Fault-tolerant automated testing system and method for can network of electric power steering system
By introducing a CAN network fault-tolerant testing system into the electric power steering system, and by using a switch array and MCU controller to automatically inject and recover faults, the problem of CAN network fault tolerance testing in EPS was solved, and efficient and low-cost testing of multiple fault tolerance capabilities was achieved.
Patent Information
- Application Number
- CN202511509153.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-22
- Publication Date
- 2026-02-24
- Estimated Expiration
- 2045-10-22
AI Technical Summary
In the existing technology, it is difficult to automate the CAN network fault tolerance test of electric power steering (EPS) system, and traditional test methods are inefficient, costly, and have poor applicability, and cannot effectively verify the fast and slow recovery time of Busoff.
A CAN network fault-tolerant testing system for an electric power steering system is adopted, including a host computer module, a CAN fault-tolerant testing fixture, a programmable power supply, and a CAN-to-serial port module. Through a switch array composed of multiple controlled chip switches and relay switches, combined with an MCU controller, fault information is automatically injected and restored. Powered by the programmable power supply, multiple fault-tolerant tests are realized.
Automated fault-tolerant testing of the CAN network for electric power steering systems has been achieved, reducing testing equipment and manpower costs, improving testing applicability and comprehensiveness, and effectively evaluating Busoff fast and slow recovery times.
Smart Images

Figure CN121000634B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of CAN network testing technology, and in particular to an automated fault-tolerant testing system and method for an electric power steering system. Background Technology
[0002] EPS (Electric Power Steering) systems rely heavily on the vehicle's CAN message system to activate or deactivate the power steering function. Therefore, the reliability of the CAN network is of paramount importance, and its reliability must be fully verified before the EPS is delivered to the customer.
[0003] The reliability of a CAN network is mainly reflected in its communication characteristics and fault tolerance characteristics. When testing the fault tolerance of a CAN network, the traditional method requires manual injection of CAN faults using switching devices, followed by manual recovery. However, this method cannot verify the fault tolerance performance of the CAN network, especially the fast and slow recovery time of Busoff, and manual operation is inefficient. If a dedicated tool is used for testing, programming development is required for the test content and the dedicated tool. Not only are dedicated tools expensive, but programming development is also difficult, highly targeted, and has low applicability. Ultimately, this leads to problems such as high equipment and personnel costs, complex testing process, and poor applicability. Summary of the Invention
[0004] This invention provides a CAN network fault tolerance testing method and system for electric power steering systems to solve the technical problem that CAN network fault tolerance testing of EPS is difficult to automate.
[0005] In a first aspect, embodiments of the present invention provide a CAN network fault-tolerant testing system for an electric power steering system, comprising:
[0006] Host computer module, CAN fault-tolerant test fixture, programmable power supply and CAN to serial port module;
[0007] The host computer module is used to run the CAN fault-tolerant test script, generate and send test sequence messages containing test instructions;
[0008] The CAN fault-tolerant test fixture includes an MCU controller and a switch array electrically connected to the MCU controller. The switch array includes multiple controlled chip switches and relay switches.
[0009] The CAN fault-tolerant test fixture is connected to the host computer module via a CAN bus to receive the test sequence message. The MCU controller parses the message and controls the operation of multiple chip switches and relay switches in the switch array to inject fault information into the electric power steering system or restore fault information.
[0010] The CAN fault-tolerant test fixture is also equipped with a CAN interface for connecting to the electric power steering system. The CAN interface includes connection terminals corresponding to the power supply pin, ground pin, ignition signal pin and CAN bus pin of the electric power steering system, respectively. The switch array is electrically connected to the connection terminals and is used to inject fault information into the electric power steering system and receive the message reply from the electric power steering system.
[0011] The programmable power supply is electrically connected to the host computer module through the CAN-to-serial module. The host computer module sends serial port commands to the programmable power supply through the CAN-to-serial module to control the output of the programmable power supply.
[0012] The output terminal of the programmable power supply is connected to the power input terminal of the CAN fault-tolerant test fixture. The programmable power supply is used to supply power to the electric steering system through the power circuit inside the test fixture according to the instructions of the host computer module.
[0013] The host computer module is also used to receive the response sequence message from the electric power steering system when injecting or restoring fault information, and to generate fault tolerance test results according to preset detection standards.
[0014] Furthermore, the switch array includes:
[0015] The first chip switch S1 is used to generate a CANH open circuit fault.
[0016] The second chip switch S2 is used to create a short circuit fault between CANH and CANL.
[0017] The third chip switch S3 is used to generate a CANL open circuit fault.
[0018] The fourth chip switch S4 is used to control the EPS ignition power supply;
[0019] The fifth chip switch S5 is used to create a short circuit fault between CANL and power ground;
[0020] The sixth chip switch S6 is used to create a short circuit fault between CANH and power ground;
[0021] The seventh chip switch S7 is used to generate a short circuit fault between CANL and the positive power supply.
[0022] The eighth chip switch S8 is used to generate a short circuit fault between CANH and the positive power supply.
[0023] The ninth chip switch S9 is used to control the connection and disconnection of the CANL between the host computer module and the test fixture;
[0024] The tenth chip switch S10 is used to control the connection and disconnection of the CANH between the host computer module and the test fixture;
[0025] The first relay switch K1 is used to control the on / off state of the EPS ground wire;
[0026] The second relay switch K2 is used to control the on / off state of the programmable power supply ground wire;
[0027] The third relay switch K3 is used to control the on / off state of the positive terminal of the programmable power supply.
[0028] The fourth relay switch K4 is used to control the on / off state of the positive terminal of the EPS power supply.
[0029] Furthermore, the sixth chip switch S6 in the switch array is configured as follows:
[0030] In response to the first fault injection command issued by the host computer module, the system closes, generating continuous error frames on the CAN bus of the CAN fault-tolerant test fixture, inducing the CAN node of the electric power steering system to enter the Busoff state.
[0031] The MCU controller is also configured to automatically control the sixth chip switch S6 to disconnect after a preset recovery time has elapsed since the switch is closed, so as to restore normal CAN bus communication of the CAN fault-tolerant test fixture. The preset recovery time is configured by the host computer module through specific data bits in the test sequence message.
[0032] Furthermore, the host computer module and the CAN fault-tolerant testing fixture communicate using a preset communication protocol:
[0033] The host computer module sends a test sequence message with frame ID 0x601 to the CAN fault-tolerant test fixture. Each signal bit of the test sequence message is used to control the closing and opening of multiple switches in the switch array.
[0034] The CAN fault-tolerant test fixture replies to the host computer module with a reply sequence message with frame ID 0x611. Each signal bit of the reply sequence message is used to feed back the current status or fault injection result of multiple switches in the switch array.
[0035] The test sequence message is a CAN message with frame ID 0x601. Bits 56-63 of the test sequence message are specific data bits of an 8-bit signal used to configure the preset recovery time. When the value of this 8-bit signal is 0x01, 0x02 or 0x03, it represents a preset recovery time of 1 second, 2 seconds or 3 seconds respectively.
[0036] Furthermore, the system also includes:
[0037] A CAN interface card is used to electrically connect the host computer module to the CAN fault-tolerant test fixture.
