Dual-clutch gearbox controller system based on functional safety requirements

The dual-clutch transmission controller system, with its dual-chip architecture and multiple diagnostic mechanisms, addresses the functional safety risks of traditional transmission controllers, enables redundant monitoring and fault detection of key signals, meets the high safety level requirements of the ISO 26262 standard, reduces system costs, and ensures supply chain security.

CN120739868AActive Publication Date: 2025-10-03南昌济铃新能源科技有限责任公司
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202511142137.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-15
Publication Date
2025-10-03
Estimated Expiration
2045-08-15

AI Technical Summary

Technical Problem

Traditional transmission controllers have development process risks, high single-point failure risks, insufficient diagnostic coverage, and high compatibility and supply chain risks in terms of functional safety, making it difficult to meet the ASIL D high safety level requirements of the ISO 26262 standard.

Method used

The dual-clutch transmission controller system adopts a dual-chip architecture, including a main control chip and a monitoring chip. It combines a lock-step core design and multiple diagnostic mechanisms, and is equipped with multiple communication interfaces and sensor acquisition circuits to achieve redundant monitoring and fault detection of key signals. It is designed with a three-level safety state and a safety state trigger mechanism that directly intervenes through hardware circuits.

Benefits of technology

It achieves multi-faceted monitoring of key signals, meets the ASIL D functional safety level requirements in ISO 26262, reduces system costs, ensures supply chain security, adapts to different vehicle communication needs, and supports multiple communication protocols and wake-up modes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120739868A_ABST
    Figure CN120739868A_ABST
Patent Text Reader

Abstract

The invention discloses a dual-clutch gearbox controller system based on functional safety requirements, which relates to the technical field of gearbox controllers, adopts a dual-chip architecture of a main control chip and a monitoring chip, and comprises a power supply management module used for providing multiple paths of power supplies; the main control chip is used for executing control logic; the monitoring chip is used for monitoring a chip state, a power supply and a sensor signal in real time; the motor driving module is used for configuring five motor driving circuits and feeding back the rotor position; the communication interface module is used for integrating four CAN (Controller Area Network) channels and one LIN (Local Interconnect Network) channel; the signal acquisition module is used for acquiring various sensor signals; and the safety state control module is used for triggering a safety mechanism. According to the invention, a lock step core design and a multiple diagnosis mechanism are combined, redundancy monitoring and fault detection of key signals are realized, the safety level requirement of an ASIL D function in ISO 26262 is met, all chips are domestic chips, the chip has the advantages of functional safety and cost, and different vehicle communication and sensor configuration requirements are met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of transmission controllers, and in particular to a dual-clutch transmission controller system based on functional safety requirements. Background Art

[0002] In recent years, with the development of automotive electronics and intelligence, dual-clutch transmissions have been widely used due to their efficient and fast shifting performance. However, traditional transmission controllers have significant defects in functional safety: 1. Risks in the development process: Traditional transmission controllers typically adopt a "design first, analyze later" model, which does not meet the development process requirements of the ISO 26262 standard. This results in potential risks not being identified early on. 2. High risk of single-point failure: The single-chip architecture lacks redundant design. Failure of key sensors or chips may cause the transmission to lose control, which cannot meet the high safety level requirements of ASIL D.

[0003] 3. Insufficient diagnostic coverage: The hardware diagnostic module does not cover all key signal chains, making it difficult to meet functional safety integrity requirements; 4. Compatibility and supply chain risks: Traditional transmission controller hardware design has poor compatibility with different dual-clutch transmission models and relies on foreign dedicated chips, resulting in high costs and great supply chain risks.

[0004] Based on this, a dual-clutch transmission controller system based on functional safety requirements is now provided, which can eliminate the disadvantages of existing technical solutions. Summary of the Invention

[0005] The purpose of the present invention is to provide a dual-clutch transmission controller system based on functional safety requirements to solve the problems in the background technology such as development process risks, high single point failure risks, insufficient diagnostic coverage, and compatibility and supply chain risks.

