AMT function security test method based on hardware-in-the-loop
Through the hardware-in-loop AMT functional safety testing method, a hardware and software platform is built to simulate fault scenarios, solving the problem of insufficient TCU functional safety testing and verification, and achieving efficient and accurate TCU safety evaluation and verification.
Patent Information
- Application Number
- CN202510347463.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-24
- Publication Date
- 2025-07-18
AI Technical Summary
In the prior art, TCU functional safety testing methods have fewer applications, making it difficult to effectively evaluate and verify the safety of AMT systems, and actual vehicle testing is dangerous and expensive.
Using hardware-in-ring AMT functional safety testing method, by building a hardware platform and software platform, including load solenoid valve sets, HIL cabinets, TCUs and host computers, the test case design and operation is used to design and run tools such as Configuration Desk, Control Desk, ECU-TEST and CANape to simulate fault scenarios and verify the functional safety of TCUs.
It improves the efficiency and accuracy of TCU functional safety testing, and is easy to simulate fault and failure scenarios, ensures the safety of testers and meets functional safety requirements and technical safety requirements.
Smart Images

Figure CN120340170A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of hardware-in-the-loop simulation, and particularly relates to a hardware-in-the-loop based AMT functional safety test method. Background Art
[0002] With the rapid development of vehicle intelligence, the number of electronic components and software codes inside and outside the vehicle has increased sharply, and functional safety has become increasingly important. As one of the most important components in the vehicle, the requirements for functional safety of the TCU are of great significance for the development of the TCU. Many upstream and downstream manufacturers have been providing products that meet the requirements of functional safety, but most of the research focuses on the failure analysis of the TCU and the corresponding functional design, and the application of the verification of the test methods that meet the requirements of functional safety is less. Summary of the Invention
[0003] The present invention provides a hardware-in-the-loop based AMT functional safety test method, which can effectively evaluate and verify the safety of the AMT system, improve the test efficiency and accuracy, and is more likely to simulate fault and failure scenarios on the HIL compared with real vehicle tests, ensuring the safety of test personnel.
[0004] To achieve the above object, the technical solutions adopted by the present invention include:
[0005] A hardware-in-the-loop based AMT functional safety test method, comprising:
[0006] According to the AMT HIL functional safety test process, the hardware-in-the-loop based AMT functional safety test method is implemented, including the construction of the hardware platform and the software platform;
[0007] Construction of the hardware platform: The hardware includes a load solenoid valve group, a HIL cabinet, a TCU, and a host computer. Connect the corresponding pins of the TCU to the HIL cabinet. The pins for the control signal of the load solenoid valve group need to be led out from the Load board of the HIL cabinet and connected to the load solenoid valve group. The host computer is connected to the HIL cabinet to provide operating software;
[0008] The construction of the software platform includes:
[0009] 1) Construct a controlled object model related to functional safety, a Configuration Desk configuration project, a ControlDesk test management project, an ECU-TEST automated test project, and a CANape test project;
[0010] 2) Use the ConfigurationDesk software to perform HIL software configuration, complete the construction of the HIL platform, establish a signal chain, establish a model interface, and perform pin assignment;
[0011] 3) Compile and generate the sdf file; the controlled object model and the model interface established in 2) are both compiled and generated into the sdf file through the Configuration Desk project;
[0012] 4) Create a test project in the Control Desk test management project;
[0013] 5) Write test cases according to requirements in the ECU-TEST automated test project, establish a test case library, and run them in batches to generate a test report;
[0014] 6) CANape calibrates parameter values and acquires measurement signals during the operation of the TCU, providing symbolic access to diagnostic data and diagnostic services;
[0015] According to the ISO26262 test requirements, conduct open-loop and closed-loop tests on the TCU, design test scenarios, test cases, debug test cases, and run test cases using the controlled object model to complete the test.
[0016] Optionally, the load solenoid valve group includes a shift solenoid valve, a clutch solenoid valve, and a PTO solenoid valve;
[0017] The DS2680 board in the HIL cabinet provides all I / O channels, connects to the analog channels of the actuator model built in the controlled object model, and connects to the real load solenoid valve group; the DS2671 board is responsible for simulating the CAN input signals required by the TCU and simultaneously acquiring the CAN output signals of the TCU under test to achieve open-loop and closed-loop tests.
[0018] Optionally, the open-loop and closed-loop tests of the TCU include:
[0019] I / O test, communication test, and function test;
[0020] Among them, the I / O test and communication test include: verifying that the signals sent by the HIL to the TCU application layer can be correctly interpreted by the TCU; verifying that the signals output by the TCU application layer can be correctly interpreted by the HIL; all signals are static values and no dynamic response is required;
[0021] The function test includes: verifying functions and modes, including verifying starting, gear up / down, automatic shifting, manual shifting, and economy / power modes.
[0022] Optionally, the design of the test cases includes:
[0023] Input shaft speed signal, the allowable input shaft speed range in the functional safety software is -3000~3000 rpm. When the speed on the actual vehicle is higher or lower than the allowable upper and lower threshold values, according to the functional safety requirements and technical safety requirements, the functional safety mechanism will be triggered;
[0024] The specific design steps are as follows: ① Set the test conditions: The vehicle's KL30 and KL15 are in the powered-on state; the engine is in the idle state; the vehicle is stationary; the handle is in the neutral state; the TCU is in the normal mode;
[0025] ② Call CANape, read the upper and lower limit thresholds of the input shaft speed in the software, and record these upper and lower limit values as Upper and Lower;
[0026] ③ Call ControlDesk, calibrate the input shaft speed to (Upper + Lower) / 2 rpm, wait for FTTI seconds, and check the Watchdog status; calibrate the input shaft speed to (Upper + 50) rpm, wait for FTTI seconds, and check the Watchdog status; calibrate the input shaft speed to (Lower - 50) rpm, wait for FTTI seconds, and check the Watchdog status;
[0027] ④ After the test passes, the Watchdog statuses in step ③ are 0, 1, 1 respectively, meeting the safety level ASIL C.
