A dual clutch transmission controller system based on functional safety requirements
The dual-clutch transmission controller system, with its dual-chip architecture and multiple diagnostic mechanisms, addresses the functional safety risks inherent in traditional transmission controllers, achieving high-level fault detection and supply chain security while reducing system costs.
Patent Information
- Application Number
- CN202511142137.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-15
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2045-08-15
AI Technical Summary
Traditional transmission controllers have significant risks in terms of functional safety, including development process risks, high single-point failure risks, insufficient diagnostic coverage, and compatibility and supply chain risks, making it difficult to meet the high safety level requirements of the ISO 26262 standard.
The dual-clutch transmission controller system adopts a dual-chip architecture, including a main control chip and a monitoring chip. It combines lockstep core design and multiple diagnostic mechanisms, and is equipped with multiple communication interfaces and sensors to achieve redundant monitoring and fault detection of key signals. It is designed with a three-level safety state and a safety state triggering mechanism that directly intervenes through hardware circuits.
It meets the ASIL D functional safety level requirements of ISO 26262, reduces system costs, ensures supply chain security, enables multi-faceted monitoring of critical signals and intelligent safety status selection, and reduces the risk of single point of failure.
Smart Images

Figure CN120739868B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of gearbox controller, and particularly relates to a double-clutch gearbox controller system based on functional safety requirements. BACKGROUND
[0002] In recent years, with the development of automobile electronics and intelligence, double-clutch gearboxes are widely used due to their efficient and fast shifting performance, but the traditional gearbox controller has significant defects in functional safety:
[0003] 1. Development process has risks: The traditional gearbox controller usually adopts the mode of "design first and then analyze", which does not meet the development process required by the ISO 26262 standard, so that potential risks cannot be identified in the early stage;
[0004] 2. High risk of single point failure: The single-chip architecture lacks redundancy design, and the failure of key sensors or chips may cause the gearbox to lose control, which cannot meet the high safety level requirement of ASIL D.
[0005] 3. Insufficient diagnostic coverage: The hardware diagnostic module does not cover all key signal chains, making it difficult to meet the functional safety integrity requirements;
[0006] 4. Compatibility and supply chain risks: The hardware design of the traditional gearbox controller has poor compatibility for different double-clutch gearbox models, and relies on foreign special chips, resulting in high cost and great supply chain risk.
[0007] Based on this, the present application provides a double-clutch gearbox controller system based on functional safety requirements, which can eliminate the drawbacks of the prior art. SUMMARY
[0008] The present application aims to provide a double-clutch gearbox controller system based on functional safety requirements to solve the problems of development process risks, high single point failure risks, insufficient diagnostic coverage, and compatibility and supply chain risks in the background art.
[0009] To achieve the above-mentioned purpose, the present application provides the following technical scheme:
[0010] A double-clutch gearbox controller system based on functional safety requirements, comprising:
[0011] A power management module for receiving constant power and being divided into a high-power power supply and a low-power power supply, and generating multiple power supplies through a power management chip to supply power to the system;
[0012] A main control chip for receiving vehicle control commands and sensor information, and executing the control logic of the double-clutch gearbox;
[0013] A monitoring chip is configured to monitor the running state of the master control chip, the core power supply voltage and key sensor signals.
[0014] A motor driving module is configured with two clutch motor drives, two gear shifting motor drives and one cooling pump motor drive, and is configured to feed back the motor rotor position to the master control chip in real time.
[0015] A communication interface module is configured with four CAN channels and one LIN channel, and is configured to adapt to different vehicle communication requirements.
[0016] A signal acquisition module is configured with two pressure sensors, three rotation speed sensors, one angle sensor and one temperature sensor, and is configured to acquire pressure, rotation speed, angle and temperature sensor signals.
[0017] A safety state control module is configured to trigger a safety mechanism through the master control chip, the monitoring chip and the power management chip when a failure mode is detected, so as to make the gearbox enter a preset safety state.
[0018] Preferably, the power management module comprises:
[0019] An input protection circuit is configured to perform overvoltage, overcurrent and reverse connection protection on the normal power supply.
[0020] A logic control circuit is configured to control the high-power power supply according to the instructions of the master control chip, so as to ensure that the motor driving module is powered only when the system is working normally.
[0021] A power management chip is configured to receive a hard-wired wake-up signal and a wake-up signal of the communication interface module, to generate a plurality of stabilized power supplies for powering the master control chip, the monitoring chip, a plurality of sensors and peripheral circuits, and to monitor the running state of the master control chip, and to trigger the safety mechanism of the safety state control module when an abnormality occurs.
