Degradation management system for safety state of steer-by-wire system
By communicating and interacting with the vehicle through the redundant subsystem of the steer-by-wire system and combining it with multi-dimensional state management, the problem of safe operation of the steer-by-wire system in the event of failure is solved, and the degradation management of the safe state and risk reduction are realized.
Patent Information
- Application Number
- CN202511715504.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-21
- Publication Date
- 2026-01-09
AI Technical Summary
When communication is lost, control is lost, or execution is lost, steer-by-wire systems are prone to losing steering ability and lack effective safety management methods.
A degraded management system for the safety status of a steer-by-wire system was designed. Through redundant subsystems of the upper and lower steering systems, the system communicates and interacts with the vehicle. Combining communication, hardware, angle, torque, and safety monitoring status, the system performs preprocessing and integrated management of the degraded status, which is divided into normal, first degraded, second degraded, and third degraded statuses, thus restricting the vehicle's operating status to ensure safety.
It realizes safe operation management when the online steering system fails, reduces the safety risks caused by system failure, meets functional safety requirements, and improves the scalability and availability of the system.
Smart Images

Figure CN121291580A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of steer-by-wire system, in particular to a degradation management system of safety state of steer-by-wire system, and belongs to the field of functional safety. BACKGROUND
[0002] Steer-by-wire system cancels the mechanical connection between steering wheel and steering execution mechanism, so as to realize the decoupling of upper steering system and lower steering system in structure, and meet the convenience of vehicle space arrangement, and also put forward new challenges for functional safety. Even if the steering assist is lost, the driver can still control the steering of the vehicle through the mechanical connection structure in the traditional steering system, so as to not lose the steering ability. Due to the particularity of the structure of the steer-by-wire system, if the communication between the upper steering and the lower steering is lost, the upper steering loses the control ability or the lower steering cannot execute the steering instruction, etc., the steering system will lose the steering ability, so it is necessary to set some methods to prevent failure or to make special processing according to the failure. SUMMARY
[0003] The technical problem to be solved by the present application is to provide a degradation management method of safety state of steer-by-wire system, which can solve the problem of safe operation of the whole vehicle when the steer-by-wire system fails.
[0004] In order to solve the above problems, the degradation management system of safety state of steer-by-wire system provided by the present application, the steer-by-wire system includes an upper steering system and a lower steering system, the upper steering system is composed of an upper steering subsystem and an upper steering redundant subsystem, the lower steering system is composed of a lower steering subsystem and a lower steering redundant subsystem, each subsystem communicates with the whole vehicle and each subsystem communicates with each other, and the degradation management system includes:
[0005] A degradation state preprocessing module determines the degradation state of the subsystem corresponding to the communication, hardware, angle, torque and safety monitoring in five aspects according to the communication state, hardware state, angle state, torque state and safety monitoring state of each subsystem;
[0006] A steer-by-wire system degradation state management module obtains the final degradation state of the subsystem according to the degradation state of the subsystem corresponding to the communication, hardware, angle, torque and safety monitoring, and fuses the final degradation state of all subsystems to obtain the degradation state of the whole steer-by-wire system.
[0007] Further, all the degradation states are classified into normal state, first degradation state, second degradation state and third degradation state according to the severity of the fault from low to high; the normal state is that the steer-by-wire system does not have any fault, at this time the steer-by-wire system is in normal operation; the first degradation state is that the steer-by-wire system has a failed function which does not affect the functional safety of the steering system, at this time the steer-by-wire system prohibits the failed function from running; the second degradation state is that the steer-by-wire system is in a half-assisted output state or the current request signal input only supports low-speed driving of the whole vehicle; the third degradation state is that the steer-by-wire system loses the steering function and the whole vehicle cannot perform steering operation.
[0008] Further, when the communication interaction between a certain subsystem and the whole vehicle fails, the communication degradation state of the subsystem enters the first degradation state; when the communication interaction of a certain subsystem transmitting signals to the corresponding subsystem in the relative steering system fails, the communication degradation state of the subsystem enters the first degradation state; when the communication interaction of a certain subsystem transmitting signals to the corresponding subsystem in the relative steering system fails, and the communication interaction of another redundant subsystem in the steering system where the subsystem is located transmitting signals to the corresponding subsystem in the relative steering system also fails, the communication degradation state of the subsystem enters the second degradation state; when the communication interaction of a certain subsystem transmitting signals to another redundant subsystem in the steering system where the subsystem is located fails, the subsystem enters the second degradation state.