[0028] Optionally, the design of the test case includes: a fault injection test, the ReqTrsmGear signal of the TC1 message, and HIL simulates the timeout of the TC1 message, that is, disable the TC1 message enable, and then wait for 10 times the period of the TC1 message to check whether the functional safety state is triggered;
[0029] The specific test case steps are as follows: ① Set the test conditions: The vehicle's KL30 and KL15 are in the powered-on state; the engine is in the idle state; the vehicle is stationary; the handle is in the neutral state; the TCU is in the normal mode;
[0030] ② In ControlDesk, no TC1 message timeout fault is injected, wait for FTTI seconds, and check the Watchdog status;
[0031] ③ Call the ControlDesk fault injection module, inject the TC1 message timeout fault, wait for FTTI seconds, and check the Watchdog status;
[0032] ④ After the test passes, the Watchdog statuses in steps ② and ③ are 0 and 1 respectively, meeting the safety level ASIL C.
[0033] Optionally, the design of the test case includes: a fault injection test, the ReqTrsmGear signal of the TC1 message, and in HIL, calibrate the ReqTrsmGear signal to exceed or be lower than the upper and lower limits allowed in the software, and then check whether the functional safety state is triggered;
[0034] The specific test case steps are as follows: ① Set the test conditions: The vehicle's KL30 and KL15 are powered on; the engine is at idle speed; the vehicle is stationary; the handle is in the neutral position; the TCU is in the normal mode;
[0035] ② Call CANape, read the upper and lower limit thresholds of the ReqTrsmGear signal in the software, and record these upper and lower limit values as Upper and Lower;
[0036] ③ Call ControlDesk, calibrate the ReqTrsmGear value of the TC1 message to (Upper + Lower) / 2 rpm, wait for FTTI seconds, and check the Watchdog status; calibrate the ReqTrsmGear value of the TC1 message to (Upper + 50) rpm, wait for FTTI seconds, and check the Watchdog status; calibrate the ReqTrsmGear value of the TC1 message to (Lower - 50) rpm, wait for FTTI seconds, and check the Watchdog status;
[0037] ④ After the test passes, the Watchdog statuses in step ③ are 0, 1, and 1 respectively, meeting the safety level ASIL C.
[0038] Optionally, the design of the test case includes: functional testing;
[0039] The function is unexpected start in automatic gear. The test case steps are as follows: ① Set the test conditions: The vehicle's KL30 and KL15 are powered on; the engine is at idle speed; the vehicle is stationary; the handle is in the neutral position; the TCU is in the normal mode; the Creep function is turned off;
[0040] ② Check the Watchdog status when the handle is in the neutral position and the vehicle is stationary;
[0041] ③ Call ControlDesk, set the brake pedal opening to 50%, place the handle in gear A, wait for 2 s, and engage the starting gear; after engaging the starting gear, release the brake, set the accelerator pedal opening to 50%, wait for the vehicle speed to increase until it stabilizes, and check the Watchdog status when the vehicle is driving normally;
[0042] ④Release the accelerator pedal, step on the brake, and wait until the vehicle speed drops to 0 and the vehicle stops. At this time, the engine is idling, the gear is in the starting gear, the clutch is in the disengaged state, and read the current clutch displacement value in CANape, marked as CluPosn; ECUTEST pulls the calibrated value of the clutch displacement in the HIL model, and uses the Stimulation / Ramp function module to simulate the clutch displacement reaching the clutch zero point from the CluPosn position at different slopes within the FTTI time, causing the vehicle to unexpectedly move with the throttle pedal at 0, and check the Watchdog status and the response after triggering the safety mechanism;
[0043] ⑤After the test passes, the Watchdog status in step ② is 0; the Watchdog status in step ③ is 0; the Watchdog status in step ④ is 1, and the response after triggering the safety mechanism: inhibit the TCU from sending CAN, the solenoid valve fails, inhibit the vehicle from moving, and the vehicle remains stationary, meeting the safety level ASIL D.
[0044] Optionally, the function further includes dynamic and static verification of the current gear, dynamic and static detection of the clutch state, E2E verification, self-learning, or engine - transmission loss torque verification;
[0045] For different functions, design different test scenarios in step ④;
[0046] After completing the design and debugging of the above test cases, establish a test case library, and use ECU-TEST to run the test cases in batches to generate a test report.
