Software safety architecture for a commercial vehicle electromechanical brake control system
By employing a software safety architecture with dual redundancy, and a functional layer and functional monitoring layer that monitor and handle faults in real time, the safety deficiencies of electromechanical braking systems are resolved, achieving redundant control and driving safety under fault conditions.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHAANXI HEAVY DUTY AUTOMOBILE CO LTD
- Filing Date
- 2024-12-02
- Publication Date
- 2026-06-02
AI Technical Summary
Electromechanical braking systems may fail to brake or brake unexpectedly while the vehicle is in motion, resulting in insufficient safety and stability, and posing a risk of traffic accidents and loss of life.
The software safety architecture, which adopts a dual-redundancy design, includes a functional layer and a functional monitoring layer. Safety redundancy is achieved through two independent control units to ensure the integrity and rationality of signals, monitor and handle faults in real time, and coordinate the various functions of the braking system.
It improves the safety and reliability of the electromechanical braking system, enabling redundant control in case of failure, avoiding brake failure, and ensuring driving safety.
Smart Images

Figure CN122126237A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of automotive chassis electronic control, and particularly relates to a software security architecture for an electromechanical braking control system for commercial vehicles. Background Technology
[0002] Electromechanical braking systems (EMBs), as the latest generation of brake-by-wire systems, use an electric motor to drive the end-effector for braking. They are characterized by their small size, light weight, faster response, and higher efficiency. EMBs are directly related to vehicle safety and stability. If the EMB control system fails to brake or brakes unexpectedly while the vehicle is in motion, it can cause traffic accidents or even endanger lives. Therefore, improving the safety and reliability of EMB systems is crucial. Summary of the Invention
[0003] To address the aforementioned safety deficiencies, this invention proposes an EMB software safety architecture. Based on two independent control units, a safety redundancy mechanism is designed. This architecture includes a functional layer and a functional monitoring layer. The functional layer responds to driver needs and coordinates anti-lock braking, vehicle stability control, and traction control modules to respond to malfunctions. The functional monitoring layer monitors the functional layer in real time, detecting functional anomalies. This architecture can coordinate and control all functions of the electromechanical braking system, while simultaneously monitoring for and rapidly addressing defects. Even in the event of functional failure, redundant control can still be maintained.
[0004] This invention is achieved using the following technical solution:
[0005] This invention proposes a software safety architecture for an electromechanical braking control system for commercial vehicles. It ensures safety redundancy through two independent control units and includes a functional layer and a functional monitoring layer. The functional layer includes the functions and scheduling of each system module and a fault handling module. The functional monitoring layer realizes real-time monitoring of EMB software defects, ensures the integrity and rationality of signals, and captures functional anomalies.
[0006] The commercial vehicle electromechanical braking system described in this invention adopts a dual-redundancy design, containing two independent control links, including independent high and low voltage power supplies, independent bus design, independent signal acquisition, control unit 1, control unit 2, EMB actuators, and other components. Specifically, the power supply consists of two independent high-voltage power supplies, one for the EMB actuator and one for the control unit and actuator, respectively. The independent signal acquisition module includes two redundant brake pedal signal acquisitions, two independent parking switch signal acquisitions, two wheel speed sensor signal acquisitions connected to control units 1 and 2 respectively, and signal acquisitions from the yaw angle sensor, steering wheel angle sensor, and vehicle signals. The EMB actuator is a high-voltage-based control mechanism, including an electric brake and an electric brake control unit; each wheel is equipped with one EMB actuator. Both the main and auxiliary EMB control units can receive relevant signals, perform functional layer calculations, and control the EMB actuators.
[0007] The software security architecture described is a redundant design, with two independent control units implementing the system in a dual-redundant configuration, each control unit capable of independent control and execution.
[0008] Based on the E-GAS architecture, a detailed architecture conforming to the electromechanical braking system is designed. Both control units feature a two-layer architecture: a functional layer and a functional monitoring layer. The functional layer includes functions such as EMB system vehicle state estimation, brake coordination control, actuator control, and fault handling. The brake coordination control module coordinates and controls a series of functions including braking, parking, anti-lock braking, vehicle stability, and traction control based on driver needs and vehicle state. The functional monitoring layer monitors the functional layer in real time, ensuring signal integrity and rationality, detecting functional anomalies, and outputting relevant fault signals to the functional layer for corresponding actions by the fault handling module. When control unit 2 detects a fault in control unit 1, control unit 2 takes over control.