[0022] A power distribution circuit is configured to divide the normal power supply into two paths, including a low-power power supply and a high-power power supply, the low-power power supply being configured to power the power management chip and the communication interface module, and the high-power power supply being configured to power the motor driving module through the logic control circuit.
[0023] Preferably, the master control chip is internally provided with a lockstep core, which is configured to run the following functional safety software:
[0024] A motor rotor position command protection program;
[0025] A motor rotor position diagnosis program;
[0026] A MOS and MOS driving power diagnosis program;
[0027] A RAM and ROM diagnosis program;
[0028] The four programs are run in the lockstep core, and if the results of the lockstep core are inconsistent, the monitoring safety state is enabled;
[0029] The main control chip is further provided with a common resource diagnosis program, which is used to realize the monitoring safety state function in cooperation with the monitoring chip.
[0030] Preferably, the monitoring chip internally runs the following functional safety software:
[0031] The main control chip WATCHDOG program is used to realize the monitoring operation of the running state of the main control chip in cooperation with the common resource diagnosis program.
[0032] The main control chip power supply monitoring program is used to monitor the power supply of the main control chip.
[0033] The gearbox gear independent diagnosis program is used to monitor the actual gear and vehicle state through the speed sensor signal transmitted by the signal acquisition module.
[0034] If one or more of the following situations occurs, the monitoring safety state is enabled:
[0035] The main control chip WATCHDOG program cannot obtain feedback in time.
[0036] The main control chip power supply monitoring program monitors that the power supply of the main control chip is abnormal.
[0037] The gearbox gear independent diagnosis program monitors that the actual gear and vehicle state are abnormal.
[0038] Preferably, the motor driving module comprises:
[0039] Two clutch motor driving circuits are used to control the combination and separation of the clutch.
[0040] Two gear shifting motor driving circuits are used to control the gear shifting operation.
[0041] One cooling pump motor driving circuit is used to control the cooling system.
[0042] A high-precision position sampling circuit is used to monitor the motor rotor position in real time.
[0043] The five motor driving circuits are all provided with high-precision position sampling circuits.
[0044] Preferably, one CAN channel and LIN channel of the communication interface module support INH wake-up mode.
[0045] Preferably, the safety state control module comprises:
[0046] A safety state triggering unit is configured to shut down all motor driving circuits when a master control chip failure, a power supply abnormality, and a sensor signal abnormality are detected.
[0047] A safety state executing unit is configured to control the gearbox to enter a safety state.
[0048] Preferably, the safety state comprises:
[0049] Safety state one: the gearbox gear position remains in the original state, and the gearbox state information reflects the real state;
[0050] Safety state two: switching to the neutral state, and the clutches are in the disengaged state;
[0051] Safety state three: activating the parking lock state when the vehicle is stationary.
[0052] According to the fault type and the vehicle state, the corresponding safety state is triggered.
[0053] Preferably, the triggering conditions of the safety state control module comprise:
[0054] The lockstep core operation results are inconsistent;
[0055] The power management chip 11 detects an abnormality;
[0056] The master control chip power supply is abnormal;
[0057] The monitoring chip voltage is abnormal;
[0058] The actual gear position, vehicle state signal, and rotational speed sensor data conflict.
[0059] Preferably, the application further discloses a dual-clutch gearbox control method based on functional safety requirements, which comprises the following steps:
[0060] Step S1: receiving constant power through a power management module and distributing it into high-power and low-power power supplies, and generating multiple power supplies for the system through a power management chip;
[0061] Step S2: receiving vehicle control commands and sensor information of a signal acquisition module through a master control chip, executing control logic of a dual-clutch gearbox, and generating motor control instructions;
[0062] Step S3: monitoring the running state of the master control chip, core power supply voltage, and key sensor signals in real time through a monitoring chip;
[0063] Step S4: driving the clutch motor, gear shifting motor, and cooling pump motor according to the instructions of the master control chip through a motor driving module, and feeding back the motor rotor position through a high-precision position sampling circuit;
[0064] Step S5, the system running state is monitored in real time, if the trigger condition is detected, the safety state control module triggers the safety mechanism through the master control chip, the monitoring chip and the power management chip, so that the gearbox enters the preset safety state.
[0065] Compared with the prior art, the beneficial effects of the present application are as follows:
[0066] In the dual clutch gearbox controller system based on functional safety requirements, the dual-chip architecture of master control chip and monitoring chip is adopted, combined with lockstep core design and multiple diagnosis mechanism, the redundant monitoring and fault detection of key signals are realized, and the ASIL D functional safety level requirement in ISO 26262 is met.
