Vehicle system fault diagnosis method, controller and vehicle system
By using data comparison and diagnostic techniques between controllers, the increased system complexity and cost caused by fault-tolerant redundancy methods are resolved, achieving comprehensive detection of vehicle system faults and high safety integrity.
Patent Information
- Application Number
- CN202410706592.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-31
- Publication Date
- 2025-12-02
AI Technical Summary
While ensuring a high level of safety integrity, existing vehicle systems employ fault-tolerant redundancy methods that increase system complexity and cost, and cannot cover all fault types, thus affecting normal system operation.
Fault detection is performed by comparing diagnostic data collected by the first and second controllers in the vehicle system. This includes software comparison, test mode diagnosis, and output monitoring diagnostic techniques, thereby improving the system's diagnostic coverage and safety integrity.
It enables comprehensive detection of various types of faults in the vehicle system, ensuring a high level of safety integrity and reducing system complexity and cost.
Smart Images

Figure CN121050221A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of system security, and in particular to a vehicle system fault diagnosis method, controller, and vehicle system. Background Technology
[0002] With the increasing speed and intelligence of train operation technology, the number and types of signals processed by train control systems are constantly increasing, and the possibility of system failures is also increasing. Therefore, system safety needs to be enhanced, requiring comprehensive fault detection to take measures to ensure normal system operation in the event of a fault. Currently, to ensure a safety integrity level (SIL) of SIL 3 or SIL 4, fault-tolerant redundancy methods are commonly used. These methods enable the controller to detect faults in software or hardware components and maintain normal system operation. SIL 3 and SIL 4 represent higher safety integrity levels, and fault-tolerant redundancy methods include hardware redundancy, software redundancy, and communication redundancy.
[0003] However, the aforementioned fault-tolerant redundancy methods require the deployment of a large amount of hardware redundancy, software redundancy, and communication redundancy in the system, which increases the system cost and complexity. Furthermore, fault-tolerant redundancy methods usually cannot cover all types of faults in the system, thus failing to detect the occurrence of certain faults and affecting the normal operation of the system. Summary of the Invention
[0004] This application discloses a vehicle system fault diagnosis method, controller, and vehicle system. The first controller in the vehicle system, which is dedicated to fault detection, performs fault detection by comparing diagnostic data collected by the first controller and the second controller. This can improve the diagnostic coverage of the system, perform comprehensive detection of various types of faults in the vehicle system, and ensure that the vehicle system has a high level of safety integrity.
[0005] In a first aspect, this application provides a vehicle system fault diagnosis method. The vehicle system includes a main controller, a first controller, and a second controller, wherein the main controller, the first controller, and the second controller are communicatively connected. The method includes: the first controller sending a diagnostic request to the second controller, so that the second controller obtains diagnostic data according to the diagnostic request; the first controller performing fault diagnosis based on the first data and the diagnostic data received from the second controller or the main controller; and if the first data and the diagnostic data are different, the first controller determining that there is a fault in the vehicle system.
[0006] In the above process, the first controller sends a diagnostic request to the second controller to receive diagnostic data sent by the second controller or the main controller, and performs fault diagnosis based on the diagnostic data and the first data in the first controller. This can realize the diagnosis of various types of faults in the vehicle system, such as controllers and communications, improve the diagnostic coverage of the system, and ensure that the vehicle system has a high level of safety integrity.
[0007] For example, the vehicle system also includes a data acquisition module, and the diagnostic request includes a first diagnostic request, which instructs a second controller to acquire vehicle operating parameters from the data acquisition module. The vehicle operating parameters may be standard analog current, used to indicate physical quantities acquired by sensors that change according to vehicle operation, such as temperature, pressure, etc.
[0008] After the first controller sends a first diagnostic request to the second controller, the first controller performs fault diagnosis based on the first data and the diagnostic data received from the second controller or the main controller. The specific process by which the first controller determines a fault in the vehicle system when the first data and the diagnostic data are different is as follows: The first controller performs fault diagnosis based on the first data and the vehicle operating parameters sent by the second controller, wherein the first data is the vehicle operating parameters obtained by the first controller from the acquisition module; when the first data and the vehicle operating parameters sent by the second controller are different, the first controller determines that one or more of the first controller or the second controller are faulty; or, when the first data and the vehicle operating parameters sent by the second controller are the same, the first controller determines that neither the first controller nor the second controller is faulty.
[0009] In the above process, the first controller uses software comparison and diagnostic technology to determine whether there is a fault in the first controller or the second controller, thereby avoiding the impact of controller faults on the operation of the vehicle system in a timely manner.