[0009] Meanwhile, the vehicle control system monitors the operation of control unit 1 and control unit 2. If both control unit 1 and control unit 2 are found to have serious malfunctions and cannot perform braking, the vehicle control system can receive the brake pedal switch signal and implement negative torque braking control to the drive motor to ensure emergency braking is still possible even if both control unit 1 and control unit 2 fail.
[0010] The functional layer architecture specifically includes vehicle state estimation, braking demand calculation, anti-lock braking module, vehicle stability control module, drive anti-slip control, actuator control, and fault handling modules. The vehicle state estimation module includes core parameter estimations such as vehicle speed, slip ratio, and vehicle weight. The braking demand torque calculation, based on inputs from the brake pedal and parking switch, outputs braking demand according to deceleration control and braking force distribution strategies. The anti-lock braking module, based on vehicle slip ratio, wheel deceleration, and other parameters, combined with the anti-lock control strategy, sends commands to the EMB actuators to increase, decrease, or maintain braking force. The vehicle stability control module determines whether the vehicle is currently in a stable state; if not, it issues control commands to return the vehicle to a stable state by reducing speed and adjusting vehicle posture. The drive anti-slip module controls the actuators to help the vehicle escape when wheels slip. The fault handling module receives alarm signals from the functional monitoring layer and takes corresponding response measures to ensure driving safety.
[0011] The aforementioned functional monitoring layer detects software defects in the functional layer, determines whether the functional layer is operating normally, and quickly locates and reports the cause of the fault to the diagnostic system. The functional monitoring layer includes three modules: input monitoring, process monitoring, and output monitoring. Its function is to monitor the data flow and causes of functional failures within the functional layer. As a monitoring module, adding this module allows for rapid fault location. The signal verification module verifies the integrity, effective range, and rationality of externally input safety-related signals, and then outputs them to the process monitoring module and output monitoring module of the functional layer and functional monitoring layer, respectively. The process monitoring module performs closed-loop real-time monitoring of key signals that need to be monitored in the functional layer and the signals output by the signal verification module, verifying and monitoring these signals to avoid problems such as abnormal signal states, abrupt changes, or discontinuities. The output monitoring module performs closed-loop real-time monitoring of the output results or CAN messages, hard-wired drive outputs, and the final execution status of the actuators in the functional layer.
[0012] The signal input and detection module includes a brake pedal signal acquisition module, a parking switch signal acquisition module, a wheel speed sensor signal acquisition module, a yaw angle sensor acquisition module, and a steering wheel angle sensor signal acquisition module. Each signal is transmitted to EMB control unit 1 and control unit 2 via hardwired wiring or a bus. Specifically, the brake pedal signal acquisition module provides two independent brake pedal signals, each input to one of the two control units; similarly, the parking switch signal acquisition module provides two independent parking signals, each input to one of the two EMB control units; the wheel speed sensor signal acquisition module corresponds to each wheel, acquiring the wheel speed signal of its corresponding wheel and transmitting it to the two EMB control units; the yaw angle sensor acquisition module acquires the vehicle's yaw rate, longitudinal acceleration, and lateral acceleration; and the steering wheel angle sensor acquisition module acquires the steering wheel angle, all inputting these values to the EMB control units.
[0013] The vehicle state estimation module includes a vehicle speed estimation module, a slip ratio estimation module, and a theoretical yaw rate estimation module. Based on the wheel speeds of each wheel calculated by the signal processing module, the Kalman filter algorithm is used to estimate the overall vehicle speed and slip ratio in real time. Based on the overall vehicle parameters and vehicle dynamics, the vehicle weight is estimated in real time. The theoretical yaw rate is estimated using a yaw rate estimation method.
[0014] The braking coordination control module includes a deceleration control module, a braking force distribution module, a vehicle stability control module, an anti-lock braking module, and a drive anti-skid control module.
[0015] The deceleration control module outputs braking requirements based on the brake pedal, parking switch, throttle information, gear information, and deceleration requests from the functional monitoring layer input monitoring module, and the vehicle weight and speed information calculated by the vehicle attitude estimation module, according to the deceleration control and braking force distribution strategy. It divides these requirements into service braking, parking braking, emergency braking, and superimposed braking, calculates the driver's braking requirements in different modes, and outputs the braking torque requirements to the braking force distribution module.