[0067] The system runs multiple diagnosis programs through the lockstep core of the master control chip, cooperates with the independent diagnosis function of the monitoring chip and the monitoring and diagnosis function of the power management chip, realizes the multi-directional monitoring of power supply, sensor signal, processor state and other key elements, designs three-level safety state, intelligently selects the appropriate safety state according to the fault type and vehicle state, and triggers the safety state through the safety state triggering mechanism of the hardware circuit direct intervention, so that the system maintains the safety state.
[0068] The system is configured with multiple CAN and LIN communication interfaces and sensor acquisition circuits, adapts to different vehicle requirements, supports multiple communication protocols and wake-up modes, and the master control chip, monitoring chip and power management chip all adopt domestic models, which not only ensures the supply chain safety, but also reduces the system cost. BRIEF DESCRIPTION OF DRAWINGS
[0069] Figure 1 It is a system structure diagram of the present application.
[0070] Figure 2 It is a schematic diagram of the built-in program of the master control chip and the monitoring chip of the present application.
[0071] Figure 3 It is a diagnosis monitoring flowchart of the master control chip and the monitoring chip of the present application.
[0072] Figure 4 It is a diagnosis monitoring flowchart of the master control chip, monitoring chip and power management chip of the present application.
[0073] Figure 5 It is a structure schematic diagram of the overall module of the present application.
[0074] Figure 6 It is a structure schematic diagram of the power management module of the present application.
[0075] The reference signs are annotated as follows: power management module 10, power management chip 11, master control chip 20, monitoring chip 30, motor drive module 40, communication interface module 50, signal acquisition module 60, and safety state control module 70. DETAILED DESCRIPTION
[0076] In order to make the purpose, technical solutions and advantages of the present application more clear, the present application is further described in detail below in combination with the drawings and examples.
[0077] In the present embodiment, as shown in Figure 1 - Figure 6 A dual clutch transmission controller system based on functional safety requirements, comprising:
[0078] The power management module 10 is used to receive constant power and is divided into a high-power power supply and a low-power power supply, and a plurality of power supplies are generated by the power management chip 11 to supply power to the system;
[0079] Specifically, the power management chip 11 is abbreviated as SBC, which is connected to the constant power through the KL30 interface, and overvoltage, overcurrent and reverse connection protection operations are performed through the input protection circuit, such as triggering protection when the voltage exceeds 16V, cutting off when the current is greater than 30A, etc. The power supply distribution circuit divides it into a low-power power supply (VBAT_LP) and a high-power power supply (VBAT_HP). The low-power power supply (VBAT_LP) supplies power to the power management chip 11 and the communication interface module 50. The low-power power supply (VBAT_LP) supplies power to the CAN1 channel and the LIN channel in the communication interface module 50. The high-power power supply (VBAT_HP) supplies power to the motor drive module 40 through a logic control circuit. The logic control circuit is controlled by the high-power power supply enable signal (12V_HP_EN) output by the master control chip 20. Only when the system is working normally, the high-power power supply enable signal (12V_HP_EN) is high, the logic control circuit is turned on, and the high-power power supply supplies power to the motor drive module 40.
[0080] The master control chip 20 is used to receive vehicle control commands and sensor information, and execute the control logic of the dual clutch transmission;
[0081] Specifically, as shown in Figure 3 and Figure 4 The chip in the master control chip 20 and the monitoring chip 30 can be abbreviated as MCU. The master control chip 20 can receive monitoring data of the core power supply and key sensor signals, and fully grasp the system running state. After the master control chip 20 calculates, it sends instructions to the motor drive module 40 through six PWM waves to drive the motor to run. The Mos off signal can directly intervene in the connection of the master control chip 20 and the system execution circuit, cut off the power in abnormal conditions, and ensure safety.
[0082] As Figure 1 shown, the main control chip 20 is integrated with a lockstep core, with rich peripheral interfaces such as LSO, HSO, DI, AI, PWM-IN, PWM-OUT, etc. input and output interfaces, so that the system realizes the functions of digital / analog signal input and output, PWM control, etc. for interaction with external sensors and actuators, and builds a complete control system. The specific functions are determined according to the application scene and hardware circuit design of the actual device, such as PWM (Pulse Width Modulation) output for controlling the motor drive module 40. The main control chip 20, monitoring chip 30 and power management chip 11 are selected according to the actual environment. The traditional scheme relies on imported chips, while the system uses domestic chips, which significantly reduces the cost.