[0009] Further, when a certain subsystem has ASIL D level hardware failure, the subsystem enters the second degradation state; when a certain subsystem has ASIL D level hardware failure, and another redundant subsystem in the steering system where the subsystem is located also has ASIL D level hardware failure, the steering system where the subsystem is located enters the required second degradation state or third degradation state.
[0010] Further, if the angle signal of a certain subsystem is not lost and another redundant angle signal in the steering system where the subsystem is located is available, the subsystem remains in the normal state; if the angle signal of a certain subsystem is lost, but another redundant angle signal in the steering system where the subsystem is located is available, the subsystem enters the first degradation state; if the angle signal of a certain subsystem is lost, and another redundant angle signal in the steering system where the subsystem is located is not available, the subsystem enters the second degradation state; if a certain subsystem has no available angle signal, the subsystem enters the third degradation state.
[0011] Further, the torque degradation state of a subsystem is determined according to the current voltage state, temperature state, current state and software running environment of the subsystem.
[0012] Further, if the safety action of a subsystem is to shut down a certain function, the subsystem enters a first degraded state; if the safety action of a subsystem is to switch to a corresponding redundant system for execution, the subsystem enters a second degraded state; if the safety action of a subsystem results in the disconnection of the upper or lower steering system in which it is located, the subsystem enters a third degraded state.
[0013] Further, the drive-by-wire system degraded state management module comprises a subsystem degraded state processing unit and a system degraded state fusion unit, the subsystem degraded state processing unit aggregates the subsystem degraded states corresponding to each subsystem in terms of communication, hardware, angle, torque and safety monitoring and selects the most serious degraded state as the degraded state of each subsystem, and the system degraded state fusion unit fuses the degraded states of all subsystems to take the degraded state of the most serious subsystem as the degraded state of the drive-by-wire steering system.
[0014] Further, when the degraded state of a subsystem fails, the degraded states of other subsystems whose degraded states are currently valid are fused.
[0015] Further, when the degraded state of a subsystem that has failed is restored, the degraded states of all subsystems whose degraded states are currently valid are reused for fusion.
[0016] The present application designs the system state and operation after the failure of the drive-by-wire steering system, classifies and manages the failure of the drive-by-wire steering system in terms of communication, hardware, angle, torque and safety monitoring, analyzes and comprehensively analyzes the most suitable operation state of the current system after the failure, interacts with the state of the whole vehicle through the internal state of the drive-by-wire steering system, coordinates the whole vehicle to enter the corresponding degraded state, and finally limits the speed and performance of the vehicle. The present application can meet the requirements of functional safety, and in the overall design, the expandability and usability of software are considered, through the collaborative processing with the whole vehicle, the safety risk caused by the system failure can be finally reduced. BRIEF DESCRIPTION OF DRAWINGS
[0017] Figure 1 FIG. 1 is a framework diagram of the drive-by-wire steering system of the present application;
[0018] Figure 2 FIG. 2 is a framework diagram of the degraded management system of the present application;
[0019] Figure 3 FIG. 3 is a data flow diagram of the present application;
[0020] Figure 4 FIG. 4 is a degraded state fusion diagram of the present application. DETAILED DESCRIPTION
[0021] The embodiments of the present invention are described below with reference to the accompanying drawings and specific examples. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. Specific details are set forth in the following description to provide a thorough understanding of the present invention; however, the present invention can also be implemented or applied through other different specific embodiments, and the details in this specification can also be based on different viewpoints and applications. Those skilled in the art can make various similar extensions and substitutions without departing from the spirit of the present invention.
[0022] This embodiment describes a degraded safety status management system for a steer-by-wire system. The steer-by-wire system includes an upper steering system and a lower steering system. The upper steering system consists of an upper rotor system and an upper redundant steering subsystem, while the lower steering system consists of a lower rotor system and a lower redundant steering subsystem. Each subsystem communicates with the vehicle and interacts with each other through inter-chip communication.
[0023] Specifically, such as Figure 1 As shown, the upper rotor system interacts with the vehicle bus via communication channel a, the upper redundant subsystem interacts with the vehicle bus via communication channel c, the lower rotor system interacts with the vehicle bus via communication channel b, and the lower redundant subsystem interacts with the vehicle bus via communication channel d. The upper rotor system interacts with the upper redundant subsystem via communication channel A, the lower rotor system interacts with the lower redundant subsystem via communication channel B, the upper rotor system interacts with the lower rotor system via communication channel X, and the upper redundant subsystem interacts with the lower redundant subsystem via communication channel Y. It should be noted that... Figure 1 The connections between the various systems are for illustrative purposes only and do not represent a single communication path. Each communication channel is bidirectional and includes, but is not limited to, CAN, CANFD, UART and other transmission methods.
