System architecture for a motor vehicle
Through a redundant system architecture, independent control equipment systems, and redundant connections, the problem of simultaneous failure of the brake actuator and steering control equipment is solved, improving the robustness and safety of the vehicle and ensuring that it can still maintain basic driving capability in the event of a failure.
Patent Information
- Application Number
- CN202510513719.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-04-23
- Filing Date
- 2025-04-23
- Publication Date
- 2025-10-24
AI Technical Summary
In modern motor vehicle system architecture, the simultaneous connection of brake actuators and steering control equipment is susceptible to malfunctions, leading to system stability and safety issues.
The system architecture employs a redundant design, comprising two independent control equipment systems. Each system controls the steering motors and brake actuators on different wheels and axles of the vehicle. These systems are redundantly connected through logic circuits, computing units, and energy supply units, ensuring that the other system can continue to operate normally if one system fails.
It improves the robustness and safety of the system, prevents overall failure caused by a single point of failure, ensures that the vehicle can still maintain basic driving ability in the event of a failure, and enhances driving safety and reliability.
Smart Images

Figure CN120828829A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present invention relates to a system architecture for a motor vehicle, in particular with regard to the arrangement of the individual components and the resulting failure reliability. BACKGROUND
[0002] System architectures in motor vehicles relate to the structure and organization of various electronic components and control systems necessary for the operation and monitoring of the vehicle. Such an architecture comprises a plurality of components, among them control devices, sensors, actuators and communication interfaces, which are connected to one another for enabling an efficient and reliable control of the vehicle.
[0003] A main component of system architectures in modern motor vehicles are control devices for steering actuators and brake actuators. These control devices are responsible for the precise control of the steering and braking of the vehicle and thus play a decisive role for safety, efficiency and driving dynamics.
[0004] Control devices that operate steering actuators are responsible for controlling the steering system of the vehicle. They receive input signals from different sources, such as the steering wheel and / or other vehicle systems, and convert them into corresponding steering movements. For this purpose, for example, electric motors are operated, which control the steering movement via a rack. Modern vehicles increasingly use fully electronic steering systems, also known as steer-by-wire systems, which dispense with the mechanical connection between the steering wheel and the wheels.
[0005] Brake actuators are responsible for controlling the braking system of the vehicle. Signals of the brake pedal and other vehicle systems are received by the control unit and converted into brake pressure for hydraulic brake systems by operating a pump. For brake-by-wire systems, the mechanical passage from the pedal to the brake caliper, which is usually implemented by means of a hydraulic system, is dispensed with. For wheel-individual brake systems without a hydraulic part, brake-by-wire technology is usually used. Control devices for brake actuators also monitor various parameters such as speed, traction and road conditions in order to adjust the brake force accordingly and to ensure the best braking performance and stability of the vehicle. Modern brake actuator systems often also include functions such as anti-lock braking systems (ABS), electronic stability control (ESC) and brake force distribution systems (EBD), which help to improve safety and driving performance.
[0006] In the system architecture of a motor vehicle, the control devices for steering actuators and brake actuators usually work closely together in order to enable precise and coordinated control of the steering and brake actuators. Through the integration of different sensors and communication interfaces, these control devices are able to collect and analyze vehicle data in real time in order to optimize vehicle efficiency and ensure safe and comfortable driving.
[0007] A system architecture of a vehicle is known from the publication DE 102021206184 A1, which comprises two control device units for redundantly configuring the steering and braking functions. The two control device units each operate steering and brake actuators and have a connection to separate data systems. Furthermore, the control device units are connected by a communication interface, wherein the first control device unit represents a primary steering control device (PLS) and a secondary brake control device (SBS), and wherein the second control device unit represents a primary brake control device (PBS) and a secondary steering control device (SLS).
[0008] It proves disadvantageous that the simultaneous connection of the brake actuators to the steering and brake control devices creates a weak point of the system with respect to faults in the control connection for the brake actuators. Thus, for example, an overvoltage in the control connection can simultaneously interfere with the steering and brake control devices and thus impair the entire steering-brake system. SUMMARY
[0009] It is therefore the task of the present invention to propose a system architecture with combined steering and braking functions with which the mentioned disadvantages can be overcome.