[0006] To achieve the above object, the present invention provides the following technical solutions: A dual-clutch transmission controller system based on functional safety requirements includes: The power management module is used to receive the normal power and divide it into high-power power and low-power power, and generate multiple power supplies for the system through the power management chip; The main control chip is used to receive vehicle control commands and sensor information and execute the control logic of the dual-clutch transmission; Monitoring chip, used to monitor the operating status of the main control chip, core power supply voltage and key sensor signals; The motor drive module is equipped with two clutch motor drives, two shift motor drives, and one cooling pump motor drive, which is used to provide real-time feedback of the motor rotor position to the main control chip. Communication interface module, equipped with 4 CAN channels and 1 LIN channel, to adapt to different vehicle communication requirements; Signal acquisition module, equipped with 2 pressure sensors, 3 speed sensors, 1 angle sensor and 1 temperature sensor, used to collect pressure, speed, angle and temperature sensor signals; The safety state control module is used to trigger the safety mechanism through the main control chip, monitoring chip and power management chip when a failure mode is detected, so that the gearbox enters a preset safety state.

[0007] Preferably, the power management module includes: Input protection circuit to protect the normal power from overvoltage, overcurrent and reverse connection; The logic control circuit is used to control the high-power power supply according to the instructions of the main control chip to ensure that the motor drive module is powered only when the system is working normally; The power management chip is used to receive the hard-wired wake-up signal and the wake-up signal of the communication interface module, generate multiple regulated power supplies to power the main control chip, monitoring chip, multiple sensors and peripheral circuits, and monitor the operating status of the main control chip. In case of abnormality, the safety mechanism of the safety state control module is triggered; The power distribution circuit is used to divide the normal power into two paths, including a low-power power supply and a high-power power supply. The low-power power supply is used to power the power management chip and the communication interface module, and the high-power power supply is used to power the motor drive module through the above-mentioned logic control circuit.

[0008] Preferably, the main control chip is internally provided with a lockstep core for running the following functional safety software: Motor rotor position command protection program; Motor rotor position diagnostic procedure; MOS and MOS driver power supply diagnostic procedures; RAM and ROM diagnostics; The above four programs are all run in the lock-step core. If the lock-step core results are inconsistent, the monitoring safety state is triggered. The main control chip is also provided with a shared resource diagnostic program for cooperating with the monitoring chip to realize the function of monitoring the safety status.

[0009] Preferably, the monitoring chip runs the following functional safety software: The main control chip WATCHDOG program is used to cooperate with the shared resource diagnostic program to monitor the operating status of the main control chip; Main control chip power monitoring program, used to monitor the power supply of the main control chip; Transmission gear independent diagnostic program, used to monitor the actual gear position and vehicle status through the speed sensor signal transmitted from the signal acquisition module; If one or more of the following situations occur, the monitoring safety status is enabled: The WATCHDOG program of the main control chip cannot get feedback in time; The main control chip power monitoring program monitors that the main control chip power supply is abnormal; The transmission gear position independent diagnostic program monitors actual gear position and vehicle status as abnormal.

[0010] Preferably, the motor drive module includes: 2 clutch motor drive circuits for controlling the engagement and disengagement of the clutch; 2 shift motor drive circuits for controlling the shift operation; 1 cooling pump motor drive circuit, used to control the cooling system; High-precision position sampling circuit for real-time monitoring of motor rotor position; Among them, the above five motor drive circuits are all equipped with high-precision position sampling circuits.

[0011] Preferably, one CAN channel and one LIN channel of the communication interface module support an INH wake-up mode.

[0012] Preferably, the security status control module includes: Safety state trigger unit, used to shut down all motor drive circuits when detecting main control chip failure, power supply abnormality and sensor signal abnormality; The safe state execution unit is used to control the transmission to enter the safe state.

[0013] Preferably, the safe state includes: Safe state 1: The gearbox position remains in its original state, and the gearbox status information reflects the actual state; Safety state 2: Switch to neutral state, clutch is disengaged; Safety state three: The parking lock state is activated when the vehicle is stationary.

[0014] Among them, the corresponding safety state is triggered according to the fault type and vehicle status.

[0015] Preferably, the triggering conditions of the safety state control module include: The results of lockstep kernel operations are inconsistent; The power management chip 11 monitors abnormalities; The main control chip power supply is abnormal; Monitor chip voltage abnormality; The actual gear position, vehicle status signal and speed sensor data conflict.

[0016] Preferably, a dual-clutch transmission control method based on functional safety requirements is also included, which specifically includes the following steps: Step S1: The power management module receives the normal power and distributes it into high-power power and low-power power. The power management chip generates multiple power supplies to power the system. Step S2: The main control chip receives the vehicle control command and the sensor information from the signal acquisition module, executes the control logic of the dual-clutch transmission, and generates the motor control command; Step S3: The monitoring chip monitors the operating status of the main control chip, the core power supply voltage and key sensor signals in real time; Step S4: The motor drive module drives the clutch motor, the shift motor, and the cooling pump motor according to the instructions of the main control chip, and feeds back the motor rotor position through the high-precision position sampling circuit; Step S5: monitor the system operating status in real time. If a trigger condition is detected, the safety status control module triggers the safety mechanism through the main control chip, monitoring chip and power management chip to put the gearbox into a preset safety state.

