Method for state arbitration and torque distribution of a steer-by-wire steering system based on safety integrity

By configuring subsystems A and B in the steer-by-wire system, establishing a full-dimensional CAN communication link and performing fault diagnosis, and dynamically arbitrating torque distribution, the problem of excessive performance degradation of the steer-by-wire system under complex fault scenarios is solved, achieving a high-safety and high-reliability 'fault-operation' capability.

CN122143996APending Publication Date: 2026-06-05辰致科技有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202610123815.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-01-29
Publication Date
2026-06-05

AI Technical Summary

Technical Problem

When a single-point fault in a steering-by-wire system expands into a multi-point composite fault or communication between subsystems is interrupted, the existing system cannot effectively maintain high safety, high reliability, and optimal performance. Existing arbitration methods suffer from high logical complexity, delayed fault diagnosis, and excessive performance degradation.

Method used

By configuring subsystems A and B in the upper steering feel unit and the lower steering execution unit, a full-dimensional CAN communication link is established and an E2E protection mechanism is configured. Combined with fault diagnosis and refined fault status judgment, and dynamic arbitration torque distribution rules, the system can maintain its 'fault-run' capability in scenarios of single-point faults, multi-point composite faults, and inter-board communication faults.

Benefits of technology

It achieves high safety and high reliability of the steer-by-wire system under complex fault scenarios, avoids excessive performance degradation, maximizes the remaining execution capacity of the subsystem, meets functional safety requirements, and ensures the stability and optimal performance of the vehicle's steering function.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122143996A_ABST
    Figure CN122143996A_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of steer-by-wire system, in particular to a steer-by-wire system state arbitration and torque distribution method based on safety integrity, which is characterized in that: in the up-turn feeling unit and the down-turn execution unit of the steer-by-wire system, subsystem A and subsystem B are configured respectively, and the subsystem A and subsystem B of the up-turn feeling unit and the subsystem A and subsystem B of the down-turn feeling unit are subjected to fault diagnosis to determine the torque and steering angle execution mode of the steer-by-wire system, which can maintain the "fault-operation" ability of the steer-by-wire system under the single-point fault, multi-point composite fault and inter-board communication fault scenarios, make up for the short board of the prior art in fault handling, especially in multi-point fault response, and greatly improve the fault tolerance, operation stability and safety and reliability of the steer-by-wire system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of steer-by-wire system technology, and more specifically to a system dynamic arbitration method for redundant steer-by-wire systems. Background Technology

[0002] A steer-by-wire system relies entirely on the coordinated operation of multiple electronic components (such as the electronic control unit, torque / angle sensor, and steering actuator motor) to achieve vehicle steering. A failure in any one of these components (a single point of failure) can lead to a complete loss of steering function, resulting in a loss of vehicle control and potentially a serious traffic accident. To mitigate this risk, a steer-by-wire system must maintain basic steering functionality even after a single point of failure, achieving a "fail-operational" safety state until the vehicle is safely brought to a stop or reaches a repair shop.

[0003] Those skilled in the art have attempted to configure two sets of redundant hardware (such as the upshift feel unit HWA and the downshift execution unit RWA, each containing two subsystems) in a redundant steering system, so that in the event of a failure in one system, the system can directly switch to the other. However, this simple arbitration method, which relies solely on "failure-based switching," has gradually revealed many technical defects under complex actual operating conditions. Practical verification by those skilled in the art has revealed the following shortcomings, for example:

[0004] The publication CN116339120A, titled "EPS Dual Redundancy System and Fault Handling Method," proposes a scheme that combines operating modes and functions for unified coding management, managing the specific functions affected by different faults. The drawbacks of this scheme are as follows:

[0005] ① The subsystem faults are simply divided into "recoverable faults" and "unrecoverable faults" without considering the feasibility of integrated operation after the two subsystems cooperate (such as HWA subsystem A calculating the target torque and subsystem B cooperating to execute FOC control). The arbitration logic lacks flexibility and cannot adapt to scenarios where some subsystem functions can be output collaboratively as long as they are normal.

[0006] ② No specific handling strategy is given for communication failures between subsystem controllers. When a software malfunction triggers the watchdog timer and causes communication loss, the system cannot make decisions based on historical states (such as the execution capability stored in RAM at the previous moment) and is prone to arbitration failure.

[0007] ③ The arbitration logic does not cover multi-point composite fault scenarios. When both subsystems have non-fatal faults (such as temporary faults or degraded faults), it cannot maintain part of the system's operational capabilities through safety integrity judgment (such as Flt_TqCal and Flt_TqAct dual fault status verification), resulting in wasted system performance.

[0008] The publication CN118062104A, titled "A Method for Managing the Execution Status of a Steer-by-Wire System," proposes an execution status management approach that comprehensively assesses various faults in the main and auxiliary steering systems for both uphill and downhill steering, identifying serious faults, temporary faults, and degraded faults. This approach is then used for arbitration and status management of the main and auxiliary steering systems. However, it suffers from the following technical defects:

[0009] (1) Comprehensive management of the fault status of the up-turn and down-turn independent subsystems will not only increase the system logic complexity and system fault judgment delay, but also violate the original design intention of the up-turn and down-turn as independent subsystems to realize information interaction through CAN communication rather than the mutual interference of fault status, which is likely to lead to fault judgment deviation and false triggering of status jump;

[0010] (2) No specific handling solution is provided for communication failures between subsystem controllers (such as the two subsystem MCUs of HWA). When the inter-board CAN communication is interrupted or the E2E verification fails, the system cannot achieve effective arbitration, and there is a risk of interruption of the switching function.

[0011] (3) The fault level classification (serious fault, temporary fault, degraded fault) is designed only for single-point faults and does not take into account the scenario of multiple compound faults in the upper or lower rotor system (such as a subsystem experiencing motor overheating and drive chain fault at the same time, or both subsystems having temporary faults). It is impossible to utilize the remaining execution capacity of the system through refined state judgment (such as the dynamic calculation of the subsystem execution capacity f_single), resulting in excessive degradation of system performance.

[0012] In summary, even if the existing arbitration methods for redundant steer-by-wire systems meet the basic safety requirements of ISO 26262 for accepting multi-point failure risks, they cannot maximize the utilization of the system's remaining performance in complex scenarios such as single-point failures expanding into multi-point composite failures or communication interruptions between subsystems. They are difficult to match the triple requirements of steer-by-wire systems for high safety, high reliability, and optimal performance output in the "failure-operation" state. Summary of the Invention

[0013] The purpose of this invention is to address the shortcomings of existing technologies by providing a system dynamic arbitration method for redundant steer-by-wire systems. This method involves configuring subsystem A and subsystem B in the upper steering feel unit and lower steering execution unit of the steer-by-wire system, respectively, and performing fault diagnosis on subsystems A and B of the upper steering feel unit and the lower steering feel unit to determine the torque and steering angle execution modes of the steer-by-wire system. This method can maintain the "fault-operation" capability of the steer-by-wire system under single-point fault, multi-point compound fault, and inter-board communication fault scenarios.

[0014] The objective of this invention is achieved through the following approach:

[0015] A method for state arbitration and torque distribution in a steer-by-wire system based on safety integrity includes the following steps:

[0016] 1) Set up two sets of redundant subsystems, which serve as the upper steering feel unit and the lower steering execution unit of the steer-by-wire system, respectively. Each set of redundant subsystems contains subsystem A and subsystem B with the same hardware architecture.

[0017] 2) Establish CAN communication between each subsystem configured in step 1) and the vehicle, as well as CAN communication between each subsystem;

[0018] 3) In the upper steering feel unit, determine the operating status of subsystem A and subsystem B of the upper steering feel unit, including target torque, target angle, communication status, fault status, and execution capability. Based on the operating status of subsystem A and subsystem B, determine the torque distribution rule and system status of the upper steering feel unit, and transmit the target angle to the lower steering execution unit.

[0019] 4) In the lower steering feel unit, the target angle transmitted by the upper steering feel unit is received, and the operating status of subsystem A and subsystem B of the lower steering feel unit is determined respectively, including the target torque calculated based on the target angle, communication status, fault status, and execution capability. The torque distribution rules and system status of the lower steering execution unit are determined according to the operating status of subsystem A and subsystem B.

[0020] 5) The system status of the upper steering feel unit and the lower steering actuator unit is transmitted to the vehicle controller. The vehicle controller performs degradation and alarm based on the system status of the upper steering feel unit and the lower steering actuator unit to maintain the 'fault-operation' capability of the steer-by-wire system.

[0021] This invention configures subsystems A and B in the upper steering feel unit and lower steering execution unit of the steer-by-wire system, respectively, and performs fault diagnosis on subsystems A and B of the upper and lower steering feel units to determine the torque distribution rules and system status of the steer-by-wire system. This allows the steer-by-wire system to maintain its "fault-operation" capability even under single-point faults, multi-point composite faults, and inter-board communication failures. It ensures that the upper steering feel unit outputs precise torque that matches the driving experience, and that the lower steering execution unit achieves the steering angle that matches the driver's intentions. Furthermore, it arbitrates the optimal execution strategy based on the principle of safety integrity priority (such as dual-system collaboration or single-system independent execution), maximizing the remaining execution capacity of the subsystems. This avoids the problem of "directly shutting down multiple systems and excessive performance degradation" in existing technologies, while also meeting ASILD safety requirements, ensuring the safety and optimal performance of the vehicle's steering function.

[0022] Preferably, in step 2), CAN communication between each subsystem A and subsystem B configured in step 1) and the vehicle, as well as CAN communication between the subsystems, are established, specifically including:

[0023] 2-1) Establish CAN communication between subsystem A and subsystem B in the upshift hand feel unit and the vehicle, respectively; establish CAN communication between subsystem A and subsystem B in the downshift execution unit and the vehicle, respectively.

[0024] 2-2) Establish CAN communication between subsystem A in the upshift feel unit and subsystem A in the downshift execution unit, and establish CAN communication between subsystem B in the upshift feel unit and subsystem B in the downshift execution unit;

[0025] 2-3) Establish CAN communication between subsystem A and subsystem B in the upshift feel unit, and establish CAN communication between subsystem A and subsystem B in the downshift execution unit;

[0026] 2-4) Configure an E2E protection mechanism in each CAN communication link established in steps 2-1)-2-3) to identify data loss, data tampering and data retransmission anomalies during the communication process, and ensure the integrity and correct sequence of end-to-end data transmission.

[0027] This invention establishes a full-dimensional CAN communication link between the subsystems of the up-turn feel unit and the down-turn execution unit and the whole vehicle and subsystems (including the same subsystems for up-turn and down-turn and the internal subsystems of the unit), and configures an E2E protection mechanism on each link. This not only ensures the integrity, correct sequence, and anti-tampering and anti-loss capabilities of end-to-end data transmission, but also provides a reliable channel for real-time interaction of key information such as target torque, fault status, and execution capability between subsystems. This lays the data foundation for subsequent fault diagnosis, main control system selection, torque distribution, and system status arbitration, effectively avoiding the risk of steering function interruption caused by communication failure, helping the system maintain "fault-operation" capability under various fault scenarios, and improving the safety, reliability, and fault tolerance performance of the steer-by-wire system.