[0010] This task is solved by the subject matter of the independent claims.
[0011] According to a first aspect of the invention, this task is solved by a system architecture for a motor vehicle, which comprises a steering actuator and comprises a brake actuator for each wheel of the motor vehicle. The steering actuator comprises a first steering motor and a second steering motor. Furthermore, the system architecture comprises a first control device system and a second control device system.
[0012] The control device systems can comprise individual control devices or combinations of a plurality of control devices for different tasks. One or a plurality of control devices are referred to as control device systems in the context of the present invention, since they have a common task, such as the coordination of the steering and braking behavior of the motor vehicle.
[0013] The wheel-individual brake actuators can be supplied directly with electrical energy and are designed as electromechanical brakes.
[0014] The first control device system is configured for operating the first steering motor and at least two first brake actuators, wherein the first brake actuators are assigned to wheels of the motor vehicle on two different vehicle sides and on at least two different axles of the vehicle.
[0015] The second control device system is configured for operating the second steering motor and at least two second brake actuators, wherein the first brake actuators and the second brake actuators are arranged on a common axle and on both sides of the motor vehicle, respectively.
[0016] A motor vehicle within the meaning of the present invention has two sides, a left side and a right side. Furthermore, the motor vehicle has a front section at the front and a rear section at the rear. In principle, the present invention relates to motor vehicles having at least two axles. For example, one control unit system actuates the front left and rear right brakes, while another control unit system actuates the front right and rear left brakes.
[0017] However, the present invention can also be used on multi-axle vehicles. For trucks with two rear axles, the control systems can actuate different vehicle sides. For example, one control system could actuate the front right, center left, and rear right, while another control system actuates the other side. However, for driving safety, it is important for each control system on each side to actuate at least one brake actuator, with the brake actuators being located on different axles. This prevents the brake actuators on all axles from being actuated if one of the control systems fails.
[0018] The first and second control unit systems are communicatively connected to each other via a logic circuit. The logic circuit can be a common logic circuit that shares the control unit system or a separate logic circuit, with each control unit system having a separate logic circuit. The common logic circuit has the advantage of being inexpensive. Separate logic circuits require more components, namely, one for each control unit system. However, a duplicate logic circuit offers higher reliability.
[0019] In any case, the logic circuits should be designed to be redundant so that failures can be compensated by corresponding backup systems.
[0020] The corresponding actuators, namely the steering actuator and the brake actuator, are preferably purely electromechanical components, manufactured without electronics and therefore cost-effectively. The spatial separation of the actuators from the control system also allows the control system to be located within the vehicle interior, where it can be better protected from physical influences. This increases the robustness of the vehicle's overall system in the event of an accident, taking redundancy into account, since damage to the control unit becomes less likely.
[0021] Even if the energy supply or energy supply port in one of the control unit systems fails, full functionality is maintained. In the event of a data distribution or vehicle computer failure, full functionality can continue to be achieved via independent data channels. This prevents a single electronic failure from affecting more than one actuator. This ensures high availability in the event of a fault, which increases driving safety in the motor vehicle.
[0022] In one embodiment, a first control device system is arranged in a first chamber of the control device unit and a second control device system is arranged in a second chamber of the control device unit.
[0023] Unlike the control device system, the control device unit is the component of the system architecture that contains one or more control devices. Here, the control device unit provides the infrastructure for the control devices, which includes, for example, current connections, data buses and / or other electronic components.
[0024] In this embodiment, the control device unit comprises two chambers, which each contain one control device system. The chambers protect the control device systems from damage, in particular physical damage, dirt, fire, water and / or moisture. The division of the control device systems into two chambers increases the safety, since it is not possible for both chambers to be damaged at the same time and thus for both control device systems to fail at the same time.
[0025] Since each control device system operates steering motors and brake actuators on at least two axes and on each vehicle side, in the event of a failure of one of the control device systems, a minimum of control possibilities can be ensured. Even if the operating possibilities are restricted, a minimum of driving ability can be maintained with only one control device system.
[0026] In one embodiment, the chambers are separated from one another by a wall.
[0027] The wall produces a higher protection for the control device systems. If the control device unit is damaged, the wall can help to block the damage from the respective other chamber and thus from the control device system located therein.