[0016] The braking force distribution module calculates the front and rear braking force distribution ratio based on the vehicle's actual deceleration and braking torque, according to the vehicle's status information, and distributes the vehicle's total braking force demand to the front, middle and rear axles according to the proportional relationship, so that the vehicle's braking force can reach the ideal braking force distribution relationship as much as possible.
[0017] The vehicle stability control module determines whether the vehicle is in a stable state by using the steering angle signal, yaw rate, lateral acceleration, and theoretical yaw rate signal. If the vehicle is not in a stable state, it issues a control command. The control unit controls the EMB actuator to apply braking force to the corresponding wheels, thereby reducing the vehicle speed and adjusting the vehicle's posture to bring the vehicle back to a stable state.
[0018] The anti-lock braking module compares the actual slip ratio and the ideal slip ratio obtained by the vehicle attitude estimation module, and combines the wheel acceleration according to the anti-lock strategy. Based on the braking requirements of the vehicle stability control and braking force distribution modules, it controls the actuator to increase, decrease, and maintain the braking force. By adjusting the magnitude of the braking torque, it ensures that the vehicle utilizes the ground adhesion to the maximum extent during braking, so that the vehicle obtains the best braking distance and stability, and ensures driving safety.
[0019] The drive anti-slip module helps the vehicle get out of trouble by controlling the actuator when the wheels slip. The fault handling module receives alarm signals from the functional monitoring layer and takes corresponding response measures to ensure driving safety.
[0020] The actuator control module controls the actuator to respond according to the braking requests issued by each module;
[0021] The fault handling module responds differently to different fault signals output by the functional monitoring layer.
[0022] Compared with the prior art, the present invention has the following beneficial effects:
[0023] 1. The software security architecture of the commercial vehicle electromechanical braking control system described in this invention includes a functional layer and a functional monitoring layer. The functional monitoring layer realizes real-time monitoring of EMB software defects, ensures the integrity and rationality of signals, captures functional anomalies, and collects safety measures. It can accurately locate faults and respond in a timely manner to ensure the safety of the EMB system.
[0024] 2. The braking control system software architecture adopts a dual-processing unit control redundancy architecture. The entire power supply, bus, and control unit are all independently redundant. The brake switch and parking switch have two independent signal inputs to the two control units. The system has higher redundancy protection function. The braking system failure problem is solved through two independent braking links, which improves the safety and reliability of the system.
[0025] 3. The aforementioned functional layer can simultaneously integrate anti-lock braking system, vehicle stability control system, drive anti-skid system, etc., with high integration and collaborative control. Attached Figure Description
[0026] Appendix Figure 1 This is a schematic diagram of the safety architecture of the commercial vehicle electromechanical braking control system of the present invention;
[0027] Appendix Figure 2 This is a detailed architectural block diagram of the safety architecture of the commercial vehicle electromechanical braking control system of the present invention;
[0028] Appendix Figure 3A flowchart for verifying bus message signals in the input monitoring module;
[0029] Appendix Figure 4 A flowchart for verifying analog signals in the input monitoring module;
[0030] Appendix Figure 5 This is a schematic diagram of the process monitoring module.
[0031] Appendix Figure 6 A schematic diagram of the output monitoring module;
[0032] Appendix Figure 7 A flowchart for the functional monitoring layer of the vehicle braking process;
[0033] Appendix Figure 8 Flowchart for the functional monitoring layer of the Vehicle Stability Control (ESC) system
[0034] Appendix Figure 9 This is a schematic diagram of the structure of the commercial vehicle electromechanical braking control system of the present invention; Detailed Implementation
[0035] To enable those skilled in the art to better understand the technical solutions of this invention, the technical solutions of the embodiments of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this invention, and not all embodiments. Based on the embodiments of this invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this invention.
[0036] Definitions of abbreviations and key terms:
[0037] EMB: Electromechanical Braking; ABS: Anti-lock Braking System; ESC: Electronic Stability Control System.
[0038] Example 1:
[0039] like Figure 1 As shown, the safety architecture of the commercial vehicle electromechanical braking control system provided by the present invention consists of two independent control units, each of which includes a functional layer and a functional monitoring layer.