[0028] Preferably, in step 3), the torque distribution rule and system state are determined in the following manner:

[0029] 3-1) In subsystems A and B of the steering feel unit, the target torque and target angle are calculated according to the input signals, respectively. The input signals include steering wheel torque, steering wheel angle, and vehicle speed.

[0030] 3-2) Perform fault diagnosis on subsystem A and subsystem B respectively to determine the fault status of each subsystem;

[0031] 3-3) Calculate the execution capabilities of subsystem A and subsystem B respectively;

[0032] 3-4) While transmitting the target torque, fault status, and execution capability of subsystem A to subsystem B, the target torque, fault status, and execution capability of subsystem B are transmitted to subsystem A.

[0033] 3-5) Detect the communication status of subsystem A and subsystem B;

[0034] 3-6) Based on the communication status, target torque, fault status, and execution capability of subsystem A, and the communication status, target torque, fault status, and execution capability of subsystem B, determine the system status of the main control system, torque distribution rules, and upper steering feel unit.

[0035] 3-7) After the main control system distributes the torque command, subsystems A and B execute the torque output according to the torque distribution rules.

[0036] Preferably, in step 3-2), the fault status of each subsystem is determined in the following manner:

[0037] 3-2-1) Perform power-on initialization self-test on subsystems A and B, including diagnosing the power management chip mechanism, MCU chip mechanism, pre-driver chip, drive link, and fault shutdown link. If an abnormality that does not meet the design requirements is detected during the power-on initialization self-test, the subsystem enters the Fail state; if no abnormality that does not meet the design requirements is detected during the power-on initialization self-test, proceed to step 3-2-2).

[0038] 3-2-2) Based on the input signals supporting the target torque calculation, including the input CAN signal, steering wheel torque signal, steering wheel angle signal, PCB temperature signal, power supply status, and MCU operating status, determine the fault status of the target torque calculation for subsystem A and subsystem B in the following manner:

[0039] If all input signals supporting the target torque calculation are fault-free, then the target torque calculation is fault-free.

[0040] If the input signal supporting the target torque calculation is faulty, and the faulty input signal can be replaced by a redundant signal or a default value, then the target torque calculation has a minor fault.

[0041] If the input signal supporting the target torque calculation is faulty, and the faulty input signal cannot be replaced by a redundant signal or a default value, then the target torque calculation has a serious fault.

[0042] 3-2-3) Based on the input signals supporting the target torque execution, including the input motor position signal, the input three-phase current signal, the PCB temperature signal, the power supply and MCU operating status, determine the fault status of subsystem A and subsystem B for target torque execution in the following manner:

[0043] If all input signals supporting the execution of the target torque are fault-free, then the execution of the target torque is fault-free.

[0044] If any input signal supporting the execution of the target torque is faulty, then the execution of the target torque is faulty;

[0045] 3-2-4) Based on the fault state calculated from the target torque and the fault state executed by the target torque, determine the fault states of subsystem A and subsystem B in the following manner:

[0046] If there is no fault in the target torque calculation and no fault in the target torque execution, the subsystem is in the Normal state.

[0047] If there is a minor fault in the target torque calculation, but no fault in the target torque execution, the subsystem is in the FailOp state.

[0048] If there is a serious fault in the target torque calculation, but no fault in the target torque execution, the subsystem is in the FailCtrl state.

[0049] If there is no fault in the target torque calculation but a fault in the target torque execution, the subsystem is in the FailCal state.

[0050] If there is a minor fault in the target torque calculation and a fault in the target torque execution, the subsystem is in the FailCalop state.

[0051] If there is a serious fault in the target torque calculation and a fault in the target torque execution, the subsystem is in a Fail state.

[0052] Preferably, in step 4), the torque distribution rule and system state are determined in the following manner:

[0053] 4-1) In subsystems A and B of the lower-turn execution unit, the target torque required for the target angle is calculated according to the input signal. The input signal includes the vehicle CAN signal, the CAN signal including the target angle emitted from the upper-turn hand feel unit, the rack position signal, and the PCB temperature signal.

[0054] 4-2) Perform fault diagnosis on subsystem A and subsystem B respectively to determine the fault status of each subsystem;

[0055] 4-3) Calculate the execution capabilities of subsystem A and subsystem B respectively;

[0056] 4-4) While transmitting the target torque, fault status and execution capability of subsystem A to subsystem B, the target torque, fault status and execution capability of subsystem B are transmitted to subsystem A.

[0057] 4-5) Detect the communication status of subsystem A and subsystem B;

[0058] 4-6) Based on the communication status, target torque, fault status, and execution capability of subsystem A, and the communication status, target torque, fault status, and execution capability of subsystem B, determine the system status of the main control system, torque distribution rules, and downstream execution units.

[0059] 4-7) After the main control system distributes the target torque, subsystems A and B respond to the target angle command by executing torque output.

[0060] Preferably, in step 4-2), the fault status of each subsystem is determined in the following manner:

[0061] 4-2-1) In the next execution unit, a power-on initialization self-test is performed on subsystems A and B, including diagnosing the power management chip mechanism, MCU chip mechanism, pre-driver chip, and drive link / fault shutdown link. If an abnormality that does not meet the design requirements is detected during the power-on initialization self-test, the subsystem enters the Fail state; if no abnormality that does not meet the design requirements is detected during the power-on initialization self-test, proceed to step 4-2-2).

[0062] 4-2-2) Based on the input signals supporting the target angle calculation, including the CAN signal from the upper steering feel unit (including the target angle), the vehicle CAN signal, the rack position signal, and the PCB temperature signal, determine the fault status of the target torque calculation for subsystem A and subsystem B in the following manner:

[0063] If all input signals supporting the target torque calculation for angle control are fault-free, then the target torque calculation is fault-free.

[0064] If the input signal for calculating the target torque that supports angle control is faulty, and the faulty input signal can be replaced by a redundant signal or a default value, then the target torque calculation has a minor fault.

[0065] If the input signal for calculating the target torque that supports angle control is faulty, and the faulty input signal cannot be replaced by a redundant signal or a default value, then the target torque calculation has a serious fault.

[0066] 4-2-3) Based on the input signals supporting the execution of the target torque, including motor position signals and three-phase current signals, determine the fault status of the target torque execution of subsystem A and subsystem B in the following manner:

[0067] If none of the input signals supporting the execution of the target torque are faulty, then the execution of the target torque is fault-free.

[0068] If any input signal supporting the execution of the target torque is faulty, then the execution of the target torque is faulty;

[0069] 4-2-4) Based on the fault state calculated from the target torque and the fault state executed by the target torque, determine the fault states of subsystem A and subsystem B in the following manner:

[0070] If there is no fault in the target torque calculation and no fault in the target torque execution, the subsystem is in Normal state and there are no functional safety faults.

[0071] If there is a minor fault in the target torque calculation, but no fault in the target torque execution, the subsystem is in the FailOp state.

[0072] If there is a serious fault in the target torque calculation, but no fault in the target torque execution, the subsystem is in the FailCtrl state.

[0073] If there is no fault in the target torque calculation but a fault in the target torque execution, the subsystem is in the FailCal state.

[0074] If there is a minor fault in the target torque calculation and a fault in the target torque execution, the subsystem is in the FailCalop state.

[0075] If there is a serious fault in the target torque calculation and a fault in the target torque execution, the subsystem is in a Fail state.

[0076] This invention proactively identifies core hardware faults through power-on initialization self-testing. It then refines the fault judgment logic based on two dimensions: target torque calculation and execution. Calculation faults are categorized into minor (redundant and replaceable) and severe (non-replaceable) types. Combining these two types of fault states forms six refined subsystem states. This approach accurately locates faulty components, avoids the crude fault classification of existing technologies, and covers both single-point and multi-point composite fault scenarios. It provides a precise basis for subsequent main control system selection and torque allocation, while preventing excessive degradation and ensuring the operational stability of the downstream execution unit, thus meeting functional safety standards and ASILD level requirements.

[0077] Preferably, the execution capabilities of subsystem A and subsystem B are calculated in the following manner:

[0078] s =min( ov , uv , ot_pcb , ot_mot )* dri ;

[0079] In the formula, s For single-board execution capability, ov This is the overvoltage and torque limiting coefficient for the bus. uv This is the undervoltage torque limiting coefficient for the bus voltage. ot_pcb This refers to the over-temperature torsion limit coefficient of the PCB board. ot_mot This is the over-temperature torque limiting coefficient of the motor. dri This is the driving chain integrity coefficient.

[0080] This invention combines key limiting factors affecting hardware output, such as bus voltage overvoltage / undervoltage, PCB board overtemperature, and motor overtemperature (taking the minimum value to reflect the "short board effect"), with the integrity of the drive chain to calculate the execution capability of subsystem A / B boards. This calculation accurately matches the actual hardware operating conditions of a single subsystem and will not overestimate the execution capability due to ignoring a certain hardware limitation (such as calculating at full capacity when the motor is overheated). It will also not miss the execution capability failure caused by drive chain failure, ensuring that the calculated single board execution capability can reflect the true output potential of the subsystem.

[0081] Preferably, the main control system, torque distribution rules, and system status are determined in the following manner:

[0082] S1) If there is no inter-board communication fault between subsystem A and subsystem B, the system status of the main control system, torque distribution rules, and upshift feel unit / downshift execution unit shall be determined in the following manner:

[0083] S1-1) Set the fault state priority rule as “Normal=FailCal>FailOp=FailCalOp>FailCtrl>Fail”, and take the subsystem with the higher fault state priority in subsystem A and subsystem B as the master control system. If the fault state priorities of subsystem A and subsystem B are the same, then subsystem A will be the master control system.

[0084] S1-2) Based on the execution capabilities of subsystem A and subsystem B, determine the torque distribution rules in the following manner:

[0085] Set the minimum execution capability of the unit to min(execution capability of subsystem A, execution capability of subsystem B), and set the maximum execution capability of the unit to max(execution capability of subsystem A, execution capability of subsystem B).

[0086] If the smaller and larger values ​​of the unit execution capability satisfy the following formula, then subsystem A and subsystem B are both torque output systems, and the output torque of subsystem A and subsystem B is 1 / 2 × the target torque calculated by the main control system:

[0087] (2*Capability_Min>Tq_Target) or (2*Capability_Min>Capability_Max);

[0088] In the formula, Capability_Min is the smaller value of the unit's execution capability, Tq_Target is the target torque calculated by the main control system, and Capability_Max is the larger value of the unit's execution capability;

[0089] If not satisfied, the subsystem with greater execution capability is selected from subsystem A and subsystem B as the torque output system. The output torque of the torque output system is min (the target torque calculated by the main control system and the execution capability of the torque output system).

[0090] S1-3) Based on the fault status of subsystem A and subsystem B, determine the preliminary system status of the upshift feel unit / downshift execution unit in the following manner:

[0091] If the fault states of subsystem A and subsystem B are both Normal, then the initial fault state of the up-turn feel unit / down-turn execution unit is SNormal.

[0092] If the fault state of subsystem A is Normal and the fault state of subsystem B is FailOp, or if the fault state of subsystem A is FailOp and the fault state of subsystem B is Normal, then the initial fault state of the up-turn feel unit / down-turn execution unit is SNormal-Limit.