[0017] Compared with the prior art, the present invention has the following beneficial effects: This functional safety-focused dual-clutch transmission controller system uses a dual-chip architecture consisting of a main control chip and a monitoring chip. Combined with a lockstep core design and multiple diagnostic mechanisms, it enables redundant monitoring of key signals and fault detection, meeting the ASIL D functional safety level requirements of ISO 26262. The system runs multiple diagnostic programs through the lock-step core of the main control chip, and cooperates with the independent diagnostic functions of the monitoring chip and the monitoring and diagnostic functions of the power management chip to achieve multi-faceted monitoring of key factors such as power supply, sensor signals, and processor status. It is designed with a three-level safety state, which can intelligently select the appropriate safety state based on the fault type and vehicle status. The safety state trigger mechanism directly intervenes through the hardware circuit to ensure that the system maintains a safe state. The system is equipped with multiple CAN and LIN communication interfaces and sensor acquisition circuits to adapt to different vehicle needs and support multiple communication protocols and wake-up modes. The main control chip, monitoring chip, and power management chip are all domestic models, which not only ensures supply chain security but also reduces system costs. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 Schematic diagram of the system structure of the present invention.

[0019] Figure 2 This is a schematic diagram of the built-in programs of the main control chip and monitoring chip of the present invention.

[0020] Figure 3 This is a flow chart of the diagnosis and monitoring of the main control chip and the monitoring chip of the present invention.

[0021] Figure 4 This is a flow chart of the diagnosis and monitoring of the main control chip, monitoring chip and power management chip of the present invention.

[0022] Figure 5 It is a structural diagram of the overall module of the present invention.

[0023] Figure 6 It is a structural diagram of the power management module of the present invention.

[0024] Notes on the accompanying drawings: power management module 10 , power management chip 11 , main control chip 20 , monitoring chip 30 , motor drive module 40 , communication interface module 50 , signal acquisition module 60 , safety state control module 70 . DETAILED DESCRIPTION

[0025] In order to make the objectives, technical solutions and advantages of the present invention more clearly understood, the present invention is further described in detail below with reference to the accompanying drawings and embodiments.

