sends a failure signal to the SY1 parking brake system. At this time, the service brake system stops working, and the brake pedal signal will be forwarded to the SY1 parking brake system. With the help of the algorithm, intermittent braking is achieved to ensure that the driver's expected braking effect is achieved. At the same time, an alarm prompt is sent to the driver. At this time, the SY2 parking brake system remains in a dormant state and awaits wake-up. When the SY1 parking brake system fails, a failure signal is sent to the SY2 parking brake system to wake it up. The parking brake system stops working, and all functions are transferred to the SY2 parking brake system, including the redundant service brake function. At the same time, an alarm prompt is sent to the driver. The specific methods for step one, which involves determining the vehicle's main operating scenarios and analyzing the failure modes and the most severe vehicle-wide hazard events resulting from different scenarios, are as follows: For high-adhesion road surfaces, when the braking system fails, a hazard analysis is performed on the system, as detailed below: For severity S, when a vehicle is traveling at 100 km / h on a dry highway and a failure occurs, it will rear-end the vehicle in front. Due to the high deceleration of the vehicle, it will cause serious injury, i.e., a high-speed collision. The probability of AIS5~6 and disability is greater than 10%. Therefore, severity S is set as S3, i.e., the third severity level. For exposure rate E, it is assumed that the time spent driving on highways is greater than 10% and occurs in every drive, so the exposure rate level is E4, which is the fourth level of exposure rate. For controllability C, for unintended longitudinal movement, the driver has difficulty controlling it, meaning less than 90% of drivers can usually avoid the hazard. The controllability level is C3, which is the third level of controllability. Analyzing the hazardous events caused by other failure modes, the highest functional safety integrity level for a vehicle is determined to be ASIL D, which is the highest functional safety integrity level for braking system failure. The functional safety objectives for step two are as follows: Unintended deceleration of the vehicle should meet the safety requirements of ISO / DIS 6597, not less than 5.8 m / s². 2 ; Unexpected reduction in a vehicle's deceleration capability should meet the safety metric for unexpected reduction in deceleration capability. Unintended longitudinal displacement of the vehicle should meet the safety metric for unintended longitudinal motion. Unintended lateral movement of the vehicle should meet the safety metric for unintended lateral movement; The specific functional security requirements derived from the system's security analysis are as follows: Implement a self-inspection mechanism, with each subsystem performing periodic self-inspections to check the system's working status, whether there are delays in signal transmission, and to interactively confirm each other's status. The signal transmission protection mechanism implements E2E and CRC protection verification to ensure the accuracy of signal transmission and avoid information errors. The failure alarm mechanism immediately sends an audio and video alarm to the driver when a malfunction occurs in the system. Step four, testing the safety of the designed braking system, is as follows: Conduct functional safety testing, derive test cases based on functional safety goals and requirements, and carry out targeted testing, including virtual simulation testing and real vehicle fault injection testing, to confirm that each safety goal has been achieved; Extreme tests are conducted, including long-term tests, back-to-back tests, and robustness tests, to ensure that the braking system maintains functionally safe and qualified braking performance even under extreme conditions.

Citation Information

Patent Citations

  • Hardware redundant integrated electro-hydraulic brake drive-by-wire system and method

    CN114312720A

  • Emergency braking control method and device based on function safety development

    CN117227746A

  • Function safety test method for brake-by-wire system

    CN117389245A