[0038] The DC power module is used to supply power to the MCU controller of the CAN fault-tolerant test fixture.
[0039] Secondly, embodiments of the present invention provide a CAN network fault-tolerant testing method for an electric power steering system, including:
[0040] S101, Write and run a CAN fault tolerance test script in the host computer module. The CAN fault tolerance test script includes at least the Busoff fast and slow recovery time test item. According to the CAN fault tolerance test script, send multiple test sequence messages to the CAN fault tolerance test fixture in sequence and execute multiple CAN bus fault tolerance tests in sequence.
[0041] S102, the CAN fault-tolerant test fixture controls the operation of the switch array according to the received test sequence message, injects corresponding fault information or restores fault information into the CAN bus of the electric power steering system, and forms the corresponding fault state or restores the connection.
[0042] S103, the host computer module receives the EPS response information fed back by the CAN fault-tolerant test fixture, uses the written test script to analyze the CAN bus fault tolerance capability of the electric power steering system based on the EPS response information, and generates a CAN network fault tolerance test report for the electric power steering system.
[0043] Furthermore, the multiple CAN bus fault tolerance tests include:
[0044] Busoff fast and slow recovery time test, CANH open circuit fault test, CANH and CANL short circuit fault test, CANL open circuit fault test, CANL short circuit to ground fault test, CANH short circuit to ground fault test, CANL short circuit to power supply fault test, CANH short circuit to power supply fault test, power loss fault test, ground loss fault test.
[0045] Furthermore, the Busoff fast and slow recovery time test includes:
[0046] According to the Busoff fast and slow recovery time test item in the CAN fault tolerance test script, the Busoff fast and slow recovery time test sequence message is sent to the CAN fault tolerance test fixture, controlling the sixth chip switch S6 in the switch array to close, generating continuous error frames on the CAN bus of the CAN fault tolerance test fixture, and triggering the CAN node of the electric power steering system to enter the Busoff state.
[0047] According to the Busoff fast and slow recovery time test sequence message, the sixth chip switch S6 is automatically controlled to open after the preset recovery time is reached, so as to restore the normal communication of the CAN bus of the CAN fault tolerance test fixture.
[0048] Furthermore, the preset recovery time includes:
[0049] The test sequence message generated by the host computer module using the CAN fault tolerance test script is a CAN message with frame ID 0x601. Bits 56-63 in the message are specific data bits of an 8-bit signal, and their values are set to 0x01, 0x02 or 0x03.
[0050] The test sequence message is sent to the CAN fault-tolerant test fixture, which configures the preset recovery time to 1 second, 2 seconds, or 3 seconds based on the value of a specific data bit in the test sequence message.
[0051] Furthermore, the method also includes:
[0052] Multiple test sequence messages are generated according to various CAN bus fault tolerance tests, and sent to the CAN fault tolerance test fixture in sequence. The CAN fault tolerance test fixture controls multiple different switch combinations in the switch array to operate simultaneously according to the different test sequence messages received, so as to realize the fault state or connection recovery corresponding to different CAN bus fault tolerance test items.
[0053] This invention provides a CAN network fault-tolerant testing system and method for an electric power steering system. It utilizes a switch array composed of multiple controlled chip switches and relay switches, which, together with an MCU controller, forms a CAN fault-tolerant testing fixture. A programmable power supply powers the testing fixture and the EPS under test. A host computer module writes and runs test scripts, sending test sequence messages to the CAN fault-tolerant testing fixture. This controls the switch array within the fixture to create different on / off combinations, generating different physical fault types for corresponding fault tests. Feedback messages from the testing fixture and the EPS messages received from it are analyzed to determine the success and quality of the tests. This allows for automated testing of the EPS's CAN network fault tolerance capabilities. The test sequence messages control the fixture to form specific switch combinations, triggering a hardware fault that causes the EPS to enter a busoff state. Simultaneously, the fast and slow recovery times of the testing fixture are set, and the busoff fast and slow recovery times of the EPS are automatically tested based on the re-received EPS messages. It eliminates the need for dedicated testing tools and specialized programming for different test items. The testing fixture can be used for multiple tests, making it widely applicable. This reduces the difficulty of programming development and the equipment and manpower costs of testing, and allows for a more comprehensive test of the CAN network fault tolerance capability of EPS. Attached Figure Description
[0054] The accompanying drawings, which form part of this invention, are used to provide a further understanding of the invention. The illustrative embodiments of the invention and their descriptions are used to explain the invention and do not constitute an undue limitation of the invention. In the drawings:
[0055] Figure 1 This is a schematic diagram of the structure of a CAN network fault-tolerant automated testing system for an electric power steering system according to Embodiment 1 of the present invention;
[0056] Figure 2 This is a schematic diagram illustrating the communication method between the host computer module and the CAN fault-tolerant testing fixture as described in Embodiment 1 of the present invention;
[0057] Figure 3 This is a flowchart of an automated fault-tolerant testing method for an electric power steering system CAN network, as described in Embodiment 2 of the present invention.
[0058] Figure 4 This is a schematic diagram of multiple test procedures for the CAN network fault-tolerant automated testing of the electric power steering system according to Embodiment 2 of the present invention. Detailed Implementation
[0059] The present invention will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and not intended to limit it. Furthermore, it should be noted that, for ease of description, the accompanying drawings show only the parts relevant to the present invention, and not all of the structures.
[0060] Example 1
[0061] Figure 1 This is a schematic diagram of the CAN network fault-tolerant automated testing system for an electric power steering system according to Embodiment 1 of the present invention. This embodiment uses a CAN fault-tolerant testing fixture consisting of a switch array composed of multiple controlled chip switches and relay switches. A script on the host computer sends test sequence messages to the CAN fault-tolerant testing fixture, and the MCU controller controls the combined actions of multiple switches in the switch array to generate multiple physical faults to test the fault tolerance capability of the EPS. Specifically, this includes:
[0062] The system comprises a host computer module, a CAN fault-tolerant test fixture, a programmable power supply, and a CAN-to-serial converter module. The host computer module primarily provides test signals and inputs them to the CAN network fault-tolerant test fixture, enabling it to enter the corresponding test state and perform the appropriate tests. The input of the CAN fault-tolerant test fixture is communicatively connected to the host computer module, and its output is communicatively connected to the input of the electric power steering system (EPS) under test. Specifically, the CAN bus of the test fixture is communicatively connected to the CAN bus of the EPS under test. After the host computer sends test signals to the test fixture to enter the corresponding test state, the test fixture injects the corresponding test content into the EPS, testing the EPS's CAN bus. The programmable power supply powers the test fixture. The host computer is electrically connected to the programmable power supply via the CAN-to-serial converter module. The host computer is connected to the input of the CAN-to-serial converter module via the CAN bus, and the output of the CAN-to-serial converter module is communicatively connected to the programmable power supply, outputting serial control signals to control the programmable power supply to power the test fixture. For example, the programmable power supply can be an ITECH IT6512D DC power supply to provide a stable 12V power supply to the EPS, and the CAN-to-serial module can be a ZHIYUAN CANFDCOM-100IE module to convert the CAN control commands issued by the host computer into serial port commands that the programmable power supply can recognize. The object under test is an electric power steering system (EPS) controller that supports CAN or CAN FD communication.