[0026] In this embodiment, if Figure 1 - Figure 6 As shown, a dual-clutch transmission controller system based on functional safety requirements includes: The power management module 10 is used to receive the normal power and divide it into high-power power and low-power power, and generate multiple power supplies for the system through the power management chip 11; Specifically, the power management chip 11 is abbreviated as SBC and is connected to the normal power supply through the KL30 interface. The input protection circuit performs overvoltage, overcurrent and reverse polarity protection operations, such as triggering protection when the voltage exceeds 16V and cutting off when the current exceeds 30A. The power distribution circuit divides it into a low-power power supply (VBAT_LP) and a high-power power supply (VBAT_HP). The low-power power supply (VBAT_LP) supplies power to the power management chip 11 and the communication interface module 50. The low-power power supply (VBAT_LP) supplies power to the CAN1 channel and the LIN channel in the communication interface module 50. The high-power power supply (VBAT_HP) supplies power to the motor drive module 40 through the logic control circuit. The logic control circuit is controlled by the high-power power enable signal (12V_HP_EN) output by the main control chip 20. Only when the system is operating normally, the high-power power enable signal (12V_HP_EN) is high, the logic control circuit is turned on, and the high-power power supply will supply power to the motor drive module 40. The main control chip 20 is used to receive vehicle control commands and sensor information and execute the control logic of the dual-clutch transmission; Specifically, if Figure 3 and Figure 4 As shown, the chip in the main control chip 20 and the monitoring chip 30 can be abbreviated as MCU. The main control chip 20 can receive monitoring data of the core power supply and key sensor signals to fully grasp the system operation status. After calculation, the main control chip 20 sends instructions to the motor drive module 40 through six PWM waves to drive the motor to run. The MOS shutdown signal can be used to directly intervene in the connection between the main control chip 20 and the system execution circuit, cutting off power in the event of an abnormality to ensure safety. like Figure 1 As shown, the main control chip 20 has an integrated lockstep core and is equipped with a rich set of peripheral interfaces, such as LSO, HSO, DI, AI, PWM-IN, PWM-OUT and other input and output interfaces, allowing the system to implement digital / analog signal input and output, PWM control and other functions, and is used to interact with external sensors and actuators to build a complete control system. The specific functions are determined based on the application scenarios and hardware circuit design of the actual equipment. For example, the PWM (pulse width modulation) output can be used to control the motor drive module 40. The main control chip 20, monitoring chip 30, and power management chip 11 are selected according to the actual environment. Traditional solutions rely on imported chips, while this system uses domestic chips, which significantly reduces costs. The monitoring chip 30 is used to monitor the operating status, core power supply voltage and key sensor signals of the main control chip 20; Specifically, a domestic chip is used with an independent power supply and clock system to ensure the reliability of the monitoring function. Multiple ADC channels are configured to monitor the power supply voltage of the main control chip 20, key sensor signals, etc., and a PWM input channel is configured to receive speed sensor signals. The motor drive module 40 is configured with two clutch motor drives, two shift motor drives, and one cooling pump motor drive, and is used to provide real-time feedback of the motor rotor position to the main control chip 20; The communication interface module 50 is configured with four CAN channels and one LIN channel to adapt to different vehicle communication requirements; Specifically, one CAN channel and one LIN channel of the communication interface module 50 support the INH wake-up mode. The CAN channels include CAN1, CAN2, CAN3, and CAN4. CAN1 supports the INH wake-up mode. The CAN communication baud rate can be configured to 250kbps or 500kbps to meet the communication rate requirements of different vehicles. The CAN interface has bus short-circuit protection and overvoltage protection functions to ensure communication stability. The LIN channel supports the INH wake-up mode with a communication baud rate of 19.2kbps. It is used to communicate with low-speed devices such as the vehicle body comfort system to display and simply control the transmission status. The signal acquisition module 60 is configured with two pressure sensors, three speed sensors, one angle sensor and one temperature sensor, and is used to collect pressure, speed, angle and temperature sensor signals; Specifically, the pressure sensor, speed sensor, angle sensor, and temperature sensor can all be adjusted according to actual environmental requirements; The safety state control module 70 is used to trigger the safety mechanism through the main control chip 20, the monitoring chip 30 and the power management chip 11 when a failure mode is detected, so that the gearbox enters a preset safety state; Specifically, if the fault is a transient interference (such as a brief abnormality in the sensor signal), the system will automatically recover after the fault disappears. If it is a permanent fault (such as a lock-step core error in the main control chip 20), the fault code must be cleared through the vehicle diagnostic instrument and the system must be restarted.

[0027] Among them Figure 1 and Figure 6 As shown, the power management module 10 includes: Input protection circuit to protect the normal power from overvoltage, overcurrent and reverse connection; The logic control circuit is used to control the high-power power supply according to the instructions of the main control chip 20 to ensure that the motor drive module 40 is powered only when the system is working normally; The power management chip 11 is used to receive the hard-wired wake-up signal and the wake-up signal of the communication interface module 50, generate multiple regulated power supplies to power the main control chip 20, the monitoring chip 30, multiple sensors, and peripheral circuits, and monitor the operating status of the main control chip 20. In the event of an abnormality, the safety mechanism of the safety state control module 70 is triggered; A power distribution circuit is used to divide the normal power into two paths, including a low-power power supply and a high-power power supply. The low-power power supply is used to power the power management chip 11 and the communication interface module 50, and the high-power power supply is used to power the motor drive module 40 through the above-mentioned logic control circuit; Specifically, the power management chip 11 supports two wake-up methods: a hard-wired wake-up signal (KL15) and an INH wake-up signal output by the CAN1 channel of the communication interface module 50. When the hard-wired wake-up signal (KL15) is activated or the CAN1 channel receives a wake-up command, the power management chip 11 activates and generates multiple regulated power supplies, such as 5V and 3.3V, to power the main control chip 20, the monitoring chip 30, multiple sensors, and peripheral circuits. During this process, the system monitors the operating status of the main control chip 20 in real time and determines whether it is functioning properly by detecting the watchdog signal output by the main control chip 20. If no watchdog signal is received within a specified time, the main control chip 20 is determined to be abnormal, triggering the safety mechanism of the safety state control module 70. The power management chip 11 performs Alive or Die monitoring operations on the main control chip 20 to detect whether key components (such as the main control chip 20, the communication interface module 50, and the drive circuit) have failed or are stuck. This allows the system to quickly identify a "fake death" state and trigger a safety response, which is a prior art technology.