[0040] like Figure 1 As shown, the functional layer includes a signal input and detection module, a vehicle state estimation module, a braking coordination control module, an actuator control module, and a fault handling module.
[0041] The functional monitoring layer comprises three modules: an input monitoring module, a process monitoring module, and an output monitoring module. It monitors the data flow and causes of functional failures within the EMB functional layer, enabling rapid fault location. The core of the functional monitoring layer's defect detection process is designing a method to determine whether the functional layer is operating normally. Analysis shows that the EMB's safety objectives are to prevent service brake failure, prevent service brake malfunctions, prevent ABS false activation, and prevent ESC false activation. Therefore, the main purpose of the functional monitoring layer is to perform real-time monitoring and diagnosis of the operating status, input and output status of modules such as the service brake module, anti-lock braking system (ABS) module, and vehicle stability control, and to quickly locate and determine the causes of faults, reporting them to the diagnostic system for repair and safety measures.
[0042] like Figure 2 As shown, the signal input and detection module includes a brake pedal signal acquisition module, a parking switch signal acquisition module, a wheel speed sensor signal acquisition module, a yaw angle sensor acquisition module, and a steering wheel angle sensor signal acquisition module. Each signal is transmitted to EMB control units 1 and 2 via hardwired connections or a bus. Specifically, the brake pedal signal acquisition module provides two independent brake pedal signals, each input to one of the two control units; similarly, the parking switch signal acquisition module provides two independent parking signals, each input to one of the two EMB control units; the wheel speed sensor signal acquisition module corresponds to each wheel, acquiring the wheel speed signal of its corresponding wheel and transmitting it to the two EMB control units; the yaw angle sensor acquisition module acquires the vehicle's yaw rate, longitudinal acceleration, and lateral acceleration; and the steering wheel angle sensor acquisition module acquires the steering wheel angle, all inputting them to the EMB control units.
[0043] The vehicle state estimation module includes a vehicle speed estimation module, a slip ratio estimation module, and a yaw rate estimation module. Based on the wheel speeds of each wheel calculated by the signal processing module, the Kalman filter algorithm is used to estimate the overall vehicle speed and slip ratio in real time. Based on the overall vehicle parameters and vehicle dynamics, the vehicle weight is estimated in real time. The theoretical yaw rate is estimated using the patented CN 113911130 B yaw rate calculation algorithm.
[0044] The braking coordination control module includes a deceleration control module, a braking force distribution module, a vehicle stability control module, an anti-lock braking module, and a drive anti-skid control module.
[0045] The deceleration control module outputs braking requirements based on the brake pedal, parking switch input, accelerator pedal opening, gear information, and deceleration demand from the functional monitoring layer input monitoring module, and the vehicle weight and speed information calculated by the vehicle state estimation module, according to the deceleration control and braking force distribution strategy. It divides these requirements into service braking, parking braking, emergency braking, and superimposed braking, calculates the driver's braking requirements in different modes, and outputs the braking torque requirements to the braking force distribution module.
[0046] The braking force distribution module calculates the front and rear braking force distribution ratio based on the vehicle's actual deceleration, braking torque, and vehicle status information, and distributes the vehicle's total braking force demand to the front, middle, and rear axles according to the proportional relationship, so that the vehicle's braking force can reach the ideal braking force distribution relationship as much as possible.
[0047] The vehicle stability control module uses signals such as steering angle signal, yaw rate, lateral acceleration, and theoretical yaw rate signal to determine whether the vehicle is in a stable state. If it is not in a stable state, it issues a control command. The control unit controls the EMB actuator to apply braking force to the corresponding wheels, thereby reducing the vehicle speed and adjusting the vehicle's posture to bring the vehicle back to a stable state.
[0048] The anti-lock braking module compares the actual slip ratio and the ideal slip ratio obtained by the vehicle attitude estimation module, and combines the wheel acceleration according to the anti-lock strategy. Based on the braking requirements of the vehicle stability control and braking force distribution modules, it controls the actuator to increase, decrease, and maintain the braking force. By adjusting the magnitude of the braking torque, it ensures that the vehicle utilizes the ground adhesion to the maximum extent during braking, so that the vehicle obtains the best braking distance and stability, and ensures driving safety.
