Volatile memory mode for secure state configuration
By using volatile memory to store fail-safe configurations in the driver circuit and utilizing multiple independent power supplies, the safety issues of the driver circuit in the event of a failure are solved, and the flexibility and update efficiency of configuration information are improved.
Patent Information
- Application Number
- CN202510979588.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-07-18
- Filing Date
- 2025-07-16
- Publication Date
- 2026-01-20
AI Technical Summary
In the prior art, the driver circuit is difficult to operate safely and reliably under fault or unexpected conditions, and the updating and flexibility of configuration information are insufficient.
The drive circuit employs a fail-safe configuration with volatile memory and is powered by multiple independent power supplies to ensure a safe state in the event of a fault, and configures the drive circuit and power switches.
It enables safe and reliable operation of the driver circuit under fault conditions, improves the flexibility and update efficiency of configuration information, and reduces the probability and complexity of errors.
Smart Images

Figure CN121364818A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to driver circuits for power switches, and more particularly, to techniques and circuits for storing a configuration of a driver circuit using volatile memory. BACKGROUND
[0002] Power switches are used in a variety of applications to control the power delivered to a load. Power switches are typically controlled by a driver circuit via a modulated control signal, such as a pulse width modulation (PWM), pulse frequency modulation (PFM), pulse duration modulation, pulse density modulation, or other type of modulated control signal. The modulated control signal can be applied to the gate of the power switch in order to control the on / off switching of the power switch, thereby controlling the average amount of power delivered through the power switch to the load. The on / off switching of the power switch effectively divides its power delivery into discrete portions. The average of the voltage and / or current fed to the load can be controlled by turning the switch on and off at a fast rate. The longer the switch is on compared to the off period, the higher the total power supplied to the load. In many applications, two different power switches are configured in a high-side configuration and a low-side configuration, and the on / off switching of the two power switches are synchronized in order to deliver a desired power to a switch node located between the high-side switch and the low-side switch. In some examples, the power switches can be intelligent power switches that perform self-diagnosis or can be configured with other diagnostic functions, and the power switches can protect themselves from over-current and over-heat conditions. SUMMARY
[0003] In general, the present disclosure describes circuits and techniques for using volatile memory to store a failsafe configuration of a driver circuit for driving a power switch. The circuits and techniques can enable writing of the failsafe configuration to the volatile memory of the driver circuit at startup, and enable configuring the driver circuit according to the failsafe configuration stored in the volatile memory when the driver circuit enters a failsafe state. The driver circuit can be separate from the power switch or can be integrated with the power switch.
[0004] A driver circuit that drives a power switch can follow a safety element out of context (SEooC) approach to ensure that the driver circuit operates safely and reliably even in the event of a failure or unexpected condition. To this end, when the driver circuit detects or receives an indication that the driver circuit or an external component has failed, the driver circuit can enter a fail-safe state to protect the driver circuit and other components controlled by the driver circuit, such as the power switch and an actuator. To this end, the driver circuit can include a volatile memory that stores a fail-safe configuration. When the driver circuit enters the fail-safe state, the driver circuit can configure itself and / or external components (e.g., the power switch) according to the fail-safe configuration.
[0005] Using volatile memory to store configuration information can potentially provide certain advantages for the driver circuit compared to using non-volatile memory. By using volatile memory to store configuration information, the configuration information does not have to be written into the memory at the time of manufacture of the driver circuit. However, the driver circuit is able to load the configuration information in the field, such as from a host controller at the time of startup of the driver circuit. Enabling the driver circuit to load configuration information in the field can increase the flexibility of the driver circuit and can enable more up-to-date configuration information to be loaded into the driver circuit. In addition, by using volatile memory to store configuration information, a host controller is able to easily update the configuration information for the driver circuit in order to improve the performance of the configuration information and reduce errors in the configuration information. Furthermore, using volatile memory to store configuration information can potentially provide additional advantages for the driver circuit compared to using non-volatile memory, such as faster read and write speeds, lower latency, lower active power consumption, lower complexity, smaller area, and lower cost.
[0006] According to the circuits and techniques of the present disclosure, a driver circuit that drives a power switch includes a volatile memory that stores a fail-safe configuration for the driver circuit. Because volatile memory generally requires continuous power to maintain stored information, the volatile memory of the driver circuit is connected to multiple independent power sources. Thus, if one of the components that provide power to the volatile memory fails, the other independent power sources can provide redundant power to enable the volatile memory to maintain stored information.
[0007] The driver circuit can determine to enter a failsafe state. For example, the driver circuit can detect a problem that causes the driver circuit to enter the failsafe state, or the driver circuit can receive an indication that a host controller that controls the driver circuit has failed. In response to determining to enter the failsafe state, the driver circuit can configure the driver circuit or the power switch according to a failsafe configuration stored in the volatile memory. For example, the driver circuit can turn on or off the power switch according to the failsafe configuration and / or can configure the driver circuit according to the failsafe configuration.
[0008] In some aspects, the technology described herein relates to a driver circuit comprising a volatile memory connected to a plurality of independent power sources, the volatile memory configured to store a failsafe configuration for the driver circuit; and driver logic connected to the volatile memory, the driver logic configured to: determine to enter a failsafe state; and in response to determining to enter the failsafe state, configure the driver circuit or a power switch according to the failsafe configuration stored in the volatile memory.
[0009] In some aspects, the technology described herein relates to a method comprising: storing, in a volatile memory of a driver circuit, a failsafe configuration for the driver circuit, the volatile memory connected to a plurality of independent power sources; determining, by the driver circuit, to enter a failsafe state; and in response to determining to enter the failsafe state, configuring, by the driver circuit, the driver circuit or a power switch according to the failsafe configuration stored in the volatile memory.
[0010] In some aspects, the technology described herein relates to a system comprising an actuator; a power switch configured to control power supplied to the actuator; a driver circuit configured to control the power switch; a host controller configured to control the driver circuit; and a monitoring device configured to: detect a failure in the host controller; and in response to detecting the failure in the host controller, send a request to enter a failsafe state to the driver circuit, wherein the driver circuit comprises a volatile memory connected to a plurality of independent power sources, the volatile memory configured to store a failsafe configuration for the driver circuit; and driver logic connected to the volatile memory, the driver logic configured to: receive the request to enter the failsafe state; and in response to receiving the request to enter the failsafe state, configure the driver circuit or the power switch according to the failsafe configuration stored in the volatile memory.
[0011] The details of these and other examples are set forth in the accompanying drawings and the description below. Other features, objects, and advantages will be apparent from the description and drawings, and from the claims. BRIEF DESCRIPTION OF DRAWINGS
[0012] Figure 1 is a block diagram of an example system that includes a power switch circuit, a driver circuit, and a controller.