[0028] In one embodiment, each chamber comprises a hazard sensor.
[0029] The hazard sensor is a sensor that can detect a hazard for the control device system. Here, it is, for example, a sensor for measuring air humidity, temperature or acceleration. Within the scope of the present application, more complex sensor systems, such as sensors that can detect a physical deformation of the control device unit or of the control device system, can also be referred to as hazard sensors. This can include, for example, imaging, inductive or electrostatic sensors.
[0030] The hazard sensor can detect a potential hazard for the control device system. If such a hazard is identified, this can be displayed to the person driving by means of a signal, who can then react to the hazard. The reaction can include, for example, driving to a repair shop or stopping the motor vehicle.
[0031] In one embodiment, the control device systems are arranged in different control device units.
[0032] The control device system is divided into different control device units, which makes each control device system have an independent electronic infrastructure. Thereby, not only the control device system itself is redundantly made, but also the connections and the like belonging thereto. If a fault occurs or exists at one connection, the respective other control device system can still be operated without fault.
[0033] In one embodiment, the control device units are arranged in the motor vehicle in a manner that they are spatially separated from one another.
[0034] The division into different control device units allows the control device system to be spatially separated, so that a simultaneous damage, in particular a physical damage, of both control device systems becomes more unlikely.
[0035] In all embodiments, each control device system is respectively connected in terms of energy with two independent energy supply units.
[0036] The energy connection is designed to enable the energy supply unit to supply the device coupled by means of the energy connection with sufficient electrical energy.
[0037] The double availability of the energy supply units leads to the advantageous result that one of the energy supply units can fail without having to directly interrupt the driving operation. Each energy supply unit itself is able to supply energy to both control device systems, so that at least a restricted driving function of the motor vehicle can be maintained.
[0038] In the embodiment with a control device unit with two chambers, the control device unit is connectable in terms of energy with two energy supply units, so that both control device systems are connected with the energy supply units by means of these connections.
[0039] In the embodiment with two control device units, the system architecture has a redundant infrastructure. Therefore, each control device unit is connected in terms of energy with two energy supply units.
[0040] In one embodiment, each energy supply unit has a safety mechanism for separating the energy connection.
[0041] The safety mechanism can be made, for example, in the form of a switch or a fuse.
[0042] The energy supply units preferably comprise means for recognizing short circuits to low impedance connections or to each other and to the vehicle ground. The energy supply units are also coupled to each other by a coupling to the redundancy of the control device system. If an energy supply unit experiences a short circuit, this also involves the respective other energy supply unit. To prevent this, the energy supply units have a safety mechanism which can separate a faulty line or connection point from the on-board electrical system in the event of a fault. In the event of a failure of the energy supply or the energy supply port on the control device, full functionality can thus continue to be achieved.
[0043] In one embodiment, each control device system is in communication with two computing units, wherein the computing units are configured to generate instructions for the control device system.
[0044] The computing units provide instructions to the control device system, which are obtained, for example, from a central on-board computer or from input variables of the person driving the vehicle, the steering wheel and the pedals. The computing units translate the received input variables into instructions, which the control device system in turn converts into signals for the actuators.
[0045] The redundancy of the computing units provides for an increased safety of the motor vehicle, since in the event of a failure of a computing unit the respective other computing unit is configured to provide instructions to both control device systems.
[0046] In one embodiment, the computing units are in communication with each other and are configured to match the instructions generated thereby to each other.
[0047] In this embodiment, the computing units can communicate directly with each other in an advantageous manner. In this way, unnecessary instructions are not generated and no instruction conflicts arise for the control device systems. In addition, the computing units can recognize that the respective other computing unit is causing a fault and is not or not responding to communication requests in accordance with the specification.
[0048] The communication between the computing units advantageously replaces a superior central computing unit.
[0049] In one embodiment, the system architecture comprises at least one hazard sensor, wherein the control device systems are configured to operate the steering actuators and the brake actuators such that the vehicle performs an emergency stop maneuver when the at least one hazard sensor detects a hazard.
[0050] In this embodiment, the danger sensor is arranged somewhere in the motor vehicle, wherein the danger sensor is preferably arranged in the vicinity of a system which is critical for the control of the vehicle. For example, the system architecture can comprise a plurality of danger sensors, wherein one danger sensor each is arranged in the vicinity of or directly on a steering actuator and in the vicinity of or directly on a brake actuator.