[0047] The advantages of the present invention are:
[0048] The hardware-in-the-loop based AMT functional safety test method introduced in the present invention is used for the integration and test verification of functional safety, mainly including: the correct implementation of functional safety requirements and technical safety requirements; the correct functional performance, accuracy, and timing of the safety mechanism; the consistency and correctness of interface implementation; the effectiveness of the diagnosis or failure coverage of the safety mechanism, and the verification of the robustness level. Description of the Drawings
[0049] The drawings are used to provide a further understanding of the present invention, and constitute a part of the specification. They are used together with the following specific embodiments to explain the present invention, but do not constitute a limitation to the present invention. In the drawings:
[0050] Figure 1 Schematic diagram of the AMT HIL functional safety test process;
[0051] Figure 2 Schematic diagram of the AMT HIL functional safety test software and hardware platform;
[0052] Figure 3 Flow chart of the test method for the unexpected start function of the automatic transmission Detailed implementation manners
[0053] The following are specific embodiments of the present invention. It should be noted that the present invention is not limited to the following specific embodiments, and any equivalent transformation based on the technical solutions of this application falls within the protection scope of the present invention.
[0054] The English terms and abbreviations appearing in this text are explained as follows:
[0055] TCU is the transmission controller;
[0056] The DSPACE cabinet represents the HIL cabinet, and dSPACE is the cabinet supplier;
[0057] The PTO solenoid valve is the power take-off solenoid valve
[0058] The controlled object model refers to a virtual controlled object that deceives the TCU into thinking that it is interacting with a real physical system;
[0059] Configuration Desk is common in the configuration engineering industry;
[0060] Control Desk is common in the test management engineering industry;
[0061] ECU-TEST is common in the automated test engineering industry;
[0062] CANape is common in the test engineering industry;
[0063] The DS2680 board is common in the industry;
[0064] The DS2671 board is common in the industry;
[0065] signal chain represents the signal chain;
[0066] model interface represents the model interface;
[0067] The vehicle KL30 and KL15 mean: KL30 is the vehicle battery power supply switch, and KL15 is the ignition switch;
[0068] The Watchdog state is the watchdog state;
[0069] The failure of the ReqTrsmGear signal means the failure of the required gear signal in the transmission lever message;
[0070] The TC1 message represents the transmission lever message;
[0071] Stimulation / Ramp function module
[0072] E2E check represents end-to-end check;
[0073] FSR / TSR analysis represents functional safety requirement / technical safety requirement analysis;
[0074] FTTI refers to fault-tolerant time interval;
[0075] The electronically controlled mechanical automatic transmission (AMT, full name Automatic Mechanical Transmission) is a transmission that realizes automatic shifting on the basis of a traditional mechanical transmission and a dry clutch by adding components such as a controller unit, an actuator, and a sensor.
[0076] Hardware In Loop (HIL) test refers to connecting the controller to the simulation model of the controlled object and comprehensively testing the functions of the controller in a real-time environment. The HIL test can simulate the dynamic responses of the AMT and the whole vehicle, and can test the performance of the system under various working conditions such as operation modes, different functions, single or multiple fault scenarios, and different road conditions. Especially when the system fails, on-road vehicle testing is both dangerous and expensive, but HIL can easily implement fault injection to test and verify the fault diagnosis function.
[0077] In addition, with the continuous upgrade of the controller software and the requirements of specifications such as ISO 26262 functional safety, the requirements for controller testing are constantly increasing, and the number of test items is constantly increasing, making the application of automated testing an inevitable trend.
[0078] The present invention provides a hardware-in-the-loop-based AMT functional safety test method, which can effectively evaluate and verify the safety of the AMT system, improve the test efficiency and accuracy, and is more likely to simulate fault and failure scenarios on HIL compared with on-road vehicle testing, ensuring the safety of testers. The method steps are as shown. Figure 1 .
[0079] Before conducting the TCU functional safety test of the present invention, it is necessary to build a necessary software and hardware test platform. The hardware platform includes: dSPACE cabinet, independent TCU, shift solenoid valve, clutch solenoid valve, PTO solenoid valve, wire harness from the real load to the HIL cabinet end, wire harness from the HIL cabinet to the TCU end, host computer, etc. Among them, the DS2680 board in the cabinet can provide all I / O channels for automotive powertrain simulation, and can be connected to the actuator simulation channel through this board, or can be connected to the real load, and can realize real-time transmission of all IO channels of the TCU; the DS2671 board is responsible for simulating the CAN input signals required by the vehicle controller, and at the same time collecting the CAN output signals of the controller under test to realize closed-loop testing.
[0080] The software platform includes: the controlled object model, the test case library, the Configuration Desk configuration project, the Control Desk test management project, the ECU-TEST automated test project, and the CANape test project. Among them, the physical models include the engine model, the transmission model, the clutch actuator model, the environment model, the driver model, the shift actuator model, and the boundary condition models related to functional safety, the fault injection model, etc.; the ConfigurationDesk software performs HIL software configuration, completes the HIL platform construction, establishes the signal chain, establishes the model interface, and performs pin assignment; the ControlDesk software comprehensively manages the test process, including the graphical management of real-time hardware, virtual instruments, and the visual management of parameters, etc.; the ECU-TEST software can write test cases, run test cases in batches, record and analyze data, and automatically generate test reports to achieve fully automated testing; CANape can calibrate parameter values and collect measurement signals simultaneously during the operation of the TCU. In addition, it also provides symbolic access to diagnostic data and diagnostic services. The connection of the software and hardware platform is as shown in the schematic Figure 2 shown below.
[0081] The test case design method introduced in the present invention is mainly applicable to the HIL test environment and is used for the integration and test verification of functional safety, mainly including: the correct implementation of functional safety requirements and technical safety requirements; the correct functional performance, accuracy, and timing of safety mechanisms; the consistency and correctness of interface implementation; the effectiveness of diagnostic or failure coverage of safety mechanisms, and the verification of the robustness level.