[0013] Figure 2 is a block diagram of an example driver circuit that is further detailed in Figure 1 .
[0014] Figure 3 is a flowchart illustrating a method of configuring a driver circuit according to the present disclosure. DETAILED DESCRIPTION
[0015] The present disclosure describes circuits and techniques for using volatile memory to store a failsafe configuration for a driver circuit that drives a power switch. The circuits and techniques enable writing the failsafe configuration to the volatile memory of the driver circuit at startup, and enable configuring the driver circuit according to the failsafe configuration.
[0016] According to the circuits and techniques of the present disclosure, a driver circuit that drives a power switch includes volatile memory that stores a failsafe configuration for the driver circuit. Because volatile memory can require continuous power to maintain stored information, the volatile memory of the driver circuit is connected to multiple independent power sources. Thus, if one of the components that provide power to the volatile memory fails, the other independent power sources can provide redundant power to enable the volatile memory to maintain stored information.
[0017] The driver circuit can enter a failsafe state if the driver circuit detects an issue that causes the driver circuit to enter the failsafe state, or if the driver circuit receives an indication that a host controller that controls the driver circuit has failed. In response to determining to enter the failsafe state, the driver circuit can configure the driver circuit or the power switch according to the failsafe configuration stored in the volatile memory. For example, the driver circuit can turn the power switch on or off according to the failsafe configuration, and / or can configure the driver circuit according to the failsafe configuration to ensure safe operation of the driver circuit and components controlled by the driver circuit (e.g., the power switch and an actuator).
[0018] Figure 1 is a block diagram of an example system 100 that includes an energy board network 110, a monitoring device 120, a host controller 130, a driver circuit 140, a power switch 154, and an actuator 152. The system 100 can be part of a vehicle, such as an automobile (e.g., a car, a truck, a motorcycle, etc.).
[0019] The driver circuit 140 can be communicatively coupled to the power switch 154 and configured to control the power switch 154. The driver circuit 140 can include any type of driver for any type of power switch, such as a high-side switch driver, a low-side switch driver, a driver within a flyback power converter, or any driver used in any circuit arrangement that controls the on / off switching of one or more power switches. The driver circuit 140 can control the power switch 154 via a modulation signal, which can control the on / off switching of a transistor within the power switch 154. The modulation signal can include, for example, a pulse width modulation (PWM) signal, a pulse frequency modulation (PFM) signal, a pulse duration modulation signal, a pulse density modulation signal, or another type of modulation control signal used to control a power transistor. In normal operation, a signal from the driver circuit 140 can be applied to the gate (or other control terminal) of a power switch within the power switch 154 in order to control the on / off switching of the power switch, and thereby control the average amount of power delivered through the power switch to a load, such as the actuator 152.
[0020] The power switch 154 can be any type of power switch, such as a high-side switch, a low-side switch, etc., that delivers power to the actuator 152. The power switch 154 includes a power transistor. For example, the power transistor within the power switch 154 can include an insulated gate bipolar transistor (IGBT) or a MOSFET. The MOSFET can be formed in silicon, in which case the MOSFET can be referred to as a silicon MOSFET. Alternatively, the MOSFET can be formed in another semiconductor material, such as silicon carbide (SiC) or gallium nitride (GaN), in which case the MOSFET can be referred to as a SiC MOSFET or a GaN MOSFET. Although the power switch 154 is illustrated as a single component, in some aspects, the power switch 154 can be integrated into the driver circuit 140. Figure 1 The driver circuit 140 and the power switch 154 are illustrated as separate components, but in some aspects, the power switch 154 can be integrated into the driver circuit 140.
[0021] The power switch 154 can deliver power to the actuator 152. The actuator 152 can be a device that coordinates an electrical signal into a physical action. For example, the actuator 152 can control the opening and closing of a valve, adjust a mirror, move a window, the locking and unlocking of a door, the turning on and off of a light, or perform other mechanical actions based on an electrical signal. In some examples, the power switch 154 can be a smart power switch that is integrated into the driver circuit 140.
[0022] The host controller 130 can include a microprocessor configured to control the driver circuit 140. The host controller 130 is communicatively coupled to the driver circuit 140 and can control the driver circuit 140 by sending command signals to the driver circuit 140. Based on these command signals, in some examples, the driver circuit 140 can send on / off signals (e.g., gate control signals) to the power switches 154 to turn on or turn off the power switches.
[0023] The energy board network 110 can be a power source for components of the system 100. In the case of a vehicle, the energy board network 110 can be an onboard electrical power distribution system responsible for distributing electrical power throughout the vehicle. For example, the energy board network 110 can include a battery, an alternator, fuses, relays, wires, etc. that connect the electrical and electronic devices of the vehicle. In Figure 1 In examples, the energy board network 110 can be a power source for the monitoring device 120, which provides a voltage, referred to herein as a “V BAT ” voltage 112, to the monitoring device 120 and the driver circuit 140.
[0024] The monitoring device 120 can monitor the operation of components of the system 100, such as the host controller 130 and the driver circuit 140. In some examples, the monitoring device 120 can be part of or can include a system base chip, which is a type of circuit device (e.g., integrated circuit, system on a chip, semiconductor, etc.) used in automotive electronics to provide functions such as power management, interface, and communication tasks for automotive systems. A system base chip can typically integrate several features, such as voltage regulation, communication interfaces (e.g., CAN bus, LIN bus), watchdog timer, and control outputs. By supplying a voltage, referred to herein as a “V DD ” voltage 126, to both the host controller 130 and the driver circuit 140, the monitoring device 120 can be a power source for the host controller 130 and the driver circuit 140.
[0025] The monitoring device 120 can be communicatively coupled to the host controller 130 and the driver circuit 140. The monitoring device 120 includes a failsafe controller 124 configured to monitor the operation of components of the system 100, such as the host controller 130 and the driver circuit 140, and determine whether the driver circuit 140 should enter a failsafe state based on the monitored operation of the components of the system 100. The failsafe controller 124 can be configured to send a request to enter the failsafe state to the driver circuit 140 in response to determining that the driver circuit 140 should enter the failsafe state. Such a request to enter the failsafe state is also referred to herein as a limp-home request, which indicates a malfunction or failure of the host controller 130 that controls the driver circuit 140.
[0026] In some examples, the failsafe controller 124 can be configured to monitor the "V DD " voltage 126 provided to the driver circuit 140. Based on the behavior of the "V DD " voltage 126, the monitoring device 120 can send a request to enter a failsafe state to the driver circuit 140. For example, in response to the failsafe controller 124 determining that the "V DD " voltage 126 provided to the driver circuit 140 is above an overvoltage threshold or below an undervoltage threshold, the monitoring device 120 can send a request to enter a failsafe state, such as in the form of a limp request, to the driver circuit 140.