[0024] The degradation management system in this embodiment, such as Figure 2 As shown, it includes:
[0025] The degradation state preprocessing module determines the degradation state of each subsystem in terms of communication, hardware, angle, torque and safety monitoring based on the communication state, hardware state, angle, torque and safety monitoring state of each subsystem.
[0026] The steer-by-wire system degradation status management module summarizes the degradation status of the corresponding communication, hardware, angle, torque and safety monitoring of the subsystems to obtain the final degradation status of the subsystems, and merges the final degradation status of all subsystems to obtain the degradation status of the entire steer-by-wire system.
[0027] According to the degradation state of the steer-by-wire system, the whole vehicle enters the corresponding degradation state, controls the operation of the vehicle, and can refer to the requirements of ISO 19725 or DIN70065 for details as follows:
[0028] When the steer-by-wire system is in a normal state, the whole vehicle does not take any limiting measures and remains normal driving.
[0029] When the steer-by-wire system is in a first degradation state, the whole vehicle does not lose the steering function but remains speed-limited driving, and the typical speed limit range is 80-120km / h, which is determined according to the whole vehicle condition.
[0030] When the steer-by-wire system is in a second degradation state, the whole vehicle has the steering function at present, but subsequent faults will cause the vehicle to lose the lateral control ability, so the whole vehicle crawls, allows high-speed driving for a period of time and finally slows down to not more than 10km / h, so as to facilitate driving to a safe parking point.
[0031] When the steer-by-wire system is in a third degradation state, the whole vehicle loses the steering function, and is finally stationary through rear wheel auxiliary steering or braking cooperation.
[0032] Specifically, as shown in Figure 2 , the degradation state preprocessing module includes a communication degradation state processing unit, a hardware degradation state processing unit, an angle degradation state processing unit, a torque degradation state processing unit, and a safety monitoring degradation state processing unit, and the steer-by-wire system degradation state management module includes a subsystem degradation state processing unit and a system degradation state fusion unit.
[0033] In the whole degradation management system, as shown in the data flow diagram Figure 3 , the signal is input into the degradation state preprocessing module to determine the degradation state of the subsystem from the aspects of communication, hardware, angle, torque, and safety monitoring, then the subsystem degradation state obtained from the above five aspects is summarized in the subsystem degradation state processing unit to determine the final subsystem degradation state, and finally the degradation state of the steer-by-wire system is obtained by fusing all subsystem degradation states in the system degradation state fusion unit, and is given to the whole vehicle.
[0034] All degradation states (including the subsystem degradation states corresponding to the five aspects of communication, hardware, angle, torque, and safety monitoring, the final degradation state of the subsystem, and the degradation state of the steer-by-wire system) are divided into a normal state (NORMAL STATE), a first degradation state (DEGRADATION 1 STATE), a second degradation state (DEGRADATION 2 STATE), and a third degradation state (DEGRADATION 3 STATE) according to the severity of the fault from low to high.
[0035] The normal state is that no failure occurs, and the steer-by-wire system operates normally; the first degraded state is that the steer-by-wire system has a failed function, and the failed function does not affect the functional safety of the steering system, and the steer-by-wire system prohibits the failed function from operating; the second degraded state is that the steer-by-wire system is in a half-assist output state or the current request signal input only supports low-speed driving of the whole vehicle; and the third degraded state is that the steer-by-wire system loses the steering function and the whole vehicle cannot perform steering operation.
[0036] First, the communication degraded state processing unit determines the degraded state of the subsystem in the communication dimension according to the state of each communication path in the subsystem. Figure 1 The specific cases are as follows:
[0037] When the communication interaction between a subsystem and the whole vehicle fails, the degraded state of the subsystem in the communication dimension enters the first degraded state; for example, when the communication path a between the upshift subsystem and the vehicle bus fails, the upshift subsystem enters the first degraded state, when the communication path c between the upshift redundant subsystem and the vehicle bus fails, the upshift redundant subsystem enters the first degraded state, when the communication path b between the downshift subsystem and the vehicle bus fails, the downshift subsystem enters the first degraded state, and when the communication path d between the downshift redundant subsystem and the vehicle bus fails, the downshift redundant subsystem enters the first degraded state.