[0028] Among them Figure 1 and Figure 2 As shown, the main control chip 20 is internally provided with a lockstep core for running the following functional safety software: The motor rotor position command protection program verifies the legitimacy of the input motor rotor position command to prevent incorrect commands from causing abnormal motor operation. The above-mentioned motors are set as shift motor 1 (SAM1) and shift motor 2 (SAM2). For example, if the received shift motor position command exceeds the normal gear range (such as gears 1-6), the command is rejected and a fault is recorded. The motor rotor position diagnostic program compares the actual motor rotor position (obtained by a high-precision position sampling circuit) with the command position in real time. If the deviation exceeds a set threshold, it is determined to be a position abnormality and triggers a diagnosis. The above motors are set as shift motor 1 (SAM1) and shift motor 2 (SAM2); MOS and MOS drive power supply diagnostic program, which monitors the on-resistance of the MOS transistor and the drive power supply voltage in the motor drive circuit. If the on-resistance of the MOS transistor is too large or the drive power supply voltage is lower than 4.5V, it is determined that the MOS or drive power supply is faulty and a fault signal is sent to the safety state control module 70; RAM and ROM diagnostic programs regularly check the internal RAM and ROM. They can detect the correctness of stored data through parity check, CRC (cyclic redundancy check), etc. If RAM data errors or ROM program verification fails, the safe state is immediately triggered. The above four programs are all run in the lock-step core. If the lock-step core results are inconsistent, the monitoring safety state is triggered. The main control chip 20 is also provided with a shared resource diagnostic program to cooperate with the monitoring chip 30 to realize the function of monitoring the safety status. It works in conjunction with the monitoring chip 30 to share system clock, interrupt and other resources to monitor the overall operation status of the system. Specifically, if the lockstep core results are inconsistent within a minimum time unit or processing cycle of a certain system, the safe state enable is triggered.

[0029] Among them Figure 1 and Figure 2 As shown, the monitoring chip 30 has the following functional safety software running inside: The main control chip WATCHDOG program is used to cooperate with the shared resource diagnostic program to monitor the operating status of the main control chip 20; Main control chip power monitoring program, used to monitor the power supply of the main control chip 20; A transmission gear position independent diagnostic program for monitoring the actual gear position and vehicle status through the speed sensor signal transmitted from the signal acquisition module 60; If one or more of the following situations occur, the monitoring safety status is enabled: The main control chip WATCHDOG program cannot get timely feedback; The main control chip power monitoring program detects that the main control chip 20 power supply is abnormal; The independent diagnostic program for the transmission gear position monitors abnormalities in the actual gear position and vehicle status; Specifically, the main control chip's WATCHDOG program sends a Watchdog signal to the monitoring chip 30, requiring the main control chip 20 to provide a response signal within a specified time. If no response is received in time, the main control chip 20 is determined to be operating abnormally, triggering a Reset signal to reset the main control chip 20 and simultaneously triggering the monitoring safety state enable. The main control chip's power supply monitoring program monitors the main control chip 20's power supply voltage in real time through the ADC channel. When the voltage deviates from the normal value by ±10%, it is determined to be a power supply abnormality and triggering the monitoring safety state enable. The transmission gear position independent diagnosis program receives the three speed sensor signals transmitted by the signal acquisition module 60 and determines the actual gear position and vehicle status by calculating the speed of each shaft. For example, when the vehicle is stationary, each speed sensor should output a zero speed signal. If a non-zero speed is detected, the vehicle status is determined to be abnormal. When the actual gear position is inconsistent with the gear position command sent by the main control chip 20 (for example, the command is D gear, but the actual detection is R gear), the monitoring safety state enable is triggered. Specifically, the monitoring chip 30 performs ALU and Sequence monitoring operations on the main control chip 20. ALU is a logic calculation unit, and Sequence is a sequential logic unit. The monitoring of ALU ensures the correctness of hardware calculations and triggers the security mechanism by capturing hardware calculation errors. The monitoring of Sequence ensures the trusted execution of program flow and triggers the security mechanism by confirming whether the program flow is hijacked. ALU monitoring and Sequence monitoring constitute the "double cornerstones" of computing security and are existing technologies. If an ALU calculation error triggers a safe state, Sequence monitoring will simultaneously check whether the error is caused by program runaway, and Alive monitoring will confirm whether the main control chip 20 is still sending heartbeat signals. The three jointly locate the fault type. When any monitoring mechanism detects an abnormality, the safety mechanism can be triggered through the safe state control module 70.