[0049] The drive anti-skid module helps the vehicle get out of trouble by controlling the actuator when the wheels slip. The fault handling module receives alarm signals from the functional monitoring layer and takes corresponding response measures to ensure driving safety.
[0050] The actuator control module controls the actuator to respond to braking requests issued by each module.
[0051] The fault handling module responds differently to different fault signals output by the functional monitoring layer, such as instrument alarm, disabling anti-lock braking, disabling the vehicle electronic stability control system, activating emergency braking, and automatic parking.
[0052] The core of the functional monitoring layer's process for detecting defects in the functional layer software is designing a method to determine whether the functional layer is operating normally. Analysis shows that the EMB's safety objectives are to prevent service brake failure, service brake malfunction, ABS false activation, and ESC false activation. Therefore, the main purpose of the functional monitoring layer is to perform real-time monitoring and diagnosis of the operating status, input and output status of modules such as the deceleration control module, ABS control module, and ESC control module, and to quickly locate and determine the cause of the fault, reporting it to the diagnostic system for repair and safety measures.
[0053] The functional monitoring layer design includes three modules: input monitoring, process monitoring, and output monitoring. It enables the monitoring of data flow and functional failure causes in the EMB functional layer, and quickly locates the cause of the failure.
[0054] The input monitoring module verifies the integrity, validity, and rationality of external inputs affecting the EMB control system's functional failures and safety-related signals, and outputs the verified signals and their valid flag bits to the process monitoring and output monitoring modules of the functional layer and functional monitoring layer.
[0055] The input monitoring module involves verifying bus message signals and hard-wired analog signals that cause functional failures at the functional layer, including the verification mechanism and timing diagram. Relevant bus message signals include vehicle-related signals, sensor signals, and high-voltage signals. Hardware analog signals include verification of brake pedal signals, parking signals, and wheel speed signals.
[0056] The process monitoring module primarily performs real-time monitoring and diagnosis of the operating and output status of modules such as deceleration control, anti-lock braking, vehicle stability control, and actuator control within the functional layer. Inputs include key signals from each functional module (including input conditions, final output results, and the final execution status of the actuators) and signals output from the signal verification module. Closed-loop real-time monitoring is used to pinpoint the causes of functional failures such as brake failure, brake malfunction, ABS misactivation, and ESC misactivation. The final output includes fault flags and alarm signals.
[0057] The input monitoring module in the functional monitoring layer includes bus message signal verification and analog signal verification.
[0058] like Figure 3 As shown, the bus message signal verification process is as follows: Message signals are received at fixed intervals (based on the system design time for the control system diagnosis). First, a communication timeout detection is performed on the signal. If the message is not received within a certain period, it is determined that the signal is lost. Otherwise, the effective range of the key signal is checked, that is, the numerical range of the communication matrix is checked. When the check passes, the signal is then checked to see if it meets the functional design requirements.
[0059] likeFigure 4 As shown, the analog signal verification process is as follows: Signal filtering is performed on the hard-wired analog signals (including brake pedal signal, parking switch signal, and wheel speed signal); signal effective range detection is performed; signal verification is performed; and signal rationality detection is performed. Analog signal acquisition includes acquiring brake pedal signal, parking switch signal, and wheel speed signal. The signal filtering stage performs glitches and mean filtering on these signals. The analog signal effective range detection stage checks whether the filtered signal value is within the effective upper and lower limits. The analog signal verification stage determines whether there are any unreasonable signals by cross-checking two brake pedal signals, two parking switch signals, or coaxial wheel speed signals during straight-line driving. The analog signal rationality verification stage judges the rationality of the signal value based on the overall vehicle operating state. For example, for wheel speed signals, under non-braking conditions during straight-line driving, it determines whether the deviation between the current wheel speed value and the instrument speed exceeds the limit.
[0060] The process monitoring module primarily performs real-time monitoring and diagnostics on the operational and output status of modules within the functional layer, including the deceleration control module, anti-lock braking module, vehicle stability control module, and actuator control module. Inputs include key signals from each functional module (including input conditions, final output results, and the final execution status of the actuators) and signals output from the monitoring module. This closed-loop real-time monitoring identifies the causes of functional failures such as brake failure, brake malfunction, ABS misactivation, and ESC misactivation. The final outputs are fault flags and alarm signals. The architecture diagram of the process monitoring module is shown below. Figure 5 As shown, by monitoring and verifying the signals, abnormal signal status, signal abrupt changes, and signal discontinuity can be detected when braking, ABS, and ESC are abnormal, leading to functional abnormalities.