[0093] If the fault state of subsystem A is Normal and the fault state of subsystem B is FailCal, FailCalOp, FailCtrl, or Fail, or if the fault state of subsystem B is Normal and the fault state of subsystem A is FailCal, FailCalOp, FailCtrl, or Fail, then the initial fault state of the up-turn feel unit / down-turn execution unit is SFailOp.

[0094] If the fault states of both subsystem A and subsystem B are FailOp, then the initial fault state of the up-turn feel unit / down-turn execution unit is SFailOp.

[0095] If the fault state of subsystem A is FailOp and the fault state of subsystem B is FailCal, FailCalOp, FailCtrl, or Fail, or if the fault state of subsystem B is FailOp and the fault state of subsystem A is FailCal, FailCalOp, FailCtrl, or Fail, then the initial fault state of the up-turn feel unit / down-turn execution unit is SFailDegrad.

[0096] If the fault state of subsystem A is FailCtrl and the fault state of subsystem B is FailCal or FailCalop, or if the fault state of subsystem B is FailCtrl and the fault state of subsystem A is FailCal or FailCalop, then the initial fault state of the up-turn feel unit / down-turn execution unit is SFailDegrad.

[0097] In other cases, the initial fault state of the upshift feel unit / downshift actuation unit is SErr;

[0098] S1-4) According to the torque distribution rule, the system execution capability of the upshift feel unit / downshift actuator unit is calculated as follows:

[0099] ① If both subsystem A and subsystem B are torque output systems, the system execution capability of the upshift feel unit / downshift actuator unit shall be calculated as follows:

[0100] System_Capability=2*Capability_Min;

[0101] Capability_Min=min(Cap_A,Cap_B);

[0102] In the formula, System_Capability is the system execution capability, Capability_Min is the smaller value of the unit execution capability, Cap_A is the execution capability of subsystem A, and Cap_B is the execution capability of subsystem B;

[0103] ② If only one of subsystems A and B is a torque output system, then the system execution capability of the upshift feel unit / downshift actuator unit shall be calculated as follows:

[0104] System_Capability=Capability_Max;

[0105] Capability_Max=max(Cap_A,Cap_B);

[0106] In the formula, System_Capability is the system execution capability, Capability_Max is the larger value of the unit execution capability, Cap_A is the execution capability of subsystem A, and Cap_B is the execution capability of subsystem B;

[0107] S1-5) Based on the system's execution capabilities, determine the capability status of the upward-turning touch unit / downward-turning execution unit in the following manner:

[0108] If the system execution capability is ≥80%, then the capability status of the up-turn feel unit / down-turn execution unit is SNormal;

[0109] If 50% ≤ system execution capability < 80%, then the capability status of the upshift feel unit / downshift execution unit is SFailOp.

[0110] If 30% ≤ system execution capability < 50%, then the capability status of the up-to-down hand feel unit / down-to-up-to-down execution unit is SFailDegrad.

[0111] If the system execution capability is less than 30%, then the capability status of the up-turn feel unit / down-turn execution unit is SErr;

[0112] S1-6) Set the severity rule of “SNormal < SNormal-Limit < SFailOp < SFailDegrad < SErr”, and take the more severe state between the initial state and the capability state of the upshifting feel unit as the fault state of the upshifting feel unit.

[0113] S2) If there is an inter-board communication failure in subsystem A or subsystem B, the system status of the main control system, torque distribution rules, and upshift feel unit / downshift execution unit shall be determined in the following manner:

[0114] S2-1) Set the arbitration priority rule as “Normal>FailOp>Failcal=FailCalOp=FailCtrl=Fail”, and determine the arbitration status of subsystem A and subsystem B in the following manner:

[0115] If the fault status of the subsystem is Normal or FailOp, then the arbitration status of the subsystem is an available system.

[0116] If the fault status of the subsystem is FailCalOp, FailCtrl, or Fail, then the arbitration status of the subsystem is unavailable.

[0117] S2-2) Based on the arbitration status of subsystem A and subsystem B, determine the master control system in the following manner:

[0118] ① If both subsystem A and subsystem B are available systems, then the difference in execution capability between subsystem A and subsystem B at the previous moment is taken as the execution capability deviation at the previous moment. Based on the execution capability deviation at the previous moment, the master control system in subsystem A and subsystem B is determined in the following manner:

[0119] If the execution capability deviation of the previous moment is greater than 10%, then the subsystem with the greater execution capability will be designated as the main control system.

[0120] If the execution capability deviation of the previous moment is ≤10%, then the master control system of the previous moment will be used as the master control system of the current moment.

[0121] ②If subsystem A or subsystem B is an unavailable system, the subsystem whose arbitration status is available shall be designated as the master control system;

[0122] ③ If both subsystem A and subsystem B are unavailable, the master control system from the previous moment will be used as the master control system.

[0123] S2-3) Set the torque distribution rule as follows: Only the main control system determined in step S2-2) is used as the torque output system, and the output torque value = min (target torque calculated by the main control system, execution capability of the main control system).

[0124] This invention addresses two scenarios: inter-board communication failure and inter-board communication failure between subsystems. It precisely selects the main control system based on clear fault state priority rules, dynamically formulates torque distribution strategies (dual-system collaborative output or single-system optimal output) based on subsystem execution capabilities, and determines the unit system state through a dual logic of preliminary fault state judgment and quantitative evaluation of system execution capabilities. This not only covers multi-point complex fault scenarios and avoids excessive degradation of "fault-based shutdown," but also ensures the effectiveness of arbitration based on historical execution states in the event of communication failure. It overcomes the shortcomings of rigid arbitration logic and incomplete fault coverage in existing technologies, significantly improving the arbitration flexibility, residual performance utilization, and operational reliability of the steer-by-wire system, and fully meets functional safety requirements.

[0125] Preferably, both subsystem A and subsystem B include a power management module, a main control module (MCU), a CAN communication module, a pre-driver module, a MOSFET full-bridge module, and a filtering module.

[0126] The power management module is used to convert the system input power into a low-voltage DC power supply that meets ASIL D level, to power the main control module MCU, pre-drive module and various sensors. At the same time, it integrates a watchdog monitoring mechanism to monitor the operating status of the main control module MCU in real time and build a safety control path to ensure the safe operation of the power supply and the core components of the system.

[0127] The main control module (MCU) is used to receive steering wheel button signals, steering wheel angle signals, and motor position sensor signals, generate motor control commands, manage information transmission within the subsystem and between the subsystem and other systems, and integrate various feedback signals to realize fault monitoring, logical operations, and execution of drive strategies, ensuring the stable and safe operation of the motor.

[0128] The CAN communication module is used to enable information interaction between the main control module and other systems, and to complete the transmission of instructions and status data;

[0129] The pre-drive module is used to receive drive waveform control commands issued by the main control module MCU, drive the MOSFET full-bridge module to output PWM drive signals, and also has the fault diagnosis function of the full-bridge circuit, which can monitor the abnormal operation status of the full-bridge in real time.

[0130] The MOSFET full-bridge module is used to receive the high-side / low-side control signals output by the pre-drive module. By controlling the on and off logic of the MOSFETs, it adjusts the phase voltage and phase current of the motor. At the same time, in conjunction with the control signals of the pre-drive module, it realizes the motor's forward and reverse rotation, speed regulation, torque regulation and other operation control actions.

[0131] The filtering module is used to filter high-frequency noise and spike pulses in the signal, ensuring that the power management module, the main control module MCU, and the MOSFET full-bridge module will not be falsely triggered or have signal distortion, thereby improving the reliability of the entire system.

[0132] The first data port of the main control module MCU is connected to the first data port of the power management module, the second data port of the main control module MCU is connected to the first data port of the pre-drive module, the third data port of the main control module MCU is connected to the first data port of the CAN communication module, and the fourth data port of the main control module MCU is connected to the second data port of the pre-drive module.

[0133] The second data port of the power management module is connected to the second data port of the pre-drive module, the third data port of the power management module is connected to the second data port of the CAN communication module, and the fourth data port of the power management module is connected to the first data port of the filter module.

[0134] The third data port of the pre-drive module is connected to the first data port of the MOSFET full-bridge module, and the fourth data port of the pre-drive module is connected to the second data port of the filter module.

[0135] The second data port of the MOSFET full-bridge module is connected to the third data port of the filter module.

[0136] The beneficial effects of this invention include the following:

[0137] ① This invention eliminates the logical redundancy caused by the traditional integrated management of cross-faults between the upper-turn feel unit (HWA) and the lower-turn execution unit (RWA) by independently determining faults, which greatly reduces system complexity and fault judgment delay, avoids fault judgment deviation and false triggering of state jump due to cross-unit fault state interference, and can ensure the accuracy and real-time performance of fault judgment. It fully conforms to the original design intention of HWA and RWA as independent subsystems that communicate information through CAN rather than faults interfering with each other.

[0138] ② This invention constructs redundant CAN dual communication links between various subsystems and clarifies the inter-board communication fault handling strategy. When inter-board communication is interrupted (such as E2E verification failure) or a software fault triggers the watchdog, resulting in communication loss, the subsystem can call the previous state of both parties (including subsystem execution capability and fault status) stored in RAM, and decide the optimal execution mode according to the principle of safety and integrity priority. This avoids the risk of arbitration failure and redirection function interruption caused by communication failure, and ensures the realization of the "fault-operation" safety goal.

[0139] ③ This invention dynamically calculates the execution capability of a subsystem based on multiple hardware parameters (overvoltage torque limiting coefficient of bus voltage, undervoltage torque limiting coefficient of bus voltage, overtemperature torque limiting coefficient of PCB board, overtemperature torque limiting coefficient of motor, and drive chain integrity coefficient). Through refined composite fault arbitration logic, it can cover multi-point composite fault scenarios (such as multiple faults occurring simultaneously in a single subsystem or faults existing in both subsystems). It can accurately identify the remaining execution capability of a subsystem, avoid excessive degradation of "shutting down upon failure", maximize the remaining performance of the system, and ensure the continuity of system operation.

[0140] ④ This invention abandons the existing technology's simple "recoverable / unrecoverable fault" classification of faults, and determines faults from two dimensions: target calculation faults and drive execution faults, accurately identifying scenarios where some subsystem functions are normal; at the same time, it designs a subsystem division of labor arbitration logic based on target calculation faults and drive execution faults (such as one party being responsible for target torque calculation and the other party being responsible for drive execution), which can meet the requirement that the subsystem can output collaboratively as long as some functions are normal, greatly improving the logical flexibility of the arbitration of the drive control system and the redundancy utilization rate of the subsystem, and avoiding the waste of functional resources caused by the rough fault classification;

[0141] ⑤ This invention establishes a real-time storage mechanism for the critical states of subsystems, storing information such as subsystem execution capabilities, fault states, and target torque in RAM in real time. When a software fault triggers the watchdog timer, causing inter-board communication to be lost, the subsystem can directly read the historical reliable states in RAM to make arbitration decisions, avoiding the system falling into arbitration failure and functional paralysis after communication loss, and improving the system's ability to resist communication interruptions caused by software faults;

[0142] ⑥ This invention can effectively cover scenarios where any subsystem in a steer-by-wire redundant system experiences a single point of failure, ensuring that the system can quickly and accurately determine a reasonable operating state. At the same time, in the case of multi-point compound failures where a single point of failure already exists and further failures occur, it can still make scientific judgments based on the safety and integrity status of each subsystem, ensuring that the system maintains a feasible operating state and fully exerts its best execution performance. This makes up for the shortcomings of existing technologies in fault handling, especially in dealing with multi-point failures, and greatly improves the fault tolerance, operational stability, and safety reliability of the steer-by-wire system.