[0010] For example, the diagnostic request further includes a second diagnostic request, which instructs the second controller to acquire detection data from the acquisition module, the detection data being determined and sent to the acquisition module by the first controller. This detection data may be a self-test current determined and sent by the first controller.
[0011] After the first controller sends a second diagnostic request to the second controller, the method further includes: the first controller performing fault diagnosis based on the first data and the detection data sent by the second controller, wherein the first data is the detection data in the first controller; if the detection data in the first controller is different from the detection data sent by the second controller, the first controller determines that the acquisition module is faulty; or, if the detection data in the first controller is the same as the detection data sent by the second controller, the first controller determines that the acquisition module is not faulty.
[0012] During the above process, the first controller uses test mode diagnostic technology to determine whether there is a fault in the acquisition module, thereby promptly avoiding the impact of acquisition module failure on the operation of the vehicle system.
[0013] For example, after the first controller sends a second diagnostic request to the second controller, the method further includes: the first controller performing fault diagnosis based on the detection data in the first controller and the detection data sent by the main controller, wherein the detection data sent by the main controller is determined based on the detection data sent by the second controller to the main controller; if the detection data in the first controller is different from the detection data sent by the main controller, the first controller determines that one or more of the multiple communication interfaces between the main controller and the first controller and the second controller are faulty; or, if the detection data in the first controller is the same as the detection data sent by the main controller, the first controller determines that the multiple communication interfaces between the main controller and the first controller and the second controller are not faulty.
[0014] During the above process, the first controller uses output monitoring and diagnostic technology to determine whether there is a fault in the acquisition module, thereby promptly avoiding the impact of acquisition module failure on the operation of the vehicle system.
[0015] For example, after the first controller determines that there is a fault in the vehicle system, the method further includes: the first controller stopping the second controller from outputting data and sending a fault report to the main controller.
[0016] In the above process, the first controller takes timely measures in case of a fault in the vehicle system, thereby avoiding any impact on the operation of the vehicle system.
[0017] For example, the method further includes: if the first controller sends multiple diagnostic requests to the second controller and the number of times a response signal for a diagnostic request not received from the second controller reaches a threshold, the first controller determines that there is a fault in the vehicle system.
[0018] For example, the first controller includes a first timer and a second timer, wherein when the first timer is triggered, it is used to instruct the first controller to send a first diagnostic request to the second controller, and when the second timer is triggered, it is used to instruct the first controller to send a second diagnostic request to the second controller.
[0019] In a second aspect, this application provides a first controller, which includes a processor and a memory, wherein the processor is configured to execute instructions stored in the memory to cause the first controller to perform the method described in the first aspect above.
[0020] Secondly, this application provides a computer program product including instructions that, when executed by a first controller, cause the first controller to perform the method provided in the first aspect.
[0021] Thirdly, this application provides a computer-readable storage medium including computer program instructions, which, when executed by a first controller, perform the method provided in the first aspect.
[0022] Fourthly, this application provides a vehicle system including a first controller, a second controller, a main controller, and a data acquisition module, wherein the first controller is used to implement the method provided in the first aspect.
[0023] Based on the implementation methods provided in the above aspects, this application can be further combined to provide more implementation methods. Attached Figure Description
[0024] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below.
[0025] Figure 1 This is a schematic diagram of the structure of a vehicle system provided in an embodiment of this application;
[0026] Figure 2 This is a schematic diagram of the structure of a data acquisition module provided in an embodiment of this application;
[0027] Figure 3 This is a flowchart of a fault diagnosis method provided in an embodiment of this application;
[0028] Figure 4 This is a flowchart of another fault diagnosis method provided in the embodiments of this application;
[0029] Figure 5 This is a schematic diagram of the structure of a controller provided in an embodiment of this application. Detailed Implementation
[0030] The technical solutions of the embodiments of the present invention will now be described with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.
[0031] Currently, to ensure a high safety integrity level (SIL) in vehicle systems, fault-tolerant redundancy methods are commonly employed. These methods include hardware redundancy, software redundancy, and communication redundancy. Hardware redundancy specifically involves using methods such as voting mechanisms, heartbeat detection, and fault injection testing to identify faults in redundant hardware within the vehicle system. Afterward, switching to backup hardware components ensures the continuous operation of the vehicle system. However, the fault identification process described above is quite complex, and the deployment of numerous redundant hardware and software components in vehicle systems increases their complexity and cost.
[0032] Therefore, this application provides a vehicle system in which the controller in the vehicle system diagnoses potential faults in the controller, the acquisition module, controller communication, and power supply based on data collected by the acquisition module. This simplifies and makes the fault detection process more comprehensive, improves the diagnostic coverage of fault diagnosis in the system, and ensures that the vehicle system has a high safety integrity level of SIL3 or SIL4 while maintaining low system complexity and cost.