[0083] The monitoring chip 30 is used to monitor the running state of the main control chip 20, the core power voltage and the key sensor signals.
[0084] Specifically, domestic chips are used, with independent power and clock systems to ensure the reliability of the monitoring function. Multiple ADC channels are configured to monitor the power voltage and key sensor signals of the main control chip 20, and PWM input channels are used to receive the speed sensor signal.
[0085] The motor drive module 40 is configured with 2 clutch motors, 2 gear shifting motors and 1 cooling pump motor, which is used to feed back the motor rotor position to the main control chip 20 in real time.
[0086] The communication interface module 50 is configured with 4 CAN channels and 1 LIN channel, which is used to adapt to different vehicle communication requirements.
[0087] Specifically, 1 CAN channel and LIN channel of the communication interface module 50 support INH wake-up mode. The CAN channel includes CAN1 channel, CAN2 channel, CAN3 channel and CAN4 channel, wherein the CAN1 channel supports INH wake-up mode, the CAN communication baud rate can be configured as 250kbps or 500kbps, which meets the different vehicle communication rate requirements. The CAN interface has bus short circuit protection and overvoltage protection function to ensure the stability of communication. The LIN channel supports INH wake-up mode, and the communication baud rate is 19.2kbps, which is used for communication with low-speed devices such as vehicle body comfort system, to realize the display and simple control of the transmission state.
[0088] The signal acquisition module 60 is configured with 2 pressure sensors, 3 speed sensors, 1 angle sensor and 1 temperature sensor, which is used to acquire pressure, speed, angle and temperature sensor signals.
[0089] Specifically, the pressure sensor, speed sensor, angle sensor and temperature sensor can be adjusted according to the actual environmental requirements.
[0090] The safety state control module 70 is configured to trigger a safety mechanism through the master control chip 20, the monitoring chip 30 and the power management chip 11 to make the gearbox enter a preset safety state when a failure mode is detected.
[0091] Specifically, if the fault is a transient disturbance (such as a temporary abnormality of a sensor signal), the system automatically recovers after the fault disappears, and if the fault is a permanent fault (such as an error of the lockstep core of the master control chip 20), the system needs to be restarted after the fault code is cleared through a vehicle diagnostic instrument.
[0092] As shown in FIGS. 1, 2 and 3, the power management module 10 includes: Figure 1 and Figure 6 As shown in FIGS. 1, 2 and 3, the power management module 10 includes:
[0093] The input protection circuit performs overvoltage, overcurrent and reverse connection protection on the constant power;
[0094] The logic control circuit is configured to control the high-power power supply according to the instruction of the master control chip 20, so as to ensure that the motor driving module 40 is powered only when the system is working normally;
[0095] The power management chip 11 is configured to receive a hard-wired wake-up signal and a wake-up signal of the communication interface module 50, generate a plurality of stabilized power supplies for powering the master control chip 20, the monitoring chip 30, a plurality of sensors and peripheral circuits, and monitor the running state of the master control chip 20, and trigger a safety mechanism of the safety state control module 70 when an abnormality occurs;
[0096] The power distribution circuit is configured to divide the constant power into two paths, including a low-power power supply and a high-power power supply. The low-power power supply is configured to power the power management chip 11 and the communication interface module 50, and the high-power power supply is configured to power the motor driving module 40 through the logic control circuit;
[0097] Specifically, the power management chip 11 supports two wake-up modes, including a hard-wire wake-up signal (KL15) and an INH wake-up signal output by the CAN1 channel of the communication interface module 50, when the hard-wire wake-up signal (KL15) is turned on or the CAN1 channel receives a wake-up instruction, the power management chip 11 is started to generate a plurality of stabilized power supplies, such as 5V, 3.3V, etc., to power the main control chip 20, the monitoring chip 30, a plurality of sensors and peripheral circuits, in the process, the system monitors the running state of the main control chip 20 in real time, judges whether it works normally by detecting the Watchdog signal output by the main control chip 20, if the Watchdog signal is not received within a specified time, it is determined that the main control chip 20 is abnormal, triggering the safety mechanism of the safety state control module 70, the power management chip 11 performs Alive or Die monitoring operation on the main control chip 20, which is used to detect whether the key components (such as the main control chip 20, the communication interface module 50, the driving circuit) are invalid or stuck, can quickly identify the "false death" state, trigger the safety response, which is the prior art.