[0063] The host computer module is used to run CAN fault-tolerant test scripts, generate and send test sequence messages containing test instructions. For example, the host computer module can be a PC with CANoe software installed. Test scripts can be developed through the CANoe platform. By running the test scripts, multiple test sequence messages corresponding to various test contents are generated and sent to the CAN fault-tolerant test fixture, which is then controlled to enter the corresponding test state and execute the corresponding test items.
[0064] The CAN fault-tolerant test fixture includes an MCU controller and a switch array electrically connected to the MCU controller. The switch array includes multiple controlled chip switches and relay switches. The structure of the CAN fault-tolerant test fixture is as follows: Figure 1As shown, by integrating a switch array including multiple controlled chip switches and relay switches, various physical fault states of the CAN bus are realized, and EPS is injected to test the CAN network fault tolerance capability of the EPS. The MCU controller in the test fixture parses the test sequence messages sent by the host computer and sends control signals to the switch array connected to it, controlling the operation of multiple chip switches and relay switches in the switch array to form the corresponding switch combination state for the test item, realizing the corresponding fault state. For example, the MCU controller can use the Renesas R7F70182 chip, the CAN communication interface can use the TI SN65HVD1040 chip to realize the communication connection between the MCU and the CAN bus, the chip switches in the switch array can use the TI MUX7612 multiplexer chip to achieve high-precision signal switching, and the relay switches can use the HF46F series relays from Hongfa (HF) to control the high-current power supply channel.
[0065] Specifically, the switch array includes:
[0066] The first chip switch S1 is used to generate a CANH open circuit fault.
[0067] The second chip switch S2 is used to create a short circuit fault between CANH and CANL.
[0068] The third chip switch S3 is used to generate a CANL open circuit fault.
[0069] The fourth chip switch S4 is used to control the EPS ignition power supply;
[0070] The fifth chip switch S5 is used to create a short circuit fault between CANL and power ground;
[0071] The sixth chip switch S6 is used to create a short circuit fault between CANH and power ground;
[0072] The seventh chip switch S7 is used to generate a short circuit fault between CANL and the positive power supply.
[0073] The eighth chip switch S8 is used to generate a short circuit fault between CANH and the positive power supply.
[0074] The ninth chip switch S9 is used to control the connection and disconnection of the CANL between the host computer module and the test fixture;
[0075] The tenth chip switch S10 is used to control the connection and disconnection of the CANH between the host computer module and the test fixture;
[0076] The first relay switch K1 is used to control the on / off state of the EPS ground wire;
[0077] The second relay switch K2 is used to control the on / off state of the programmable power supply ground wire;
[0078] The third relay switch K3 is used to control the on / off state of the positive terminal of the programmable power supply.
[0079] The fourth relay switch K4 is used to control the on / off state of the positive terminal of the EPS power supply.
[0080] like Figure 1 As shown, switches S1 and S3 are located on CANH and CANL of the test fixture's CAN bus, respectively, and are used to control the on / off state of CANH and CANL of the test fixture; the two ends of switch S2 are electrically connected to CANH and CANL of the test fixture, respectively, and are used to control the on / off state between CANH and CANL; the two ends of switch S4 are electrically connected to the ignition signal generator of the programmable power supply and the ignition signal receiving node of the EPS, respectively; the two ends of switch S5 are electrically connected to CANL and power ground of the test fixture, respectively; the two ends of switch S6 are electrically connected to CANH and power ground of the test fixture, respectively; the two ends of switch S7 are electrically connected to CANH and power ground of the test fixture, respectively. NL is electrically connected to the positive terminal of the power supply; the two ends of switch S8 are electrically connected to the CANH of the test fixture and the positive terminal of the power supply, respectively; the two ends of switch S9 are electrically connected to the CANL of the test fixture and the CAN communication control interface of the MCU, respectively; the two ends of switch S10 are electrically connected to the CANH of the test fixture and the CAN communication control interface of the MCU, respectively; the two ends of switch K1 are electrically connected to the ground terminal of the EPS and the negative terminal of the programmable power supply, respectively; the two ends of switch K2 are electrically connected to the ground terminal of the test fixture and the negative terminal of the programmable power supply, respectively; the two ends of switch K3 are electrically connected to the positive terminal of the test fixture and the positive terminal of the programmable power supply, respectively; the two ends of switch K4 are electrically connected to the positive terminal of the test fixture and the positive terminal of the EPS, respectively.
[0081] For example, by controlling S1, S3, S9, S10, K1, K2, K3, and K4 to close while the remaining switches are open, K1, K2, K3, and K4 closing provides power to the EPS, and S1, S3, S9, and S10 closing establishes a CAN connection between the host computer and the test fixture, and subsequently a CAN connection with the EPS, thus providing power to the EPS. By controlling S1, S3, S4, S9, S10, K1, K2, K3, and K4 to close while the remaining switches are open, power is supplied to the ignition terminal (KEY) of the EPS, controlling EPS ignition. By controlling S1, S3, S9, S10, K1, K2, K3, and K4 to close while the remaining switches are open, the ignition power supply to the EPS is turned off. By controlling S1, S3, S9, and S10 to close while the remaining switches are open, the power supply to the EPS is turned off.
[0082] By controlling the closure of switches S1, S3, S4, S6, K1, K2, K3, and K4, while keeping the other switches open, error frames are continuously generated on the CAN bus of the test fixture. This injects Busoff fault information into the EPS, causing the EPS's CAN node to enter the Busoff state. Based on the EPS's fast and slow recovery, the fault tolerance capability of the EPS's CAN network is tested.
[0083] By controlling S1, S3, S4, S8, S9, S10, K1, K2, K3, and K4 to close and the rest to open, or by controlling S1, S3, S4, S7, S9, S10, K1, K2, K3, and K4 to close and the rest to open, a fault state of CANH or CANL short-circuited to the power supply can be created and injected into the EPS. This is used to test the EPS's ability to recover from the CANH or CANL short-circuited to the power supply fault. Disconnecting S8 or S7 will restore the CANH and CANL short-circuited to the power supply fault.
[0084] By controlling S1, S3, S4, S6, S9, S10, K1, K2, K3, and K4 to close and the rest to open, or by controlling S1, S3, S4, S5, S9, S10, K1, K2, K3, and K4 to close and the rest to open, a fault state of CANH or CANL short-circuited to ground (GND) can be formed and injected into the EPS. This is used to test the fault recovery capability of the EPS when CANH or CANL is short-circuited to ground. Disconnecting S6 or S5 can restore the fault state of CANH and CANL short-circuited to ground.
[0085] By controlling S3, S9, S10, K1, K2, K3, and K4 to close and the rest to open, or by controlling S1, S4, S9, S10, K1, K2, K3, and K4 to close and the rest to open, an open circuit fault state of CANH or CANL can be formed and injected into the EPS. This is used to test the EPS's ability to recover from CANH or CANL open circuit faults. Closing S1 and S4 can recover from a CANH open circuit fault, and closing S3 can recover from a CANL open circuit fault.
[0086] By controlling S1, S3, S4, S9, S10, K1, K2, K3 to be closed while the others are open, or by controlling S1, S3, S4, S9, S10, K2, K3, K4 to be closed while the others are open, a power loss fault or a ground loss fault can be generated respectively. This is used to test the recovery capability of the EPS from power loss faults or ground loss faults. Closing K4 or closing K1 can restore the power loss fault or ground loss fault respectively.