[0027] In some examples, the failsafe controller 124 can be configured to monitor the operation of the host controller 130 to determine the behavior of the host controller 130 (e.g., whether the host controller 130 is operating properly or malfunctioning). The failsafe controller 124 can be configured to monitor the operation of the host controller 130 to determine whether the host controller 130 is operating properly using any suitable technique. In some examples, the failsafe controller 124 can communicate with the host controller 130 to determine whether the host controller 130 is malfunctioning or otherwise malfunctioning using a watchdog timer, a heartbeat signal, a test command, a self-test routine, or any other suitable technique. In response to the failsafe controller 124 determining that the host controller 130 is malfunctioning or otherwise malfunctioning, the monitoring device 120 can send a request to enter a failsafe state to the driver circuit 140.
[0028] The driver circuit 140 includes a communication interface 142, driver logic 144, and volatile memory 150. The communication interface 142 can be any suitable communication interface that enables the driver circuit 140 to communicate with other components of the system 100, such as the monitoring device 120, the host controller 130, and the power switch 154. For example, the communication interface 142 can include one or more digital interfaces, such as a multi-channel serial interface, a bus, or the like, to send and receive signals and data to and from other components of the system 100.
[0029] The driver logic 144 can be digital logic that can be configured, such as through configuration information stored in the volatile memory 150, to control the operation of the power switch 154. By way of example, the driver logic 144 can be implemented as one or more microcontrollers, application specific integrated circuits (ASICs), or any other suitable form of configurable digital logic.
[0030] The driver logic 144 is configured to implement a safety state controller 146 that can be configured to determine whether to cause the driver circuit 140 to enter a failsafe state and / or perform operations to transition the driver circuit 140 to a failsafe state. The failsafe state for the driver circuit 140 can be a protective mode of operation with predefined operating conditions designed to ensure safety and prevent damage to the driver circuit 140 and other components of the system 100. When the driver circuit 140 is in the failsafe state, the driver circuit 140 can be in a safe mode of operation that minimizes risk to components of the system 100 and users of the system 100. When the driver circuit 140 is in the failsafe state, the driver circuit 140 can be configured to prevent unintended current flow to a load (e.g., the actuator 152) and / or ensure that critical loads remain powered to maintain basic functionality.
[0031] In some examples, the safety state controller 146 is configured to detect a problem in the operation of the driver circuit 140 and, in response, can cause the driver logic 144 to enter a failsafe state. For example, the safety state controller 146 is configured to detect an overcurrent condition, an undercurrent condition, an overvoltage condition, an undervoltage condition, an overtemperature condition, an open load condition, or other problems in the operation of the driver circuit 140. In some examples, the power switch 154 can detect such a condition and can send an indication of the detected condition to the safety state controller 146 via the digital interface. The safety state controller 146 can be configured to cause the driver circuit 140 to enter a failsafe state in response to detecting a problem in the operation of the driver circuit 140 that can require the driver circuit 140 to enter a failsafe state.
[0032] In some examples, the driver circuit 140 can receive a request to enter a failsafe state from the monitoring device 120 via the communication interface 142. In response to the driver circuit 140 receiving a request to enter a failsafe state, the safety state controller 146 can determine to cause the driver circuit 140 to enter a failsafe state.
[0033] According to the present disclosure, the driver circuit 140 includes a volatile memory 150 that is configured to store a failsafe configuration 122 for the driver circuit 140. The failsafe configuration 122 is information for configuring the driver circuit 140 and / or the power switch 154 to a particular failsafe configuration when the driver circuit 140 is in a failsafe state.
[0034] The volatile memory 150 can be any memory, such as random access memory (RAM), dynamic random access memory (DRAM), static random access memory (SRAM), etc., that requires continuous power to maintain stored information. Because the volatile memory 150 can require continuous power to maintain stored information, the volatile memory 150 is connected to multiple independent power sources. That is, two or more independent components of the system 100 can each be a voltage source for the volatile memory 150. In Figure 1 the example, the volatile memory 150 is connected to a "V BAT " voltage 112 provided by the energy panel network 110 and a "V DD " voltage 126 provided by the monitoring device 120. Connecting the volatile memory 150 to multiple independent voltage sources increases the reliability of the volatile memory 150 by ensuring that the volatile memory 150 is powered even if one of the multiple power sources connected to the volatile memory 150 stops providing power to the volatile memory 150.
[0035] To enter the fail-safe state, the safe state controller 146 is configured to block digital write communications from the master controller 130 to the communication interface 142. Blocking digital write communications from the master controller 130 to the communication interface 142 can protect the driver circuit 140 from receiving erroneous commands from the master controller 130.
[0036] To enter the fail-safe state, the safe state controller 146 can also configure the power switch 154 according to the fail-safe configuration 122 stored in the volatile memory 150. For example, the fail-safe configuration 122 can specify configuration information about the power switch 154, such as whether to turn the power switch 154 on or off (e.g., connect or disconnect the actuator 152 from the power switch 154). For example, if the actuator 152 is an actuator for a light of a vehicle, the fail-safe configuration 122 can configure the power switch 154 to turn the light of the vehicle on. In another example, if the actuator 152 is an actuator for a door lock of a vehicle, the fail-safe configuration 122 can configure the power switch 154 to unlock the door of the vehicle.
[0037] In some examples, as part of causing the drive circuit 140 to enter the fail-safe state, the safety state controller 146 can also configure the drive circuit 140 according to the fail-safe configuration 122. The fail-safe configuration 122 can include configuration information regarding various behaviors, speeds, and / or timings of the drive circuit 140 that the safety state controller 146 can apply to the drive circuit 140. In some examples, the fail-safe configuration 122 can include configuration information regarding the drive circuit 140 such as any combination of turn-on and turn-off slew rates, soft start / stop, control logic, rise time, fall time, propagation delay, dead time, delay timers, etc. of the drive circuit 140. The fail-safe configuration 122 can also include configuration information regarding various thresholds of the drive circuit 140 that the safety state controller 146 can apply to the drive circuit 140 such as overvoltage detection thresholds, undervoltage detection thresholds, overcurrent detection thresholds, undereurrent detection thresholds, temperature thresholds, etc.