[0098] As shown in Figure 1 and Figure 2 The main control chip 20 is internally provided with a lockstep core for running the following function safety software:
[0099] The motor rotor position command protection program performs legality verification on the input motor rotor position command to prevent false commands from causing abnormal operation of the motor, and the above-mentioned motors are shift motor one (SAM1) and shift motor two (SAM2), for example, when the received shift motor position command exceeds the normal gear range (such as outside 1-6 gears), the command is refused to be executed and the fault is recorded;
[0100] The motor rotor position diagnosis program compares the actual motor rotor position (obtained through a high-precision position sampling circuit) with the command position in real time, and if the deviation exceeds the set threshold, it is determined that the position is abnormal, triggering diagnosis, and the above-mentioned motors are shift motor one (SAM1) and shift motor two (SAM2);
[0101] The MOS and MOS driving power diagnosis program monitors the on-resistance of the MOS tube in the motor driving circuit and the driving power voltage, such as when the on-resistance of the MOS tube is too large or the driving power voltage is lower than 4.5V, it is judged that the MOS or driving power is faulty, and a fault signal is sent to the safety state control module 70;
[0102] The RAM and ROM diagnosis program periodically checks the internal RAM and ROM, which can detect the correctness of the stored data through parity check, CRC (cyclic redundancy check), etc., if the RAM data error or ROM program check fails, the safety state enable is triggered immediately;
[0103] If the lockstep core results are inconsistent, the safety state enable is triggered;
[0104] The main control chip 20 is further provided with a common resource diagnosis program, which is used for realizing the safety state monitoring function in cooperation with the monitoring chip 30, and is used for sharing the system clock, the interrupt and other resources in cooperation with the monitoring chip 30, and realizing the monitoring on the overall running state of the system.
[0105] Specifically, if the lockstep core results are inconsistent in the minimum time unit or the processing period of a certain system, the safety state enable is triggered.
[0106] As shown in Figure 1 and Figure 2 The monitoring chip 30 internally runs the following function safety software:
[0107] The main control chip WATCHDOG program is used for realizing the monitoring operation on the running state of the main control chip 20 in cooperation with the common resource diagnosis program.
[0108] The main control chip power supply monitoring program is used for monitoring the power supply of the main control chip 20.
[0109] The gearbox gear independent diagnosis program is used for monitoring the actual gear and the vehicle state through the speed sensor signal transmitted by the signal acquisition module 60.
[0110] If one or more of the following situations occurs, the safety state enable is triggered:
[0111] The main control chip WATCHDOG program cannot obtain feedback in time;
[0112] The main control chip power supply monitoring program monitors that the power supply of the main control chip 20 is abnormal;
[0113] The gearbox gear independent diagnosis program monitors that the actual gear and the vehicle state are abnormal;
[0114] Specifically, the watchdog program of the master chip sends a watchdog signal to the monitoring chip 30, requiring the master chip 20 to feedback a response signal within a specified time. If the feedback is not received in time, it is determined that the master chip 20 is running abnormally, a reset signal is triggered to reset the master chip 20, and the monitoring safety state enable is triggered at the same time. The power supply monitoring program of the master chip monitors the power voltage of the master chip 20 in real time through the ADC channel. When the voltage deviates from the normal value ± 10%, it is determined that the power supply is abnormal, the monitoring safety state enable is triggered, and the gearbox gear independent diagnosis program receives the signals sent by the signal acquisition module 60. The three speed sensor signals are used to calculate the actual gear and vehicle state by calculating the speed of each shaft. For example, when the vehicle is in a stationary state, each speed sensor should output a 0 speed signal. If a non-0 speed is detected, it is determined that the vehicle state is abnormal. When the actual gear is inconsistent with the gear command sent by the master chip 20 (such as the command is D, and the actual detection is R), the monitoring safety state enable is triggered.
[0115] Specifically, the monitoring chip 30 performs ALU and Sequnence monitoring operations on the master chip 20. ALU is a logic calculation unit, and Sequence is a timing logic unit. The monitoring of ALU ensures the correctness of hardware calculation by capturing hardware calculation errors to trigger the safety mechanism. The monitoring of Sequence ensures the trusted execution of program flow by confirming whether the program flow is hijacked to trigger the safety mechanism. ALU monitoring and Sequence monitoring constitute the "double cornerstone" of calculation safety. If ALU calculation error triggers the safety state, Sequence monitoring will check whether the error is caused by program runaway. The Alive monitoring confirms whether the master chip 20 is still sending a heartbeat signal. The three together locate the fault type. When any monitoring mechanism detects an abnormality, the safety mechanism can be triggered through the safety state control module 70.