[0082] Specifically, the hardware-in-the-loop based AMT functional safety test method of the present invention includes:
[0083] According to the AMT HIL functional safety test process, the hardware-in-the-loop based AMT functional safety test method is implemented, including the construction of the hardware platform and the construction of the software platform;
[0084] Hardware platform construction: The hardware includes a load solenoid valve group, a HIL cabinet, a TCU, and a host computer. Connect the TCU to the corresponding pins of the HIL cabinet. The pins of the control signal of the load solenoid valve group need to be led out from the Load board of the HIL cabinet and connected to the load solenoid valve group. The host computer is connected to the HIL cabinet to provide operating software;
[0085] The software platform construction includes:
[0086] 1) Build the controlled object model related to functional safety, Configuration Desk configuration project, ControlDesk test management project, ECU-TEST automated test project, and CANape test project;
[0087] 2) Use the ConfigurationDesk software to perform HIL software configuration, complete the HIL platform setup, establish a signal chain, establish a model interface, and perform pin assignment;
[0088] 3) Compile to generate an sdf file; both the controlled object model and the model interface established in 2) are compiled through the Configuration Desk project to generate an sdf file;
[0089] 4) Create a test project in the Control Desk test management project;
[0090] 5) Write test cases according to requirements in the ECU-TEST automated test project, establish a test case library, and run them in batches to generate a test report;
[0091] 6) CANape calibrates parameter values and collects measurement signals during the operation of the TCU, providing symbolic access to diagnostic data and diagnostic services;
[0092] The controlled object model refers to a virtual controlled object that deceives the TCU into thinking it is interacting with a real physical system; the test case library refers to the unified management of all test cases developed for this invention, facilitating batch operation by the automated test project;
[0093] According to the ISO26262 test requirements, conduct open-loop and closed-loop tests on the TCU, design test scenarios, test cases, debug test cases, and run test cases using the controlled object model to complete the test.
[0094] In the embodiments of the present disclosure, the load solenoid valve group includes a shift solenoid valve, a clutch solenoid valve, and a PTO solenoid valve; the DS2680 board in the HIL cabinet provides all I / O channels, which are connected to the simulation channels of the actuator models (such as the clutch model and the shift actuator model) built in the controlled object model, and are connected to the real load solenoid valve group; the DS2671 board is responsible for simulating the CAN input signals required by the TCU and simultaneously collecting the CAN output signals of the TCU under test to achieve open-loop and closed-loop tests.
[0095] In an embodiment of the present disclosure, the open-loop and closed-loop debugging of the TCU includes: I / O testing, communication testing, and function testing; wherein the I / O testing and communication testing include: verifying that the signals sent by the HIL to the TCU application layer can be correctly interpreted by the TCU; verifying that the signals output by the TCU application layer can be correctly interpreted by the HIL; all signals are static values, and dynamic response is not required; the function testing includes: verifying functions and modes, including verifying starting, gear up / down, automatic gear shifting, manual gear shifting, and economy / power modes.
[0096] In an embodiment of the present disclosure, the design of the test case includes: the input shaft speed signal. The allowable input shaft speed range in the functional safety software is -3000 to 3000 rpm. When the speed on the actual vehicle is higher or lower than the allowable upper and lower limit thresholds, according to the functional safety requirements and technical safety requirements, the functional safety mechanism will be triggered; the specific design steps are as follows: ① Set the test conditions: The vehicle KL30 and KL15 are in the powered-on state; the engine is in the idle state; the vehicle is stationary; the handle is in the neutral state; the TCU is in the normal mode; ② Call CANape to read the upper and lower limit thresholds of the input shaft speed in the software, and record these upper and lower limit values as Upper and Lower; ③ Call ControlDesk to calibrate the input shaft speed to (Upper + Lower) / 2 rpm, wait for FTTI seconds, and check the Watchdog status; calibrate the input shaft speed to (Upper + 50) rpm, wait for FTTI seconds, and check the Watchdog status; calibrate the input shaft speed to (Lower - 50) rpm, wait for FTTI seconds, and check the Watchdog status; ④ After the test passes, the Watchdog statuses in step ③ are 0, 1, and 1 respectively, meeting the safety level ASIL C.
[0097] In an embodiment of the present disclosure, the design of the test case includes: fault injection testing. For the ReqTrsmGear signal of the TC1 message, the HIL simulates the timeout of the TC1 message, that is, closes the TC1 message enable, and then waits for 10 times the period of the TC1 message to check whether the functional safety state is triggered; the specific test case steps are as follows: ① Set the test conditions: The vehicle KL30 and KL15 are in the powered-on state; the engine is in the idle state; the vehicle is stationary; the handle is in the neutral state; the TCU is in the normal mode; ② In ControlDesk, no TC1 message timeout fault is injected, wait for FTTI seconds, and check the Watchdog status; ③ Call the ControlDesk fault injection module to inject the TC1 message timeout fault, wait for FTTI seconds, and check the Watchdog status; ④ After the test passes, the Watchdog statuses in steps ② and ③ are 0 and 1 respectively, meeting the safety level ASIL C.