[0143] Definitions:

[0144] Steer-by-Wire (SBW) is an electronic steering technology without mechanical connection. It uses electronic signals to replace the traditional mechanical transmission mechanism to transmit the driver's steering commands and wheel steering actions.

[0145] "Fault-on" mode: This is the core of the safety design of the steer-by-wire system. It requires that after the system detects a single fault (such as an ECU crash, abnormal sensor signal, short circuit in motor windings, etc.), it can not only identify the fault in a timely and reliable manner, but also immediately and seamlessly take over the operation of the faulty component through the built-in redundant architecture (such as redundant ECUs, redundant sensors, redundant power supplies, and redundant actuators). This ensures that the system continues to meet basic operating conditions throughout the entire degraded operation period (e.g., until the vehicle is safely parked or arrives at a repair shop).

[0146] Upper steering feel unit: This is the core component of the steer-by-wire system. Its main function is to provide the driver with a realistic tactile feel for steering wheel operation by simulating the road feel feedback of a mechanical steering system.

[0147] Downward steering actuator: It is the core component of the steer-by-wire system. Its core function is to convert the steering commands of the electronic control unit (ECU) into the actual steering actions of the wheels, thereby realizing the directional control of the vehicle.

[0148] DIN standards (Deutsche Industrienormen, German Industrial Standards) refer to a system of technical specifications covering multiple fields such as industry, automobiles, electronics, and machinery.

[0149] Normal: No functional safety faults, can calculate target torque and drive control normally.

[0150] FailOp: It can perform calculations and controls, but the input signal supporting the target torque calculation has a minor fault. The faulty signal can be replaced by a redundant signal or a default value. For example, after a CAN communication failure, the default value can be used. If there are two NTCs for the PCB temperature signal, the other NTC can be used after one NTC fails.

[0151] FailCal: It can perform calculations but cannot control them (due to drive-related faults). A fault in the drive link will shut down the drive output, such as a pre-drive IC failure or a three-phase current failure.

[0152] FailCalop: It can calculate, but cannot control (drive-related fault), and the input signal supporting the target torque calculation has a minor fault.

[0153] FailCtrl: The target cannot be calculated correctly, but control can be executed correctly. A critical input signal supporting target torque calculation is faulty, such as the steering wheel torque / angle signal.

[0154] Fail: Unable to calculate or control. The key input signal supporting the target torque calculation is faulty, and the drive chain is faulty.

[0155] SNormal: No functional safety-related faults.

[0156] SNormal-Limit: Even with a fault, sufficient redundancy ensures that a further failure in another independent system will not lead to a complete loss of assistance.

[0157] SFailOp: There is a fault; further failure of another independent system may result in a complete loss of power.

[0158] SFailDegrad: There is a fault, and further faults may result in a complete loss of power steering; and both subsystems are faulty, but steering capability is still supported or partially supported.

[0159] SErr: Power steering is completely lost; steering control is not supported. Attached Figure Description

[0160] Figure 1 This is a flowchart of the method of the present invention; Figure 2 This is a schematic diagram of the system architecture of the upper rotary feel unit in an embodiment of the present invention; Figure 3 This is a schematic diagram of the architecture of the upper rotary feel unit system 1 in an embodiment of the present invention; Figure 4 This is a schematic diagram of the architecture of the upper rotary feel unit system 2 in an embodiment of the present invention; Figure 5 This is a schematic diagram illustrating how the vehicle controller degrades based on the system state in an embodiment of the present invention. Detailed Implementation

[0161] like Figures 1 to 5 As shown, a system dynamic arbitration method for a redundant steering-by-wire system includes the following steps:

[0162] 1) Set up two sets of redundant subsystems, which serve as the upper steering feel unit and the lower steering execution unit of the steer-by-wire system, respectively. Each set of redundant subsystems contains subsystem A and subsystem B with the same hardware architecture.

[0163] 2) Establish CAN communication between each subsystem configured in step 1) and the vehicle, as well as CAN communication between each subsystem;

[0164] 3) In the upper steering feel unit, determine the operating status of subsystem A and subsystem B of the upper steering feel unit, including target torque, target angle, communication status, fault status, and execution capability. Based on the operating status of subsystem A and subsystem B, determine the torque distribution rule and system status of the upper steering feel unit, and transmit the target angle to the lower steering execution unit.

[0165] 4) In the lower steering feel unit, the target angle transmitted by the upper steering feel unit is received, and the operating status of subsystem A and subsystem B of the lower steering feel unit is determined respectively, including the target torque calculated based on the target angle, communication status, fault status, and execution capability. The torque distribution rules and system status of the lower steering execution unit are determined according to the operating status of subsystem A and subsystem B.

[0166] 5) The system status of the upper steering feel unit and the lower steering actuator unit is transmitted to the vehicle controller. The vehicle controller performs graded degradation and alarm based on the system status of the upper steering feel unit and the lower steering actuator unit to maintain the 'fault-operation' capability of the steer-by-wire system.

[0167] The following is an example of implementing the above method:

[0168] 1) Set up two sets of redundant subsystems, which serve as the upper steering feel unit and the lower steering execution unit of the steer-by-wire system, respectively. Each set of redundant subsystems includes subsystem A (also known as system 1) and subsystem B (also known as system 2) with the same hardware architecture.

[0169] The hardware architecture of subsystem A and subsystem B is completely identical and serves as a backup for each other. Specifically, it includes a power management chip TLF35584, an MCU chip TC377, a pre-driver chip TB9083, a MOSFET full bridge, and a sensor module. Each chip meets the ASILD level requirements and can form a dual backup at the hardware level, providing basic hardware support for system fault tolerance and avoiding functional failure due to the failure of a single subsystem.

[0170] Subsystem A and subsystem B each include a power management module, a main control module (MCU), a CAN communication module, a pre-driver module, a MOSFET full-bridge module, and a filtering module.

[0171] The power management module is used to convert the system input power into a low-voltage DC power supply that meets ASIL D level, to power the main control module MCU, pre-drive module and various sensors. At the same time, it integrates a watchdog monitoring mechanism to monitor the operating status of the main control module MCU in real time and build a safety control path to ensure the safe operation of the power supply and the core components of the system.

[0172] The main control module (MCU), as the core control unit of the system, is used to receive steering wheel button signals, steering wheel angle signals, and motor position sensor signals, run the target torque and FOC control algorithm to generate motor control commands, manage information transmission within the subsystem and between the subsystem and other systems, and integrate various feedback signals to realize fault monitoring, logical operations and drive strategy execution, so as to ensure the stable and safe operation of the motor.

[0173] The CAN communication module is used to enable information interaction between the main control module and other systems (including external systems and subsystems A / B), and to complete the transmission of instructions and status data.

[0174] The pre-drive module is used to receive drive waveform control commands issued by the main control module MCU, drive the MOSFET full-bridge module to output PWM drive signals, and also has the fault diagnosis function of the full-bridge circuit, which can monitor the abnormal operation status of the full-bridge in real time.

[0175] The MOSFET full-bridge module, as the core part of the motor drive, is composed of a three-phase full-bridge circuit made up of phase line MOSFETs. It is used to receive the high-side / low-side control signals output by the pre-drive module. By controlling the on and off logic of the MOSFETs, it adjusts the phase voltage and phase current of the motor. At the same time, in conjunction with the control signals of the pre-drive module, it realizes the motor's forward and reverse rotation, speed regulation, torque regulation and other operation control actions.

[0176] The filtering module is used to filter high-frequency noise and spike pulses (such as electromagnetic interference) in the wake-up signal and power signal to ensure that devices such as the power management module and the main control module MCU will not be falsely triggered or have signal distortion, thereby improving the reliability of the entire system.

[0177] The first data port of the main control module MCU is bidirectionally connected to the first data port of the power management module, and is used to transmit power status data (such as voltage and current status after power conversion) and watchdog monitoring signals (such as operating status feedback of the main control module MCU and heartbeat / reset signals of the watchdog).

[0178] The second data port of the main control module MCU is bidirectionally connected to the first data port of the pre-drive module, and is used to transmit motor drive waveform control commands, fault feedback data such as abnormal operation status of the MOSFET full-bridge module monitored by the pre-drive module;

[0179] The third data port of the main control module MCU is bidirectionally connected to the first data port of the CAN communication module, and is used to transmit command data of external systems / subsystems (such as steering wheel button signals and steering wheel angle signals) and internal system status data (such as motor running status and fault status).

[0180] The fourth data port of the main control module MCU is connected to the second data port of the pre-drive module, and is used to transmit the operating status data of the pre-drive module (such as the working status of the pre-drive circuit and the feedback signal acquisition data).

[0181] The second data port of the power management module is connected to the second data port of the pre-drive module, and is used to transmit the power supply status data of the pre-drive module (such as the power supply voltage and current of the pre-drive module) and power safety control signals (such as power enable / disable commands);

[0182] The third data port of the power management module is connected to the second data port of the CAN communication module, and is used to transmit the working status data of the power management module (such as power conversion status, watchdog running status) and external control commands for power management.

[0183] The fourth data port of the power management module is connected to the first data port of the filtering module and is used to transmit filtered power signals and wake-up signals (such as IGN signals and INH signals).

[0184] The third data port of the pre-drive module is bidirectionally connected to the first data port of the MOSFET full-bridge module, and is used to transmit high-side / low-side control signals (PWM drive signals) and feedback data of the MOSFET full-bridge module (such as phase line current feedback and MOSFET on / off status).

[0185] The fourth data port of the pre-drive module is connected to the second data port of the filter module and is used to transmit the filtered input signal of the pre-drive module (such as the denoised signal of the control signal).

[0186] The second data port of the MOSFET full-bridge module is connected to the third data port of the filter module, and is used to transmit the filtered signals of the MOSFET full-bridge module (such as the filtered feedback signal of the motor phase current).

[0187] It is worth noting the hardware architecture of the upper-turn feel unit and the lower-turn execution unit. Figure 1 To (such as) Figure 2As shown in the diagram, the only difference between the two is that the upward-turning unit receives steering wheel torque and angle signals, while the downward-turning unit receives rack position signals. In terms of software functionality, the upward-turning feel unit senses the driver's needs and provides the required torque, while the downward-turning execution unit executes the driver's desired angle. The hardware architecture of the upward-turning feel unit (System 1) is as follows: Figure 3 As shown, the hardware architecture of System 2 with the upper rotary feel unit is as follows: Figure 4 As shown, System 1 and System 2 together form the hardware architecture of the upper rotation feel unit.

[0188] In this embodiment, the hardware architectures of subsystem A and subsystem B are completely identical, which ensures that subsystem A and subsystem B have hardware homogeneity, reduces the difficulties of redundant switching and adaptation caused by hardware differences, and allows the other subsystem to seamlessly take over when one system fails. At the same time, the complete consistency of the hardware architectures of subsystem A and subsystem B can simplify material management, assembly processes and subsequent maintenance costs in the manufacturing process, and improve the compatibility and reliability of the system hardware.