[0087] The CAN fault-tolerant test fixture connects to a host computer module via a CAN bus to receive test sequence messages. The MCU controller parses these messages and controls the operation of multiple chip switches and relay switches in the switch array to inject or recover fault information from the electric power steering system. In the host computer, test scripts are written and run to generate test sequence messages, which are then sent to the CAN fault-tolerant test fixture via the CAN bus. Upon receiving the test sequence messages, the MCU controller parses them and, based on the parsing results, controls the operation of multiple chip switches and relay switches in the switch array to form different switch combinations. These combinations simulate different physical fault states and inject them into the EPS (Electric Power Steering) system, or recover from fault states, testing the fault tolerance capability of the EPS's CAN network for corresponding faults.
[0088] The CAN fault-tolerant test fixture also includes a CAN interface for connecting to the electric power steering system. The CAN interface includes connection terminals corresponding to the power supply pin, ground pin, ignition signal pin, and CAN bus pin of the electric power steering system. A switch array is electrically connected to the connection terminals to inject fault information into the electric power steering system and receive messages from the electric power steering system. For example, the test fixture has a CAN interface for connecting to the electric power steering system. The CAN interface includes a power input terminal (BAT+), a ground terminal (GND), an ignition signal terminal (IGN), and CANH and CANL terminals of the CAN bus, which are connected to the positive power supply pin and ground pin of the EPS respectively via wiring harnesses. The power input terminal of the test fixture is controlled by switch K4 to switch on / off with the BAT+ terminal of the EPS; the ground terminal of the test fixture is controlled by switch K1 to switch on / off with the GND terminal of the EPS; the ignition signal terminal of the test fixture is connected to the... The ignition signal input pin of the EPS is connected, and its connection to the programmable power supply output is controlled by switch S4. The CANH and CANL terminals of the test fixture are connected to the CANH and CANL pins of the EPS via wiring harnesses, respectively. Switch S1 is connected in series in the CANH circuit inside the test fixture to create a CANH open-circuit fault, and switch S10 is used to control the connection to the host computer. Switch S3 is connected in series in the CANL circuit inside the test fixture to create a CANL open-circuit fault, and switch S9 is used to control the connection to the host computer. Furthermore, switch S2 is connected in parallel between the CANH and CANL circuits inside the test fixture to create a short-circuit fault. Switches S8 and S6 are connected in parallel between the CANH circuit and the power supply positive / ground, respectively. Switches S7 and S5 are connected in parallel between the CANL circuit and the power supply positive / ground, respectively.
[0089] Optionally, the system further includes a CAN interface card for electrically connecting the host computer module to the CAN fault-tolerant test fixture. The host computer connects to the CAN fault-tolerant test fixture via the CAN interface card. For example, the CAN interface card can be a Vector VN1640A model, with its input connected to the host computer via USB and its output connected to the CAN fault-tolerant test fixture via a set of CAN buses (including CANH and CANL). The host computer sends the test sequence messages generated by the test script to the CAN fault-tolerant test fixture via the CAN interface card and receives the response messages from the test fixture.
[0090] The DC power module is used to supply power to the MCU controller of the CAN fault-tolerant test fixture. Since the CAN fault-tolerant test fixture needs to control its internal components based on received test sequence messages, especially since the MCU and other control cores require DC power, a separate DC power module is used to supply power to the control and switching devices inside the CAN fault-tolerant test fixture.
[0091] The programmable power supply (PPS) is electrically connected to the host computer module via a CAN-to-serial converter. The host computer module sends serial commands to the PPS via the CAN-to-serial converter to control its output. Since the host computer module sends test sequence messages or control commands via the CAN bus, and the information follows the CAN communication protocol, while the PPS's control signal receiver is a serial port (RS232), a CAN-to-serial converter is needed to establish communication between the host computer module and the PPS. This allows the CAN control commands sent by the host computer module to be converted into serial commands (such as SCPI commands) that the PPS can recognize, thereby controlling the PPS to supply power to the CAN fault-tolerant test fixture and the EPS system under test.
[0092] The output of the programmable power supply is connected to the power input of the CAN fault-tolerant test fixture. The programmable power supply powers the electric power steering system (EPS) through the internal power circuit of the test fixture according to instructions from the host computer module. For example, the positive output of the programmable power supply is electrically connected to the positive power input (BAT+) of the test fixture; the negative output of the programmable power supply is electrically connected to the ground input (GND) of the test fixture. Inside the test fixture, switches K2 (control ground) and K3 (control positive) are connected in series to the internal power bus. The positive terminal of the internal power bus is electrically connected to the power input terminal (BAT+) of the CAN interface of the test fixture via switch K4 to power the EPS, and also to the ignition signal terminal (IGN) of the CAN interface via switch S4 to provide an ignition signal to the EPS. All relay switches and chip switches are controlled by the MCU controller of the test fixture according to the test sequence messages sent by the host computer module. The remote control interface (such as RS232) of the programmable power supply is connected to the host computer module through a CAN-to-serial module. The host computer sends commands through the CAN bus, which are converted by the CAN-to-serial module and then sent to the programmable power supply. The programmable power supply realizes remote automatic control of output voltage, current and switch on / off according to the received commands.
[0093] The host computer module is also used to receive the response sequence messages from the electric power steering system when injecting or restoring fault information, and to generate fault-tolerant test results according to preset detection standards. During testing, a test sequence message is sent to the CAN fault-tolerant test fixture via a test script. After the test fixture forms the corresponding fault state and injects fault information into the electric power steering system, it sends feedback to the host computer module regarding whether the fault information injection was successful. The host computer module can determine whether the test was successful based on the received result. After restoring the fault state of the test fixture by sending a test sequence message to the CAN fault-tolerant test fixture, the response sequence message from the EPS system is received through the restored CAN fault-tolerant test fixture. Based on the time of re-receiving the EPS CAN message, combined with preset detection standards, it determines whether the EPS CAN network has been restored and whether the restoration time is qualified, and outputs the fault-tolerant test results for testers to refer to and verify the EPS quality. In actual testing, the operator only needs to connect the wiring harness plug of the EPS under test to the CAN interface of the test fixture, and connect the output end of the programmable power supply to the power input end of the test fixture. Subsequent test procedures, including power-on, ignition, fault injection, and result judgment, can be automatically executed by the test script in the host computer module, realizing automated testing capabilities.
[0094] Optionally, the sixth chip switch S6 in the switch array is configured as follows:
[0095] In response to the first fault injection command issued by the host computer module, the CAN bus is closed, generating continuous error frames on the CAN bus of the CAN fault-tolerant test fixture, inducing the CAN node of the electric power steering system to enter the Busoff state. To automate the testing of the EPS's Busoff fast and slow recovery time, when the sixth chip switch S6 is closed (at which point S1, S3, S4, K1, K2, K3, and K4 also need to be closed to provide the corresponding test environment), the CANH of the EPS is short-circuited to the power supply ground via the CANH of the test fixture, causing the CAN bus waveform to be disrupted and generating continuous error frames. At this time, the EPS's CAN controller continuously detects errors, and the error count keeps increasing (TEC>255, forcing the CAN controller to enter the Busoff state, the bus "isolates" the node to prevent further communication disruption), eventually entering the Busoff state and ceasing to send and receive messages.