[0038] When the communication interaction of a subsystem transmitting a signal to the corresponding subsystem in the relative steering system fails, the degraded state of the subsystem receiving the transmitted signal in the communication dimension enters the first degraded state; for example, when the communication path of the upshift subsystem transmitting a signal to the downshift subsystem fails, the downshift subsystem enters the first degraded state, when the communication path of the downshift subsystem transmitting a signal to the upshift subsystem fails, the upshift subsystem enters the first degraded state, when the communication path of the upshift redundant subsystem transmitting a signal to the downshift redundant subsystem fails, the downshift redundant subsystem enters the first degraded state, and when the communication path of the downshift redundant subsystem transmitting a signal to the upshift redundant subsystem fails, the upshift redundant subsystem enters the first degraded state.
[0039] When the communication interaction of a subsystem transmitting signals to the corresponding subsystem in the opposite steering system fails, and the communication interaction of another redundant subsystem in the steering system where the subsystem is located transmitting signals to the corresponding subsystem in the opposite steering system fails at the same time, the subsystem receiving the transmission signals of the subsystem enters the second degraded state in the communication dimension; for example, when the communication path of the up steering subsystem transmitting signals to the down steering subsystem fails and the communication path of the up steering redundant subsystem transmitting signals to the down steering redundant subsystem fails, the down steering subsystem enters the second degraded state; when the communication path of the up steering redundant subsystem transmitting signals to the down steering redundant subsystem fails and the communication path of the up steering subsystem transmitting signals to the down steering subsystem fails, the down steering redundant subsystem enters the second degraded state; when the communication path of the down steering subsystem transmitting signals to the up steering subsystem fails and the communication path of the down steering redundant subsystem transmitting signals to the up steering redundant subsystem fails, the up steering subsystem enters the second degraded state; when the communication path of the down steering redundant subsystem transmitting signals to the up steering redundant subsystem fails and the communication path of the down steering subsystem transmitting signals to the up steering subsystem fails, the up steering redundant subsystem enters the second degraded state;
[0040] When the communication interaction of a subsystem transmitting signals to the corresponding subsystem in the opposite steering system fails, and the communication interaction of another redundant subsystem in the steering system where the subsystem is located transmitting signals to the corresponding subsystem in the opposite steering system fails at the same time, the subsystem receiving the transmission signals of the subsystem enters the second degraded state in the communication dimension; for example, when the communication path of the up steering subsystem transmitting signals to the down steering subsystem fails and the communication path of the up steering redundant subsystem transmitting signals to the down steering redundant subsystem fails, the down steering subsystem enters the second degraded state; when the communication path of the up steering redundant subsystem transmitting signals to the down steering redundant subsystem fails and the communication path of the up steering subsystem transmitting signals to the down steering subsystem fails, the down steering redundant subsystem enters the second degraded state; when the communication path of the down steering subsystem transmitting signals to the up steering subsystem fails and the communication path of the down steering redundant subsystem transmitting signals to the up steering redundant subsystem fails, the up steering subsystem enters the second degraded state; when the communication path of the down steering redundant subsystem transmitting signals to the up steering redundant subsystem fails and the communication path of the down steering subsystem transmitting signals to the up steering subsystem fails, the up steering redundant subsystem enters the second degraded state;
[0041] In the hardware degradation state processing unit, when a subsystem (or a redundant subsystem) has ASIL D level hardware (including hardware components or hardware circuits, such as pre-drive, MCU, SBC, MOSFET, etc.) failure, the subsystem (or the redundant subsystem) enters the second degradation state. When a subsystem has ASIL D level hardware failure, and another redundant subsystem in the steering system where the subsystem is located also has ASIL D level hardware failure, the upper steering system or the lower steering system where the subsystem is located can enter the second degradation state or the third degradation state according to actual needs, for example, when the lower subsystem has ASIL D level hardware failure but the lower redundant subsystem is normal, the lower subsystem enters the second degradation state, when the lower redundant subsystem has ASIL D level hardware failure but the lower subsystem is normal, the lower redundant subsystem enters the second degradation state, and when the lower subsystem has ASIL D level hardware failure and the lower redundant subsystem also has ASIL D level hardware failure, the lower steering system enters the third degradation state. Of course, the degradation management system of the present application can also select a suitable degradation state according to customer needs or safety considerations, for example, when the upper subsystem has ASIL D level hardware failure and the upper redundant subsystem also has ASIL D level hardware failure, the upper steering system can relax the requirements to enter the second degradation state.