[0030] Among them Figure 1 and Figure 5 As shown, the motor drive module 40 includes: Two clutch motor drive circuits, used to control the engagement and disengagement of the clutch. The clutch motors include clutch motor 1 (CAPM1) and clutch motor 2 (CAPM2). They are powered by the high-power power supply (VBAT_HP) provided by the power management module 10 and receive PWM signals output by the main control chip 20 to control the engagement and disengagement of the clutch. Two shift motor drive circuits are used to control the shift operation. The shift motors include shift motor 1 (SAM1) and shift motor 2 (SAM2). The forward and reverse rotation and speed of the shift motors are controlled by PWM signals to achieve gear switching. A cooling pump motor drive circuit controls the cooling system. The cooling pump motor, abbreviated as CCPM, adjusts the cooling pump speed based on the transmission temperature sensor signal. When the temperature is above 80°C, the cooling pump runs at full speed. When the temperature is below 50°C, the cooling pump runs at low speed or stops. High-precision position sampling circuit for real-time monitoring of motor rotor position; Among them, the above five motor drives are all equipped with high-precision position sampling circuits, using three-phase Hall signals. The high-precision position sampling signals are PWM signals emitted by a dedicated chip.

[0031] The safety state control module 70 includes: The safety state trigger unit is used to shut down all motor drive circuits when a fault in the main control chip 20, a power supply anomaly, or a sensor signal anomaly is detected. This unit is implemented by a hardware circuit. When any fault signal is detected, it immediately outputs a high-level signal to the enable terminal of the motor drive module 40, shutting down all motor drive circuits, cutting off the motor power supply, and stopping the motor. A safe state execution unit is used to control the transmission to enter a safe state; Specifically, the security status includes: Safe state 1: The gearbox position remains in its original state, and the gearbox status information reflects the actual state; Safety state 2: Switch to neutral state, clutch is disengaged; Safety state three: parking lock state activated when the vehicle is stationary; Specifically, according to HARA (Hazard Analysis and Risk Assessment) analysis, the dual-clutch transmission has the above three safety states. The main control chip 20, the monitoring chip 30 and the power management chip 11 work together to control the safety state entered according to the fault type and vehicle status. For example, when a non-serious fault is detected (such as an abnormal single sensor signal), the transmission is controlled to enter safety state one, which is applicable to non-serious faults. When a serious fault is detected (such as inconsistent lockstep core results of the main control chip 20, abnormal power supply of the main control chip 20), the transmission is controlled to enter safety state two. When the vehicle is stationary and an electronic parking-related fault is detected (such as improper SAM2 motor position control leading to electronic parking failure), the transmission is controlled to enter safety state three, which is applicable to electronic parking faults. Among them Figure 1 and Figure 2 As shown, the triggering conditions of the safety state control module 70 include: The results of lockstep kernel operations are inconsistent; The power management chip 11 monitors abnormalities; The power supply of the main control chip 20 is abnormal; The voltage of the monitoring chip 30 is abnormal; The actual gear position, vehicle status signal and speed sensor data conflict; Specifically, the trigger mechanism for inconsistent lock-step core calculation results: the lock-step core inside the main control chip 20 runs the same functional safety program (such as motor control, sensor diagnosis, etc.) and compares the calculation results at each system clock cycle. If an inconsistent result is detected, it is determined to be a hardware or software fault, and the safe state enable signal is immediately triggered. The motor drive module 40 is forcibly shut down through the hardware circuit, and a fault code (DTC) is sent to the entire vehicle through the communication interface module 50. The transmission enters safe state 2 (neutral). The power management chip 11 monitors its own output voltage and the main control chip 20, and triggers the safety mechanism if an abnormality occurs: If the output voltage of the power management chip 11 itself is overvoltage or overcurrent, or the timing of each power supply is abnormal, the safety mechanism is triggered, and the main control chip 20 is monitored for Alive and Die. The main control chip 20 needs to periodically send a "heartbeat" signal. The monitor checks the signal within a fixed time window to verify whether the task or function is executed periodically. If the task is stalled, the safety mechanism is triggered; Monitoring method for power anomalies of the main control chip 20: The monitoring chip 30 monitors the main control chip's power supply voltage in real time through the ADC channel. If the voltage exceeds a calibration range (e.g., ±10%), or a voltage drop is detected (e.g., below a threshold for a sustained period of time), it is determined to be a power anomaly. The motor drive module 40 is shut down through an independent hardware circuit. If the vehicle is stationary, the gearbox enters safety state three; if the vehicle is moving, the gearbox enters safety state two. The monitoring chip 30 monitors the voltage. If an abnormality occurs, the safety mechanism is triggered. The voltage includes the 5V voltage of the main control chip 20 (generated by the power management chip 11), the 3.3V voltage of the main control chip 20 (generated by the main control chip 20 itself), the core voltage of the main control chip 20 (generated by the main control chip 20 itself or an external power chip), and the power supply voltage of the monitoring chip 30 itself (supplied by the power management chip 11); Diagnostic logic for conflicts between actual gear position, vehicle status, and speed sensor data: The transmission ratio is calculated using three speed sensors (input shaft, output shaft, and intermediate shaft) and compared with the gear position command sent by the main control chip 20. For example, the gear ratio should be 1.5:1 in D gear. If 0.8:1 is detected, it is determined to be a gear abnormality. If the speed sensor shows that the vehicle speed is 0, but the angle sensor detects that the shift motor is operating, it is determined to be an "unexpected shift" and the safety state is immediately triggered. The shift motor (SAM1 / SAM2) is forced to return to the neutral position, the clutch (CAPM1 / CAPM2) is disengaged, and the vehicle enters safety state two. Monitoring process when the main control chip's Watchdog program cannot provide timely feedback: The monitoring chip 30 sends a Watchdog trigger signal to the main control chip 20 at regular intervals. The main chip must provide feedback within the corresponding time through a dedicated GPIO pin or SPI communication. If no feedback is received for multiple consecutive times, it is determined that the main control chip 20 is abnormal. The monitoring chip 30 restarts the main control chip 20 through the hardware reset line (Reset Line) and takes over safety control during this period. If the vehicle is in motion, it enters safety state two; if the vehicle is stationary, it enters safety state three.