[0051] Furthermore, this embodiment can be combined with the previously mentioned embodiment in which the control device unit comprises the danger sensor.
[0052] The emergency stop maneuver can for example comprise an emergency brake. As soon as the motor vehicle is equipped with autonomous or semi-autonomous driving functions, the emergency stop maneuver can also comprise that the motor vehicle drives on a side lane or at the edge of the road and stops there. Such a maneuver can also be referred to as a minimum risk maneuver.
[0053] In an embodiment, at least two of the brake actuators comprise a parking brake function. Each control device system is configured for maneuvering at least one of the brake actuators with a parking brake function.
[0054] The parking brake function of the motor vehicle ensures that the motor vehicle does not roll down a hill even in the event of a failure of the brake system. Especially for hydraulic brake systems, damage to the hydraulic system can lead to a failure of the brake system.
[0055] Each control device system comprises a brake actuator with a parking brake function, whereby safe parking of the motor vehicle is ensured even in the event of damage or failure of one of the control device systems.
[0056] In an embodiment, each steering motor comprises a rotor position sensor, wherein the control device system is configured for reading the rotor position sensor of the steering motor which it maneuvers.
[0057] The rotor position signal is important for the maneuvering of the motor. The rotor position signal is generated directly on the motor shaft by the rotor position sensor and is transmitted to the control device system which maneuvers the respective motor.
[0058] In an embodiment, the steering motors act onto a common rack, wherein the rotor position detected with the rotor position sensor is continuously exchanged between the first control device system and the second control device system.
[0059] In the case of central steering, the challenge that also exists is that the two steering motors must act onto a common rack or onto a common motor shaft. Failure of the individual rotor position sensor on the steering actuator can be compensated for in such a way that the rotor position information is continuously exchanged between the control device systems. Real-time distribution of the rotor position signal is important here, since the motor regulation works in the range of microseconds.
[0060] The described design solutions and refinements can be combined with one another arbitrarily.
[0061] Further possible design solutions, refinements and implementation forms of the application also include combinations of the features described above or below with respect to the embodiments which are not explicitly mentioned. BRIEF DESCRIPTION OF DRAWINGS
[0062] The accompanying drawings are included to provide a further understanding of implementations of the application. The drawings illustrate implementations and, together with the description, serve to explain the principles and solutions of the application.
[0063] Other implementations and many of the referred advantages will be more fully understood in view of the drawings. The shown elements of the drawings are not necessarily to scale relative to each other.
[0064] wherein:
[0065] Figure 1 A first system architecture according to a first implementation is shown; and
[0066] Figure 2 A first system architecture according to a second implementation is shown.
[0067] In the drawings, like reference numerals indicate like or functionally similar elements, components or assemblies unless otherwise indicated. DETAILED DESCRIPTION
[0068] Figure 1 A vehicle 10 with a system architecture according to an implementation is shown. The vehicle 10 has a front portion 12 in front and a rear portion 14 in the rear. Viewed in the direction of travel, it has a left side 16 and a right side 18. Correspondingly, the vehicle has two axles, each of which has two wheels, namely a left front wheel, a right front wheel, a left rear wheel and a right rear wheel.
[0069] The front wheels 20 are steered by a steering actuator 22. To this end, the steering actuator 22 has two steering motors 24a and 24b. The steering motors 24a and 24b act onto a rack, which is connected with a steering tie rod and can steer the front wheels 20 to the left and to the right.
[0070] Each wheel is provided with a brake actuator 26a, 26b, 26c or 26d with which each wheel can be braked individually.
[0071] The control device systems 28a and 28b take over the control of the brake actuators 26a, 26b, 26c and 26d and of the steering motors 24a and 24b. The control device systems 28a and 28b can each comprise a single control device which controls not only the steering function but also the brake function, or they each comprise a plurality of control devices which control the steering function and the brake function individually or in groups. For the sake of simplicity, one or more control devices are referred to as control device systems.
