Commercial vehicle steer-by-wire function safety system and control method thereof
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- WUHAN UNIV OF TECH
- Filing Date
- 2026-06-23
- Publication Date
- 2026-08-07
AI Technical Summary
其一,通信架构耦合度高:内部控制报文与整车外部交互报文共享物理链路,非关键报文(如整车状态广播、诊断日志)易占用带宽资源,导致关键控制报文面临阻塞风险,无法满足转向控制的毫秒级响应需求;
[0016]The beneficial effects of this invention are as follows: By constructing a layered communication architecture with decoupled internal and external controls, the internal control network uses multiple independent high-speed vehicle buses to carry key messages such as driver input, target steering angle, and actuator feedback. Combined with the high-speed characteristics of the CAN FD protocol, the accuracy of the steering closed-loop control is ensured. The four-controller closed-loop topology formed by interconnecting the upper and lower steering master/slave controllers through four independent buses can realize real-time and accurate location of fault nodes and links, and trigger the coordinated takeover and output reconstruction between the master and slave controllers accordingly. Under normal operating conditions, the master and slave controllers work together to drive the execution unit to balance the load. Under fault conditions, the system can quickly switch to 100% output or degraded operation mode through redundant links, so that it can still maintain basic steering controllability and road feel simulation function under single-point failure conditions, which greatly improves the functional safety level and operational reliability of the commercial vehicle steer-by-wire system.
Smart Images

Figure CN122519366A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of automotive electronic and electrical architecture and functional safety technology, and in particular to a steer-by-wire functional safety system for commercial vehicles and its control method. Background Technology
[0002] With the accelerated transformation of commercial vehicles towards intelligence and electrification, steer-by-wire systems have become a core development direction for commercial vehicle steering systems. This system typically consists of an upper steering unit (responsible for collecting driver steering intentions and providing road feel feedback) and a lower steering unit (responsible for driving wheel steering). The information exchange between these two units and the vehicle chassis domain highly depends on the onboard communication network. Currently, the communication architecture of commercial vehicle steer-by-wire systems generally uses CAN bus, FlexRay bus, or a single-function architecture to achieve full message transmission. Key control messages, status feedback messages, diagnostic messages, and network management messages between the upper and lower steering units share the same communication link.
[0003] However, commercial vehicles, due to their large loads, complex operating conditions, and long continuous operating time requirements, have significantly higher thresholds for real-time communication performance, reliability, and functional safety than passenger vehicles. Existing technical solutions have three inherent shortcomings in practical implementation: First, the communication architecture is highly coupled: internal control messages and external vehicle interaction messages share physical links. Non-critical messages (such as vehicle status broadcasts and diagnostic logs) are prone to occupying bandwidth resources, which leads to the risk of blocking of critical control messages and makes it impossible to meet the millisecond-level response requirements of steering control. Secondly, the bus load and latency are uncontrollable: Under high load scenarios, the message queuing latency and jitter of a single bus architecture increase exponentially, which directly affects the stability of the steering closed-loop control and may cause control deviations under extreme conditions. Third, the redundancy and fault location capabilities are weak: existing redundancy designs mostly focus on local hardware backup (such as switching between primary and backup controllers), without building a closed-loop communication mechanism for multi-controller collaboration. Fault detection can only cover the connection and disconnection of primary and backup links, and cannot achieve accurate fault location. It is also difficult to support collaborative switching and output reconstruction after a fault.
[0004] The aforementioned defects together make it difficult for existing commercial vehicle steer-by-wire systems to simultaneously meet the engineering requirements of high real-time performance, high reliability, and high safety. Summary of the Invention
[0005] The main objective of this invention is to provide a safety system for steer-by-wire in commercial vehicles and its control method, constructing a decoupled communication architecture between internal and external controls and a redundant architecture of four controllers, thereby improving communication real-time performance, system fault tolerance, and fault location efficiency.