[0098] In an embodiment of the present disclosure, the design of test cases includes: fault injection testing, TC1 message ReqTrsmGear signal, calibrating the ReqTrsmGear signal in HIL to exceed or be lower than the upper and lower limits allowed in the software, and then checking whether the functional safety state is triggered; the specific test case steps are as follows: ① Set the test conditions: The vehicle KL30 and KL15 are powered on; the engine is in the idle state; the vehicle is stationary; the handle is in the neutral state; the TCU is in the normal mode; ② Call CANape, read the upper and lower limit thresholds of the ReqTrsmGear signal in the software, and record these upper and lower limit values as Upper and Lower; ③ Call ControlDesk, calibrate the ReqTrsmGear value of the TC1 message to (Upper + Lower) / 2 rpm, wait for FTTI seconds, and check the Watchdog state; calibrate the ReqTrsmGear value of the TC1 message to (Upper + 50) rpm, wait for FTTI seconds, and check the Watchdog state; calibrate the ReqTrsmGear value of the TC1 message to (Lower - 50) rpm, wait for FTTI seconds, and check the Watchdog state; ④ After the test passes, the Watchdog states in step ③ are 0, 1, and 1 respectively, meeting the safety level ASIL C.
[0099] In the embodiments of the present disclosure, the design of test cases includes: functional testing; the function is accidental start in the automatic gear, and the steps of the test case are as follows: ① Set the test conditions: the vehicle KL30 and KL15 are powered on; the engine is in the idle state; the vehicle is stationary; the handle is in the neutral state; the TCU is in the normal mode; the Creep function is turned off; ② Check the status of the Watchdog when the handle is in the neutral position and the vehicle is stationary; ③ Call ControlDesk, set the brake pedal opening to 50%, set the handle to the A gear, wait for 2 s, and engage the starting gear; after engaging the starting gear, release the brake, set the accelerator pedal opening to 50%, wait for the vehicle speed to increase until the vehicle speed is stable, and check the Watchdog status when the vehicle is driving normally; ④ Release the accelerator, step on the brake, wait until the vehicle speed drops to 0, the vehicle is stationary, at this time the engine is in the idle state, the gear is in the starting gear, the clutch is in the disengaged state, and read the current clutch displacement value in CANape, marked as CluPosn; ECUTEST pulls the calibrated value of the clutch displacement in the HIL model, and uses the Stimulation / Ramp function module to simulate the clutch displacement reaching the clutch zero point from the CluPosn position at different slopes within the FTTI time, so that the vehicle accidentally travels under the condition of zero accelerator pedal, and check the Watchdog status and the response after triggering the safety mechanism; ⑤ After the test passes, the Watchdog status in step ② is 0; the Watchdog status in step ③ is 0; the Watchdog status in step ④ is 1, and the response after triggering the safety mechanism: inhibit the TCU from sending CAN, the solenoid valve fails, inhibit the vehicle from traveling, and the vehicle remains stationary, meeting the safety level ASIL D.
[0100] In the embodiments of the present disclosure, the functions further include dynamic and static verification of the current gear, dynamic and static detection of the clutch state, E2E verification, self-learning or engine-transmission loss torque verification; for different functions, different test scenarios are designed in step ④; after completing the design and debugging of the above test cases, a test case library is established, and ECU-TEST is used to batch-run the test cases to generate a test report.
[0101] Embodiment 1:
[0102] Combined with the requirements related to software integration testing in ISO26262, the present invention designs a hardware-in-the-loop test method that meets the functional safety requirements for an integrated heavy truck AMT.
[0103] The test object of the present invention is an integrated heavy-duty truck AMT, and the tool platform used is dSPACE+Matlab / Simulink+ECUTEST. The invention content is to build a whole vehicle simulation model in combination with specific functional requirements, run the simulation model with a real-time processor to simulate the operating state of the controlled object, connect with the tested TCU through the IO interface, perform fault injection based on the specific technical safety requirements of functional safety, and verify the correct implementation of safety measures and diagnostic mechanisms.
[0104] According to the AMT HIL functional safety test process, the AMT functional safety test method based on HIL is first implemented, which is divided into hardware connection and the establishment of related software engineering. Figure 2 As shown, the TCU is connected to the corresponding pins of the HIL cabinet. The pins of the solenoid valve control signal need to be led out from the HIL cabinet Load board to connect the real solenoid valve. The software platform project is implemented as follows: 1) According to the electrical specifications of all I / O interfaces of the TCU, perform HIL related configurations in the ConfigurationDesk software, including establishing signal flows and model interfaces, and performing pin allocations; 2) Build failure condition models, boundary conditions, and fault injection models related to functional safety, transmission body models, actuator models, vehicle models, engine models, clutch models, etc.; 3) Compile and generate sdf files; 4) Create a test project in ControlDesk, which mainly includes loading the files compiled by the physical model, operating the human-machine interface and test data, etc., and can perform manual testing; 5) Write test cases in ECU-TEST according to requirements and run them in batches to generate test reports.
[0105] Based on the above-mentioned software and hardware platform, after completing the construction and connection, the present invention debugs the open and closed loop of the integrated heavy-duty truck AMT application layer software. It mainly includes I / O test, communication test and basic function test. Among them, the open-loop test mainly verifies two aspects: on the one hand, it verifies that the signal sent by HIL to the TCU application layer (such as displacement sensor, speed sensor signal, etc.) can be correctly interpreted by TCU; on the other hand, it verifies that the signal output by the TCU application layer (such as solenoid valve drive signal) can be correctly interpreted by HIL; all signals are static values, and dynamic response is not required. Functional testing mainly verifies the various functions and modes of the system as a whole. For the integrated heavy-duty truck AMT system, it mainly verifies functions such as starting, shifting, automatic shifting, manual shifting, economy / power mode, etc.