[0061] The output monitoring module performs closed-loop real-time monitoring of security-related signals, message output signals, and hard-wired driver output signals at the functional layer. The architecture is as follows: Figure 6 As shown, it is divided into three levels.
[0062] a) Control output monitoring: The functional monitoring layer uses control logic independent of the functional layer to monitor safety-related signals and message output signals in the functional layer, including actuator control torque signals, drive motor torque limit signals, etc. By verifying and monitoring the rationality of control torque signals, as well as monitoring the rationality of torque signals and drive motor torque limit signals, logical errors or abnormal problems are avoided.
[0063] b) Driver output monitoring: The hardwired driver output signal of the functional layer is sent to the driver output monitoring module. The output monitoring module needs to confirm for a certain period of time to determine whether the driver output is correct.
[0064] c) Actuator Monitoring: After responding to the control signal output by the functional layer, the actuator reports back the execution torque and parking status. The actuator monitoring module monitors the actuator to determine if there is a fault in the actuator and whether it can perform the response normally. Faults are identified by monitoring the fault information reported by the actuator, monitoring communication, and judging the difference between the required and the feedback torque. If one or more monitoring faults occur, an instrument alert is sent to the driver, and an actuator shutdown signal or fault signal is sent to the functional layer, putting the system into a safe state.
[0065] Example 2:
[0066] The following is a detailed description of how to design the functional monitoring layer software for the vehicle's deceleration control module and body stability control module:
[0067] The flowchart of the functional monitoring layer for the vehicle braking process is as follows: Figure 7 As shown:
[0068] Factors influencing service brake loss include brake pedal failure, EMB controller failure, EMB actuator failure, low-voltage power supply failure, high-voltage power supply failure, and bus communication failure. For example,... Figure 7 As shown, the input monitoring module needs to monitor the brake pedal signal, low-voltage power supply signal, high-voltage power supply signal, and bus communication signal; the process monitoring module needs to monitor the rationality of the required torque output by the EMB controller; and the output monitoring module needs to monitor the feedback signal and fault signal of the EMB actuator.
[0069] The input monitoring module includes: brake pedal monitoring, which monitors open / short circuit faults at the brake pedal power supply pins output from the controller, brake pedal signal monitoring, and real-time monitoring of both pedal signals through methods such as rationality judgment and dual-channel redundancy verification. Low-voltage and high-voltage power supply monitoring are performed in real-time by monitoring the high and low voltage signals input to the control unit and actuators. Bus communication monitoring detects message timeouts and checksum verification logic for critical messages.
[0070] The process monitoring module monitors the torque demand output by the deceleration control module of the functional layer. It obtains the required deceleration by looking up the table through the opening of the brake pedal pressed by the driver. Based on the dynamic formula, it calculates the braking torque as the required deceleration multiplied by the vehicle weight and the tire radius to obtain a reasonable torque demand. It compares this torque demand with the torque demand output by the functional layer. When the actual difference exceeds 20%, it is considered that a fault has occurred.
[0071] The output monitoring module includes: timeout detection for messages output to the actuator, monitoring of fault signals, feedback torque, and parking status from the actuator, and detecting the difference between the required torque and the feedback torque. It also calculates the torque range using the brake pedal signal and the actuator's feedback torque to check the reasonableness of the required torque.
[0072] The above tests are used to diagnose the cause of service brake failure or malfunction and output a service brake failure or malfunction flag.
[0073] The flowchart of the functional monitoring layer of the Vehicle Stability Control (ESC) system is as follows: Figure 8 As shown:
[0074] Factors influencing ESC malfunction include brake pedal failure, steering wheel angle sensor failure, parking switch failure, yaw angle sensor failure, wheel speed sensor failure, and EMB actuator failure. Real-time monitoring of relevant mechanisms within the ESC control module is crucial. The input monitoring module monitors the steering wheel angle sensor, yaw angle sensor, and wheel speed sensors. For the steering wheel angle sensor, monitoring includes message timeout monitoring, power supply anomaly monitoring, and monitoring of fault information from the steering wheel angle sensor. For the yaw angle sensor, monitoring includes message timeout monitoring, power supply anomaly monitoring, and monitoring of yaw angle sensor feedback faults. Wheel speed sensor monitoring includes filtering, debouncing, range detection, and reasonableness judgment of wheel speed signals. Reasonableness judgment involves detecting the difference range of the four wheels under different operating conditions such as acceleration, deceleration, left turn, right turn, and constant speed. If any wheel exceeds the range, it is considered abnormal. The output monitoring module monitors the EMB actuator.