[0006] The technical solution adopted in this invention is: a commercial vehicle steer-by-wire safety system, including an upper steering unit, a lower steering unit, an internal control communication network, an external control communication network, and a chassis domain controller; The up-turn unit includes a redundant master controller and a slave controller, and the down-turn unit includes a redundant master controller and a slave controller; the master controller and the slave controller work together to execute control commands under normal operating conditions and take over from each other under fault conditions. The internal control communication network consists of multiple independent high-speed vehicle buses, used to carry internal key control messages between the upper and lower turning units; the internal key control messages include driver input signals, target turning angle commands, and actuator feedback signals. The external control communication network adopts a communication bus compatible with the vehicle chassis domain protocol to carry vehicle interaction messages between the steer-by-wire safety system and the chassis domain controller; the vehicle interaction messages include vehicle dynamic status parameters and system fault information. The internal control communication network connects the up-to-up main controller, the up-to-up slave controller, the down-to-down main controller, and the down-to-down slave controller.
[0007] According to the above technical solution, the internal control communication network specifically includes four independent internal control CAN FD buses, of which: two buses are respectively connected to the upstream master controller and the downstream master controller, and the upstream slave controller and the downstream slave controller, for cross-unit key control message transmission; the other two buses are respectively connected to the upstream master controller and the upstream slave controller, and the downstream master controller and the downstream slave controller, for status synchronization and data interaction within the same unit.
[0008] According to the above technical solution, the fault location mechanism based on heartbeat counting specifically includes: each controller sends a first preset value of heartbeat signal to adjacent nodes when working normally; when any controller fails to receive a normal heartbeat signal from an adjacent node multiple times in a row, it sends a second preset value of fault indication heartbeat signal to the node in the opposite direction; subsequently, nodes that receive abnormal heartbeat signals update the heartbeat signal value according to a preset incrementing rule and propagate it to its reverse node until each node in the system identifies the location of the fault source based on the received heartbeat value.
[0009] According to the above technical solution, the multiple independent high-speed vehicle buses all adopt the CAN FD protocol, with an arbitration segment rate of ≥500kbps and a data segment rate of ≥2Mbps.
[0010] According to the above technical solution, the main controller and the slave controller of the upper rotation unit jointly drive the dual windings of the road feel motor, each bearing 50% of the rated output torque; the main controller and the slave controller of the lower rotation unit jointly drive the steering actuator motor, each bearing 50% of the rated output torque.
[0011] According to the above technical solution, when the fault location mechanism identifies a fault in any controller, drive unit or winding, the system performs output reconstruction: after completing fault isolation, the normally functioning controller takes over all the output torque on the faulty side and independently drives the remaining available motor windings or actuator motor.
[0012] According to the above technical solution, when a single-sided fault occurs in the steering unit, causing a single actuator motor to work independently, the system enters a degraded operation mode, limits the maximum value of the steering output torque, and outputs a fault alarm signal to the chassis domain controller.
[0013] According to the above technical solution, the external control communication network adopts the CAN bus or J1939 bus protocol.
[0014] According to the above technical solution, a consistency verification mechanism is also configured between the master controller and the slave controller. The slave controller receives the target control command and status information sent by the master controller in real time and performs cross-verification on the output result of the master controller. When the deviation exceeds the preset threshold, the fault location mechanism is triggered.
[0015] Another aspect of the present invention provides a control method for the above-mentioned commercial vehicle steer-by-wire safety system, comprising: Under normal operating conditions, the internal control communication network transmits internal key control messages containing driver input signals, target steering angle commands, and actuator feedback signals between the up-turn main controller, up-turn slave controller, down-turn main controller, and down-turn slave controller, and controls the main controller and slave controller in the up-turn unit and down-turn unit to coordinately execute control commands. The external control communication network uses a communication bus compatible with the vehicle chassis domain protocol to transmit vehicle interaction messages containing vehicle dynamic status parameters and system fault information between the steer-by-wire safety system and the chassis domain controller. Fault monitoring is based on a heartbeat counting mechanism, which locates fault nodes or fault links by periodically exchanging heartbeat signals between controllers in the internal control communication network. Based on the located fault, a redundant control strategy is triggered, and the normally functioning controller takes over control through the redundant link and performs output reconfiguration.