[0106] Based on the above process, combined with the software safety requirement testing method for a specified ASIL level defined in ISO26262, the present invention designs and verifies test cases for the interface, communication, fault diagnosis and functions of the functional safety of the integrated heavy-duty truck AMT.
[0107] 1) Interface and Communication Testing (Interface and communication testing is a major category of tests. Taking the input shaft speed signal test as an example, it also includes a total of 29 tests such as the intermediate shaft speed, output shaft speed, shift selector displacement sensor signal, and CAN communication (the design steps are the same as those of the input shaft speed signal, but the test scenario designs are different).)
[0108] This part mainly verifies the consistency of the functional safety software interface. Taking the input shaft speed signal as an example, the allowable input shaft speed range in the functional safety software is -3000 - 3000 rpm. When the vehicle speed is higher or lower than the allowable upper and lower threshold values, according to the functional safety requirements and technical safety requirements, the functional safety mechanism will be triggered. Based on ISO26262, the test methods involved are boundary value testing, interface testing, and requirements-based testing.
[0109] The specific design steps are as follows: ① Set the test conditions: The vehicle's KL30 and KL15 are powered on; the engine is in the idle state; the vehicle is stationary; the handle is in the neutral state; the TCU is in the normal mode. ② Call CANape to read the upper and lower threshold values of the input shaft speed in the software and record these values as Upper and Lower. ③ Call ControlDesk to calibrate the input shaft speed to ((Upper + Lower) / 2) rpm, wait for the FTTI (Fault Tolerant Time Interval) seconds, and check the Watchdog status; calibrate the input shaft speed to (Upper + 50) rpm, wait for the FTTI seconds, and check the Watchdog status; calibrate the input shaft speed to (Lower - 50) rpm, wait for the FTTI seconds, and check the Watchdog status. ④ After the test passes, the Watchdog statuses in step ③ are 0, 1, and 1 respectively, meeting the safety level ASIL C.
[0110] 2) Fault Injection Testing (Taking the failure of the ReqTrsmGear signal in the TC1 message as an example, it also includes a total of 63 items such as input shaft, intermediate shaft, output shaft, shift selector displacement, and CAN communication faults. Each item also has two test methods (the design steps are the same as those of the failure of the ReqTrsmGear signal in the TC1 message, but the test scenario designs are different).)
[0111] Taking the failure of the ReqTrsmGear signal in the TC1 message as an example, there are two fault injection methods.
[0112] Method 1: HIL simulates the timeout of the TC1 message, that is, closes the TC1 message enable, and then waits for 10 times the period of the TC1 message to check whether the functional safety state is triggered. Based on ISO26262, the test methods involved are fault injection and requirements analysis testing.
[0113] The specific test case steps are as follows: ① Set the test conditions: The vehicle's KL30 and KL15 are powered on; the engine is at idle speed; the vehicle is stationary; the handle is in neutral; the TCU is in normal mode. ② No TC1 message timeout fault is injected in ControlDesk, wait for FTTI seconds, and check the Watchdog status. ③ Call the ControlDesk fault injection module, inject a TC1 message timeout fault, wait for FTTI seconds, and check the Watchdog status. ④ After the test passes, the Watchdog statuses in steps ② and ③ are 0 and 1 respectively, meeting the safety level ASIL C.
[0114] Method 2: In HIL, calibrate the ReqTrsmGear signal to exceed or be lower than the upper and lower limits allowed in the software, and then check whether the functional safety state is triggered. Based on ISO26262, the test methods involved are fault injection, requirement analysis, boundary value testing, and interface testing.
[0115] The specific test case steps are as follows: ① Set the test conditions: The vehicle's KL30 and KL15 are powered on; the engine is at idle speed; the vehicle is stationary; the handle is in neutral; the TCU is in normal mode. ② Call CANape to read the upper and lower limit thresholds of the ReqTrsmGear signal in the software, and record these values as Upper and Lower. ③ Call ControlDesk to calibrate the ReqTrsmGear value of the TC1 message to ((Upper + Lower) / 2) rpm, wait for FTTI seconds, and check the Watchdog status; calibrate the ReqTrsmGear value of the TC1 message to (Upper + 50) rpm, wait for FTTI seconds, and check the Watchdog status; calibrate the ReqTrsmGear value of the TC1 message to (Lower - 50) rpm, wait for FTTI seconds, and check the Watchdog status. ④ After the test passes, the Watchdog statuses in step ③ are 0, 1, and 1 respectively, meeting the safety level ASIL C.
[0116] 3) Functional testing (functional type testing, taking unexpected start in automatic gear as an example, other functions also include 56 items such as dynamic and static verification of the current gear, dynamic and static detection of the clutch state, E2E verification, self - learning or engine - transmission loss torque verification, etc. (the design steps are the same as those for unexpected start in automatic gear, and there are differences in the test scenario design))
[0117] Function - related testing is a reverse testing method. Through FSR / TSR analysis, various failure, abnormal working conditions, and function boundaries are simulated to ensure that the system is triggered to enter a safe state within the fault - tolerance time. Based on ISO26262, the test methods involved are: experience - based testing, requirement analysis testing.