[0096] The MCU controller is also configured to automatically disconnect the sixth chip switch S6 after a preset recovery time has elapsed since its closure, thus restoring normal CAN bus communication for the CAN fault-tolerant test fixture. The preset recovery time is configured by the host computer module using specific data bits in the test sequence message. Since the EPS automatically clears TEC&REC and exits Busoff to rejoin communication once the bus idle time is sufficiently long (≥128 consecutive 11 recessive bits) after entering Busoff state, the EPS continues to send its original Pending messages. Therefore, after the sixth chip switch S6 closes, the MCU controller of the test fixture starts a timer of corresponding duration based on the value of a specific data bit in the test sequence message. When the timer expires, the MCU automatically controls the sixth chip switch S6 to open, removing the fault and restoring the normal physical state of the CAN bus, i.e., automatically disconnecting it after the preset recovery time has elapsed. At this time, the host computer module can continue to monitor the CAN bus through the test script and determine whether the EPS's Busoff fast / slow recovery time test is qualified based on the time of the re-received EPS message.
[0097] One optional implementation of this embodiment is as follows: Figure 2 As shown, the host computer module and the CAN fault-tolerant testing fixture communicate using a preset communication protocol:
[0098] The host computer module sends a test sequence message with frame ID 0x601 to the CAN fault-tolerant test fixture. Each signal bit in this test sequence message is used to control the closing and opening of multiple switches in the switch array. After writing and running a test script on the CANoe platform in the host computer module, the test script sends a test sequence message to the CAN fault-tolerant test fixture with frame ID 0x601, a message period of 10ms, and a message frame format of Intel's CAN message. Different signal bits in the test sequence message are used to control different switches in the switch array, and different switch combinations are used to achieve different fault states and perform different fault tests. For example, the signal content sent by the host computer module to the CAN fault-tolerant test fixture through the test script is shown in Table 1.
[0099] Table 1. Signal content sent by the test script to the CAN fault-tolerant test fixture
[0100]
[0101] The CAN fault-tolerant test fixture replies to the host computer module with a reply sequence message of frame ID 0x611. Each signal bit of this reply sequence message is used to feedback the current state of multiple switches in the switch array or the fault injection result. After the corresponding fault state is formed and EPS is injected in the test fixture, the test fixture will send a reply sequence message to the host computer module to indicate whether the injection was successful. This message has a frame ID of 0x611, a message period of 10ms, and a message frame format of Intel. Different signal bits in the reply sequence message are used to feedback different fault injection results, thereby determining whether the corresponding fault test was successfully executed. For example, the signal content fed back by the CAN fault-tolerant test fixture to the host computer module is shown in Table 2.
[0102] Table 2. Signal content fed back from the CAN fault-tolerant test fixture to the host computer module
[0103]
[0104] The test sequence message is a CAN message with frame ID 0x601. Bits 56-63 of the test sequence message are specific data bits of an 8-bit signal used to configure the preset recovery time. When the value of this 8-bit signal is 0x01, 0x02 or 0x03, it represents a preset recovery time of 1 second, 2 seconds or 3 seconds respectively.
[0105] When performing EPS busoff fast and slow recovery tests, 8 specific data bits (bits 56-63) of the test sequence message are used to configure the busoff fast and slow recovery time. The ability to automatically recover and the duration of the fast or slow recovery can be used to test the EPS's recovery capability from a busoff fault state. Different automatic recovery times can be set using the value of these 8 specific data bits to perform tests of different standards. Setting the value of these 8 specific data bits to 0x01, 0x02, or 0x03 indicates an automatic recovery time of 1 second, 2 seconds, or 3 seconds, respectively. By analyzing the time interval between the EPS fast recovery and slow recovery messages within this set automatic recovery time, and the final recovery result, the EPS's busoff fast and slow recovery capability can be automatically tested.
[0106] This embodiment uses a switch array composed of multiple controlled chip switches and relay switches, and forms a CAN fault-tolerant test fixture with an MCU controller. A programmable power supply powers the test fixture and the EPS under test. A host computer module writes and runs test scripts, sending test sequence messages to the CAN fault-tolerant test fixture. This controls the switch array within the test fixture to create different on / off combinations, generating different physical fault types for corresponding fault tests. Feedback messages from the test fixture and the EPS messages returned by the fixture are analyzed to determine if the tests were successfully performed and if the results are satisfactory. This allows for automated testing of the EPS's CAN network's fault tolerance capabilities. The test fixture can be controlled via test sequence messages to form specific switch combinations, triggering a hardware fault that causes the EPS to enter a busoff state. Simultaneously, the automatic recovery time of the test fixture can be set, and the busoff recovery time of the EPS can be automatically tested based on the re-received EPS messages. It eliminates the need for dedicated testing tools and specialized programming for different test items. The testing fixture can be used for multiple tests, making it widely applicable. This reduces the difficulty of programming development and the equipment and manpower costs of testing, and allows for a more comprehensive test of the CAN network fault tolerance capability of EPS.
[0107] Example 2
[0108] Figure 2 This is a flowchart of a CAN network fault tolerance testing method for an electric power steering system according to Embodiment 2 of the present invention. The method described in this embodiment is used in the CAN network fault tolerance testing system of the above-mentioned electric power steering system. In this embodiment, a CAN fault tolerance test script is written and run in the host computer module to control the CAN fault tolerance test fixture to inject faults into the EPS under test, and the CAN network fault tolerance capability of the EPS is tested according to the corresponding fault recovery situation. Specifically, it includes the following process:
[0109] S101, writes and runs a CAN fault tolerance test script in the host computer module. The CAN fault tolerance test script includes at least the Busoff fast and slow recovery time test item, and sends multiple test sequence messages to the CAN fault tolerance test fixture in sequence according to the CAN fault tolerance test script, and performs multiple CAN bus fault tolerance tests in sequence.
[0110] The host computer module can be a PC. Using the installed CANoe software platform (version 12.0), a CAN fault-tolerant test script is written based on the test items to be tested. The fault-tolerant test script can generate test sequence messages sequentially according to the corresponding test items, test content, and test order, and send them to the CAN fault-tolerant test fixture via the CAN bus. The test fixture parses the test sequence messages and controls the aforementioned switch array to form different switch combinations, creating fault states corresponding to the test items to be tested, thus testing the fault tolerance capability of the EPS's CAN network (nodes / controllers). The CAN fault-tolerant test script must include at least the Busoff fast and slow recovery time test item. Due to the fast and slow recovery characteristics (including fast and slow recovery) of EPS and Busoff states, using dedicated testing tools and targeted programming development not only faces the high cost of dedicated tools but also the poor applicability of targeted programming development, resulting in high testing costs. Therefore, by using a CAN fault-tolerant testing fixture that can not only test Busoff fast and slow recovery times but also has other testing functions, and writing matching CAN fault-tolerant test scripts, we can achieve automated testing of the CAN network fault tolerance capabilities of multiple EPS, including Busoff fast and slow recovery times. This can effectively improve the applicability and comprehensiveness of EPS testing, reduce testing costs, and simplify the testing process.