[0042] In the angle degradation state processing unit, the steer-by-wire system needs to combine the effectiveness and availability of the angle signal for degradation in combination with the request angle and the execution angle for closed-loop control. Specifically:
[0043] If the angle signal of a subsystem is not lost and another redundant angle signal in the steering system where the subsystem is located is available, the subsystem remains in a normal state;
[0044] If the angle signal of a subsystem is lost, but another redundant angle signal in the steering system where the subsystem is located is available, the subsystem enters the first degradation state;
[0045] If the angle signal of a subsystem is lost, and another redundant angle signal in the steering system where the subsystem is located is not available, the subsystem enters the second degradation state;
[0046] If a subsystem has no available angle signal, the subsystem enters the third degradation state.
[0047] It should be noted that the angle signal loss refers to the inability to collect the angle signal inside the subsystem, and no angle signal available refers to the fact that for the upturn / downturn, in addition to the angle signal collected by the subsystem and the angle signal collected by the redundant subsystem in the same system, the angle signal collected by the external sensor is transmitted to the subsystem for use. If the angle signal collected by the subsystem, the angle signal collected by the redundant subsystem in the same system, and the angle signal transmitted externally are all invalid, then there is no angle signal available.
[0048] In the torque degradation state processing unit, the system needs to be degraded in combination with the current voltage state, temperature state, current state, and software running environment to avoid systematic failure caused by high-load software operation. Specifically, the assist capability allowed to be output by the upturn system or the downturn system is calculated according to the current voltage state, temperature state, current state, and software running environment, and then the degradation state of the current subsystem is determined according to the assist capability.
[0049] The way of determining the system degradation according to the voltage state, temperature state, current state, and software running environment is the same as the way of determining the system degradation according to the temperature state, so the temperature state is taken as an example to describe the system degradation, which will be described in detail later. If the current environmental temperature of a subsystem or the temperature of a component is too high, and the continued execution will cause damage to the component, then the assist capability allowed to be output by the upturn system or the downturn system in which the subsystem is located needs to be obtained in combination with the temperature characteristics (for example, the corresponding relationship chart between the temperature and the assist capability allowed to be output by the system can be obtained through a temperature calibration experiment, and then the assist capability allowed to be output by the system corresponding to the current temperature is obtained by looking up the table), and then whether the current subsystem needs to be degraded is determined according to the assist capability allowed to be output by the upturn system or the downturn system.
[0050] Specifically, first, the subsystem and the redundant subsystem determine the assist capability allowed to be output by themselves according to the temperature characteristics of themselves, and then transmit the assist capability allowed to be output by themselves to the other party. Then, the subsystem and the redundant subsystem calculate the assist capability allowed to be output by the upturn system or the downturn system in which they are located. Finally, the subsystem and the redundant subsystem determine the degradation state of themselves on the temperature level according to the assist capability allowed to be output by the upturn system or the downturn system in which they are located.
[0051] If the assist capability allowed to be output by the upturn system or the downturn system is greater than X2 and less than X1 and the duration is not less than Y1, then the corresponding subsystem enters the normal state, and if the duration is less than Y1, then the subsystem still processes the subsequent process according to the last degradation state.
[0052] If the assist force of the output of the upper steering system or the lower steering system is less than or equal to X2 and greater than X3 and the duration is not less than Y2, the corresponding subsystem enters the first degradation state, and if the duration is less than Y2, the subsystem still follows the previous degradation state for subsequent processing;
[0053] If the assist force of the output of the upper steering system or the lower steering system is less than or equal to X3 and greater than X4 and the duration is not less than Y3, the corresponding subsystem enters the second degradation state, and if the duration is less than Y3, the subsystem still follows the previous degradation state for subsequent processing;
[0054] If the assist force of the output of the upper steering system or the lower steering system is less than or equal to X4 and the duration is not less than Y4, the corresponding subsystem enters the third degradation state, and if the duration is less than Y4, the subsystem still follows the previous degradation state for subsequent processing.