[0032] During use, the power management module 10 receives normal power and distributes it into high-power power and low-power power. The power management chip 11 generates multiple power supplies to power the system. The main control chip 20 receives the vehicle control command and the sensor information of the signal acquisition module 60, executes the control logic of the dual-clutch transmission, and generates motor control instructions. The monitoring chip 30 monitors the operating status, core power supply voltage and key sensor signals of the main control chip 20 in real time. The motor drive module 40 drives the clutch motor, shift motor and cooling pump motor according to the instructions of the main control chip 20, and feeds back the motor rotor position through a high-precision position sampling circuit to monitor the system operation status in real time. If a trigger condition is detected, the safety state control module 70 triggers the safety mechanism through the main control chip 20, the monitoring chip 30 and the power management chip 11, so that the transmission enters a preset safety state.

[0033] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. A dual-clutch transmission controller system based on functional safety requirements, characterized in that: include: A power management module (10) is used to receive normal power and divide it into a high-power power supply and a low-power power supply, and generate multiple power supplies to power the system through a power management chip (11); A main control chip (20) is used to receive vehicle control commands and sensor information and execute the control logic of the dual-clutch transmission; A monitoring chip (30) for monitoring the operating status, core power supply voltage and key sensor signals of the main control chip (20); A motor drive module (40) configured with two clutch motor drives, two shift motor drives, and one cooling pump motor drive, for real-time feedback of the motor rotor position to the main control chip (20); A communication interface module (50) is configured with four CAN channels and one LIN channel for adapting to different vehicle communication requirements; A signal acquisition module (60) is configured with two pressure sensors, three speed sensors, one angle sensor and one temperature sensor, and is used to collect pressure, speed, angle and temperature sensor signals; A safety state control module (70) is used to trigger a safety mechanism via the main control chip (20), the monitoring chip (30) and the power management chip (11) when a failure mode is detected, so that the gearbox enters a preset safety state; The safety state control module (70) includes: A safety state trigger unit, used to shut down all motor drive circuits when a main control chip (20) failure, power supply anomaly, or sensor signal anomaly is detected; A safe state execution unit is used to control the transmission to enter a safe state; The triggering conditions of the safety state control module (70) include: The results of lockstep kernel operations are inconsistent; The power management chip (11) monitors abnormalities; The power supply of the main control chip (20) is abnormal; The voltage of the monitoring chip (30) is abnormal; The actual gear position, vehicle status signal and speed sensor data conflict.