[0075] The fault flag is output from the functional monitoring layer to the fault handling module of the functional layer. The fault handling module performs different operations according to different fault flags, such as instrument alarm, disabling ABS, disabling ESC, and activating emergency braking. At the same time, control unit 2 monitors the faults of control unit 1 in real time through messages. When a brake pedal fault, parking switch fault, wheel speed sensor fault, or control unit 1 communication timeout fault is detected, control unit 2 takes over control.
[0076] The above description is merely an example of embodiments of the present invention and is not intended to limit the present invention in any way. The scope of protection of the present invention is defined by the claims and is not limited to the specific embodiments described above. Any simple modifications or equivalent changes and alterations made to the above embodiments based on the technical essence of the present invention shall fall within the scope of protection of the present invention.
Claims
1. A software security architecture for an electromechanical braking control system for commercial vehicles, characterized in that, The software security architecture is designed with two independent control units and dual redundancy, each of which can independently control execution. Each control unit includes a functional layer and a functional monitoring layer. The functional layer includes the functions and scheduling of each system module, while the functional monitoring layer realizes real-time monitoring of EMB software defects, ensuring the integrity and rationality of signals and capturing functional anomalies.
2. The software security architecture according to claim 1, characterized in that, The aforementioned commercial vehicle electromechanical braking system adopts a dual-redundancy design, containing two independent control links, including independent high and low voltage power supplies, independent bus design, independent signal acquisition, control unit 1, control unit 2, and EMB actuator components. The power supply consists of two independent high-voltage power supplies, one for the EMB actuator and one for the control unit and actuator, respectively. The independent signal acquisition module includes two redundant brake pedal signal acquisitions, two independent parking switch signal acquisitions, two independent wheel speed sensor signal acquisitions connected to control units 1 and 2, and signal acquisitions from the yaw angle sensor, steering wheel angle sensor, and vehicle signals. The EMB actuator is a high-voltage-based control mechanism, including an electric brake and an electric brake control unit, with one EMB actuator configured for each wheel. The EMB control units can receive relevant signals, perform functional layer calculations, and control the EMB actuators.
3. The software security architecture according to claim 1, characterized in that: The functional layer includes a signal input and detection module, a vehicle state estimation module, a braking coordination control module, an actuator control module, and a fault handling module. The functional layer coordinates and controls a series of functions such as braking, parking, anti-lock braking, vehicle stability, drive anti-skid, and fault detection according to the driver's needs and vehicle state.
4. The software security architecture according to claim 1, characterized in that: The functional monitoring layer includes three modules: an input monitoring module, a process monitoring module, and an output monitoring module. It monitors the data flow and causes of functional failures in the EMB functional layer, and quickly locates the cause of the fault. The functional monitoring layer detects defects in the functional layer software, and performs real-time monitoring and diagnosis of the operating status, input and output status of the service braking module, anti-lock braking module, and vehicle stability control module. It also quickly locates and judges the cause of the fault and reports it to the diagnostic system for repair and safety measures.