[0116] As shown in Figure 1 and Figure 5 The motor drive module 40 includes:
[0117] Two clutch motor drive circuits are used to control the combination and separation of the clutch. The clutch motor includes a clutch motor one (CAPM1) and a clutch motor two (CAPM2), which are powered by the high-power power supply (VBAT_HP) provided by the power management module 10, and receive the PWM signal output by the master chip 20 to control the combination and separation of the clutch.
[0118] Two gear shifting motor drive circuits are used to control gear shifting operations. The gear shifting motor includes a gear shifting motor one (SAM1) and a gear shifting motor two (SAM2), which control the forward and reverse rotation and speed of the gear shifting motor through the PWM signal to realize gear shifting.
[0119] 1. A cooling pump motor drive circuit for controlling the cooling system, the cooling pump motor is abbreviated as CCPM, the speed of the cooling pump is adjusted according to the signal of the gearbox temperature sensor, when the temperature is higher than 80℃, the cooling pump runs at full speed, when the temperature is lower than 50℃, the cooling pump runs at low speed or stops;
[0120] A high-precision position sampling circuit for real-time monitoring of the motor rotor position;
[0121] Among them, the above-mentioned 5 motor drives are all equipped with high-precision position sampling circuits, three-phase Hall signals are used, and the high-precision position sampling signals are PWM signals sent by special chips.
[0122] The safety state control module 70 includes:
[0123] A safety state triggering unit for shutting down all motor drive circuits when detecting a master control chip 20 failure, a power supply anomaly, and a sensor signal anomaly, realized by a hardware circuit, when detecting any failure signal, immediately outputting a high-level signal to the enable end of the motor drive module 40, shutting down all motor drive circuits, cutting off the motor power supply, and stopping the motor from running;
[0124] A safety state execution unit for controlling the gearbox to enter a safety state;
[0125] Specifically, the safety state includes:
[0126] Safety state one: the gearbox gear position remains the original state, and the gearbox state information reflects the true state;
[0127] Safety state two: switching to the neutral state, and the clutches are all in the disengaged state;
[0128] Safety state three: activating the parking lock state when the vehicle is stationary;
[0129] Specifically, according to the HARA (Hazard Analysis and Risk Assessment) analysis, the double-clutch gearbox has the above-mentioned three safety states, the master control chip 20, the monitoring chip 30, and the power management chip 11 work cooperatively, and the entered safety state is controlled according to the fault type and the vehicle state, such as when detecting a non-serious fault (such as a single sensor signal anomaly), controlling the gearbox to enter safety state one, which is suitable for non-serious faults, when detecting a serious fault (such as the master control chip 20 lockstep core results being inconsistent, the master control chip 20 power supply anomaly), controlling the gearbox to enter safety state two, when the vehicle is stationary and an electronic parking related fault is detected (such as SAM2 motor position control leading to electronic parking failure), controlling the gearbox to enter safety state three, which is suitable for electronic parking faults;
[0130] Among them, such as Figure 1 and Figure 2The trigger conditions of the safety state control module 70 are shown as follows:
[0131] Inconsistent results of lockstep core operation;
[0132] Abnormality of the power management chip 11;
[0133] Abnormality of the power supply of the master chip 20;
[0134] Abnormality of the voltage of the monitoring chip 30;
[0135] Conflict between the actual gear, vehicle state signal and the data of the speed sensor;
[0136] Specifically, the trigger mechanism of inconsistent results of lockstep core operation: the master chip 20 runs the same functional safety program (such as motor control, sensor diagnosis, etc.) in the internal lockstep core, and compares the operation results at each system clock cycle. If the results are inconsistent, it is determined that there is a hardware or software failure, and the safety state enable signal is triggered immediately to forcibly shut down the motor drive module 40 through the hardware circuit, and send a fault code (DTC) to the whole vehicle through the communication interface module 50, and the gearbox enters safety state two (neutral);
[0137] The power management chip 11 monitors the output voltage of itself and the master chip 20, and triggers the safety mechanism if there is an abnormality:
[0138] If there is overvoltage, overcurrent or abnormal power sequence of the power management chip 11 itself, the safety mechanism is triggered to monitor the Alive and Die of the master chip 20. The master chip 20 needs to periodically send a "heartbeat" signal, and the monitor checks the signal within a fixed time window to verify whether the task or function is periodically executed. If the task is stalled, the safety mechanism is triggered;
[0139] The monitoring method of the abnormality of the power supply of the master chip 20: the monitoring chip 30 monitors the power supply voltage of the master chip in real time through the ADC channel. If the voltage exceeds the calibrated range (such as ±10%), or the voltage drop is detected (such as below the threshold for a period of time), it is determined that the power supply is abnormal, and the motor drive module 40 is turned off through an independent hardware circuit. If the vehicle is stationary, the gearbox enters safety state three, and if the vehicle is driving, the gearbox enters safety state two;
[0140] The monitoring chip 30 monitors the voltage. If there is an abnormality, the safety mechanism is triggered. The voltage includes the 5V voltage of the master chip 20 (generated by the power management chip 11), the 3.3V voltage of the master chip 20 (generated by the master chip 20 itself), the core voltage of the master chip 20 (generated by the master chip 20 itself or an external power chip), and the power supply voltage of the monitoring chip 30 (supplied by the power management chip 11);