[0038] In some examples, the powered drive circuit 140 can enter a power saving state, which is also referred to in this disclosure as a hibernate state. While the drive circuit 140 is in the power saving state, the volatile memory 150 is configured to receive a trickle power supply from one or more of the plurality of independent power sources connected to the volatile memory 150. That is, although one or more of the plurality of independent power sources connected to the volatile memory 150 can stop providing power while the drive circuit 140 is in the power saving state, another one or more of the plurality of independent power sources connected to the volatile memory 150 can reduce the amount of power provided to the volatile memory 150 to a trickle power supply. The trickle power supply can provide enough power to the volatile memory 150 to maintain information stored in the volatile memory 150 such as the fail-safe configuration 122.
[0039] The drive circuit 140 can also exit from the power saving state such as by transitioning from the power saving state to an active state (also referred to as an active mode or a full power mode). This can sometimes be referred to as waking up the drive circuit 140. For example, the drive circuit 140 can be configured to exit the power saving state in response to receiving a wake-up request while the drive circuit 140 is in the power saving state. The drive circuit 140 can receive the wake-up request from the monitoring device 120 and / or the host controller 130. The drive logic 144 of the drive circuit 140 can be configured to receive the wake-up request while the drive circuit 140 is in the power saving state and, in response, configure the drive circuit 140 according to the default start-up configuration of the drive circuit 140 stored in the volatile memory 150.
[0040] Similar to the failsafe configuration 122, the default startup configuration can include configuration information for configuring the power switch 154 and / or for configuring the driver circuit 140. For example, the default startup configuration can specify that the power switch 154 is turned on or turned off. The default startup configuration can also include configuration information regarding various behaviors, speeds, and / or timings of the driver circuit 140 that the driver logic 144 can apply to the driver circuit 140. In some examples, the default startup configuration can include configuration information regarding any combination of turn-on and turn-off slew rates, soft start / stop, control logic, rise time, fall time, propagation delay, dead time, delay timers, and the like of the driver circuit 140. The default startup configuration can also include configuration information regarding various thresholds of the driver circuit 140 that the driver logic 144 can apply to the driver circuit 140, such as overcurrent detection thresholds, undercurrent detection thresholds, overvoltage detection thresholds, undervoltage detection thresholds, and the like.
[0041] Upon startup of the driver circuit 140, such as when the driver circuit 140 is powered on, the communication interface 142 is configured to receive a digital write communication from the host controller 130 via the digital interface that specifies the failsafe configuration 122. The driver logic 144 can be configured to receive the failsafe configuration 122 from the communication interface 142 via one or more internal buses and write the received failsafe configuration 122 into the volatile memory 150. The driver logic 144 is configured to lock the volatile memory 150 in response to writing the failsafe configuration 122 into the volatile memory 150. Locking the volatile memory 150 can prevent any further changes, such as write commands or other operations, to the volatile memory 150 until the volatile memory 150 is unlocked.
[0042] Figure 2 is a block diagram of an example driver circuit 140 that is further detailed in Figure 1 FIG. 4. As shown in Figure 2 FIG. 4, the driver circuit 140 includes a power management unit 260, a communication interface 142, a driver logic 144, and a volatile memory 150.
[0043] The power management unit 260 includes circuitry configured to manage the delivery of power to other components, such as the driver logic 144 and the volatile memory 150 of the driver circuit 140. For example, the power management unit 260 can be configured to regulate and control the voltage applied to the power switch 154. The power management unit 260 can also be configured to protect the driver circuit 140, such as by providing overcurrent protection and overvoltage protection for the driver circuit 140. The power management unit 260 can also be configured to implement a power saving mode for the driver circuit 140, such as a sleep mode for the driver circuit 140.
[0044] In Figure 2 the example, the power management unit 260 is configured to connect to the energy panel network 110 and a plurality of independent power sources in the form of the monitoring device 120 to receive the “V BAT ” voltage 112 from the energy panel network 110 and the “V DD ” voltage 126 from the monitoring device 120. The power management unit 260 is configured to provide power received from the energy panel network 110 and the monitoring device 120 to the driver logic 144 and the volatile memory 150.
[0045] The power management unit 260 can be configured to provide power in the form of the always-on power supply voltage 262 and the digitally-switched power supply voltage 264. The power management unit 260 can be configured to supply the digitally-switched power supply voltage 264 during normal operation of the driver circuit 140, such as when the driver circuit 140 is in a full-power state. When the driver circuit 140 is in a power-saving state, such as a hibernate state, the power management unit 260 can be configured to stop supplying the digitally-switched power supply voltage 264. Similarly, the power management unit 260 can be configured to provide the always-on power supply voltage 262 as long as the power management unit 260 receives at least one of the “V BAT ” voltage 112 from the energy panel network 110 or the “V DD ” voltage 126 from the monitoring device 120.
[0046] The power management unit 260 is configured to supply both the always-on power supply voltage 262 and the digitally-switched power supply voltage 264 to the volatile memory 150 and to supply the digitally-switched power supply voltage 264 to the driver logic 144. In normal operation of the driver circuit 140, the power management unit 260 can be configured to supply the digitally-switched power supply voltage 264 and the always-on power supply voltage 262 to the driver logic 144 and the volatile memory 150. The power management unit 260 can be configured to supply the digitally-switched power supply voltage 264 to the volatile memory 150 for use in level-shifting voltage levels of the volatile memory 150 and can be configured to supply the always-on power supply voltage 262 to the volatile memory 150 for use in the volatile memory 150 maintaining stored information.
[0047] When the driver circuit 140 is in the sleep state, the power management unit 260 can stop supplying the digital switching supply voltage 264, which means that the power management unit 260 can stop supplying power to the driver logic 144 when the driver circuit 140 is in the sleep state. However, when the driver circuit 140 is in the sleep state, the power management unit 260 can continue to supply a trickle voltage supply to the volatile memory 150 in the form of the always-awake power supply voltage 262 to enable the volatile memory 150 to retain stored information in the volatile memory 150, such as the fail-safe configuration 122.
[0048] The communication interface 142 provides a digital interface for communicating with the host controller 130. The communication interface 142 can be configured to receive commands or other data from the host controller 130 from the digital interface and to send data, such as responses to received commands, to the host controller 130. The communication interface 142 can communicate with the driver logic 144 via one or more on-chip buses, such as by sending commands received from the host controller 130 to the driver logic 144 via an on-chip output bus and by receiving data from the driver logic 144 via an on-chip input bus.
[0049] The driver logic 144 is configured to control operation of the power switch 154, such as by sending signals to the power switch 154 to turn the power switch 154 on and off and to connect and disconnect the actuator 152 from a power source. The driver logic 144 is also configured to implement the safety state controller 146, which can be configured to determine whether to cause the driver circuit 140 to enter a fail-safe state and / or to perform operations to transition the driver circuit 140 to a fail-safe state.