[0072] The control device system 28a is connected to the steering motor 24a on the right front wheel 20 and to the brake actuator 26a and to the brake actuator 26d on the left rear wheel 20, so that it can actuate these elements. In the drawing, these elements connected to one another are identified by uniform hatching.
[0073] The control device system 28b is connected to the steering motor 24b on the left front wheel 20 and to the brake actuator 26b and to the brake actuator 26c on the right rear wheel 20, in order to actuate these elements.
[0074] For the driving stability of the motor vehicle 10, it is important in critical situations to activate the brake actuators crosswise, that is to say to activate the front brake actuator on one side and the rear brake actuator on the other side. If the control device systems only actuate the brake actuators on one side or on one axle, the motor vehicle 10 can only be braked on one side in the event of a failure of the control device systems. This can lead to a skid of the motor vehicle in the worst case and possibly to a tragic accident.
[0075] The control device systems 28a and 28b are arranged in a control device unit 30. The control unit 30 can comprise a housing for the control device systems 28a and 28b, which protects the control device systems from damage due to physical influences, heat and / or moisture. Furthermore, the control device unit 30 can have a partition wall which divides the housing into two chambers and increases the protection for the control devices.
[0076] Each chamber is protected in itself against dangers such as fire, the ingress of moisture or even water and against physical influences. The division of the housing into chambers reduces the likelihood of both control device systems 28a and 28b failing at the same time due to external influences.
[0077] In Figure 1In the embodiment shown, the control device systems 28a and 28b share a common, but still redundantly constituted, logic circuit 32, which manipulates the control device systems. The logic circuit 32, in turn, obtains instructions from two computing units 34a and 34b.
[0078] The computing units 34a and 34b are likewise redundantly constituted, so that a failure of one of the computing units 34a, 34b can be compensated by the respective other computing unit or the control of the motor vehicle 10 can be taken over by the remaining computing unit.
[0079] The computing units 34a and 34b are also communicatively connected to one another. By means of this communication connection, the computing units 34a and 34b exchange information with one another as to which computing unit is producing which instructions. Thereby, it is possible to avoid contradictions of the instructions for the control device systems 28a and 28b. Furthermore, the computing units 34a and 34b can recognize from the response of the respective other computing unit whether a functional failure exists. If this is the case, the remaining computing unit 34a or 34b can take corresponding measures, such as generating a warning signal in a user interface of the motor vehicle 10.
[0080] The control device systems 28a and 28b are supplied with energy by energy supply units 36a and 36b. Energy is required not only for the operation of the control device systems 28a and 28b, but also for the operation or activation of the steering motors 24a and 24b and the brake actuators 26a, 26b, 26c, 26d.
[0081] In the embodiment shown, the control device systems 28a and 28b are supplied with energy by separate connections. The two control device systems 28a and 28b are connected to the energy supply units 36a and 36b in terms of energy by this connection. Thereby, the energy supply units 36a and 36b are also provided with redundancy, so that the driving function of the motor vehicle is continued even with restrictions in the event of a failure of one of the energy supply units 36a or 36b.
[0082] If a fault or a danger is detected in the system architecture, for example if one of the computing units 34a, 34b, one of the control device systems 28a, 28b or one of the energy supply units 36a, 36b is damaged or defective, the remaining system can bring the motor vehicle 10 to a safe stop. If the motor vehicle 10 has autonomous or semi-autonomous driving functions, the computing units 34a and 34b can be configured in such a way that they perform a minimum-risk maneuver in the event of damage and bring the motor vehicle 10 to a standstill at the roadside. Furthermore, the brake actuators 26a, 26b, 26c and / or 26d can be equipped with a parking brake function on at least two wheels 20, which is also activated in the event of damage and fixes the motor vehicle 10 against rolling away.
[0083] In Figure 2 an embodiment shown as an alternative to the embodiment shown in Figure 1 the system architecture of the motor vehicle 10 comprises two control device systems 28a and 28b in this embodiment, which are arranged in different control device units 30a and 30b. Each control device unit 30a and 30b has its own logic circuit 32a or 32b, wherein each of the logic circuits 32a and 32b is connected to a computing unit 34a and 34b.
[0084] Furthermore, each of the control device units 30a, 30b is connected in terms of energy to an energy supply unit 36a and 36b.