[0141] Diagnostic logic for actual gear, vehicle state and speed sensor data conflict: Calculate the transmission ratio through the three speed sensors (input shaft, output shaft, intermediate shaft), compare with the gear command sent by the main control chip 20, for example, when in D, the transmission ratio should be 1.5:1, if 0.8:1 is detected, it is determined that the gear is abnormal, if the speed sensor shows that the vehicle speed is 0, but the angle sensor detects that the shift motor is moving, it is determined that "unexpected gear shifting" occurs, the safety state is enabled immediately, the shift motor (SAM1 / SAM2) is forced to return to the neutral position, the clutch (CAPM1 / CAPM2) is separated, and the safety state two is entered;
[0142] Monitoring process for watchdog program of main control chip: The monitoring chip 30 sends a watchdog trigger signal to the main control chip 20 at regular intervals, and the main control chip needs to feedback through a dedicated GPIO pin or SPI communication within the corresponding time. If no feedback is received for several times in a row, it is determined that the main control chip 20 is abnormal, the monitoring chip 30 restarts the main control chip 20 through the hardware reset line (Reset Line), and takes over the safety control during this period. If the vehicle is in motion, it enters safety state two, and if the vehicle is stationary, it enters safety state three.
[0143] In use, the power management module 10 receives constant power and distributes it as high-power and low-power power sources, the power management chip 11 generates multiple power sources for system power supply, the main control chip 20 receives vehicle control commands and sensor information of the signal acquisition module 60, executes the control logic of the dual-clutch transmission, generates motor control instructions, the monitoring chip 30 monitors the running state of the main control chip 20, the core power voltage and the key sensor signals in real time, the motor drive module 40 drives the clutch motor, shift motor and cooling pump motor according to the instructions of the main control chip 20, and feeds back the motor rotor position through the high-precision position sampling circuit, monitors the system running state in real time, and if the trigger condition is detected, the safety state control module 70 triggers the safety mechanism through the main control chip 20, the monitoring chip 30 and the power management chip 11, so that the transmission enters the preset safety state.
[0144] The above is only a specific embodiment of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A dual clutch transmission controller system based on functional safety requirements, characterized in that, The application relates to a dual clutch transmission control system, which comprises the following parts: a power management module (10) for receiving constant power and being divided into a high-power power supply and a low-power power supply, and generating multiple power supplies through a power management chip (11) to supply power to a system; a main control chip (20) for receiving vehicle control commands and sensor information and executing control logic of a dual clutch transmission; a monitoring chip (30) for monitoring the running state of the main control chip (20), core power supply voltage and key sensor signals; a motor drive module (40) configured with 2 clutch motor drives, 2 gear shifting motor drives and 1 cooling pump motor drive, which is used for feeding back motor rotor positions to the main control chip (20) in real time; a communication interface module (50) configured with 4 CAN channels and 1 LIN channel, which is used for adapting to different vehicle communication requirements; a signal acquisition module (60) configured with 2 pressure sensors, 3 rotation speed sensors, 1 angle sensor and 1 temperature sensor, which is used for acquiring pressure, rotation speed, angle and temperature sensor signals; a safety state control module (70) for triggering a safety mechanism through the main control chip (20), the monitoring chip (30) and the power management chip (11) when a failure mode is detected, so that the transmission enters a preset safety state; the safety state control module (70) comprises: a safety state triggering unit for shutting down all motor drive circuits when the main control chip (20) fails, power supply is abnormal and sensor signals are abnormal; a safety state execution unit for controlling the transmission to enter a safety state; triggering conditions of the safety state control module (70) include: inconsistent lockstep core operation results; abnormal monitoring of the power management chip (11); abnormal power supply of the main control chip (20); abnormal voltage of the monitoring chip (30); conflict between actual gear, vehicle state signals and rotation speed sensor data; the main control chip (20) is internally provided with lockstep cores for running the following functional safety software: motor rotor position command protection program; motor rotor position diagnosis program; MOS and MOS drive power diagnosis program; RAM and ROM diagnosis program; the four programs are all run in the lockstep cores, and if the lockstep core results are inconsistent, the monitoring safety state function is triggered; the main control chip (20) is further internally provided with a common resource diagnosis program for realizing the monitoring safety state function in cooperation with the monitoring chip (30); the monitoring chip (30) internally runs the following functional safety software: a main control chip WATCHDOG program for realizing monitoring operation on the running state of the main control chip (20) in cooperation with the common resource diagnosis program; a main control chip power monitoring program for monitoring the power supply of the main control chip (20); a transmission gear independent diagnosis program for monitoring actual gears and vehicle states through rotation speed sensor signals transmitted by the signal acquisition module (60); if one or more of the following situations occurs, the monitoring safety state function is triggered: the main control chip WATCHDOG program cannot be fed back in time; the main control chip power monitoring program monitors that the power supply of the main control chip (20) is abnormal; The gearbox gear independent diagnosis program monitors the actual gear and vehicle state abnormalities.