[0111] Specifically, multiple CAN bus fault tolerance tests include: Busoff fast and slow recovery time test, CANH open circuit fault test, CANH and CANL short circuit fault test, CANL open circuit fault test, CANL short circuit to ground fault test, CANH short circuit to ground fault test, CANL short circuit to power supply fault test, CANH short circuit to power supply fault test, power loss fault test, and ground loss fault test.
[0112] When performing multiple CAN bus fault tolerance tests, such as Figure 4 As shown, these are the test items that can be performed sequentially using a CAN fault-tolerant test fixture and a CAN fault-tolerant test script. Each test item is performed independently, and the next test item will only begin after the previous one has been completely completed. The test script can receive the test result of the previous test item and then send the test sequence message for the next test item, thus controlling the CAN fault-tolerant test fixture to perform the above test items independently and sequentially.
[0113] Optionally, multiple test sequence messages are generated according to the various CAN bus fault tolerance tests, and sent to the CAN fault tolerance test fixture in sequence. The CAN fault tolerance test fixture controls multiple different switch combinations in the switch array to operate simultaneously according to the different test sequence messages received, so as to realize the fault state or connection recovery corresponding to different CAN bus fault tolerance test items.
[0114] For example, the test sequence messages generated by the test script for different test items are shown in Table 3:
[0115] Table 3 Test sequence messages generated by the test script for different test items
[0116]
[0117] The test procedure for each test item is as follows: Figure 4 As shown in the flowchart on the right, different CAN fault injections and CAN fault recovery are performed according to different test items. At the beginning of each test item, the programmable power supply needs to be turned on to supply power to the EPS and the ignition (KEY) power supply to the EPS is used to ignite the EPS. After ignition, the EPS ignition power supply is turned off. Then the corresponding test item can be started. The switch array is controlled to form the corresponding fault state and recover the fault state. After receiving the message returned by the EPS through the CAN fault tolerance test fixture, the EPS ignition power supply is turned off to end one test.
[0118] S102, the CAN fault-tolerant test fixture controls the switch array to operate according to the received test sequence message, injecting corresponding fault information or restoring fault information into the CAN bus of the electric power steering system, forming the corresponding fault state or restoring the connection.
[0119] During testing, the CAN fault-tolerant testing fixture receives different test sequence messages. After being parsed by the MCU controller, it controls different switch array actions. First, it performs pre-test preparation, including controlling EPS power supply and ignition based on the received messages. Then, based on the received messages, it forms the corresponding fault state of the test item through different switch combinations and injects the corresponding fault information into the EPS's CAN bus (node / controller). Next, based on the received test sequence messages again, it restores the CAN bus connection, receives EPS messages, and determines and generates test results. Finally, based on the last received test sequence message, it shuts off the power supply to end this test process.
[0120] For example, when performing a CANH short circuit to power failure test, the test script first uses a CAN message to control the programmable power supply to output 12V voltage through the CAN to serial port module. At this time, the CAN fault-tolerant test fixture replies with a 01 01 00 00 0000 03 00 message, indicating that the 1640A, EPS and the test fixture CAN connection are normal.
[0121] Then, a message 01 01 06 03 00 00 03 00 is sent to the test fixture to control the EPS BAT power supply. At this time, the test fixture controls S1, S3, S9, S10, K1, K2, K3, and K4 to close according to the message, and the other switches to open. The programmable power supply supplies power to the EPS power supply through the test fixture. The test fixture replies with a message 01 01 06 03 00 00 03 06 to indicate that the programmable power supply has supplied power to the EPS power supply.
[0122] Then, a message 01 01 07 03 00 00 03 00 is sent to the test fixture to control the EPS ignition (KEY) power supply. At this time, the test fixture controls S1, S3, S4, S9, S10, K1, K2, K3, and K4 to close according to the message, and the other switches to open. The programmable power supply supplies power to the EPS ignition through the test fixture. The test fixture replies with a message 01 01 07 03 00 00 03 07 to indicate that the programmable power supply has supplied power to the EPS ignition.
[0123] Then, a 05 01 07 03 00 00 03 00 message is sent to the test fixture to perform a CANH short-circuit to power supply fault test. At this time, the test fixture controls S1, S3, S4, S8, S9, S10, K1, K2, K3, and K4 to close according to the message, while the other switches are opened. The test fixture is controlled to short-circuit CANH to BAT to form a CANH short-circuit to power supply fault and inject EPS. The test fixture replies with a 05 01 07 03 00 00 03 03 message to indicate that it has short-circuited to the power supply BAT.
[0124] Then, a 01 01 07 03 00 00 03 00 message is sent to the test fixture to perform fault recovery. At this time, the test fixture controls S1, S3, S4, S9, S10, K1, K2, K3, and K4 to close according to the message, while the other switches are opened. This controls the test fixture to restore the normal connection between the 1640A, EPS, and the test fixture CAN, and controls the programmable power supply to continue supplying power to the EPS and ignition. The test fixture replies with a 01 01 07 03 00 00 03 07 message, indicating that the normal connection between the 1640A, EPS, and the test fixture CAN has been restored. It continues to control the programmable power supply to continue supplying power to the EPS and ignition. At this time, the test result for this test can be generated based on the time when the EPS CAN message is received again.
[0125] Then, a message 01 01 00 00 00 00 03 00 is sent to the test fixture to shut off the power supply. At this time, the test fixture controls S1, S3, S9, and S10 to close and the other switches to open according to the message. It controls the programmable power supply to shut off the EPS power supply and ignition power supply. The test fixture replies with a message 01 01 00 00 00 00 03 03 to confirm that the programmable power supply has been shut off the EPS power supply and ignition power supply, thus ending this test procedure. Only then can the next test procedure be completed.
[0126] An optional implementation of this embodiment is that the Busoff fast and slow recovery time test includes:
[0127] According to the Busoff fast and slow recovery time test item in the CAN fault tolerance test script, the Busoff fast and slow recovery time test sequence message is sent to the CAN fault tolerance test fixture. The sixth chip switch S6 in the control switch array is closed, and the CANH signal line is shorted to the power ground. A continuous error frame is generated on the CAN bus of the CAN fault tolerance test fixture, triggering the CAN node of the electric power steering system to enter the Busoff state.
[0128] By running the Busoff fast and slow recovery time test in the CAN fault tolerance test script, a fault can be generated in the test fixture by sending a Busoff fast and slow recovery time test sequence message to the test fixture, causing the test fixture to short-circuit the CANH signal line with the power ground, thus inducing the CAN node of the EPS to enter the Busoff state. Based on the situation of receiving the EPS message again, it can be determined whether the Busoff fast and slow recovery time of the EPS is qualified, and then the fault tolerance capability of the EPS CAN network can be tested.
[0129] For example, Busoff fast and slow recovery time tests include:
[0130] Power Supply and Connection Establishment: The test script first sends a 01 01 06 03 00 00 03 00 message. The test fixture MCU parses this message and controls switches S1, S3, S9, S10, K1, K2, K3, and K4 to close, while the remaining switches open. At this time, the programmable power supply begins to supply power to the EPS, and the CAN bus path between the 1640A and the EPS is established. The test fixture then replies with a 01 01 06 03 0000 03 06 message indicating that the programmable power supply has supplied power to the EPS.