2. A dual clutch transmission controller system based on functional safety requirements according to claim 1, characterized in that: The power management module (10) comprises: Input protection circuit to protect the normal power from overvoltage, overcurrent and reverse connection; A logic control circuit for controlling the high-power power supply according to instructions from the main control chip (20) to ensure that the motor drive module (40) is powered only when the system is operating normally; A power management chip (11) is used to receive a hard-wired wake-up signal and a wake-up signal from a communication interface module (50), generate a multi-channel regulated power supply to power a main control chip (20), a monitoring chip (30), a plurality of sensors, and peripheral circuits, and monitor the operating state of the main control chip (20), and trigger a safety mechanism of a safety state control module (70) when an abnormality occurs; A power distribution circuit is used to divide the normal power into two paths, including a low-power power supply and a high-power power supply, wherein the low-power power supply is used to supply power to the power management chip (11) and the communication interface module (50), and the high-power power supply is used to supply power to the motor drive module (40) through the above-mentioned logic control circuit.

3. A dual clutch transmission controller system based on functional safety requirements according to claim 1, characterized in that: The main control chip (20) is internally provided with a lockstep core for running the following functional safety software: Motor rotor position command protection program; Motor rotor position diagnostic procedure; MOS and MOS driver power supply diagnostic procedures; RAM and ROM diagnostics; The above four programs are all run in the lock-step core. If the lock-step core results are inconsistent, the monitoring safety state is triggered. The main control chip (20) is also provided with a shared resource diagnostic program for cooperating with the monitoring chip (30) to realize the function of monitoring the safety status.

4. A dual clutch transmission controller system based on functional safety requirements according to claim 3, characterized in that: The monitoring chip (30) runs the following functional safety software: The main control chip WATCHDOG program is used to cooperate with the shared resource diagnostic program to realize the monitoring operation of the operating status of the main control chip (20); A main control chip power monitoring program for monitoring the power supply of the main control chip (20); A gearbox gear position independent diagnostic program for monitoring the actual gear position and vehicle status through a speed sensor signal transmitted from a signal acquisition module (60); If one or more of the following situations occur, the monitoring safety status is enabled: The WATCHDOG program of the main control chip cannot get feedback in time; The main control chip power monitoring program monitors that the main control chip (20) has a power anomaly; The transmission gear position independent diagnostic program monitors actual gear position and vehicle status as abnormal.

5. The dual clutch transmission controller system based on functional safety requirements according to claim 1, characterized in that: The motor drive module (40) comprises: 2 clutch motor drive circuits for controlling the engagement and disengagement of the clutch; 2 shift motor drive circuits for controlling the shift operation; 1 cooling pump motor drive circuit, used to control the cooling system; High-precision position sampling circuit for real-time monitoring of motor rotor position; Among them, the above five motor drive circuits are all equipped with high-precision position sampling circuits.

6. A dual clutch transmission controller system based on functional safety requirements according to claim 1, characterized in that: One CAN channel and a LIN channel of the communication interface module (50) support an INH wake-up mode.

7. A dual clutch transmission controller system based on functional safety requirements according to claim 1, characterized in that: The security status includes: Safe state 1: The gearbox position remains in its original state, and the gearbox status information reflects the actual state; Safety state 2: Switch to neutral state, clutch is disengaged; Safety state three: parking lock state activated when the vehicle is stationary; Among them, the corresponding safety state is triggered according to the fault type and vehicle status.

8. The dual clutch transmission controller system based on functional safety requirements according to claim 1, characterized in that: The invention also includes a dual-clutch transmission control method based on functional safety requirements, which specifically includes the following steps: Step S1: The power management module (10) receives normal power and distributes it into high-power power and low-power power, and the power management chip (11) generates multiple power supplies to power the system; Step S2: The main control chip (20) receives the vehicle control command and the sensor information of the signal acquisition module (60), executes the control logic of the dual-clutch transmission, and generates a motor control instruction; Step S3, the monitoring chip (30) monitors the operating status, core power supply voltage and key sensor signals of the main control chip (20) in real time; Step S4, the motor driving module (40) drives the clutch motor, the shift motor and the cooling pump motor according to the instruction of the main control chip (20), and feeds back the motor rotor position through the high-precision position sampling circuit; Step S5: monitor the system operating status in real time. If a trigger condition is detected, the safety state control module (70) triggers the safety mechanism through the main control chip (20), the monitoring chip (30) and the power management chip (11), so that the gearbox enters a preset safety state.

Citation Information

Patent Citations

  • Electronic control unit for dry-type 5-speed-grade double clutch transmission and application thereof

    CN102619970A

  • Control system of dual-clutch transmission case and implementation method thereof

    CN104279310A

  • Safety monitoring system for car mechanical automatic-transmission electronic control unit

    CN106838296A

  • A vehicle safety electronic control system

    CN107531250A

  • Vehicle safety control method and device, electronic equipment and storage medium

    CN115610434A