2. A dual clutch transmission controller system based on functional safety requirements according to claim 1, characterized in that, The power management module (10) comprises: An input protection circuit for overvoltage, overcurrent and reverse connection protection of the normal power supply; A logic control circuit for controlling the high-power power supply according to the instructions of the master control chip (20) to ensure that the motor drive module (40) is powered only when the system is working normally; A power management chip (11) for receiving the hard-wire wake-up signal and the wake-up signal of the communication interface module (50), generating multiple stabilized power supplies for the master control chip (20), the monitoring chip (30), multiple sensors and peripheral circuits, and monitoring the operating state of the master control chip (20) to trigger the safety mechanism of the safety state control module (70) in case of abnormality; A power distribution circuit for dividing the normal power supply into two paths, including a low-power power supply and a high-power power supply, the low-power power supply being used to power the power management chip (11) and the communication interface module (50), and the high-power power supply being used to power the motor drive module (40) through the above-mentioned logic control circuit.
3. A dual clutch transmission controller system based on functional safety requirements according to claim 1, characterized in that, The motor drive module (40) comprises: Two clutch motor drive circuits for controlling the engagement and disengagement of the clutch; Two gear shifting motor drive circuits for controlling gear shifting operations; One cooling pump motor drive circuit for controlling the cooling system; A high-precision position sampling circuit for real-time monitoring of the motor rotor position; Among them, the above-mentioned 5 motor drive circuits are all equipped with high-precision position sampling circuits.
4. A dual clutch transmission controller system based on functional safety requirements according to claim 1, characterized in that, One CAN channel and LIN channel of the communication interface module (50) support INH wake-up mode.
5. A dual clutch transmission controller system based on functional safety requirements as claimed in claim 1, wherein, The safety states include: Safety state one: the gearbox gear remains in the original state, and the gearbox state information reflects the true state; Safety state two: switching to the neutral state, and the clutches are all disengaged; Safety state three: activating the parking lock state when the vehicle is stationary; Among them, the corresponding safety state is triggered according to the fault type and vehicle state.
6. A dual clutch transmission controller system based on functional safety requirements according to claim 1, characterized in that, It also includes a dual-clutch gearbox control method based on functional safety requirements, which specifically includes the following steps: Step S1, receiving the normal power supply through the power management module (10) and dividing it into a high-power power supply and a low-power power supply, and the power management chip (11) generating multiple power supplies for the system power supply; Step S2, the master control chip (20) receives the vehicle control command and the sensor information of the signal acquisition module (60), executes the control logic of the dual-clutch gearbox, and generates motor control instructions; Step S3, the monitoring chip (30) monitors the operating state of the master control chip (20), the core power supply voltage and the key sensor signals in real time; Step S4, the motor drive module (40) drives the clutch motor, gear shifting motor and cooling pump motor according to the instructions of the master control chip (20), and feeds back the motor rotor position through the high-precision position sampling circuit; Step S5, real-time monitoring of the system operating state, if the trigger condition is detected, the safety state control module (70) triggers the safety mechanism through the master control chip (20), the monitoring chip (30) and the power management chip (11), so that the gearbox enters the preset safety state.
Citation Information
Patent Citations
A vehicle safety electronic control system
CN107531250A
Vehicle safety control method and device, electronic equipment and storage medium
CN115610434A