[0189] 2) Establish CAN communication between each subsystem A and subsystem B configured in step 1) and the vehicle, as well as CAN communication between the subsystems, specifically including:

[0190] 2-1) Establish CAN communication between subsystem A and subsystem B in the upshift hand feel unit and the vehicle, respectively; establish CAN communication between subsystem A and subsystem B in the downshift execution unit and the vehicle, respectively.

[0191] 2-2) Establish CAN communication between subsystem A in the upshift feel unit and subsystem A in the downshift execution unit, and establish CAN communication between subsystem B in the upshift feel unit and subsystem B in the downshift execution unit;

[0192] 2-3) Establish CAN communication between subsystem A and subsystem B in the upshift feel unit, and establish CAN communication between subsystem A and subsystem B in the downshift execution unit;

[0193] 2-4) Configure an E2E protection mechanism in each CAN communication link established in steps 2-1)-2-3) to identify data loss, data tampering and data retransmission anomalies during the communication process, and ensure the integrity and correct sequence of end-to-end data transmission.

[0194] In this embodiment, each subsystem of the upper-side feel unit receives TAS sensor signals via ADC sampling sensor information or the SENT protocol. The software then uses mechanisms such as range verification and rationality judgment to determine the fault status of the information. If all signals are normal and reliable, the software calculates the target torque and performs FOC control. Simultaneously, it transmits information such as the target torque of each controller, subsystem execution capability, and subsystem fault status to the other subsystem via CAN transceiver through inter-board communication. By default, subsystem A is the master controller. System A calculates the target torque and allocates it to systems A and B. Systems A and B each execute FOC control, as detailed below:

[0195] 3) In the upper steering feel unit, the operating status of subsystem A and subsystem B is determined, including target torque, target angle, communication status, fault status, and execution capability. Based on the operating status of subsystem A and subsystem B, the torque distribution rules and system status of the upper steering feel unit are determined, and the target angle is transmitted to the lower steering execution unit. Specifically, this includes:

[0196] 3-1) In subsystems A and B of the steering feel unit, the target torque is calculated based on the input signals, including steering wheel hand torque Tq_hand, steering wheel angle ngle_sw, vehicle speed VehSpd, and other vehicle status information.

[0197] 3-2) Perform fault diagnosis on subsystem A and subsystem B respectively to determine the fault status of each subsystem. The specific process is as follows:

[0198] 3-2-1) Perform power-on initialization self-test on subsystems A and B, including diagnosing the power management chip mechanism, MCU chip mechanism, pre-driver chip, drive link, and fault shutdown link. If an abnormality that does not meet the design requirements is detected during the power-on initialization self-test, the subsystem enters the Fail state; if no abnormality that does not meet the design requirements is detected during the power-on initialization self-test, proceed to step 3-2-2).

[0199] 3-2-2) Based on the input signals supporting the target torque calculation, including the input CAN signal, steering wheel torque signal, steering wheel angle signal, PCB temperature signal, power supply status, and MCU operating status, determine the fault status of the target torque calculation for subsystem A and subsystem B in the following manner:

[0200] If all input signals supporting the target torque calculation are fault-free, then the target torque calculation is fault-free.

[0201] If the input signal supporting the target torque calculation is faulty, and the faulty input signal is a non-critical input signal that can be replaced by a redundant signal or a default value (such as a faulty input CAN signal or PCB temperature signal), then the target torque calculation has a slight fault. The calculated target torque can be used for target torque execution, but the target torque is not the best or most accurate.

[0202] If the input signal supporting the target torque calculation is faulty, and the faulty input signal is a critical input signal (such as steering wheel torque signal or steering wheel angle signal) that cannot be replaced by redundant signals or default values, then the target torque calculation has a serious fault.

[0203] 3-2-3) Based on the input signals supporting the target torque execution, including the input motor position signal (MPS), the input three-phase current signal, the PCB temperature signal, the power supply and MCU operating status, determine the fault status of subsystem A and subsystem B for target torque execution in the following manner:

[0204] If all input signals supporting the execution of the target torque are fault-free, then the execution of the target torque is fault-free.

[0205] If any input signal supporting the execution of the target torque is faulty, then the execution of the target torque is faulty;

[0206] 3-2-4) Based on the fault state calculated from the target torque and the fault state executed by the target torque, determine the fault states of subsystem A and subsystem B in the following manner:

[0207] If there is no fault in the target torque calculation and no fault in the target torque execution, the subsystem is in the Normal state.

[0208] If there is a minor fault in the target torque calculation, but no fault in the target torque execution, the subsystem is in the FailOp state.

[0209] If there is a serious fault in the target torque calculation, but no fault in the target torque execution, the subsystem is in the FailCtrl state.

[0210] If there is no fault in the target torque calculation but a fault in the target torque execution, the subsystem is in the FailCal state.

[0211] If there is a minor fault in the target torque calculation and a fault in the target torque execution, the subsystem is in the FailCalop state.

[0212] If there is a serious fault in the target torque calculation and a fault in the target torque execution, the subsystem is in a Fail state.

[0213] 3-3) Calculate the execution capabilities of subsystem A and subsystem B respectively according to the following formulas;

[0214] s =min( ov , uv , ot_pcb , ot_mot )* dri ;

[0215] In the formula, s For single-board execution capability, ov This is the overvoltage and torque limiting coefficient for the bus. uv This is the undervoltage torque limiting coefficient for the bus voltage. ot_pcb This refers to the over-temperature torsion limit coefficient of the PCB board. ot_mot This is the over-temperature torque limiting coefficient of the motor. dri This is the driving chain integrity coefficient.

[0216] It is worth noting that, ov For bus voltage overvoltage torque limiting coefficient, uv For undervoltage and torque limiting coefficient of bus voltage, ot_pcb For PCB board over-temperature torsion limit coefficient, ot_mot For motor over-temperature torque limiting coefficient, dri The drive chain integrity coefficient is a core parameter for quantifying the hardware operation constraints and link reliability of the subsystem. Its value range is uniformly limited to 0% to 100%. 0% represents that the corresponding hardware is completely restricted (such as severe overvoltage or overtemperature) or the drive chain is completely failed. 100% represents that the corresponding hardware has no operating restrictions (such as normal voltage and temperature) or the drive chain is completely intact. The higher the value, the better the hardware operation and the stronger the drive link reliability.

[0217] In this embodiment, the execution capability is calculated based on the fault diagnosis results of key components such as drive circuits, motors, sensors, and power supplies. It is a value between 0 and 1, where 1 represents complete normal operation, 0 represents complete failure, and 0.x represents partial capability degradation. For example, an execution capability of 0.3 indicates severe capability degradation, which may include abnormalities such as severe PCB overheating, undervoltage bus, or partial drive chain failure. An execution capability of 0.6 indicates moderate execution capability degradation, which may include abnormalities such as moderate motor overheating or single MOSFET failure in the drive chain. An execution capability of 0.9 indicates slight execution capability degradation, which may include slight PCB overheating.

[0218] 3-4) While transmitting the target torque, fault status, and execution capability of subsystem A to subsystem B, the target torque, fault status, and execution capability of subsystem B are transmitted to subsystem A.

[0219] 3-5) Detect the communication status of subsystem A and subsystem B. If there is no communication failure in either subsystem A or subsystem B, enter the collaborative working mode; if there is a communication failure in either subsystem A or subsystem B, enter the independent emergency mode.

[0220] 3-6) Based on the communication status, target torque, fault status, and execution capability of subsystem A, and the communication status, target torque, fault status, and execution capability of subsystem B, determine the system status of the main control system, torque distribution rules, and upper steering feel unit.

[0221] 3-7) After the main control system distributes the torque command, subsystems A and B execute the torque output according to the torque distribution rules.

[0222] 4) In the lower steering feel unit, the target angle transmitted by the upper steering feel unit is received, and the operating status of subsystem A and subsystem B is determined respectively, including the target torque calculated based on the target angle, communication status, fault status, and execution capability. Based on the operating status of subsystem A and subsystem B, the torque distribution rules and system status of the lower steering execution unit are determined, as follows:

[0223] 4-1) In subsystems A and B of the lower-turn execution unit, the target torque required for the target angle is calculated according to the input signal. The input signal includes the vehicle CAN signal, the CAN signal including the target angle emitted from the upper-turn hand feel unit, the rack position signal, and the PCB temperature signal.

[0224] 4-2) Perform fault diagnosis on subsystem A and subsystem B respectively to determine the fault status of each subsystem, as follows:

[0225] 4-2-1) In the next execution unit, a power-on initialization self-test is performed on subsystems A and B, including diagnosing the power management chip mechanism, MCU chip mechanism, pre-driver chip, and drive link / fault shutdown link. If an abnormality that does not meet the design requirements is detected during the power-on initialization self-test, the subsystem enters the Fail state; if no abnormality that does not meet the design requirements is detected during the power-on initialization self-test, proceed to step 4-2-2).

[0226] 4-2-2) Based on the input signals supporting the target angle calculation, including the CAN signal containing the target angle emitted from the upper steering feel unit, the vehicle CAN signal, the rack position signal, the PCB temperature signal, etc., determine the fault status of the target angle calculation for subsystem A and subsystem B in the following manner:

[0227] If all input signals supporting the target torque calculation for angle control are fault-free, then the target torque calculation is fault-free.

[0228] If the input signal for calculating the target torque that supports angle control is faulty, and the faulty input signal can be replaced by a redundant signal or a default value (e.g., a single control subsystem has temperature NTC redundancy, and if only one NTC is faulty, another NTC can be used; or if the vehicle speed signal is faulty, the default vehicle speed can be used), then the target torque calculation has a minor fault.

[0229] If the input signal for calculating the target torque that supports angle control is faulty, and the faulty input signal cannot be replaced by a redundant signal or a default value (such as the CAN signal representing the driver's target angle transmitted from the uplink, or the rack position signal), then the target torque calculation has a serious fault.

[0230] 4-2-3) Based on the input signals supporting the execution of the target torque, including motor position signals and three-phase current signals, determine the fault status of the target torque execution of subsystem A and subsystem B in the following manner:

[0231] If none of the input signals supporting the execution of the target torque are faulty, then the execution of the target torque is fault-free.

[0232] If any input signal supporting the execution of the target torque is faulty, then the execution of the target torque is faulty;

[0233] 4-2-4) Based on the fault state calculated from the target torque and the fault state executed by the target torque, determine the fault states of subsystem A and subsystem B in the following manner:

[0234] If there is no fault in the target torque calculation and no fault in the target torque execution, the subsystem is in Normal state and there are no functional safety faults.

[0235] If there is a minor fault in the target torque calculation, but no fault in the target torque execution, the subsystem is in the FailOp state.

[0236] If there is a serious fault in the target torque calculation, but no fault in the target torque execution, the subsystem is in the FailCtrl state.

[0237] If there is no fault in the target torque calculation but a fault in the target torque execution, the subsystem is in the FailCal state.

[0238] If there is a minor fault in the target torque calculation and a fault in the target torque execution, the subsystem is in the FailCalop state.

[0239] If there is a serious fault in the target torque calculation and a fault in the target torque execution, the subsystem is in a Fail state.