[0050] In some examples, the safety state controller 146 is configured to cause the driver circuit 140 to enter a fail-safe state in response to detecting a problem in operation of the driver circuit 140. For example, the safety state controller 146 can be configured to detect that the driver circuit 140 is in an overvoltage condition, an undervoltage condition, an overcurrent condition, an undervoltage condition, an overheat condition, an open- circuit load condition, or other problems in operation of the driver circuit 140. The safety state controller 146 can be configured to cause the driver circuit 140 to enter a fail-safe state in response to detecting a problem in operation of the driver circuit 140.
[0051] In some examples, the communication interface 142 can include a digital interface for communicating with the monitoring device 120 to receive limp-home requests from the monitoring device 120. The communication interface 142 can pass any received limp-home requests to the safe state controller 146. The safe state controller 146 can be configured to cause the driver circuit 140 to enter a failsafe state in response to receiving a limp-home request from the monitoring device 120.
[0052] The driver logic 144 is connected to the volatile memory 150 via one or more internal buses to write data to and read data from the volatile memory 150, such as the failsafe configuration 122. To enter the failsafe state, the safe state controller 146 is configured to block digital write communications from the main controller 130 to the communication interface 142, which can protect the driver circuit 140 from receiving erroneous commands from the main controller 130.
[0053] To enter the failsafe state, the safe state controller 146 is also configured to read the failsafe configuration 122 from the volatile memory 150 and configure the driver circuit 140 and / or the power switch 154 according to the failsafe configuration 122. For example, the failsafe configuration 122 can specify configuration information regarding the power switch 154, such as whether to turn the power switch 154 on or off and / or whether to connect or disconnect the actuator 152 from a power source. The failsafe configuration 122 can also specify configuration information regarding various behaviors, speeds, and / or timings of the driver circuit 140, which the safe state controller 146 can apply to the driver circuit 140. Thus, the safe state controller 146 can be configured to configure the driver circuit 140 and / or the power switch 154 according to the failsafe configuration 122.
[0054] Because the volatile memory 150 can need continuous power to maintain stored information, the volatile memory 150 does not maintain stored information when the driver circuit 140 is off. Thus, during startup of the driver circuit 140, the driver circuit 140 can be configured to receive the failsafe state configuration 122 and write the failsafe state configuration 122 into the volatile memory 150.
[0055] At startup of the driver circuit 140, such as when the driver circuit 140 is powered on, the communication interface 142 is configured to receive a digital write communication from the host controller 130 specifying the failsafe configuration 122 via the digital interface. The driver logic 144 can be configured to receive the failsafe configuration 122 from the communication interface 142 via one or more internal buses and write the received failsafe configuration 122 into the volatile memory 150. The driver logic 144 is configured to lock the volatile memory 150 in response to writing the failsafe configuration 122 into the volatile memory 150. Locking the volatile memory 150 can prevent any further changes to the volatile memory 150, such as write commands or other operations, until the volatile memory 150 is unlocked.
[0056] The driver logic 144 is configured to check the integrity of the failsafe configuration 122 before or after writing the failsafe configuration 122 into the volatile memory 150. For example, the driver logic 144 can be configured to check the integrity of the failsafe configuration 122 before writing the failsafe configuration 122 into the volatile memory 150. If the driver logic 144 determines that the failsafe configuration 122 fails the integrity check, the driver logic 144 can be configured to refrain from writing the failsafe configuration 122 into the volatile memory 150 and send a request to the host controller 130 via the communication interface 142 to resend the failsafe configuration 122.
[0057] For example, the driver logic 144 can be configured to generate a checksum for the failsafe configuration 122 via any suitable technique, such as Fletcher's checksum, Adler-32, etc. The driver logic 144 can be configured to compare the generated checksum for the failsafe configuration 122 to a valid checksum for the failsafe configuration 122. For example, the digital write communication specifying the failsafe configuration 122, as received by the driver circuit 140, can include a valid checksum for the failsafe configuration 122. The driver logic 144 can be configured to compare the generated checksum for the failsafe configuration 122 to the valid checksum for the failsafe configuration 122 received as part of the digital write communication to check the integrity of the failsafe configuration 122. The driver logic 144 can be configured to write the failsafe configuration 122 into the volatile memory 150 in response to determining that the integrity of the failsafe configuration 122 is not compromised.
[0058] In some examples, the driver logic 144 can be configured to output the generated checksum for the failsafe configuration 122 to an external component, such as the monitoring device 120 or the host controller 130. The external component can be configured to, in response to receiving the generated checksum for the failsafe configuration 122, compare the generated checksum for the failsafe configuration 122 to a valid checksum for the failsafe configuration 122 to determine whether the failsafe configuration 122 has been correctly written to the volatile memory. Accordingly, the external component can be configured to send a signal to the driver circuit 140 indicating whether the generated checksum for the failsafe configuration 122 is valid. In response to the driver circuit 140 receiving the signal from the external component indicating that the generated checksum for the failsafe configuration 122 is valid, the driver logic 144 can write the failsafe configuration 122 to the volatile memory 150.
[0059] In another example, the driver logic 144 can be configured to, after writing the failsafe configuration 122 to the volatile memory 150, check the integrity of the failsafe configuration 122. If the driver logic 144 determines that the failsafe configuration 122 fails the integrity check, the driver logic 144 can be configured to delete the failsafe configuration 122 from the volatile memory 150 and send a request to the 130 via the communication interface 142 to resend the failsafe configuration 122.
[0060] In some examples, the driver logic 144 can be configured to compare the generated checksum for the failsafe configuration 122 to a valid checksum for the failsafe configuration 122. For example, the digital write communication specifying the failsafe configuration 122, as received by the driver circuit 140, can include a valid checksum for the failsafe configuration 122. The driver logic 144 can compare the generated checksum for the failsafe configuration 122 to the valid checksum for the failsafe configuration 122 received as part of the digital write communication to determine whether the failsafe configuration 122 has been correctly written to the volatile memory.
[0061] In some examples, the driver logic 144 can be configured to check whether the failsafe configuration 122 has been correctly written to the volatile memory 150. The driver logic 144 can perform the check before or after locking writes to the volatile memory 150. For example, the volatile memory 150 can be configured to, in response to the failsafe configuration 122 being written to the memory, generate a checksum for the failsafe configuration 122 using any suitable technique, such as by performing a cyclic redundancy check (CRC) on the portion of the volatile memory 150 to which the failsafe configuration 122 has been written.
[0062] In some examples, the driver logic 144 can be configured to output the generated checksum for the failsafe configuration 122 to an external component, such as the monitoring device 120 or the host controller 130. The external component can be configured to, in response to receiving the generated checksum for the failsafe configuration 122, compare the generated checksum for the failsafe configuration 122 to a valid checksum for the failsafe configuration 122 to determine whether the failsafe configuration 122 has been correctly written into the volatile memory. Thus, the external component can be configured to send a signal to the driver circuit 140 indicating whether the generated checksum for the failsafe configuration 122 is valid.