[0016] The beneficial effects of this invention are as follows: By constructing a layered communication architecture with decoupled internal and external controls, the internal control network uses multiple independent high-speed vehicle buses to carry key messages such as driver input, target steering angle, and actuator feedback. Combined with the high-speed characteristics of the CAN FD protocol, the accuracy of the steering closed-loop control is ensured. The four-controller closed-loop topology formed by interconnecting the upper and lower steering master / slave controllers through four independent buses can realize real-time and accurate location of fault nodes and links, and trigger the coordinated takeover and output reconstruction between the master and slave controllers accordingly. Under normal operating conditions, the master and slave controllers work together to drive the execution unit to balance the load. Under fault conditions, the system can quickly switch to 100% output or degraded operation mode through redundant links, so that it can still maintain basic steering controllability and road feel simulation function under single-point failure conditions, which greatly improves the functional safety level and operational reliability of the commercial vehicle steer-by-wire system.
[0017] Furthermore, by constructing a grid-shaped closed-loop topology with four controllers connected by four independent CAN FD buses, the risk of a single-point bus failure causing the entire network to crash is eliminated from the physical architecture. This achieves decoupling of control flow and synchronization flow, significantly improving the robustness of the communication architecture itself.
[0018] Furthermore, a distributed fault location mechanism based on counting propagation logic is proposed, which breaks through the limitation of traditional bus communication that can only determine the continuity, and realizes accurate self-location of fault sources.
[0019] Furthermore, the introduction of a dual-winding / dual-motor 50% torque-sharing operating mechanism ensures the continuity of torque output during master-slave switching, avoiding sudden changes in steering feel or torque jumps caused by the handover of control.
[0020] Furthermore, when a unilateral fault is detected, the continuity of the power steering function is ensured through direct hardware takeover logic in the fault state.
[0021] Furthermore, by setting up a consistency verification mechanism, malfunctions caused by controller logic malfunctions or hidden faults are effectively prevented. Attached Figure Description
[0022] Figure 1 This is an overall architecture block diagram of the commercial vehicle steer-by-wire safety system according to an embodiment of the present invention; Figure 2 This is a schematic diagram of the communication network security control node of the steer-by-wire system according to an embodiment of the present invention; Detailed Implementation To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.
[0023] Example 1 This embodiment provides a safety system for steer-by-wire functionality in commercial vehicles, aiming to address the problems of critical control messages being easily blocked, high bus load rates, insufficient real-time performance, and weak fault location and fault tolerance capabilities in existing steer-by-wire systems for commercial vehicles. Its architecture is as follows: Figure 1 As shown: It includes a road sensor motor, a steering wheel angle and torque sensor, an up-turn master controller (SWA-M), an up-turn slave controller (SWA-S), a down-turn master controller (RWA-M), a down-turn slave controller (RWA-S), an internal control bus group, an external control bus, and a chassis domain controller.
[0024] The upper steering main controller and the upper steering slave controller constitute the upper steering unit, which is responsible for collecting the driver's steering intentions and providing road feel feedback; the lower steering main controller and the lower steering slave controller constitute the lower steering unit, which is responsible for driving the wheels to complete the steering action. The main controllers and slave controllers in the upper steering unit and the lower steering unit work together to execute control commands under normal operating conditions, and take over from each other in case of failure, forming a redundant backup.
[0025] In terms of communication architecture, this embodiment adopts a decoupled design for internal and external control. The internal control communication network consists of multiple independent high-speed vehicle buses, specifically carrying critical internal control messages between the upper and lower control units. These messages specifically include the actual and target currents of the road sensor motor, the steering wheel angle signal and the steering wheel torque signal, the lower control actuator sensor signal, the target angle signal and the steering wheel angle signal, the actual and target currents of the actuator motor, and the actuator torque and actuator angle signals.