[0033] like Figure 1 As shown, Figure 1 This is a schematic diagram of a vehicle system provided in an embodiment of this application. The vehicle system includes a main controller 110, a first controller 120, a second controller 130, and a data acquisition module 140. The main controller, the first controller, and the second controller are communicatively connected to each other, and the data acquisition module is communicatively connected to the first controller and the second controller, respectively.
[0034] Specifically, the main controller 110 is used to receive data sent by the second controller, and to perform logical judgments and operations based on the received data to realize various functions of the vehicle system, and to send control commands to the first controller and the second controller, etc. This application does not make specific limitations on this.
[0035] Specifically, the first controller and the second controller, the first controller and the main controller, and the second controller and the main controller can be connected via a universal asynchronous receiver-transmitter (UART). A UART is a serial communication interface used to transmit data between controllers in the form of a bit stream. It should be understood that controllers can also be connected via other types of interfaces, which are not specifically limited in this application. The communication between the first controller and the second controller operates in a master-slave mode, with the first controller initiating communication and receiving responses from the second controller, and the second controller receiving and responding to instructions sent by the first controller. The acquisition module and the first controller, and the acquisition module and the second controller, can be connected via a synchronous serial peripheral interface (SPI).
[0036] Specifically, the first controller 120 and the second controller 130 can be microcontrollers with independent clocks, such as the LPC2292 chip. Independent clocks ensure that each controller can send and receive data at the correct time during data exchange, achieving data synchronization and guaranteeing that the controllers can operate simultaneously without interfering with each other. It is understood that the first and second controllers can also be other similar (advanced RISC machines, ARM) chips, and this application does not specifically limit their application to these.
[0037] The first and second controllers each include multiple interrupts. These interrupts are hardware interrupts, typically triggered by external events. When an external event occurs, the hardware in the controller generates an interrupt request signal to notify the processor, causing the processor to suspend the currently executing task and perform the operation corresponding to the interrupt.
[0038] The first controller 120 includes a timer for instructing the first controller to send a diagnostic request to the second controller. Specifically, when the first timer is triggered, the first controller sends a first diagnostic request to the second controller, which instructs the second controller to obtain first diagnostic data from the acquisition module; when the second timer is triggered, the first controller sends a second diagnostic request to the second controller, which instructs the second controller to obtain second diagnostic data from the acquisition module.
[0039] The first controller 120 is also used to perform fault diagnosis upon receiving a response signal from the second controller based on a diagnostic request, identifying potential faults within the controller, the acquisition module, and communication between controllers. If a system fault is identified, the second controller stops outputting data and sends a fault report to the main controller. If no system fault is found, fault diagnosis continues.
[0040] The second controller 130 is used to send a collection signal to the collection module when it receives a diagnostic request from the first controller, and send the response signal of the diagnostic request and the data collected from the collection module to the first controller. It can also send the collected data to the main controller so that the first controller can perform fault diagnosis. This application does not specifically limit this.
[0041] The data acquisition module 140 is used to acquire data. Specifically, as follows... Figure 2 As shown, Figure 2 This is a schematic diagram of the structure of a data acquisition module provided in an embodiment of this application. The data acquisition module 140 includes a polling selection unit 141, a judgment unit 142, multiple analog input (AI) units 143, a first analog-to-digital (AD) conversion unit 144, and a second AD unit 145.
[0042] The polling selection unit 141 is used to receive the acquisition signal sent by the second controller 130 and perform polling sampling according to the acquisition signal. Specifically, the acquisition signal is the strobe signal corresponding to each AI unit so that the corresponding AI unit can perform data acquisition until each AI unit performs data acquisition once.
[0043] The judgment unit 142 is used to receive the self-test trigger signal sent by the first controller 120 and determine the source of the data collected by each AI unit based on the self-test trigger signal. When the first controller 120 sends a second diagnostic request, the first controller sets the self-test trigger signal to 1 and sends it to the judgment unit. The judgment unit determines that the data collected by each AI unit is detection data, which is the self-test current determined by the first controller through a pulse width modulation (PWM) wave controlled by a timer. When the first controller 120 sends a first diagnostic request, the first controller does not send a self-test trigger signal to the judgment unit, and the judgment unit determines that the data collected by each AI unit is vehicle operating parameters collected while the system is running.
[0044] AI unit 143 is used to acquire data upon receiving a strobe signal.
[0045] If the judgment unit 142 does not receive a self-test trigger signal, the vehicle operating parameters collected by the AI unit 143 can be standard analog current that varies according to the system operation. The standard analog current is converted from the monitored quantity of the vehicle system obtained by the sensor. The monitored quantity can be temperature, pressure, flow rate, etc. The range of the standard analog current is usually within 0mA to 20mA. The vehicle operating parameters can also be other possible parameter forms, which are not specifically limited in this application.