[0085] With this system architecture, although the infrastructure for the control device units 30a and 30b has to be provided twice. However, by the spatial separation of the control device units 30a and 30b and thus of the control device systems 28a and 28b, the likelihood of both control device units 30a and 30b being damaged at the same time due to influences from the outside is reduced.
[0086] In the event of a collision of the motor vehicle 10 with an obstacle, it is quite possible that individual systems are damaged and even fail. By the spatial separation of the control device systems 28a and 28b, the likelihood of both systems being damaged by the collision at the same time is less. Thus, even in the event of damage to the control device systems 28a, 28b, a minimum of driving ability of the motor vehicle 10 can be maintained.
Claims
1. System architecture for a motor vehicle (10) comprising a steering actuator (22) and comprising a brake actuator (26a, 26b, 26c, 26d) for each wheel (20) of the motor vehicle (10), wherein the steering actuator (22) comprises a first steering motor (24a) and a second steering motor (24b), wherein the system architecture comprises a first control device system (28a) and a second control device system (28b), wherein the first control device system (28a) is configured for actuating the first steering motor (24a) and at least two first brake actuators (26a, 26d), wherein the first brake actuators (26a, 26d) are assigned to wheels (20) of the motor vehicle (10) on two different vehicle sides (16, 18) of the motor vehicle (10) and on at least two different axles, wherein the second control device system (28b) is configured for actuating the second steering motor (24b) and at least two second brake actuators (26b, 26c), wherein the first brake actuators (26a, 26d) and the second brake actuators (26b, 26c) are arranged on a common axle and on two vehicle sides (16, 18) of the motor vehicle (10), respectively, wherein the first control device system (28a) and the second control device system (28b) are communicatively connected to each other by means of a logic circuit (32, 32a, 32b).
2. System architecture according to claim 1, wherein the first control device system (28a) is arranged in a first chamber of a control device unit (30) and the second control device system (28b) is arranged in a second chamber of the control device unit (30).
3. System architecture according to claim 2, wherein each chamber comprises a hazard sensor.
4. System architecture according to claim 1, wherein the control device systems (28a, 28b) are arranged in different control device units (30a, 30b).
5. System architecture according to claim 4, wherein the control device units (28a, 28b) are arranged in the motor vehicle (10) in a spatially separated manner from each other.
6. System architecture according to any of the preceding claims, wherein each control device system (28a, 28b) is connected in terms of energy to two independent energy supply units (36a, 36b), respectively.
7. System architecture according to any of the preceding claims, wherein each energy supply unit (36a, 36b) has a safety mechanism for disconnecting the energy connection.
8. System architecture according to any of the preceding claims, wherein each control device system (28a, 28b) is communicatively connected to two computing units (34a, 34b), wherein the computing units (34a, 34b) are configured for generating instructions for the control device systems (28a, 28b).
9. The system architecture according to any of the preceding claims, wherein the computing units (34a, 34b) are communicatively connected to each other and wherein the computing units (34a, 34b) are configured for matching the instructions generated thereby with each other.
10. The system architecture according to any of the preceding claims, wherein the system architecture comprises at least one hazard sensor, wherein the control device systems (28a, 28b) are configured for operating the steering actuators (22) and the brake actuators (26a, 26b, 26c, 26d) such that the vehicle (10) performs an emergency stop maneuver when the at least one hazard sensor detects a hazard.
11. The system architecture according to any of the preceding claims, wherein at least two of the brake actuators (26a, 26b, 26c, 26d) comprise a parking brake function, and wherein each control device system (28a, 28b) is configured for operating at least one of the brake actuators (26a, 26b, 26c, 26d) having a parking brake function.
12. The system architecture according to any of the preceding claims, wherein each steering motor (24a, 24b) comprises a rotor position sensor, wherein the control device systems (28a, 28b) are configured for reading the rotor position sensor of the steering motor (24a, 24b) they operate.
13. The system architecture according to any of the preceding claims, wherein the steering motors (24a, 24b) act onto a common rack, and wherein the rotor position detected with the rotor position sensor is continuously exchanged between the first control device system (28a) and the second control device system (28b).
Citation Information
Patent Citations
Mechatronic system architecture for fusion of a vehicle's steering and braking systems
DE102021206184A1