[0240] 4-3) Calculate the execution capabilities of subsystem A and subsystem B respectively, as follows:

[0241] s =min( ov , uv , ot_pcb , ot_mot )* dri ;

[0242] In the formula, s For single-board execution capability, ov This is the overvoltage and torque limiting coefficient for the bus. uv This is the undervoltage torque limiting coefficient for the bus voltage. ot_pcb This refers to the over-temperature torsion limit coefficient of the PCB board. ot_mot This is the over-temperature torque limiting coefficient of the motor. dri This is the driving chain integrity coefficient.

[0243] 4-4) While transmitting the target angle, fault status and execution capability of subsystem A to subsystem B, transmit the target angle, fault status and execution capability of subsystem B to subsystem A.

[0244] 4-5) Detect the communication status of subsystem A and subsystem B. If there is no communication failure in either subsystem A or subsystem B, enter the collaborative working mode; if there is a communication failure in either subsystem A or subsystem B, enter the independent emergency mode.

[0245] 4-6) Based on the communication status, target angle, fault status and execution capability of subsystem A, and the communication status, target torque, fault status and execution capability of subsystem B, determine the angle allocation rules and the system status of the next execution unit.

[0246] In this embodiment, in steps 3-6) and 4-6), the main control system, torque distribution rules, and system status are determined in the following manner:

[0247] S1) If there is no inter-board communication fault between subsystem A and subsystem B, the system status of the main control system, torque distribution rules, and upshift feel unit / downshift execution unit shall be determined in the following manner:

[0248] S1-1) Set the fault state priority rule as “Normal=FailCal>FailOp=FailCalOp>FailCtrl>Fail”, and take the subsystem with the higher fault state priority in subsystem A and subsystem B as the master control system. If the fault state priorities of subsystem A and subsystem B are the same, then subsystem A will be the master control system.

[0249] S1-2) Based on the execution capabilities of subsystem A and subsystem B, determine the torque distribution rules in the following manner:

[0250] Set the minimum execution capability of the unit to min(execution capability of subsystem A, execution capability of subsystem B), and set the maximum execution capability of the unit to max(execution capability of subsystem A, execution capability of subsystem B).

[0251] If the smaller and larger values ​​of the unit execution capability satisfy the following formula, then subsystem A and subsystem B are both torque output systems, and the output torque of subsystem A and subsystem B is 1 / 2 × the target torque calculated by the main control system:

[0252] (2*Capability_Min>Tq_Target) or (2*Capability_Min>Capability_Max)

[0253] In the formula, Capability_Min is the smaller value of the unit's execution capability, Tq_Target is the target torque calculated by the main control system, and Capability_Max is the larger value of the unit's execution capability;

[0254] If not satisfied, the subsystem with greater execution capability is selected from subsystem A and subsystem B as the torque output system. The output torque of the torque output system is min (the target torque calculated by the main control system and the execution capability of the torque output system).

[0255] S1-3) Based on the fault status of subsystem A and subsystem B, determine the preliminary system status of the upshift feel unit / downshift execution unit in the following manner:

[0256] If the fault states of subsystem A and subsystem B are both Normal, then the initial fault state of the up-turn feel unit / down-turn execution unit is SNormal.

[0257] If the fault state of subsystem A is Normal and the fault state of subsystem B is FailOp, or if the fault state of subsystem A is FailOp and the fault state of subsystem B is Normal, then the initial fault state of the up-turn feel unit / down-turn execution unit is SNormal-Limit.

[0258] If the fault state of subsystem A is Normal and the fault state of subsystem B is FailCal, FailCalOp, FailCtrl, or Fail, or if the fault state of subsystem B is Normal and the fault state of subsystem A is FailCal, FailCalOp, FailCtrl, or Fail, then the initial fault state of the up-turn feel unit / down-turn execution unit is SFailOp.

[0259] If the fault states of both subsystem A and subsystem B are FailOp, then the initial fault state of the up-turn feel unit / down-turn execution unit is SFailOp.

[0260] If the fault state of subsystem A is FailOp and the fault state of subsystem B is FailCal, FailCalOp, FailCtrl, or Fail, or if the fault state of subsystem B is FailOp and the fault state of subsystem A is FailCal, FailCalOp, FailCtrl, or Fail, then the initial fault state of the up-turn feel unit / down-turn execution unit is SFailDegrad.

[0261] If the fault state of subsystem A is FailCtrl and the fault state of subsystem B is FailCal or FailCalop, or if the fault state of subsystem B is FailCtrl and the fault state of subsystem A is FailCal or FailCalop, then the initial fault state of the up-turn feel unit / down-turn execution unit is SFailDegrad.

[0262] In other cases, the initial fault state of the upshift feel unit / downshift actuation unit is SErr;

[0263] S1-4) According to the torque distribution rule, the system execution capability of the upshift feel unit / downshift actuator unit is calculated as follows:

[0264] ① If both subsystem A and subsystem B are torque output systems, the system execution capability of the upshift feel unit / downshift actuator unit shall be calculated as follows:

[0265] System_Capability=2*Capability_Min

[0266] Capability_Min=min(Cap_A,Cap_B)

[0267] In the formula, System_Capability is the system execution capability, Capability_Min is the smaller value of the unit execution capability, Cap_A is the execution capability of subsystem A, and Cap_B is the execution capability of subsystem B;

[0268] ② If only one of subsystems A and B is a torque output system, then the system execution capability of the upshift feel unit / downshift actuator unit shall be calculated as follows:

[0269] System_Capability=Capability_Max

[0270] Capability_Max=max(Cap_A,Cap_B)

[0271] In the formula, System_Capability is the system execution capability, Capability_Max is the larger value of the unit execution capability, Cap_A is the execution capability of subsystem A, and Cap_B is the execution capability of subsystem B;

[0272] S1-5) Based on the system's execution capabilities, determine the capability status of the upward-turning touch unit / downward-turning execution unit in the following manner:

[0273] If the system execution capability is ≥80%, then the capability status of the up-turn feel unit / down-turn execution unit is SNormal;

[0274] If 50% ≤ system execution capability < 80%, then the capability status of the upshift feel unit / downshift execution unit is SFailOp.

[0275] If 30% ≤ system execution capability < 50%, then the capability status of the up-to-down hand feel unit / down-to-up-to-down execution unit is SFailDegrad.

[0276] If the system execution capability is less than 30%, then the capability status of the up-turn feel unit / down-turn execution unit is SErr;

[0277] S1-6) Set the severity rule of “SNormal < SNormal-Limit < SFailOp < SFailDegrad < SErr”, and take the more severe state between the initial state and the capability state of the upshifting feel unit as the fault state of the upshifting feel unit.

[0278] S2) If there is an inter-board communication failure in subsystem A or subsystem B, the system status of the main control system, torque distribution rules, and upshift feel unit / downshift execution unit shall be determined in the following manner:

[0279] S2-1) Set the arbitration priority rule as “Normal>FailOp>Failcal=FailCalOp=FailCtrl=Fail”, and determine the arbitration status of subsystem A and subsystem B in the following manner:

[0280] If the fault status of the subsystem is Normal or FailOp, then the arbitration status of the subsystem is an available system.

[0281] If the fault status of the subsystem is FailCalOp, FailCtrl, or Fail, then the arbitration status of the subsystem is unavailable.

[0282] S2-2) Based on the arbitration status of subsystem A and subsystem B, determine the master control system in the following manner:

[0283] ① If both subsystem A and subsystem B are available systems, then the difference in execution capability between subsystem A and subsystem B at the previous moment is taken as the execution capability deviation at the previous moment. Based on the execution capability deviation at the previous moment, the master control system in subsystem A and subsystem B is determined in the following manner:

[0284] If the execution capability deviation of the previous moment is greater than 10%, then the subsystem with the greater execution capability will be designated as the main control system.

[0285] If the execution capability deviation of the previous moment is ≤10%, then the master control system of the previous moment will be used as the master control system of the current moment.

[0286] ②If subsystem A or subsystem B is an unavailable system, the subsystem whose arbitration status is available shall be designated as the master control system;

[0287] ③ If both subsystem A and subsystem B are unavailable, the master control system from the previous moment will be used as the master control system.

[0288] S2-3) Set the torque distribution rule as follows: Only the main control system determined in step S2-2) is used as the torque output system, and the output torque value = min (target torque calculated by the main control system, execution capability of the main control system).

[0289] 4-7) After the main control system distributes the target torque, subsystems A and B respond to the target angle command by executing torque output.

[0290] 5) The system status of the upper steering feel unit and the lower steering actuator unit is transmitted to the vehicle controller. The vehicle controller performs graded degradation and alarm based on the system status of the upper steering feel unit and the lower steering actuator unit to maintain the 'fault-operation' capability of the steer-by-wire system.

[0291] In this embodiment, the specific method of hierarchical degradation is as follows:

[0292] (1) According to the severity rule of “SNormal<SNormal-Limit<SFailOp<SFailDegrad<SErr”, the more severe system state between the system state of the upper hand feel unit and the system state of the lower execution unit shall be used as the benchmark state for degradation judgment.

[0293] (2) such as Figure 3 As shown, based on the downgrade determination baseline status, downgrades are performed in the following manner:

[0294] If the downgrade determination benchmark state is SNormal, the entire vehicle will not be downgraded;

[0295] If the downgrade determination benchmark status is SNormal-Limit, the vehicle can be downgraded to level 1 according to DIN standard (standard number DIN70065), which restricts continuous driving.

[0296] If the downgrade determination benchmark status is SFailOp or SFailOpD, the whole vehicle shall comply with DIN standard X-2;

[0297] If the degradation judgment benchmark status is SFailDegrad, the whole vehicle will prematurely end the DIN standard X-2 and implement DIN X-3;

[0298] If the downgrade determination baseline state is SErr, then determine whether the vehicle has a steering backup or whether the vehicle is in a downgrade 2 state, and perform the downgrade as follows:

[0299] If the vehicle has a steering backup, then DIN standard X-3 can be implemented;

[0300] If the vehicle is in a downgraded state 2, then DIN standard 2-3 shall be followed;

[0301] If the vehicle does not have a steering backup and is not in a downgraded state 2, the vehicle will immediately enter the DIN standard X-emergency stop.

[0302] The term "downgrade 1" refers to the system maintaining limited driving capability under minor fault conditions, performing optional speed reduction operations, and simultaneously maintaining limited continuous driving privileges.

[0303] The aforementioned "downgrade 2" refers to the system implementing slow-moving and restricted driving under moderate fault conditions, retaining basic driving rights for short-distance return trips, relying on functional redundancy to ensure basic driving, and guiding vehicles to "slowly drive home".

[0304] The X-2 system executes a graded degraded driving strategy under moderate fault conditions, sequentially entering the process of "speed reduction (stage A) → limited duration continuous driving (stage B) → automatic speed reduction (stage C)" to maintain basic functional redundancy and avoid complete loss of power assist.

[0305] The X-3 system executes a stringent degradation strategy under severe fault conditions, including operations such as "slowly returning home and continuously automatically reducing speed," eventually bringing the vehicle to a near standstill. In some scenarios, it can be combined with "vehicle support" for execution.

[0306] The X-Emergency Stop: The emergency braking operation triggered by the system in the event of a fatal malfunction (such as complete loss of power steering) to bring the vehicle to a rapid stop. It is the highest priority fault response action.