[0046] When the judgment unit 142 receives the self-test trigger signal, the AI unit 143 collects the self-test current.
[0047] The first AD unit 144 and the second AD unit 145 are used to convert the standard analog current or self-test current collected by the AI unit 143 into digital signals. The first AD unit 144 is used to send the converted digital signal to the first controller via SPI. The second AD unit 145 is used to send the converted digital signal to the second controller via SPI.
[0048] In one possible implementation, the acquisition module includes four AI units. When the second controller needs to poll and sample the AI units in the acquisition module, the polling selection unit sequentially receives the gating signals corresponding to the four AI units sent by the second controller. Regardless of whether the judgment unit receives the self-test trigger signal sent by the first controller, when the polling selection unit receives the gating signal corresponding to an AI unit, it samples that AI unit. The current sampled by the AI unit is converted into a digital signal by the second AD unit and sent to the second controller. Subsequently, when the polling selection unit receives the gating signal corresponding to the next AI unit, it samples the next AI unit. The current sampled by this AI unit is converted into a digital signal by the second AD unit and sent to the second controller. This process continues, sampling one AI unit at a time, until all AI units in the acquisition module have been sampled once. The current obtained from the above polling sampling can also be converted into a digital signal by the first AD unit and sent to the first controller; this application does not specifically limit this.
[0049] In one possible implementation, the above Figure 1 and Figure 2 This is merely one possible implementation method provided by the embodiments of this application. The controllers, modules, and units shown in the figure may have more types and quantities depending on the different system application scenarios. This application does not make specific limitations in this regard. In addition to vehicles, application scenarios may also include industrial automation control, medical equipment, nuclear power plant control systems, etc. This application does not make specific limitations in this regard.
[0050] like Figure 3As shown, Figure 3 This is a flowchart of a fault diagnosis method provided in an embodiment of this application. The method is applied to... Figure 1 In the second controller of the system shown, the method includes the following steps.
[0051] S310: Enable interrupt function.
[0052] After the system is powered on, the first controller, second controller, main controller, and acquisition module operate according to... Figure 1 Connect the components as shown. The second controller starts the interrupt function and keeps interrupts enabled. Enabling interrupts is usually achieved by setting a specific interrupt enable bit or special register in the second controller.
[0053] Upon receiving an external event that triggers an interrupt, the second controller immediately stops the currently executing program, responds, and performs the corresponding interrupt operation.
[0054] In one possible implementation, the second controller takes the following steps when interrupts are enabled: when the second controller receives a complete set of 8 bytes of data, it determines that an interrupt event has occurred; then, it immediately stops the currently executing program and executes a predefined interrupt operation, which varies depending on the interrupt event, and this application does not specifically limit this operation; after processing the interrupt event, the second controller resumes its original program execution state.
[0055] If the interrupt function is started normally by the second controller, the second controller executes step S320.
[0056] If, during the process of starting the interrupt function in the second controller, there is a fault in the interrupt-related hardware (such as power supply) in the second controller during the initialization process, resulting in the inability to start the interrupt function, the second controller executes step S360.
[0057] The second controller's interrupt activation function can execute interrupt operations when an interrupt event is detected, enabling data acquisition and transmission, thereby achieving fault diagnosis.
[0058] S320: Upon receiving a diagnostic request from the first controller, determine the type of the diagnostic request.
[0059] Diagnostic requests include a first diagnostic request and a second diagnostic request. Detailed explanations of each diagnostic request are provided below. Figure 1 This has already been explained in the text, so it will not be repeated here.
[0060] When the second controller receives a diagnostic request sent by the first controller via the UART interface, it determines to perform a UART interrupt operation. The UART interrupt operation includes the second controller determining whether the diagnostic request is a first diagnostic request or a second diagnostic request based on the diagnostic request sent by the first controller.
[0061] If the diagnostic request sent by the first controller is a first diagnostic request, the second controller executes step S330.
[0062] If the diagnostic request sent by the first controller is a second diagnostic request, the second controller executes step S340.
[0063] S330: Obtain the first diagnostic data from the acquisition module and send the first diagnostic data to the first controller.
[0064] Upon receiving a first diagnostic request from the first controller, the second controller sends a sampling signal to the acquisition module, polls and samples multiple AI units in the acquisition module, and obtains first diagnostic data. Each piece of first diagnostic data includes a digital signal corresponding to a standard analog current determined by the system operation and collected by an AI unit.