[0118] Taking the unexpected start of an automatic transmission as an example, the test case steps are as follows: ① Set the test conditions: The vehicle's KL30 and KL15 are powered on; the engine is at idle speed; the vehicle is stationary; the handle is in the neutral position; the TCU is in the normal mode; the Creep function (when this function is enabled, the clutch will engage at 0 throttle and the vehicle will move) is turned off. ② Check the status of the Watchdog when the handle is in the neutral position and the vehicle is stationary. ③ Call ControlDesk, set the brake pedal opening to 50%, move the handle to gear A, wait for 2 s, and engage the starting gear; after engaging the starting gear, release the brake, set the accelerator pedal opening to 50%, wait for the vehicle speed to increase until it stabilizes, and check the Watchdog status when the vehicle is moving normally. ④ Release the accelerator, step on the brake, wait until the vehicle speed drops to 0 and the vehicle is stationary. At this time, the engine is at idle speed, the gear is in the starting gear, and the clutch is disengaged. Read the current clutch displacement value in CANape and mark it as CluPosn; ECU-TEST pulls the calibrated clutch displacement value in the HIL model (i.e., the controlled object model), and uses the Stimulation / Ramp function module to simulate the clutch displacement reaching the clutch 0 point (the fully engaged position of the clutch) from the CluPosn position at different slopes within the FTTI time, so that the vehicle moves unexpectedly at 0 accelerator pedal, and check the Watchdog status and the response after triggering the safety mechanism. ⑤ After the test passes, the Watchdog status in step ② is 0; the Watchdog status in step ③ is 0; the Watchdog status in step ④ is 1, and the response after triggering the safety mechanism: inhibit the TCU from sending CAN, the solenoid valve fails, inhibit the vehicle from moving, and the vehicle remains stationary, meeting the safety level ASILD. The test process is as Figure 3 shown.
[0119] The remaining functions include a total of 56 items such as dynamic and static verification of the current gear, dynamic and static detection of the clutch status, E2E verification, self-learning, and engine-transmission loss torque verification. For different functions, different test scenarios need to be designed in step ④ to meet the real-time performance.
[0120] After completing the design and debugging of the above test cases, establish a test case library, use ECU-TEST to run the test cases in batches, and generate a test report. According to the test results, feedback to the system design stage for necessary improvement and iteration until all safety requirements, test coverage, and test real-time performance are met.
[0121] The test method of this invention has been applied and verified in the integrated heavy truck AMT, providing technical reserves for the functional safety testing of other products, improving the safety of software testing at the same time, meeting the requirements of the host factory and users for aspects such as the transmission R & D process and functional safety level, and thus enhancing the market competitiveness of the product.
[0122] Although the present invention has been described in detail above with general descriptions and specific embodiments, modifications or improvements can be made to it on the basis of the present invention, which will be obvious to those skilled in the art. Therefore, these modifications or improvements made without departing from the spirit of the present invention all fall within the scope of the present invention claimed.
Claims
1. A hardware-in-the-loop based AMT functional safety test method, characterized in that, Including: According to the AMT HIL functional safety test process, the AMT functional safety test method based on HIL is implemented, including the construction of the hardware platform and the software platform; Hardware platform construction: The hardware includes a load solenoid valve group, a HIL cabinet, a TCU, and a host computer. Connect the TCU to the corresponding pins of the HIL cabinet. The pins for the control signals of the load solenoid valve group need to be led out from the Load board card of the HIL cabinet and connected to the load solenoid valve group. The host computer is connected to the HIL cabinet to provide the operating software; The software platform construction includes: 1) Build a controlled object model related to functional safety, a Configuration Desk configuration project, a Control Desk test management project, an ECU-TEST automated test project, and a CANape test project; 2) Use the ConfigurationDesk software to configure the HIL software, complete the construction of the HIL platform, establish a signal chain, establish a model interface, and perform pin allocation; 3) Compile to generate an sdf file; both the controlled object model and the model interface established in 2) are compiled through the Configuration Desk project to generate an sdf file; 4) Create a test project in the Control Desk test management project; 5) Write test cases according to requirements in the ECU-TEST automated test project, establish a test case library, and run them in batches to generate a test report; 6) CANape calibrates parameter values and collects measurement signals during the operation of the TCU, providing symbolic access to diagnostic data and diagnostic services; According to the ISO26262 test requirements, conduct open-loop and closed-loop tests on the TCU. Use the controlled object model to design test scenarios, design test cases, debug test cases, and run test cases to complete the test.
2. The hardware-in-the-loop based AMT functional safety test method according to claim 1, wherein The load solenoid valve group mentioned above includes a shift solenoid valve, a clutch solenoid valve, and a PTO solenoid valve; The DS2680 board card in the HIL cabinet provides all I / O channels, connects to the simulation channels of the actuator model built in the controlled object model, and connects to the real load solenoid valve group; The DS2671 board card is responsible for simulating the CAN input signals required by the TCU and simultaneously collecting the CAN output signals of the TCU under test to achieve open-loop and closed-loop tests.
3. The hardware-in-the-loop based AMT functional safety test method according to claim 1 or 2, characterized in that The open-loop and closed-loop tests of the TCU mentioned above include: I / O test, communication test, and function test; Among them, the I / O test and communication test include: verifying that the signals sent by the HIL to the TCU application layer can be correctly interpreted by the TCU; verifying that the signals output by the TCU application layer can be correctly interpreted by the HIL; all signals are static values and dynamic response is not required; The function test includes: verifying functions and modes, including verifying starting, gear up / down, automatic shifting, manual shifting, and economy / power modes.