[0131] Ignition Power Supply: The test script sends the 01 01 07 03 00 00 03 00 message again. The test fixture keeps the S4 control closed, supplying power to the EPS ignition (KEY). The EPS ignition starts and begins communicating with the host computer via the CAN bus. At this time, the test fixture replies with the 01 01 07 03 00 00 03 07 message, indicating that the programmable power supply has provided ignition power to the EPS.
[0132] Busoff Injection Fault: The test script resends the 09 01 07 03 00 00 00 03 message. After parsing, the test fixture MCU controls S6 to remain closed, while keeping S1, S3, S4, S9, S10, K1, K2, K3, and K4 closed, and other switches open. At this time, the EPS's CANH line is shorted to power ground, the CAN bus waveform is corrupted, and continuous error frames are generated.
[0133] Triggering and Timing: When the EPS's CAN controller continuously detects errors, it enters a Busoff state. At this time, the EPS attempts to recover the CAN bus by sending messages to the CAN bus. The test script in the host computer module starts timing at the same time as sending the injected fault command and monitors the interval between the EPS's recovery attempts to confirm the number of Busoff recovery attempts and the time interval.
[0134] According to the Busoff fast and slow recovery time test sequence message, the sixth chip switch S6 is automatically controlled to open after the preset recovery time is reached, so as to restore the normal communication of the CAN bus of the CAN fault tolerance test fixture.
[0135] After S6 is closed, the MCU controller of the test fixture starts a timer for a corresponding duration based on the value of a specific data bit (BusoffRecover field) in the Busoff fast / slow recovery time test sequence message (e.g., a value of 0x03 indicates a timer of 3 seconds). After the timer expires, the MCU automatically controls S6 to open, removing the fault state where CANH was shorted to power ground. At this time, the test fixture replies with a message 01 01 07 03 00 00 03 07, indicating the restoration of normal CAN connections between the 1640A and EPS, and between the CAN bus and the test fixture board, thus restoring the physical state of the CAN bus to normal. The test script in the host computer module continuously monitors the CAN bus, and starts timing once a message is received from the EPS. The time interval obtained from this timing (from the injection of the fault to the re-receipt of the EPS message) is the Busoff fast / slow recovery time. The test script can compare this time with the required pass / fail standard and record the Busoff fast / slow recovery time test result as "pass" or "fail" in the test report. The criteria for determining whether the EPS fast and slow recovery tests are qualified can be as follows: Fast recovery time: the interval between sending to the CAN bus is relatively short, generally 50ms, and the number of times is 5; Slow recovery time: the interval between sending to the CAN bus is relatively long, generally 200ms. This is because after the EPS enters the Busoff state, it first quickly sends CAN messages to the CAN bus, which is called fast recovery. After a certain number of times (generally 5 times), the time interval between sending is lengthened, which is called slow recovery. According to the required requirements, the corresponding fast recovery time, fast recovery count, and slow recovery time are tested. At this point, the test script still needs to send a 01 01 00 00 00 00 03 00 message to control the switches K1, K2, K3, K4, and S4 of the test fixture to disconnect, cutting off the power supply to the EPS. The test fixture then replies with a 01 01 0000 00 00 03 03 message, indicating that the programmable power supply has been turned off to power the EPS and ignition, while maintaining the CAN connection between the 1640A and the EPS, and the CAN connection between the 1640A and the test fixture board. This test procedure then ends, and preparations are made for the next test.
[0136] Optional, preset recovery times include:
[0137] The test sequence message generated by the host computer module using the CAN fault tolerance test script is a CAN message with frame ID 0x601. Bits 56-63 in the message are specific data bits of an 8-bit signal, and their values are set to 0x01, 0x02 or 0x03.
[0138] In the test sequence message generated by the CAN fault-tolerant test script, bits 56-63 are specific data bits of an 8-bit signal, namely the BusoffRecover field. The value of this field is used to set a timer for automatic recovery to normal status. Specifically, this field's value configures a timer that, upon the timer's expiration, controls a specified switch action, ending the fault state of the CAN network test fixture and restoring normal CAN communication between the EPS and the host computer module test script via the test fixture. This value can be set to 0x01, 0x02, or 0x03, or, depending on requirements, to target values such as 0x05 or 0x10 that need to be tested.
[0139] The test sequence message is sent to the CAN fault-tolerant test fixture. The CAN fault-tolerant test fixture configures the preset recovery time to 1 second, 2 seconds or 3 seconds according to the value of a specific data bit in the test sequence message.
[0140] After the CAN fault-tolerant test script sends the above test sequence message to the CAN fault-tolerant test fixture, the MCU of the test fixture parses the message and configures the timer's timing interval based on the value of specific data bits 56-63 (i.e., the BusoffRecover field). Depending on the value of 0x01, 0x02, or 0x03, the timer's timing interval is configured to 1 second, 2 seconds, or 3 seconds respectively, which is the preset automatic recovery time. It can also be set to target values such as 0x05 or 0x10 as needed, correspondingly configuring the timer's timing interval to 5 seconds, 10 seconds, etc.
[0141] S103, the host computer module receives the EPS response information fed back by the CAN fault-tolerant test fixture, uses the written test script to analyze the CAN bus fault tolerance capability of the electric power steering system based on the EPS response information, and generates a CAN network fault tolerance test report for the electric power steering system.
[0142] After each test, the test script of the host computer module will determine the test results based on the response information received from the EPS (message recovery time, content, etc.), analyze the CAN bus fault tolerance capability (recovery capability) of the EPS system based on the results of whether each test is qualified, and finally generate a complete test report to comprehensively evaluate the CAN network fault tolerance performance of the EPS for testers to refer to and verify the quality of the EPS.
[0143] This embodiment involves writing and running CAN fault-tolerant test scripts on a host computer to send multiple test sequence messages corresponding to various tests to the CAN fault-tolerant test fixture. Multiple CAN bus fault-tolerant tests are executed independently and sequentially. Based on the received test sequence messages, the CAN fault-tolerant test fixture controls the switch array to either establish a fault state corresponding to each test item or terminate the corresponding fault state to restore normal communication. The test results are then determined based on the re-received EPS response information, analyzing whether each test is qualified and ultimately generating a comprehensive test report evaluating the CAN network fault-tolerant performance of the EPS. This allows the CAN fault-tolerant test fixture to be used for multiple tests, comprehensively testing the CAN network fault-tolerant capability of the EPS through sequentially executed independent tests. This ensures the broad adaptability of the test fixture, reduces programming development difficulty, and lowers equipment and manpower costs for testing.
[0144] Note that the above description is merely a preferred embodiment of the present invention and the technical principles employed. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and various obvious changes, readjustments, and substitutions can be made without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments, and may include many other equivalent embodiments without departing from the concept of the present invention, the scope of which is determined by the scope of the appended claims.