[0065] The second controller generates a first response signal for the first diagnostic request and sends the first response signal and the first diagnostic data to the first controller, so that the first controller can perform fault diagnosis based on the received first diagnostic data and the first data it collects from the acquisition module when it receives the first response signal. The first data is a digital signal corresponding to the standard analog current determined by the vehicle system operation and obtained by the first controller from the acquisition module.
[0066] If the first controller determines that the first diagnostic data is different from the first data, the first controller sends a shutdown output command to the second controller, and the second controller executes step S350.
[0067] If the first controller determines that the first diagnostic data is the same as the first data, the first controller does not send an instruction to the second controller. The second controller returns to the execution step S310 and waits to receive a new diagnostic request sent by the first controller.
[0068] Through the above process, the second controller can send the collected diagnostic data to the first controller, which can promptly diagnose whether there are faults in the first and second controllers, and respond promptly if a fault is found, so as to avoid affecting the operation of the vehicle system.
[0069] In one possible implementation, the second controller includes a counter whose value indicates whether the second controller can respond normally to the diagnostic request sent by the first controller, and also indicates whether the second controller can normally obtain the first diagnostic data from the acquisition module.
[0070] Upon receiving a first diagnostic request from the first controller and generating a corresponding first response signal, the second controller increments the counter value by a first value, which can be 500 or other possible values, without specific limitation in this application. Subsequently, the second controller polls and samples multiple AI units in the acquisition module according to the first diagnostic request. For each AI unit sampled, the second controller decrements the counter value by a second value, which can be 1 or other possible values, without specific limitation in this application.
[0071] To ensure the consistency and stability of the collected data and reduce interference from the terminal during the polling sampling process, the second controller switches sampling channels while interrupts are disabled. After switching sampling channels, the second controller needs to check the counter value. If the counter value changes, it continues sampling the next AI unit until the polling sampling ends. Then, the second controller returns to step S310 and waits to receive a new diagnostic request from the first controller.
[0072] However, if the counter value does not decrease after switching the sampling channel, the second controller determines that there is a fault in the sampling process of the acquisition module and executes step S360.
[0073] In addition, if the counter value does not increase after receiving a diagnostic request, the second controller determines that there is a fault in the response to the diagnostic request and executes step S360.
[0074] By judging the counter value as described above, the second controller can diagnose system faults in a timely manner and stop outputting, reducing the adverse effects on system operation caused by untimely or undetected faults, and increasing the safety of the vehicle system.
[0075] S340: Obtain the second diagnostic data from the acquisition module and send the second diagnostic data to the first controller and the main controller.
[0076] Upon receiving the second diagnostic data sent by the first controller, the second controller sends a sampling signal to the acquisition module to poll and sample multiple AI units in the acquisition module to obtain the second diagnostic data. Each piece of second diagnostic data includes a digital signal corresponding to the self-test current determined by the first controller, which is collected by an AI unit.
[0077] The second controller generates a second response signal for the second diagnostic request and sends the second response signal and the second diagnostic data to the first controller, so that the first controller, upon receiving the second response signal, performs fault diagnosis based on the received second diagnostic data and the first data it acquires from the acquisition module. The first data is a digital signal corresponding to the self-test current determined by the PWM wave sent by the first controller, obtained from the acquisition module.
[0078] If the first controller determines that the second diagnostic data is different from the first data, the first controller sends a shutdown output command to the second controller, and the second controller executes step S350.
[0079] If the first controller determines that the second diagnostic data is the same as the first data, the first controller performs a fault diagnosis technique of monitoring output based on the third diagnostic data sent by the main controller and the first data. The third diagnostic data is determined by the main controller after receiving the second diagnostic data sent by the second controller, and the third diagnostic data is the same as the second diagnostic data.
[0080] In the above process, the second controller sends the self-test current collected from the acquisition module to the first controller and the main controller, so that the first controller can perform fault diagnosis based on the self-test current obtained from the second controller and the main controller respectively. Combined with the above step S330, the fault diagnosis in the system can be more comprehensive, so that the system has a higher safety integrity level, such as reaching SIL3 or SIL4.
[0081] If the first controller determines that the third diagnostic data is different from the first data, the first controller sends a shutdown output command to the second controller, and the second controller executes step S350.
[0082] If the first controller determines that the third diagnostic data is the same as the first data, the first controller does not send an instruction to the second controller. The second controller returns to the execution step S310 and waits to receive a new diagnostic request from the first controller.
[0083] S350: Receives the shutdown output command sent by the first controller.
[0084] S360: Stop output and send a fault report to the main controller.
[0085] If the second controller fails to start the interrupt or receives a shutdown output command from the first controller, it performs a fault interrupt operation. The fault interrupt operation includes stopping the output and sending a fault report to the main controller. The fault report is used to indicate the fault in the system, and its specific form is not specifically limited in this application.