[0307] It is worth noting that when performing a degradation, the system also needs to consider whether the system currently meets the conditions for state transition, such as... Figure 3 As shown, each jump condition corresponds to a number from "1" to "11", as detailed below:

[0308] "1": Faults that restrict system integrity and security integrity;

[0309] "2": Reach the speed limit for "Transformation X-2, Stage B";

[0310] “3”: The time interval for transitioning to “X-2, B stage”;

[0311] "4": The speed limit for reaching "Degraded State 2";

[0312] "5": Lateral control is about to be lost or has already been lost (e.g., due to subsequent failures);

[0313] "6": The vehicle has come to a complete stop;

[0314] "7": Loss of lateral control of the vehicle;

[0315] "8": A fault that restricts system integrity but provides sufficient security integrity;

[0316] "9": The speed limit for reaching "Degraded State 1";

[0317] "10": The possibility of switching again within the driving cycle;

[0318] "11": Lateral guidance of the vehicle is limited after a subsequent malfunction.

[0319] It is worth noting that this embodiment uses the more severe state between the upward and downward steering units as the degradation benchmark, and maximizes the continuity of steering function through a gradient-based layered degradation strategy, abandoning the "one-size-fits-all" crude degradation mode. At the same time, the redundant protection design of the SErr state balances safety and driving convenience, making up for the shortcomings of existing technologies in dealing with multiple complex faults and excessive degradation, meeting the ISO26262 functional safety standard and ASILD level requirements, and significantly improving the fault tolerance and operational reliability of the steer-by-wire system.

[0320] In summary, this invention, within the steering feel unit, uses the execution capabilities, fault states, communication states, and target torque calculation results of subsystems A and B as the core judgment criteria. It selects the main control system through explicit fault state priority rules and formulates torque distribution rules based on the quantitative relationship between the unit's execution capability extreme value and the target torque. This design avoids the problem of underperforming output caused by forcibly distributing torque when a single system's execution capability is insufficient, and also eliminates resource idleness in scenarios with redundant execution capabilities. It achieves optimal resource utilization for steering feel torque distribution while ensuring accurate and stable response to the driver's feel needs, meeting the core requirement of steer-by-wire systems for realistic road feel feedback.

[0321] In the downward steering unit, the core function is to achieve precise execution of the driver's target angle through torque control. Fault diagnosis is consistent with that of the upward steering feel unit, both based on target torque calculation and torque execution status. Therefore, the downward steering unit fully adopts the same core judgment logic as the upward steering unit (including main control system selection, execution capability quantification, fault status linkage, and torque distribution rules). This not only adapts to the downward steering's functional positioning of "torque-driven angle execution," ensuring precise matching of torque distribution with the subsystem's actual execution capability, achieving efficient and stable steering angle output, but also significantly simplifies the overall system control architecture through the uniformity of the control logic between the upward and downward steering units. This reduces the risk of logical conflicts during software development and debugging, as well as the complexity and cost of later maintenance.

[0322] In summary, this invention, through a refined fault diagnosis mechanism, dynamic execution capability calculation, and flexible torque distribution strategy, enables the steer-by-wire system to achieve balanced cooperation between the two systems under normal operating conditions. In complex scenarios such as single-point faults, multi-point composite faults, and inter-board communication failures, it maximizes the remaining execution potential of subsystems, continuously maintaining "fault-to-operation" capability and always preserving the system's optimal performance. This method significantly improves the fault tolerance, operational stability, and reliability of the steer-by-wire system, fully meeting ASILD level functional safety requirements and overcoming the shortcomings of existing technologies that suffer from excessive performance degradation under complex fault scenarios.

[0323] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications made to the present invention by those skilled in the art without departing from the spirit of the present invention shall fall within the protection scope of the present invention.

Claims

1. A method for state arbitration and torque distribution in a steer-by-wire system based on safety integrity, characterized in that, Includes the following steps: 1) Set up two sets of redundant subsystems, which serve as the upper steering feel unit and the lower steering execution unit of the steer-by-wire system, respectively. Each set of redundant subsystems contains subsystem A and subsystem B with the same hardware architecture. 2) Establish CAN communication between each subsystem configured in step 1) and the vehicle, as well as CAN communication between each subsystem; 3) In the upper steering feel unit, determine the operating status of subsystem A and subsystem B of the upper steering feel unit, including target torque, target angle, communication status, fault status, and execution capability. Based on the operating status of subsystem A and subsystem B, determine the torque distribution rule and system status of the upper steering feel unit, and transmit the target angle to the lower steering execution unit. 4) In the lower steering feel unit, the target angle transmitted by the upper steering feel unit is received, and the operating status of subsystem A and subsystem B of the lower steering feel unit is determined respectively, including the target torque calculated based on the target angle, communication status, fault status, and execution capability. The torque distribution rules and system status of the lower steering execution unit are determined according to the operating status of subsystem A and subsystem B. 5) The system status of the upper steering feel unit and the lower steering actuator unit is transmitted to the vehicle controller. The vehicle controller performs degradation and alarm based on the system status of the upper steering feel unit and the lower steering actuator unit to maintain the 'fault-operation' capability of the steer-by-wire system.

2. The method according to claim 1, characterized in that: In step 2), CAN communication between each subsystem configured in step 1) and the vehicle, as well as CAN communication between the subsystems, are established. Specifically, this includes: 2-1) Establish CAN communication between subsystem A and subsystem B in the upshift hand feel unit and the vehicle, respectively; establish CAN communication between subsystem A and subsystem B in the downshift execution unit and the vehicle, respectively. 2-2) Establish CAN communication between subsystem A in the upshift feel unit and subsystem A in the downshift execution unit, and establish CAN communication between subsystem B in the upshift feel unit and subsystem B in the downshift execution unit; 2-3) Establish CAN communication between subsystem A and subsystem B in the upshift feel unit, and establish CAN communication between subsystem A and subsystem B in the downshift execution unit; 2-4) Configure an E2E protection mechanism in each CAN communication link established in steps 2-1)-2-3) to identify data loss, data tampering and data retransmission anomalies during the communication process, and ensure the integrity and correct sequence of end-to-end data transmission.

3. The method according to claim 1, characterized in that: In step 3), the torque distribution rule and system state are determined in the following manner: 3-1) In subsystems A and B of the steering feel unit, the target torque and target angle are calculated according to the input signals, respectively. The input signals include steering wheel torque, steering wheel angle, and vehicle speed. 3-2) Perform fault diagnosis on subsystem A and subsystem B respectively to determine the fault status of each subsystem; 3-3) Calculate the execution capabilities of subsystem A and subsystem B respectively; 3-4) While transmitting the target torque, fault status, and execution capability of subsystem A to subsystem B, the target torque, fault status, and execution capability of subsystem B are transmitted to subsystem A. 3-5) Detect the communication status of subsystem A and subsystem B; 3-6) Based on the communication status, target torque, fault status, and execution capability of subsystem A, and the communication status, target torque, fault status, and execution capability of subsystem B, determine the system status of the main control system, torque distribution rules, and upper steering feel unit. 3-7) After the main control system distributes the torque command, subsystems A and B execute the torque output according to the torque distribution rules.

4. The method according to claim 3, characterized in that: In step 3-2), the fault status of each subsystem is determined as follows: 3-2-1) Perform power-on initialization self-test on subsystems A and B, including diagnosing the power management chip mechanism, MCU chip mechanism, pre-driver chip, drive link, and fault shutdown link. If an abnormality that does not meet the design requirements is detected during the power-on initialization self-test, the subsystem enters the Fail state; if no abnormality that does not meet the design requirements is detected during the power-on initialization self-test, proceed to step 3-2-2). 3-2-2) Based on the input signals supporting the target torque calculation, including the input CAN signal, steering wheel torque signal, steering wheel angle signal, PCB temperature signal, power supply status, and MCU operating status, determine the fault status of the target torque calculation for subsystem A and subsystem B in the following manner: If all input signals supporting the target torque calculation are fault-free, then the target torque calculation is fault-free. If the input signal supporting the target torque calculation is faulty, and the faulty input signal can be replaced by a redundant signal or a default value, then the target torque calculation has a minor fault. If the input signal supporting the target torque calculation is faulty, and the faulty input signal cannot be replaced by a redundant signal or a default value, then the target torque calculation has a serious fault. 3-2-3) Based on the input signals supporting the target torque execution, including the input motor position signal, the input three-phase current signal, the PCB temperature signal, the power supply and MCU operating status, determine the fault status of subsystem A and subsystem B for target torque execution in the following manner: If all input signals supporting the execution of the target torque are fault-free, then the execution of the target torque is fault-free. If any input signal supporting the execution of the target torque is faulty, then the execution of the target torque is faulty. 3-2-4) Based on the fault state calculated from the target torque and the fault state executed by the target torque, determine the fault states of subsystem A and subsystem B in the following manner: If there is no fault in the target torque calculation and no fault in the target torque execution, then the subsystem is in the Normal state. If there is a minor fault in the target torque calculation, but no fault in the target torque execution, the subsystem is in the FailOp state. If there is a serious fault in the target torque calculation, but no fault in the target torque execution, the subsystem is in the FailCtrl state. If there is no fault in the target torque calculation but a fault in the target torque execution, the subsystem is in the FailCal state. If there is a minor fault in the target torque calculation and a fault in the target torque execution, the subsystem is in the FailCalop state. If there is a serious fault in the target torque calculation and a fault in the target torque execution, the subsystem is in a Fail state.

5. The method according to claim 1, characterized in that: In step 4), the torque distribution rule and system state are determined in the following manner: 4-1) In subsystems A and B of the lower-turn execution unit, the target torque required for the target angle is calculated according to the input signal. The input signal includes the vehicle CAN signal, the CAN signal including the target angle emitted from the upper-turn hand feel unit, the rack position signal, and the PCB temperature signal. 4-2) Perform fault diagnosis on subsystem A and subsystem B respectively to determine the fault status of each subsystem; 4-3) Calculate the execution capabilities of subsystem A and subsystem B respectively; 4-4) While transmitting the target torque, fault status and execution capability of subsystem A to subsystem B, the target torque, fault status and execution capability of subsystem B are transmitted to subsystem A. 4-5) Detect the communication status of subsystem A and subsystem B; 4-6) Based on the communication status, target torque, fault status, and execution capability of subsystem A, and the communication status, target torque, fault status, and execution capability of subsystem B, determine the system status of the main control system, torque distribution rules, and downstream execution units. 4-7) After the main control system distributes the target torque, subsystems A and B respond to the target angle command by executing torque output.