[0055] Wherein, X1 is usually 100% assist force output capacity, X2, X3, X4, Y1, Y2, Y3, Y4 all need to be determined by vehicle calibration corresponding system, the specific value can be modified according to the calibration result. During the degradation or recovery process from the degradation state, Y1, Y2, Y3, Y4 can be set to different times to meet the real-time response of the system to the degradation, and to avoid the misjump of the degradation state.
[0056] In the safety monitoring degradation state processing unit, a software level safety mechanism is designed according to the possible failure of the software, and if the safety mechanism monitors the failure, the degradation processing is performed according to the safety action of the software:
[0057] If the software safety action of a subsystem is to shut down a certain function, the subsystem enters the first degradation state;
[0058] If the software safety action of a subsystem is to switch to the corresponding redundant system for execution, the subsystem enters the second degradation state;
[0059] If the software safety action of a subsystem causes the disconnection of the upper steering system or the lower steering system in which it is located, the subsystem enters the third degradation state.
[0060] The degraded state preprocessing module obtains the degraded states of the upper rotor system, the upper redundant subsystem, the lower rotor system and the lower redundant subsystem from five aspects of communication state, hardware state, angle state, torque state and safety monitoring state. The subsystem degraded state processing unit collects the degraded states of each subsystem in the five aspects of communication, hardware, angle, torque and safety monitoring and selects the most serious degraded state as the final degraded state of each subsystem. That is, the degraded state preprocessing module outputs five degraded states of each subsystem, and the subsystem degraded state processing unit selects the most serious degraded state from the five degraded states as the final degraded state of each subsystem. For example, taking the lower rotor system as an example, the degraded state of the lower rotor system determined according to the communication state is the first degraded state, the degraded state of the lower rotor system determined according to the hardware state is the normal state, the degraded state of the lower rotor system determined according to the angle state is the second degraded state, the degraded state of the lower rotor system determined according to the torque state is the normal state, and the degraded state of the lower rotor system determined according to the safety monitoring is the first degraded state. Then the final degraded state of the lower rotor system is determined as the most serious second degraded state.
[0061] Finally, the system degraded state fusion unit fuses the final degraded states of all subsystems to take the final degraded state of the most serious subsystem as the degraded state of the steer-by-wire system. As shown in Figure 4 The final degraded states of the upper rotor system, the upper redundant subsystem, the lower redundant subsystem and the lower rotor system are fused through inter-board communication, and the most serious final degraded state of all subsystems is taken. Assuming that the final degraded state of the upper rotor system is the first degraded state, the final degraded state of the upper redundant subsystem is the normal state, the final degraded state of the lower redundant subsystem is the first degraded state, and the final degraded state of the lower rotor system is the second degraded state, then the final degraded state of the lower rotor system is taken as the degraded state of the steer-by-wire system, that is, the degraded state of the steer-by-wire system is the second degraded state.
[0062] When the degraded state of a certain subsystem fails to cause the overall degraded state to be unable to be fused, the degraded states of other subsystems with valid current degraded states are fused. When the degraded state of the subsystem that fails is restored, the degraded states of all subsystems with valid current degraded states are used for fusion again.
[0063] The application designs the system state and operation after the failure of the steer-by-wire system, classifies and manages the failure of the steer-by-wire system in five dimensions of communication, hardware, angle, torque and safety monitoring, analyzes the most suitable operation state of the current system after comprehensive failure, interacts with the internal state of the steer-by-wire system and the state of the whole vehicle, coordinates the whole vehicle to enter the corresponding degraded state, finally limits the speed and performance of the vehicle, realizes the management of the overall degraded state of the steering system, and meets the degradation requirements of the whole vehicle factory and functional safety. The application can meet the requirements of functional safety, and the expandability and usability of software are considered in the overall design, through the collaborative processing with the whole vehicle, the safety risk caused by the system failure can be finally reduced.
[0064] The application is described in detail above through specific embodiments, and the above embodiments are only preferred embodiments of the application, and the application is not limited to the above embodiments. Equivalent substitutions and improvements made by those skilled in the art without departing from the principles of the application should be considered within the technical scope protected by the application.
Claims
1. A degradation management system for a safe state of a steer-by-wire system, the steer-by-wire system comprising an upper steering system and a lower steering system, the upper steering system consisting of an upper rotor system and an upper redundant subsystem, the lower steering system consisting of a lower rotor system and a lower redundant subsystem, each subsystem communicating with the whole vehicle and each subsystem communicating with each other, characterized in that, The degradation management system comprises: a degradation state preprocessing module which determines the degradation state of each subsystem in terms of communication, hardware, angle, torque and safety monitoring according to the communication state, hardware state, angle state, torque state and safety monitoring state of each subsystem; a system degradation state management module which collects the degradation state of each subsystem in terms of communication, hardware, angle, torque and safety monitoring to obtain the final degradation state of each subsystem, and fuses the final degradation state of all subsystems to obtain the degradation state of the entire steer-by-wire system.