[0086] In summary, the fault diagnosis method provided in this application involves a second controller executing an interrupt operation. Upon receiving a diagnostic request from the first controller, the second controller acquires diagnostic data from the acquisition module and sends the data to the first controller, enabling the first controller to perform fault diagnosis. Based on a shutdown command sent by the first controller, the second controller stops outputting all data and sends a fault report to the main controller in the event of a system fault. This method enables simple and comprehensive fault diagnosis of the controller, data acquisition, and communication within the system. It allows for timely measures to ensure system operation in the event of a fault, thereby guaranteeing a high safety integrity level (SIL3 or SIL4) for the system.
[0087] like Figure 4 As shown, Figure 4 This is a flowchart of another fault diagnosis method provided in an embodiment of this application, which is applied to... Figure 1 In the first controller of the system shown, the method includes the following steps.
[0088] S410: Send a diagnostic request to the second controller.
[0089] After the system is powered on, the first controller, second controller, main controller, and acquisition module operate according to... Figure 1 The connection relationship shown is used for connection. The first controller includes at least a first timer and a second timer. When the first timer is triggered after the first controller is started, a first diagnostic request is sent to the second controller; when the second timer is triggered after the first controller is started, a second diagnostic request is sent to the second controller.
[0090] In one possible implementation, after initialization and connection to the second controller, the main controller, and the acquisition module, the first controller first triggers a first timer. Then, based on the triggering status of the first and second timers, it sends different diagnostic requests. The first timer can trigger every 10 seconds, and the second timer can trigger every 2 seconds. The triggering times of the first and second timers can also be other possible values, which are not specifically limited in this application.
[0091] After the first timer is triggered and the first controller sends a first diagnostic request to the second controller, step S420 is executed; after the second timer is triggered and the first controller sends a second diagnostic request to the second controller, step S430 is executed.
[0092] S420: Receives the first diagnostic data sent by the second controller and performs fault diagnosis based on the first diagnostic data.
[0093] Upon receiving a first response signal and first diagnostic data sent by the second controller in accordance with a first diagnostic request, the first controller performs fault diagnosis based on the first diagnostic data and the first data sampled by the first controller from the acquisition module. The first data is a digital signal corresponding to a standard analog current determined based on the operation of the system.
[0094] In one possible implementation, the first controller performs fault diagnosis based on the first diagnostic data and the first data, using a software mutual comparison diagnostic technique. Specifically, the software mutual comparison diagnostic technique determines whether the first diagnostic data is the same as the first data. If the first diagnostic data is the same as the first data, the first controller resets the first timer so that the first timer starts counting again and returns to step S410. If the first diagnostic data is different from the first data, the first controller executes step S460.
[0095] The aforementioned software comparison and diagnostic technology, through fault diagnosis, can avoid the impact of failures in the first and second controllers on system operation, thereby improving system security.
[0096] S430: Sends the self-test trigger signal to the sampling module and outputs a PWM wave to determine the self-test current.
[0097] When the first controller determines that the second timer has been triggered and sends a second diagnostic request to the second controller, it sets the self-test trigger signal to 1 and sends it to the acquisition module. This allows the acquisition module to determine, based on the received self-test trigger signal, that the data acquired by each AI unit is determined by the self-test current determined by the first controller. The magnitude of the self-test current is determined by the PWM wave output by the first controller.
[0098] In one possible implementation, the PWM wave can be determined based on the number of times the second timer is triggered. When the second timer is triggered for the first time, the initial value of the self-test current determined by the PWM wave is 4 mA. Subsequently, each time the second timer is triggered, the first controller increases the self-test current by 1 mA based on the previously determined self-test current by outputting the PWM wave. It is understood that the initial value of the self-test current can also be other possible values, and the first controller can also determine the magnitude of the self-test current in other ways; this application does not specifically limit this.
[0099] S440: Receives second diagnostic data sent by the second controller and performs fault diagnosis based on the second diagnostic data.
[0100] Upon receiving the second response signal and second diagnostic data sent by the second controller according to the second diagnostic request, the first controller performs fault diagnosis based on the second diagnostic data and the first data sampled by the first controller from the acquisition module. The first data is a digital signal corresponding to the self-test current determined by the PWM wave sent by the first controller.
[0101] In one possible implementation, the first controller performs fault diagnosis based on the second diagnostic data and the first data, and adopts a test mode diagnostic technique. Specifically, the test mode diagnostic technique includes determining whether the second diagnostic data is the same as the first data. If the second diagnostic data is the same as the first data, step S450 is executed. If the second diagnostic data is different from the first data, the first controller executes step S460.
[0102] The aforementioned test mode diagnostic technology, through fault diagnosis, can avoid the impact of faults in the acquisition of various AI units in the acquisition module on the system operation, thereby improving the system's security.