Claims
1. A CAN network fault-tolerant automated testing system for an electric power steering system, characterized in that, include: Host computer module, CAN fault-tolerant test fixture, programmable power supply and CAN to serial port module; The host computer module is used to run the CAN fault-tolerant test script, generate and send test sequence messages containing test instructions; The CAN fault-tolerant test fixture includes an MCU controller and a switch array electrically connected to the MCU controller. The switch array includes multiple controlled chip switches and relay switches. The CAN fault-tolerant test fixture is connected to the host computer module via a CAN bus to receive the test sequence message. The MCU controller parses the message and controls the operation of multiple chip switches and relay switches in the switch array to inject fault information into the electric power steering system or restore fault information. The CAN fault-tolerant test fixture is also equipped with a CAN interface for connecting to the electric power steering system. The CAN interface includes connection terminals corresponding to the power supply pin, ground pin, ignition signal pin and CAN bus pin of the electric power steering system, respectively. The switch array is electrically connected to the connection terminals and is used to inject fault information into the electric power steering system and receive the message reply from the electric power steering system. The programmable power supply is electrically connected to the host computer module through the CAN-to-serial module. The host computer module sends serial port commands to the programmable power supply through the CAN-to-serial module to control the output of the programmable power supply. The output terminal of the programmable power supply is connected to the power input terminal of the CAN fault-tolerant test fixture. The programmable power supply is used to supply power to the electric steering system through the power circuit inside the test fixture according to the instructions of the host computer module. The host computer module is also used to receive the response sequence message of the electric steering system when injecting or restoring fault information in the electric steering system, and generate fault tolerance test results according to the preset detection standards. The sixth chip switch S6 in the switch array is configured as follows: In response to the first fault injection command issued by the host computer module, the system closes, generating continuous error frames on the CAN bus of the CAN fault-tolerant test fixture, inducing the CAN node of the electric power steering system to enter the Busoff state. The MCU controller is also configured to automatically control the sixth chip switch S6 to disconnect after the sixth chip switch S6 is closed for a preset recovery time, so as to restore the normal communication of the CAN bus of the CAN fault-tolerant test fixture. The preset recovery time is configured by the host computer module through specific data bits in the test sequence message. The host computer module and the CAN fault-tolerant testing fixture communicate using a preset communication protocol. The host computer module sends a test sequence message with frame ID 0x601 to the CAN fault-tolerant test fixture. Each signal bit of the test sequence message is used to control the closing and opening of multiple switches in the switch array. The CAN fault-tolerant test fixture replies to the host computer module with a reply sequence message with frame ID 0x611. Each signal bit of the reply sequence message is used to feed back the current status or fault injection result of multiple switches in the switch array. The test sequence message is a CAN message with frame ID 0x601. Bits 56-63 of the test sequence message are specific data bits of an 8-bit signal used to configure the preset recovery time. When the value of this 8-bit signal is 0x01, 0x02 or 0x03, it represents a preset recovery time of 1 second, 2 seconds or 3 seconds respectively.
2. The CAN network fault-tolerant automated testing system for the electric power steering system according to claim 1, characterized in that, The switch array includes: The first chip switch S1 is used to generate a CANH open circuit fault. The second chip switch S2 is used to create a short circuit fault between CANH and CANL. The third chip switch S3 is used to generate a CANL open circuit fault. The fourth chip switch S4 is used to control the EPS ignition power supply; The fifth chip switch S5 is used to create a short circuit fault between CANL and power ground; The sixth chip switch S6 is used to create a short circuit fault between CANH and power ground; The seventh chip switch S7 is used to generate a short circuit fault between CANL and the positive power supply. The eighth chip switch S8 is used to generate a short circuit fault between CANH and the positive power supply. The ninth chip switch S9 is used to control the connection and disconnection of the CANL between the host computer module and the test fixture; The tenth chip switch S10 is used to control the connection and disconnection of the CANH between the host computer module and the test fixture; The first relay switch K1 is used to control the on / off state of the EPS ground wire; The second relay switch K2 is used to control the on / off state of the programmable power supply ground wire; The third relay switch K3 is used to control the on / off state of the positive terminal of the programmable power supply. The fourth relay switch K4 is used to control the on / off state of the positive terminal of the EPS power supply.
3. The CAN network fault-tolerant automated testing system for the electric power steering system according to claim 1, characterized in that, The system also includes: A CAN interface card is used to electrically connect the host computer module to the CAN fault-tolerant test fixture. The DC power module is used to supply power to the MCU controller of the CAN fault-tolerant test fixture.
4. An automated test method for CAN network fault tolerance of an electric power steering system used in an automated test system for CAN network fault tolerance of an electric power steering system as described in any one of claims 1-3, characterized in that, include: S101, Write and run a CAN fault tolerance test script in the host computer module. The CAN fault tolerance test script includes at least the Busoff fast and slow recovery time test item. According to the CAN fault tolerance test script, send multiple test sequence messages to the CAN fault tolerance test fixture in sequence and execute multiple CAN bus fault tolerance tests in sequence. S102, the CAN fault-tolerant test fixture controls the operation of the switch array according to the received test sequence message, injects corresponding fault information or restores fault information into the CAN bus of the electric power steering system, and forms the corresponding fault state or restores the connection. S103, the host computer module receives the EPS response information fed back by the CAN fault-tolerant test fixture, uses the written test script to analyze the CAN bus fault tolerance capability of the electric power steering system based on the EPS response information, and generates a CAN network fault tolerance test report for the electric power steering system. The Busoff fast and slow recovery time test includes: According to the Busoff fast and slow recovery time test item in the CAN fault tolerance test script, the Busoff fast and slow recovery time test sequence message is sent to the CAN fault tolerance test fixture, controlling the sixth chip switch S6 in the switch array to close, generating continuous error frames on the CAN bus of the CAN fault tolerance test fixture, and triggering the CAN node of the electric power steering system to enter the Busoff state. According to the Busoff fast and slow recovery time test sequence message, the sixth chip switch S6 is automatically controlled to open after the preset recovery time is reached, so as to restore the normal communication of the CAN bus of the CAN fault tolerance test fixture. The preset recovery time includes: The test sequence message generated by the host computer module using the CAN fault tolerance test script is a CAN message with frame ID 0x601. Bits 56-63 in the message are specific data bits of an 8-bit signal, and their values are set to 0x01, 0x02 or 0x03. The test sequence message is sent to the CAN fault-tolerant test fixture, which configures the preset recovery time to 1 second, 2 seconds, or 3 seconds based on the value of a specific data bit in the test sequence message.
5. The method according to claim 4, characterized in that, The multiple CAN bus fault tolerance tests include: Busoff fast and slow recovery time test, CANH open circuit fault test, CANH and CANL short circuit fault test, CANL open circuit fault test, CANL short circuit to ground fault test, CANH short circuit to ground fault test, CANL short circuit to power supply fault test, CANH short circuit to power supply fault test, power loss fault test, ground loss fault test.
6. The method according to claim 4, characterized in that, The method further includes: Multiple test sequence messages are generated according to various CAN bus fault tolerance tests, and sent to the CAN fault tolerance test fixture in sequence. The CAN fault tolerance test fixture controls multiple different switch combinations in the switch array to operate simultaneously according to the different test sequence messages received, so as to realize the fault state or connection recovery corresponding to different CAN bus fault tolerance test items.
Citation Information
Patent Citations
Automatic vehicle-mounted electronic control unit CAN bus communication testing device and system
CN104298224A
Automobile CAN communication fault test system, method and device and storage medium
CN113259209A