[0063] In some examples, the driver circuit 140 can be configured to protect writes to the volatile memory 150. That is, the driver logic 144 can be configured to, in response to receiving a request to write data into the volatile memory 150, determine whether the request specifies a valid password. Such a password can be stored in a read-only memory (not shown) of the driver circuit 140. The driver logic 144 can be configured to, in response to determining that the request specifies a valid password, unlock the volatile memory 150 for writing data into the volatile memory 150.
[0064] In some examples, the valid password can be in the form of a specific write pattern to a specific register and / or a specific location in the volatile memory 150. Such a specified write pattern can be a write pattern of specific data to a specific register and / or a specific location in the volatile memory 150. The driver circuit 140 can be configured to receive a request to write data into the volatile memory 150, such as from the monitoring device 120 or the host controller 130, that specifies a write pattern to a specific register and / or a specific location in the volatile memory 150. The driver logic 144 can be configured to, in response to receiving the request to write data into the volatile memory 150, determine whether the write pattern specified by the request matches a specified write pattern, such as stored in a ROM of the driver circuit 140. The driver logic 144 can be configured to, in response to determining that the write pattern specified by the request matches the specified write pattern to unlock the volatile memory, unlock the volatile memory 150 for writing data into the volatile memory 150.
[0065] In some examples, the driver circuit 140 can enter a power saving state, also referred to in this disclosure as a hibernate state. For example, the driver logic 144 can be configured to determine whether the driver circuit 140 has been idle for an amount of time that exceeds an idle threshold, such as one minute, five minutes, etc. In response to determining that the driver circuit 140 has been idle for an amount of time that exceeds the idle threshold, the driver logic 144 can operate to transition the driver circuit 140 to the power saving state.
[0066] While the driver circuit 140 is in the power saving state, the volatile memory 150 is configured to receive a trickle power supply from one or more of a plurality of independent power sources connected to the volatile memory 150. For example, the power management unit 260 can be configured to receive the trickle power supply from one of the “V BAT ” voltage 112 or the “V DD ” voltage 126. The trickle power supply can provide sufficient power to the volatile memory 150 to maintain information stored in the volatile memory 150, such as the fail-safe configuration 122.
[0067] The driver circuit 140 can also exit from the power saving state, such as by transitioning from the power saving state to an active state, also referred to as an active mode or a full power mode. This can sometimes be referred to as waking up the driver circuit 140. For example, the driver circuit 140 can be configured to exit from the power saving state in response to receiving a wake-up request while the driver circuit 140 is in the power saving state. The driver circuit 140 can receive the wake-up request from the monitoring device 120 and / or the host controller 130. The driver logic 144 of the driver circuit 140 can be configured to receive the wake-up request while the driver circuit 140 is in the power saving state, and in response, configure the driver circuit 140 according to a default start-up configuration for the driver circuit 140 stored in the volatile memory 150.
[0068] Similar to the fail-safe configuration 122, the default start-up configuration can include configuration information for configuring the power switch 154 and / or for configuring the driver circuit 140. For example, the default start-up configuration can specify that the power switch 154 is turned on or turned off.
[0069] The default startup configuration can also include configuration information regarding various behaviors, speeds, and / or timings of the driver circuit 140 that the driver logic 144 can apply to the driver circuit 140. In some examples, the default startup configuration can include configuration information regarding any combination of turn-on and turn-off slew rates, soft start / stop, control logic, rise time, fall time, propagation delay, dead time, delay timer, etc. of the driver circuit 140. The default startup configuration can also include configuration information regarding various thresholds of the driver circuit 140 that the driver logic 144 can apply to the driver circuit 140, such as overcurrent detection thresholds, undervoltage detection thresholds, etc.
[0070] Figure 3 is a flowchart illustrating a method of configuring a driver circuit according to the present disclosure. The method will be described from the perspective of the driver circuit 140 as shown in Figure 1 and Figure 2 The method will be described from the perspective of the driver circuit 140 as shown in Figure 3 , although the method can be applied to various other driver circuits.
[0071] As shown in Figure 3 , the driver circuit 140 can store a failsafe configuration 122 for the driver circuit 140 in a volatile memory 150 of the driver circuit 140, the volatile memory 150 being connected to the plurality of independent power supplies 112 and 126 (302).
[0072] In some examples, in response to a startup of the driver circuit 140, the driver circuit 140 can receive a digital write communication from the host controller 130 specifying the failsafe configuration 122. The driver circuit 140 can write the failsafe configuration 122 to the volatile memory 150, and can lock the volatile memory 150 in response to writing the failsafe configuration 122 to the volatile memory 150.
[0073] In some examples, to receive the digital write communication specifying the failsafe configuration 122, the driver circuit 140 can receive a write pattern (e.g., a write operation) to the volatile memory 150 from the host controller 130. The driver circuit 140 can determine that the write pattern matches a specified write pattern that unlocks the volatile memory 150. In response to determining that the write pattern matches the specified write pattern, the driver circuit 140 can unlock the volatile memory 150.
[0074] In some examples, to write the failsafe configuration into the volatile memory 150, in response to receiving a digital write communication specifying the failsafe configuration 122, the driver circuit 140 can determine a checksum of the failsafe configuration 122. The driver circuit 140 can output the checksum of the failsafe configuration to the monitoring device 120. In response to outputting the checksum of the failsafe configuration 122 to the monitoring device 120, the driver circuit 140 can receive a signal from the monitoring device 120 indicating that the checksum of the failsafe configuration 122 is valid. In response to receiving the signal indicating that the checksum of the failsafe configuration 122 is valid, the driver circuit 140 can write the failsafe configuration 122 into the volatile memory 150.
[0075] The driver circuit 140 can determine to enter a failsafe state (304). In some examples, to determine to enter the failsafe state, the driver circuit 140 can receive a request to enter the failsafe state. In response to receiving the request to enter the failsafe state, the driver circuit 140 can enter the failsafe state. In some examples, to receive the request to enter the failsafe state, the driver circuit 140 can receive a limp-home request from the monitoring device 120 indicating a failure of the host controller 130 controlling the driver circuit 140. In some examples, in response to receiving the request to enter the failsafe state, the driver circuit 140 can block digital write communications to the volatile memory 150.
[0076] In response to determining to enter the failsafe state, the driver circuit 140 can configure the driver circuit 140 or the power switch 154 according to the failsafe configuration 122 stored in the volatile memory 150 (306).