[0103] In one possible implementation, if the first controller sends multiple first diagnostic requests or multiple second diagnostic requests but does not receive corresponding multiple response signals, the first controller determines that the second controller or there is a communication failure between the first controller and the second controller, and the first controller executes step S460.
[0104] S450: Receives third diagnostic data sent by the main controller and performs fault diagnosis based on the third diagnostic data.
[0105] Upon receiving the second response signal sent by the second controller based on the second diagnostic request and the third diagnostic data sent by the main controller, the first controller performs fault diagnosis based on the third diagnostic data and the first data sampled by the first controller from the acquisition module. The first data is the digital signal corresponding to the standard analog current determined according to the operation of the system, and the third diagnostic data is determined by the main controller based on the second diagnostic data sent by the second controller and is the same as the second diagnostic data.
[0106] In one possible implementation, the first controller performs fault diagnosis based on the third diagnostic data and the first data, and adopts output monitoring and diagnostic technology. Specifically, the output monitoring and diagnostic technology determines whether the third diagnostic data is the same as the first data. If the third diagnostic data is the same as the first data, the first controller resets the second timer so that the second timer starts counting again and returns to the execution step S410. If the third diagnostic data is different from the first data, the first controller executes step S460.
[0107] The aforementioned output monitoring and diagnostic technology, through fault diagnosis, can avoid the impact of communication failure between the second controller and the main controller on system operation, thereby improving system security.
[0108] S460: Send a shutdown output command to the second controller.
[0109] If the first controller determines during the fault diagnosis process that the diagnostic data is different from the first data, it sends a shutdown output command to the second controller to make the second controller stop outputting.
[0110] S470: Sends a fault report to the main controller.
[0111] If the first controller determines during the fault diagnosis process that the diagnostic data is different from the first data, it sends a fault report to the main controller so that the main controller can identify the fault in the system and avoid the impact of the system fault on the logic operation of the main controller.
[0112] In summary, the fault diagnosis method provided in this application sends different diagnostic requests to the second controller by triggering different timers, thereby performing fault diagnosis on the vehicle system based on different received diagnostic data and different diagnostic methods. This achieves comprehensive fault diagnosis, avoids vehicle system operation problems caused by undetected faults, and ensures that the system's safety integrity level is SIL3 or SIL4. Compared with current fault-tolerant redundancy methods, the fault diagnosis method provided in this application is simpler, greatly reduces system complexity, and saves costs.
[0113] like Figure 5 As shown, Figure 5 This is a schematic diagram of the structure of a controller provided in an embodiment of this application. This controller can be used as a first controller or a second controller in [application / application]. Figure 1 In the system shown, the controller 500 includes a processor 510, a memory 520, a peripheral interface 530, an interrupt controller 540, and a bus 550. The processor 510, the memory 520, the peripheral interface 530, and the interrupt controller 540 communicate via the bus 550.
[0114] The processor includes a 32-bit ARM processor core, providing high-performance processing capabilities and low power consumption.
[0115] The memory includes flash memory, static random access memory (SRAM), and many other types and quantities of memory, which are not specifically limited in this application. The memory is used to store information for implementing… Figure 3 or Figure 4The program code for the fault diagnosis method shown is provided so that the processor can implement the fault diagnosis method provided in this application by executing the above program code. In addition, the memory can also store more types and quantities of data, such as data acquired from the acquisition module, etc., which is not specifically limited in this application.
[0116] Peripheral interfaces include UART, SPI, and I2C (inter-integrated circuit) interfaces, used to connect with other controllers or acquisition modules in the system to achieve corresponding communication functions. Additionally, when the controller is the first controller, it also includes a pulse width modulation interface, which is not specifically limited in this application.
[0117] The interrupt controller is used to provide interrupt control functions, process external events according to priority and respond in real time, and this application does not specifically limit this.
[0118] The bus can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, and can be divided into address bus, data bus, control bus, etc., which are not specifically limited in this application. For ease of representation, Figure 5 The fact that a bus is represented by a single line does not mean that there is only one bus or one type of bus.
[0119] In one possible implementation, controller 500 is applied as a first controller. Figure 1 In the system shown, the controller 500 also includes at least two timers 560 for generating and timing the system clock. The first timer and the second timer are used to determine the type of diagnostic request sent by the first controller. When the first timer is triggered, the diagnostic request sent by the first controller is a first diagnostic request. When the second timer is triggered, the diagnostic request sent by the first controller is a second diagnostic request.
[0120] In one possible implementation, controller 500 is used as a second controller. Figure 1 In the case of the system shown, the controller 500 may also include devices such as a counter 570, which is not specifically limited in this application.