2. The degradation management system of a safe state of a steer-by-wire system according to claim 1, characterized by, All degradation states are classified into normal state, first degradation state, second degradation state and third degradation state from low to high according to the severity of faults; the normal state is that the steer-by-wire system has no fault, and the steer-by-wire system operates normally; the first degradation state is that the steer-by-wire system has a failed function which does not affect the functional safety of the steering system, and the steer-by-wire system prohibits the failed function from operating; the second degradation state is that the steer-by-wire system is in a half-assisted output state or the current request signal input only supports low-speed driving of the vehicle; and the third degradation state is that the steer-by-wire system loses the steering function and the vehicle cannot perform steering operation.
3. The degradation management system of the safety state of the steer-by-wire system according to claim 2, wherein when the communication interaction between a subsystem and the vehicle fails, the communication degradation state of the subsystem enters the first degradation state; when the communication interaction of a subsystem transmitting signals to the corresponding subsystem in the relative steering system fails, the communication degradation state of the subsystem enters the first degradation state; when the communication interaction of a subsystem transmitting signals to the corresponding subsystem in the relative steering system fails, and the communication interaction of another redundant subsystem in the steering system of the subsystem transmitting signals to the corresponding subsystem in the relative steering system also fails, the communication degradation state of the subsystem enters the second degradation state; when the communication interaction of a subsystem transmitting signals to another redundant subsystem in the steering system of the subsystem fails, the subsystem enters the second degradation state.
4. The degradation management system of the safety state of the steer-by-wire system according to claim 2, wherein when a subsystem has ASIL D level hardware failure, the subsystem enters the second degradation state; when a subsystem has ASIL D level hardware failure, and another redundant subsystem in the steering system of the subsystem also has ASIL D level hardware failure, the steering system of the subsystem enters the required second degradation state or third degradation state.
5. The degradation management system of the safety state of the steer-by-wire system according to claim 2, wherein if the angle signal of a subsystem is not lost and another redundant angle signal in the steering system of the subsystem is available, the subsystem remains in the normal state; if the angle signal of a subsystem is lost, but another redundant angle signal in the steering system of the subsystem is available, the subsystem enters the first degradation state; If the angle signal of a subsystem is lost and another redundant angle signal in the steering system where the subsystem is located is not available, the subsystem enters a second degraded state; If a subsystem has no available angle signal, the subsystem enters a third degraded state.
6. The degrading management system of the safe state of the steer-by-wire system according to claim 2, characterized by, The torque degraded state of a subsystem is determined according to the current voltage state, temperature state, current state and software running environment of the subsystem.
7. The degraded state management system of the steer-by-wire system safety state according to claim 2, characterized in that, If the safety action of a subsystem is to shut down a function, the subsystem enters a first degraded state; If the safety action of a subsystem is to switch to the corresponding redundant system for execution, the subsystem enters a second degraded state; If the safety action of a subsystem results in the disconnection of the upper steering system or the lower steering system where the subsystem is located, the subsystem enters a third degraded state.
8. The degrading management system of the safe state of the steer-by-wire system according to claim 1, characterized by, The steer-by-wire system degraded state management module includes a subsystem degraded state processing unit and a system degraded state fusion unit, the subsystem degraded state processing unit collects the degraded states of each subsystem in the five aspects of communication, hardware, angle, torque and safety monitoring and selects the most serious degraded state as the degraded state of each subsystem, and the system degraded state fusion unit fuses the degraded states of all subsystems to take the degraded state of the most serious subsystem as the degraded state of the steer-by-wire system.
9. The degrading management system of the safe state of a steer-by-wire system according to claim 8, characterized in that, When the degraded state of a subsystem fails, the degraded states of other subsystems whose current degraded states are valid are fused.
10. The degrading management system of the safe state of a steer-by-wire system according to claim 9, characterized in that, When the degraded state of a subsystem that has failed is restored, the degraded states of all subsystems whose current degraded states are valid are fused again.
Citation Information
Cited By
Fault judgment method and device for upper steering system and lower steering system of vehicle
CN121716784A