[0077] In some examples, when the driver circuit 140 is in a hibernation state, the volatile memory 150 receives a trickle supply from one of the plurality of independent power sources 112 and 126. In some examples, the volatile memory 150 stores a default startup configuration for the driver circuit 140. While the driver circuit 140 is in the hibernation state, the driver circuit 140 can receive a wake-up request. In response to receiving the wake-up request, the driver circuit 140 can configure the driver circuit 140 or the power switch 154 according to the default startup configuration stored in the volatile memory 150. In some examples, the power switch 154 is configured to control power provided to an actuator 152 in a vehicle.
[0078] The following clauses can illustrate one or more aspects of the present disclosure.
[0079] Clause 1. A driver circuit comprising: a volatile memory connected to a plurality of independent power supplies, the volatile memory configured to store a failsafe configuration for the driver circuit; and driver logic connected to the volatile memory, the driver logic configured to: determine to enter a failsafe state; and in response to determining to enter the failsafe state, configure the driver circuit or a power switch in accordance with the failsafe configuration stored in the volatile memory.
[0080] Clause 2. The driver circuit of clause 1, wherein the driver logic is further configured to: in response to a start-up of the driver circuit, receive a digital write communication from a host controller specifying the failsafe configuration; write the failsafe configuration into the volatile memory; and in response to writing the failsafe configuration into the volatile memory, lock the volatile memory.
[0081] Clause 3. The driver circuit of clause 2, wherein to receive the digital write communication specifying the failsafe configuration, the driver logic is configured to: receive a write mode from the host controller to the volatile memory; determine that the write mode matches a specified write mode that unlocks the volatile memory; and in response to determining that the write mode matches the specified write mode, unlock the volatile memory.
[0082] Clause 4. The driver circuit of any of clauses 2 or 3, wherein to write the failsafe configuration into the volatile memory, the driver logic is further configured to: in response to receiving the digital write communication specifying the failsafe configuration, determine a checksum of the failsafe configuration; output the checksum of the failsafe configuration to a monitoring device; in response to outputting the checksum of the failsafe configuration to the monitoring device, receive a signal from the monitoring device indicating that the checksum of the failsafe configuration is valid; and in response to receiving the signal indicating that the checksum of the failsafe configuration is valid, write the failsafe configuration into the volatile memory.
[0083] Clause 5. The driver circuit of any of clauses 1-4, wherein to determine to enter the failsafe state, the driver circuit is configured to: receive a request to enter the failsafe state; and in response to receiving the request to enter the failsafe state, enter the failsafe state.
[0084] Clause 6. The driver circuit of clause 5, wherein to receive the request to enter the failsafe state, the driver logic is configured to: receive a limp-home request from a monitoring device indicating a failure of a host controller that controls the driver circuit.
[0085] Clause 7. The driver circuit of any of clauses 5 and 6, wherein the driver logic is further configured to: in response to receiving the request to enter the failsafe state, block digital write communications to the volatile memory.
[0086] Clause 8. The driver circuit of any one of clauses 1-7, wherein the volatile memory is configured to receive the trickle source from one of the plurality of independent power sources while the driver circuit is in the dormant state.
[0087] Clause 9. The driver circuit of clause 8, wherein the volatile memory is configured to store a default startup configuration for the driver circuit; and wherein the driver logic is further configured to: receive a wake-up request while the driver circuit is in the dormant state; and in response to receiving the wake-up request, configure the driver circuit or the power switch in accordance with the default startup configuration stored in the volatile memory.
[0088] Clause 10. The driver circuit of any one of clauses 1-9, wherein the power switch is configured to control power supplied to an actuator in a vehicle.
[0089] Clause 11. A method comprising: storing, in a volatile memory of a driver circuit, a failsafe configuration for the driver circuit, the volatile memory connected to a plurality of independent power sources; determining, by the driver circuit, entry into a failsafe state; and in response to determining entry into the failsafe state, configuring, by the driver circuit, the driver circuit or a power switch in accordance with the failsafe configuration stored in the volatile memory.
[0090] Clause 12. The method of clause 11, further comprising: in response to startup of the driver circuit, receiving, by the driver circuit, a digital write communication from a host controller specifying the failsafe configuration; writing, by the driver circuit, the failsafe configuration into the volatile memory; and in response to writing the failsafe configuration into the volatile memory, locking, by the driver circuit, the volatile memory.
[0091] Clause 13. The method of clause 12, wherein receiving the digital write communication specifying the failsafe configuration further comprises: receiving, by the driver circuit, a write mode for the volatile memory from the host controller; determining, by the driver circuit, that the write mode matches a specified write mode that unlocks the volatile memory; and in response to determining that the write mode matches the specified write mode, unlocking, by the driver circuit, the volatile memory.
[0092] Clause 14. The method of any of clauses 12 or 13, wherein writing the failsafe configuration into the volatile memory further comprises: in response to receiving the digital write communication specifying the failsafe configuration, determining, by the driver circuit, a checksum of the failsafe configuration; outputting, by the driver circuit, the checksum of the failsafe configuration to the monitoring device; in response to outputting the checksum of the failsafe configuration to the monitoring device, receiving, by the driver circuit from the monitoring device, a signal indicating that the checksum of the failsafe configuration is valid; and in response to receiving the signal indicating that the checksum of the failsafe configuration is valid, writing, by the driver circuit, the failsafe configuration into the volatile memory.
[0093] Clause 15. The method of any of clauses 11 to 14, wherein determining to enter the failsafe state further comprises: receiving, by the driver circuit, a request to enter the failsafe state; and in response to receiving the request to enter the failsafe state, entering, by the driver circuit, the failsafe state.
[0094] Clause 16. The method of clause 15, wherein receiving the request to enter the failsafe state further comprises: receiving, by the driver circuit from the monitoring device, a limp-home request indicating a failure of a host controller controlling the driver circuit.
[0095] Clause 17. The method of any of clauses 15 or 16, further comprising: in response to receiving the request to enter the failsafe state, blocking digital write communications to the volatile memory.
[0096] Clause 18. The method of any of clauses 11 to 17, wherein the volatile memory receives a trickle source from one of the plurality of independent power sources when the driver circuit is in the hibernation state.
[0097] Clause 19. The method of clause 18, wherein the volatile memory stores a default startup configuration for the driver circuit, further comprising: receiving, by the driver circuit, a wake-up request when the driver circuit is in the hibernation state; and in response to receiving the wake-up request, configuring, by the driver circuit, the driver circuit or the power switch according to the default startup configuration stored in the volatile memory.
[0098] Clause 20. The method of any of clauses 11 to 19, wherein the power switch is configured to control power supplied to an actuator in the vehicle.