[0121] Understandable. Figure 5 This is merely a schematic diagram of one possible controller structure provided in this application. The first controller and the second controller may also include more types and numbers of components such as independent clocks, which are not specifically limited in this application.
[0122] This application also provides a computer program product containing instructions. This computer program product can be software or program products containing instructions, capable of running on a controller or stored on any usable medium. When the computer program product runs on the controller, it causes the controller to execute the functions provided in this application. Figure 3 or Figure 4 The fault diagnosis method shown.
[0123] This application also provides a computer-readable storage medium, which includes instructions that instruct a controller to execute the instructions provided in this application. Figure 3 or Figure 4 The fault diagnosis method shown.
[0124] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for diagnosing vehicle system faults, characterized in that, The vehicle system includes a main controller, a first controller, and a second controller, wherein the main controller, the first controller, and the second controller are communicatively connected, and the method includes: The first controller sends a diagnostic request to the second controller, so that the second controller can obtain diagnostic data according to the diagnostic request; The first controller performs fault diagnosis based on the first data and the diagnostic data received from the second controller or the main controller; If the first data is different from the diagnostic data, the first controller determines that there is a fault in the vehicle system.
2. The method according to claim 1, characterized in that, The vehicle system also includes a data acquisition module, and the diagnostic request includes a first diagnostic request, which is used to instruct the second controller to obtain vehicle operating parameters from the data acquisition module. After the first controller sends the first diagnostic request to the second controller, the first controller performs fault diagnosis based on the first data and the diagnostic data received from the second controller or the main controller. If the first data differs from the diagnostic data, the first controller determines that the vehicle system has a fault, including: The first controller performs fault diagnosis based on the first data and the vehicle operating parameters sent by the second controller, wherein the first data is the vehicle operating parameters obtained by the first controller from the acquisition module; If the first data is different from the vehicle operating parameters sent by the second controller, the first controller determines that one or more of the first controller or the second controller are faulty; or, If the first data is the same as the vehicle operating parameters sent by the second controller, the first controller determines that there is no fault in either the first controller or the second controller.
3. The method according to claim 2, characterized in that, The diagnostic request further includes a second diagnostic request, which instructs the second controller to acquire detection data from the acquisition module; the detection data is determined by the first controller and sent to the acquisition module. After the first controller sends the second diagnostic request to the second controller, the method further includes: The first controller performs fault diagnosis based on the first data and the detection data sent by the second controller, wherein the first data is the detection data in the first controller; If the detection data in the first controller is different from the detection data sent by the second controller, the first controller determines that the acquisition module is faulty; or, If the detection data in the first controller is the same as the detection data sent by the second controller, the first controller determines that the acquisition module is not faulty.
4. The method according to claim 3, characterized in that, After the first controller sends the second diagnostic request to the second controller, the method further includes: The first controller performs fault diagnosis based on the detection data in the first controller and the detection data sent by the main controller, wherein the detection data sent by the main controller is determined based on the detection data sent by the second controller to the main controller; If the detection data in the first controller is different from the detection data sent by the main controller, the first controller determines that one or more of the multiple communication interfaces between the main controller and the first controller and the second controller are faulty; or, If the detection data in the first controller is the same as the detection data sent by the main controller, the first controller determines that there is no fault in the multiple communication interfaces between the main controller and the first controller and the second controller.
5. The method according to any one of claims 1-4, characterized in that, After the first controller determines that there is a fault in the vehicle system, the method further includes: The first controller stops the second controller from outputting data and sends a fault report to the main controller.
6. The method according to any one of claims 1-5, characterized in that, The method further includes: If the number of times the first controller sends multiple diagnostic requests to the second controller and does not receive a response signal for the diagnostic requests sent by the second controller reaches a threshold, the first controller determines that there is a fault in the vehicle system.
7. The method according to claim 3 or 4, characterized in that, The first controller includes a first timer and a second timer. When the first timer is triggered, it is used to instruct the first controller to send the first diagnostic request to the second controller. When the second timer is triggered, it is used to instruct the first controller to send the second diagnostic request to the second controller.
8. A first controller, characterized in that, The first controller includes a processor and a memory; The processor is configured to execute instructions stored in the memory such that the first controller performs the method as described in any one of claims 1 to 7.
9. A computer program product, characterized in that, The instruction includes an instruction that, when executed by the first controller, causes the first controller to perform the method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, Includes computer program instructions that, when executed on a first controller, cause the first controller to perform the method as described in any one of claims 1 to 7.
11. A vehicle system, characterized in that, The system includes a first controller, a second controller, a main controller, and a data acquisition module, wherein the first controller is used to implement the method as described in any one of claims 1 to 7.