4. The hardware-in-the-loop based AMT functional safety test method according to claim 1 or 2, characterized in that The design of the test cases mentioned above includes: Input shaft speed signal. The allowable input shaft speed range in the functional safety software is -3000 to 3000 rpm. When the actual vehicle speed is higher or lower than the allowable upper and lower threshold values, according to the functional safety requirements and technical safety requirements, the functional safety mechanism will be triggered; The specific design steps are as follows: ① Set the test conditions: The vehicle's KL30 and KL15 are powered on; the engine is in the idle state; the vehicle is stationary; the handle is in the neutral state; the TCU is in the normal mode; ② Call CANape to read the upper and lower threshold values of the input shaft speed in the software and record these values as Upper and Lower; ③ Call ControlDesk to calibrate the input shaft speed to (Upper + Lower) / 2 rpm, wait for FTTI seconds, and check the Watchdog status; calibrate the input shaft speed to (Upper + 50) rpm, wait for FTTI seconds, and check the Watchdog status; calibrate the input shaft speed to (Lower - 50) rpm, wait for FTTI seconds, and check the Watchdog status; ④ After the test passes, the Watchdog statuses in step ③ are 0, 1, 1 respectively, meeting the safety level ASIL C.
5. The hardware-in-the-loop based AMT functional safety test method according to claim 1 or 2, characterized in that The design of the test case includes: fault injection test, TC1 message ReqTrsmGear signal, HIL simulates the timeout of the TC1 message, that is, closes the TC1 message enable, and then waits for 10 times the period of the TC1 message to check whether the functional safety state is triggered; The specific test case steps are as follows: ① Set the test conditions: The vehicle's KL30 and KL15 are powered on; the engine is in the idle state; the vehicle is stationary; the handle is in the neutral state; the TCU is in the normal mode; ② In ControlDesk, no TC1 message timeout fault is injected, wait for FTTI seconds, and check the Watchdog status; ③ Call the ControlDesk fault injection module to inject the TC1 message timeout fault, wait for FTTI seconds, and check the Watchdog status; ④ After the test passes, the Watchdog statuses in steps ② and ③ are 0, 1 respectively, meeting the safety level ASIL C.
6. The hardware-in-the-loop based AMT functional safety test method according to claim 1 or 2, characterized in that The design of the test case includes: fault injection test, TC1 message ReqTrsmGear signal, in HIL, calibrate the ReqTrsmGear signal to exceed or be lower than the upper and lower limits allowed in the software, and then check whether the functional safety state is triggered; The specific test case steps are as follows: ① Set the test conditions: The vehicle's KL30 and KL15 are powered on; the engine is in the idle state; the vehicle is stationary; the handle is in the neutral state; the TCU is in the normal mode; ② Call CANape to read the upper and lower threshold values of the ReqTrsmGear signal in the software and record these values as Upper and Lower; ③ Call ControlDesk, calibrate the ReqTrsmGear value of the TC1 message to (Upper + Lower) / 2 rpm, wait for FTTI seconds, and check the Watchdog status; calibrate the ReqTrsmGear value of the TC1 message to (Upper + 50) rpm, wait for FTTI seconds, and check the Watchdog status; calibrate the ReqTrsmGear value of the TC1 message to (Lower - 50) rpm, wait for FTTI seconds, and check the Watchdog status. ④ After the test passes, the Watchdog statuses in step ③ are 0, 1, and 1 respectively, meeting the safety level ASIL C.
7. The hardware-in-the-loop based AMT functional safety test method according to claim 1 or 2, characterized in that The design of the test cases described includes: functional testing. The function described is unexpected start in automatic gear. The steps of the test case are as follows: ① Set the test conditions: The vehicle's KL30 and KL15 are powered on; the engine is at idle speed; the vehicle is stationary; the handle is in the neutral position; the TCU is in the normal mode; the Creep function is turned off. ② Check the status of the Watchdog when the handle is in the neutral position and the vehicle is stationary. ③ Call ControlDesk, set the brake pedal opening to 50%, place the handle in gear A, wait for 2 s, and engage the starting gear; after engaging the starting gear, release the brake, set the accelerator pedal opening to 50%, wait for the vehicle speed to increase until it stabilizes, and check the Watchdog status when the vehicle is driving normally. ④ Release the accelerator, step on the brake, wait until the vehicle speed drops to 0 and the vehicle is stationary. At this time, the engine is at idle speed, the gear is in the starting gear, and the clutch is disengaged. Read the current clutch displacement value in CANape and mark it as CluPosn; ECUTEST pulls the calibrated clutch displacement value in the HIL model and uses the Stimulation / Ramp function module to simulate the clutch displacement reaching the clutch zero point from the CluPosn position at different slopes within the FTTI time, causing the vehicle to move unexpectedly with the accelerator pedal at 0, and check the Watchdog status and the response after triggering the safety mechanism. ⑤ After the test passes, the Watchdog status in step ② is 0; the Watchdog status in step ③ is 0; the Watchdog status in step ④ is 1. The response after triggering the safety mechanism: Suppress the TCU from sending CAN, the solenoid valve fails, suppress the vehicle from moving, and the vehicle remains stationary, meeting the safety level ASIL D.
8. The hardware-in-the-loop based AMT functional safety test method according to claim 1 or 2, characterized in that The function also includes dynamic and static verification of the current gear, dynamic and static detection of the clutch status, E2E verification, self-learning, or engine - transmission loss torque verification. For different functions, different test scenarios are designed in step ④. After completing the design and debugging of the above test cases, establish a test case library, use ECU-TEST to run the test cases in batches, and generate a test report.
Citation Information
Cited By
Hardware-in-the-loop test platform and test method for AMT and retarder controller
CN121832518A