[0099] Clause 21. A system comprising: an actuator; a power switch configured to control power supplied to the actuator; a driver circuit configured to control the power switch; a host controller configured to control the driver circuit; and a watchdog device configured to: detect a fault in the host controller; and in response to detecting the fault in the host controller, send a request to enter a failsafe state to the driver circuit; wherein the driver circuit comprises: a volatile memory connected to a plurality of independent power sources, the volatile memory configured to store a failsafe configuration for the driver circuit; and a driver logic connected to the volatile memory, the driver logic configured to: receive the request to enter the failsafe state; and in response to receiving the request to enter the failsafe state, configure the driver circuit or the power switch according to the failsafe configuration stored in the volatile memory.
[0100] Various aspects are described in this disclosure. These and other aspects are within the scope of the following claims.
Claims
1. A driver circuit comprising: a volatile memory connected to a plurality of independent power sources, the volatile memory configured to store a failsafe configuration for the driver circuit; and driver logic connected to the volatile memory, the driver logic configured to: determine to enter a failsafe state; and in response to determining to enter the failsafe state, configure the driver circuit or a power switch according to the failsafe configuration stored in the volatile memory.
2. The driver circuit of claim 1, wherein the driver logic is further configured to: in response to a start-up of the driver circuit, receive a digital write communication from a host controller specifying the failsafe configuration; write the failsafe configuration into the volatile memory; and in response to writing the failsafe configuration into the volatile memory, lock the volatile memory.
3. The driver circuit of claim 2, wherein to receive the digital write communication specifying the failsafe configuration, the driver logic is configured to: receive a write mode from the host controller to the volatile memory; determine that the write mode matches a specified write mode to unlock the volatile memory; and in response to determining that the write mode matches the specified write mode, unlock the volatile memory.
4. The driver circuit of claim 2, wherein to write the failsafe configuration into the volatile memory, the driver logic is further configured to: in response to receiving the digital write communication specifying the failsafe configuration, determine a checksum of the failsafe configuration; output the checksum of the failsafe configuration to a monitoring device; in response to outputting the checksum of the failsafe configuration to the monitoring device, receive a signal from the monitoring device indicating that the checksum of the failsafe configuration is valid; and in response to receiving the signal indicating that the checksum of the failsafe configuration is valid, write the failsafe configuration into the volatile memory.
5. The driver circuit of claim 1, wherein to determine to enter the failsafe state, the driver circuit is configured to: receive a request to enter the failsafe state; and in response to receiving the request to enter the failsafe state, enter the failsafe state.
6. The driver circuit of claim 5, wherein to receive the request to enter the failsafe state, the driver logic is configured to: receive a limp request from a monitoring device indicating a failure of a host controller controlling the driver circuit.
7. The driver circuit of claim 5, wherein the driver logic is further configured to: in response to receiving the request to enter the failsafe state, block digital write communications to the volatile memory. 8. The driver circuit of claim 1, wherein the volatile memory is configured to receive a trickle source from one of the plurality of independent power sources while the driver circuit is in a hibernation state.
9. The driver circuit of claim 8, wherein the volatile memory is configured to store a default startup configuration for the driver circuit; and wherein the driver logic is further configured to: receive a wake-up request while the driver circuit is in the hibernation state; and configure the driver circuit or the power switch according to the default startup configuration stored in the volatile memory in response to receiving the wake-up request.
10. The driver circuit of claim 1, wherein the power switch is configured to control power supplied to an actuator in a vehicle.
11. A method comprising: storing a failsafe configuration for a driver circuit in a volatile memory of the driver circuit, the volatile memory connected to a plurality of independent power sources; determining, by the driver circuit, to enter a failsafe state; and configuring, by the driver circuit, the driver circuit or a power switch according to the failsafe configuration stored in the volatile memory in response to determining to enter the failsafe state.
12. The method of claim 11, further comprising: receiving, by the driver circuit from a host controller, a digital write communication specifying the failsafe configuration in response to startup of the driver circuit; writing, by the driver circuit, the failsafe configuration into the volatile memory; and locking, by the driver circuit, the volatile memory in response to writing the failsafe configuration into the volatile memory.
13. The method of claim 12, wherein receiving the digital write communication specifying the failsafe configuration further comprises: receiving, by the driver circuit from the host controller, a write mode for the volatile memory; determining, by the driver circuit, that the write mode matches a specified write mode that unlocks the volatile memory; and unlocking, by the driver circuit, the volatile memory in response to determining that the write mode matches the specified write mode.
14. The method of claim 12, wherein writing the failsafe configuration into the volatile memory further comprises: determining, by the driver circuit, a checksum for the failsafe configuration in response to receiving the digital write communication specifying the failsafe configuration; outputting, by the driver circuit, the checksum for the failsafe configuration to a monitoring device; receiving, by the driver circuit from the monitoring device, a signal indicating that the checksum for the failsafe configuration is valid in response to outputting the checksum for the failsafe configuration to the monitoring device; and writing, by the driver circuit, the failsafe configuration into the volatile memory in response to receiving the signal indicating that the checksum for the failsafe configuration is valid.
15. The method of claim 11, wherein determining to enter the failsafe state further comprises: receiving, by the driver circuit, a request to enter the failsafe state; and entering, by the driver circuit, the failsafe state in response to receiving the request to enter the failsafe state.
16. The method of claim 15, wherein receiving the request to enter the failsafe state further comprises: receiving, by the driver circuit, a limp-home request from a monitoring device indicating a failure of a host controller that controls the driver circuit.
17. The method of claim 11, wherein the volatile memory receives a trickle source from one of the plurality of independent power sources when the driver circuit is in a hibernation state.
18. The method of claim 17, wherein the volatile memory stores a default startup configuration for the driver circuit, further comprising: receiving, by the driver circuit, a wake-up request when the driver circuit is in the hibernation state; and configuring, by the driver circuit, the driver circuit or the power switch according to the default startup configuration stored in the volatile memory in response to receiving the wake-up request.
19. The method of claim 11, wherein the power switch is configured to control power supplied to an actuator in a vehicle.
20. A system comprising: an actuator; a power switch configured to control power supplied to the actuator; a driver circuit configured to control the power switch; a host controller configured to control the driver circuit; and a monitoring device configured to: detect a failure in the host controller; and send a request to enter a failsafe state to the driver circuit in response to detecting the failure in the host controller; wherein the driver circuit comprises: a volatile memory connected to a plurality of independent power sources, the volatile memory configured to store a failsafe configuration for the driver circuit; and driver logic connected to the volatile memory, the driver logic configured to: receive a request to enter a failsafe state; and configure the driver circuit or the power switch according to the failsafe configuration stored in the volatile memory in response to receiving the request to enter the failsafe state.