6. The method according to claim 5, characterized in that: In step 4-2), the fault status of each subsystem is determined in the following manner: 4-2-1) In the next execution unit, a power-on initialization self-test is performed on subsystems A and B, including diagnosing the power management chip mechanism, MCU chip mechanism, pre-driver chip, and drive link / fault shutdown link. If an abnormality that does not meet the design requirements is detected during the power-on initialization self-test, the subsystem enters the Fail state; if no abnormality that does not meet the design requirements is detected during the power-on initialization self-test, proceed to step 4-2-2). 4-2-2) Based on the input signals supporting the target angle calculation, including the CAN signal from the upper steering feel unit (including the target angle), the vehicle CAN signal, the rack position signal, and the PCB temperature signal, determine the fault status of the target torque calculation for subsystem A and subsystem B in the following manner: If all input signals supporting the target torque calculation for angle control are fault-free, then the target torque calculation is fault-free. If the input signal for calculating the target torque that supports angle control is faulty, and the faulty input signal can be replaced by a redundant signal or a default value, then the target torque calculation has a minor fault. If the input signal for calculating the target torque that supports angle control is faulty, and the faulty input signal cannot be replaced by a redundant signal or a default value, then the target torque calculation has a serious fault. 4-2-3) Based on the input signals supporting the execution of the target torque, including motor position signals and three-phase current signals, determine the fault status of the target torque execution of subsystem A and subsystem B in the following manner: If none of the input signals supporting the execution of the target torque are faulty, then the execution of the target torque is fault-free. If any input signal supporting the execution of the target torque is faulty, then the execution of the target torque is faulty. 4-2-4) Based on the fault state calculated from the target torque and the fault state executed by the target torque, determine the fault states of subsystem A and subsystem B in the following manner: If there is no fault in the target torque calculation and no fault in the target torque execution, the subsystem is in Normal state and there are no functional safety faults. If there is a minor fault in the target torque calculation, but no fault in the target torque execution, the subsystem is in the FailOp state. If there is a serious fault in the target torque calculation, but no fault in the target torque execution, the subsystem is in the FailCtrl state. If there is no fault in the target torque calculation but a fault in the target torque execution, the subsystem is in the FailCal state. If there is a minor fault in the target torque calculation and a fault in the target torque execution, the subsystem is in the FailCalop state. If there is a serious fault in the target torque calculation and a fault in the target torque execution, the subsystem is in a Fail state.

7. The method according to claim 3 or 5, characterized in that: The execution capabilities of subsystem A and subsystem B are calculated as follows: s =min( ov , uv , ot_pcb , ot_mot )* dri ; In the formula, s For single-board execution capability, ov This is the overvoltage and torque limiting coefficient for the bus. uv This is the undervoltage torque limiting coefficient for the bus voltage. ot_pcb This refers to the over-temperature torsion limit coefficient of the PCB board. ot_mot This is the over-temperature torque limiting coefficient of the motor. dri This is the driving chain integrity coefficient.

8. The method according to claim 3 or 5, characterized in that: The main control system, torque distribution rules, and system status are determined in the following manner: S1) If there is no inter-board communication fault between subsystem A and subsystem B, the system status of the main control system, torque distribution rules, and upshift feel unit / downshift execution unit shall be determined in the following manner: S1-1) Set the fault state priority rule "Normal=FailCal>FailOp=FailCalOp>FailCtrl>Fail" and designate the subsystem with the higher fault state priority in subsystem A and subsystem B as the master control system; S1-2) Based on the execution capabilities of subsystem A and subsystem B, determine the torque distribution rules in the following manner: Set the minimum execution capability of the unit to min(execution capability of subsystem A, execution capability of subsystem B), and set the maximum execution capability of the unit to max(execution capability of subsystem A, execution capability of subsystem B). If the smaller and larger values ​​of the unit execution capability satisfy the following formula, then subsystem A and subsystem B are both torque output systems, and the output torque of subsystem A and subsystem B is 1 / 2 × the target torque calculated by the main control system: (2*Capability_Min>Tq_Target) or (2*Capability_Min>Capability_Max); In the formula, Capability_Min is the smaller value of the unit's execution capability, Tq_Target is the target torque calculated by the main control system, and Capability_Max is the larger value of the unit's execution capability; If not satisfied, the subsystem with greater execution capability is selected from subsystem A and subsystem B as the torque output system. The output torque of the torque output system is min (the target torque calculated by the main control system and the execution capability of the torque output system). S1-3) Based on the fault status of subsystem A and subsystem B, determine the preliminary system status of the upshift feel unit / downshift execution unit in the following manner: If the fault states of subsystem A and subsystem B are both Normal, then the initial fault state of the up-turn feel unit / down-turn execution unit is SNormal. If the fault state of subsystem A is Normal and the fault state of subsystem B is FailOp, or if the fault state of subsystem A is FailOp and the fault state of subsystem B is Normal, then the initial fault state of the up-turn feel unit / down-turn execution unit is SNormal-Limit. If the fault state of subsystem A is Normal and the fault state of subsystem B is FailCal, FailCalOp, FailCtrl, or Fail, or if the fault state of subsystem B is Normal and the fault state of subsystem A is FailCal, FailCalOp, FailCtrl, or Fail, then the initial fault state of the up-turn feel unit / down-turn execution unit is SFailOp. If the fault states of both subsystem A and subsystem B are FailOp, then the initial fault state of the up-turn feel unit / down-turn execution unit is SFailOp. If the fault state of subsystem A is FailOp and the fault state of subsystem B is FailCal, FailCalOp, FailCtrl, or Fail, or if the fault state of subsystem B is FailOp and the fault state of subsystem A is FailCal, FailCalOp, FailCtrl, or Fail, then the initial fault state of the up-turn feel unit / down-turn execution unit is SFailDegrad. If the fault state of subsystem A is FailCtrl and the fault state of subsystem B is FailCal or FailCalop, or if the fault state of subsystem B is FailCtrl and the fault state of subsystem A is FailCal or FailCalop, then the initial fault state of the up-turn feel unit / down-turn execution unit is SFailDegrad. In other cases, the initial fault state of the upshift feel unit / downshift actuation unit is SErr; S1-4) According to the torque distribution rule, the system execution capability of the upshift feel unit / downshift actuator unit is calculated as follows: ① If both subsystem A and subsystem B are torque output systems, the system execution capability of the upshift feel unit / downshift actuator unit shall be calculated as follows: System_Capability=2*Capability_Min; Capability_Min=min(Cap_A,Cap_B); In the formula, System_Capability is the system execution capability, Capability_Min is the smaller value of the unit execution capability, Cap_A is the execution capability of subsystem A, and Cap_B is the execution capability of subsystem B; ② If only one of subsystems A and B is a torque output system, then the system execution capability of the upshift feel unit / downshift actuator unit shall be calculated as follows: System_Capability=Capability_Max; Capability_Max=max(Cap_A,Cap_B); In the formula, System_Capability is the system execution capability, Capability_Max is the larger value of the unit execution capability, Cap_A is the execution capability of subsystem A, and Cap_B is the execution capability of subsystem B; S1-5) Based on the system's execution capabilities, determine the capability status of the upward-turning touch unit / downward-turning execution unit in the following manner: If the system execution capability is ≥80%, then the capability status of the up-turn feel unit / down-turn execution unit is SNormal; If 50% ≤ system execution capability < 80%, then the capability status of the upshift feel unit / downshift execution unit is SFailOp. If 30% ≤ system execution capability < 50%, then the capability status of the up-to-down hand feel unit / down-to-up-to-down execution unit is SFailDegrad. If the system execution capability is less than 30%, then the capability status of the up-turn feel unit / down-turn execution unit is SErr; S1-6) Set the state severity rule "SNormal<SNormal-Limit<SFailOp<SFailDegrad<SErr" to take the more severe state between the initial state and the capability state of the upshifting feel unit as the fault state of the upshifting feel unit. S2) If there is an inter-board communication failure in subsystem A or subsystem B, the system status of the main control system, torque distribution rules, and upshift feel unit / downshift execution unit shall be determined in the following manner: S2-1) Set the arbitration priority rule as "Normal>FailOp>Failcal=FailCalOp=FailCtrl=Fail", and determine the arbitration status of subsystem A and subsystem B in the following manner: If the fault status of the subsystem is Normal or FailOp, then the arbitration status of the subsystem is an available system. If the fault status of the subsystem is FailCalOp, FailCtrl, or Fail, then the arbitration status of the subsystem is unavailable. S2-2) Based on the arbitration status of subsystem A and subsystem B, determine the master control system in the following manner: ① If both subsystem A and subsystem B are available systems, then the difference in execution capability between subsystem A and subsystem B at the previous moment is taken as the execution capability deviation at the previous moment. Based on the execution capability deviation at the previous moment, the master control system in subsystem A and subsystem B is determined in the following manner: If the execution capability deviation of the previous moment is greater than 10%, then the subsystem with the greater execution capability will be designated as the main control system. If the execution capability deviation of the previous moment is ≤10%, then the master control system of the previous moment will be used as the master control system of the current moment. ②If subsystem A or subsystem B is an unavailable system, the subsystem whose arbitration status is available shall be designated as the master control system; ③ If both subsystem A and subsystem B are unavailable, the master control system from the previous moment will be used as the master control system. S2-3) Set the torque distribution rule as follows: Only the main control system determined in step S2-2) is used as the torque output system, and the output torque value = min (target torque calculated by the main control system, execution capability of the main control system).

9. The method according to claim 1, characterized in that: Subsystem A and subsystem B each include a power management module, a main control module (MCU), a CAN communication module, a pre-driver module, a MOSFET full-bridge module, and a filtering module. The power management module is used to convert the system input power into a low-voltage DC power supply that meets ASIL D level, to power the main control module MCU, pre-drive module and various sensors. At the same time, it integrates a watchdog monitoring mechanism to monitor the operating status of the main control module MCU in real time and build a safety control path to ensure the safe operation of the power supply and the core components of the system. The main control module (MCU) is used to receive steering wheel button signals, steering wheel angle signals, and motor position sensor signals, generate motor control commands, manage information transmission within the subsystem and between the subsystem and other systems, and integrate various feedback signals to realize fault monitoring, logical operations, and execution of drive strategies, ensuring the stable and safe operation of the motor. The CAN communication module is used to enable information interaction between the main control module and other systems, and to complete the transmission of instructions and status data; The pre-drive module is used to receive drive waveform control commands issued by the main control module MCU, drive the MOSFET full-bridge module to output PWM drive signals, and also has the fault diagnosis function of the full-bridge circuit, which can monitor the abnormal operation status of the full-bridge in real time. The MOSFET full-bridge module is used to receive the high-side / low-side control signals output by the pre-drive module. By controlling the on and off logic of the MOSFETs, it adjusts the phase voltage and phase current of the motor. At the same time, in conjunction with the control signals of the pre-drive module, it realizes the motor's forward and reverse rotation, speed regulation, torque regulation and other operation control actions. The filtering module is used to filter high-frequency noise and spike pulses in the signal, ensuring that the power management module, the main control module MCU, and the MOSFET full-bridge module will not be falsely triggered or have signal distortion, thereby improving the reliability of the entire system. The first data port of the main control module MCU is connected to the first data port of the power management module, the second data port of the main control module MCU is connected to the first data port of the pre-drive module, the third data port of the main control module MCU is connected to the first data port of the CAN communication module, and the fourth data port of the main control module MCU is connected to the second data port of the pre-drive module. The second data port of the power management module is connected to the second data port of the pre-drive module, the third data port of the power management module is connected to the second data port of the CAN communication module, and the fourth data port of the power management module is connected to the first data port of the filter module. The third data port of the pre-drive module is connected to the first data port of the MOSFET full-bridge module, and the fourth data port of the pre-drive module is connected to the second data port of the filter module. The second data port of the MOSFET full-bridge module is connected to the third data port of the filter module.

Citation Information

Patent Citations

  • EPS dual-redundancy system and fault processing method

    CN116339120A

  • Execution state management method of steer-by-wire system

    CN118062104A