5. The software security architecture according to claim 3, characterized in that: The signal input and detection module includes a brake pedal signal acquisition module, a parking switch signal acquisition module, a wheel speed sensor signal acquisition module, a yaw angle sensor acquisition module, and a steering wheel angle sensor signal acquisition module. Each signal is transmitted to EMB control unit 1 and control unit 2 via hardwired wiring or a bus. Specifically, the brake pedal signal acquisition module provides two independent brake pedal signals, each input to one of the two control units; similarly, the parking switch signal acquisition module provides two independent parking signals, each input to one of the two EMB control units; the wheel speed sensor signal acquisition module corresponds to each wheel, acquiring the wheel speed signal of its corresponding wheel and transmitting it to the two EMB control units; the yaw angle sensor acquisition module acquires the vehicle's yaw rate, longitudinal acceleration, and lateral acceleration; and the steering wheel angle sensor acquisition module acquires the steering wheel angle, all inputting these values to the EMB control units. The vehicle state estimation module includes a vehicle speed estimation module, a slip ratio estimation module, and a theoretical yaw rate estimation module. Based on the wheel speeds of each wheel calculated by the signal processing module, the Kalman filter algorithm is used to estimate the overall vehicle speed and slip ratio in real time. Based on the overall vehicle parameters and vehicle dynamics, the vehicle weight is estimated in real time. The theoretical yaw rate is estimated using a yaw rate estimation method. The braking coordination control module includes a deceleration control module, a braking force distribution module, a vehicle stability control module, an anti-lock braking module, and a drive anti-skid control module. The deceleration control module outputs braking requirements based on the brake pedal, parking switch, throttle information, gear information, and deceleration requests from the functional monitoring layer input monitoring module, and the vehicle weight and speed information calculated by the vehicle attitude estimation module, according to the deceleration control and braking force distribution strategy. It divides these requirements into service braking, parking braking, emergency braking, and superimposed braking, calculates the driver's braking requirements in different modes, and outputs the braking torque requirements to the braking force distribution module.
6. The software security architecture according to claim 3, characterized in that: The braking force distribution module calculates the front and rear braking force distribution ratio based on the vehicle's actual deceleration and braking torque, according to the vehicle's status information, and distributes the vehicle's total braking force demand to the front, middle and rear axles according to the proportional relationship, so that the vehicle's braking force can reach the ideal braking force distribution relationship as much as possible. The vehicle stability control module determines whether the vehicle is in a stable state by using the steering angle signal, yaw rate, lateral acceleration, and theoretical yaw rate signal. If the vehicle is not in a stable state, it issues a control command. The control unit controls the EMB actuator to apply braking force to the corresponding wheels, thereby reducing the vehicle speed and adjusting the vehicle's posture to bring the vehicle back to a stable state. The anti-lock braking module compares the actual slip ratio and the ideal slip ratio obtained by the vehicle attitude estimation module, and combines the wheel acceleration according to the anti-lock strategy. Based on the braking requirements of the vehicle stability control and braking force distribution modules, it controls the actuator to increase, decrease, and maintain the braking force. By adjusting the magnitude of the braking torque, it ensures that the vehicle utilizes the ground adhesion to the maximum extent during braking, so that the vehicle obtains the best braking distance and stability, and ensures driving safety. The drive anti-slip module helps the vehicle get out of trouble by controlling the actuator when the wheels slip. The fault handling module receives alarm signals from the functional monitoring layer and takes corresponding response measures to ensure driving safety. The actuator control module controls the actuator to respond according to the braking requests issued by each module; The fault handling module responds differently to different fault signals output by the functional monitoring layer.
7. The software security architecture according to claim 6, characterized in that: The input monitoring module verifies the integrity, validity, and rationality of external inputs affecting the EMB control system's functional failures and safety-related signals. It outputs the verified signals and their valid flags to the process monitoring and output monitoring modules in the functional layer and functional monitoring layer. The input monitoring module in the functional monitoring layer includes bus message signal verification and analog signal verification.
8. The software security architecture according to claim 6, characterized in that: The input monitoring module involves verifying bus message signals and hard-wired analog signals that cause functional failures at the functional layer, including verification mechanisms and timing diagrams; the relevant bus message signals include vehicle-related signals, sensor signals, and high-voltage signals; the hardware analog signals include brake pedal signals, parking signals, and wheel speed signals.
9. The software security architecture according to claim 1, characterized in that, When a serious fault occurs in the braking link and the function cannot be performed, the function monitoring layer detects the relevant fault and immediately reports the fault signal, and controls the output signal 1 to shut down. At the same time, when the control unit 2 receives the fault signal, including brake pedal fault, parking switch fault, wheel speed sensor fault, or control unit 1 communication timeout fault, it immediately responds and controls the EMB actuator.
10. The software security architecture according to claim 1, characterized in that, When both control units 1 and 2 experience serious malfunctions and are unable to brake, the vehicle controller monitors control units 1 and 2 and controls the drive motor to apply negative torque for deceleration.