[0026] Furthermore, the internal control communication network specifically includes four independent internal control CAN FD buses: the first bus (CAN FD1) connects the upstream master controller and the downstream master controller; the second bus (CAN FD2) connects the upstream slave controller and the downstream slave controller. These two cross-unit buses are mainly used for transmitting critical control commands and feedback data; the third bus (CAN FD3) connects the upstream master controller and the upstream slave controller; and the fourth bus (CAN FD4) connects the downstream master controller and the downstream slave controller. These two same-unit buses are mainly used for state synchronization, data interaction, and consistency verification between the master and slave controllers. All four buses adopt the CAN FD protocol, configured with an arbitration segment rate of 500 kbps, a data segment rate of 2 Mbps, and a maximum data length of 16 bytes per frame, which improves data transmission efficiency and reserves space for the expansion of security information.
[0027] The external control communication network uses a communication bus compatible with the vehicle chassis domain protocol, specifically the CAN / J1939 bus. The up-turn master controller, up-turn slave controller, down-turn master controller, and down-turn slave controller all connect to this external control bus and interact with the chassis domain controller. The vehicle interaction messages carried by the external control network include vehicle speed signals, yaw rate signals, lateral acceleration signals, sensor data, and fault information, ensuring good compatibility with the existing vehicle chassis domain network. By physically separating the internal and external control networks, layered transmission of internal high-speed control communication and external vehicle communication is achieved, effectively preventing critical control messages from being blocked by non-critical messages.
[0028] Regarding control logic and redundancy strategies, under normal operating conditions, the upper-steering main controller and the upper-steering slave controller jointly drive the dual windings of the road feel motor, each bearing 50% of the rated output torque to simulate road feel. The lower-steering main controller and the lower-steering slave controller jointly drive the corresponding steering actuator motor, each bearing 50% of the rated output torque to complete the steering action. The main controller is responsible for acquiring sensor signals, executing control algorithms, and generating target commands. The slave controller receives the target information and status information from the main controller in real time for consistency verification and performs cross-verification of the main controller's output results. It also performs operational status monitoring and redundancy standby. The main and slave controllers maintain real-time communication through the internal control bus of the same unit, forming a dual-channel control structure.
[0029] To achieve accurate fault location, this embodiment introduces a heartbeat counting-based fault location mechanism. During normal operation, each controller sends and receives heartbeat signals of value 1 to its adjacent nodes. When a controller fails to receive a heartbeat signal of value 1 from a forward or backward node three consecutive times, it determines that a link or node in that direction has failed and immediately sends a fault indication with a heartbeat signal value of 2 to the node in the opposite direction. If a subsequent node receives a heartbeat signal n (n>1) from a forward / backward node, it sends a heartbeat signal n+1 to the node in the opposite direction. Through this incremental propagation mechanism, fault information is rapidly transmitted within the four-controller closed-loop network, enabling each node in the system to locate the fault source in real time based on the received heartbeat values.
[0030] For example, for the uplink main controller (SWA-M), it can determine the specific fault location (such as CAN FD1 interruption, CAN FD3 interruption or specific controller failure) based on the combination of the received forward node heartbeat (S_MC) and backward node heartbeat (N_MC) values and the vehicle speed conditions, and enter the normal state, the full takeover state or the failure state accordingly.
[0031] Based on the above fault location results, the system executes a hierarchical redundancy control strategy.
[0032] When a fault occurs on the main controller side (such as a SWA-M fault), the slave controller takes over control after confirming the failure of the main controller, switches to full takeover mode, and independently assumes 100% of the road feel motor assist output; when a fault occurs on the slave controller side, the main controller maintains the current control and disconnects the faulty channel.
[0033] For the downlink unit, if the CAN FD4 communication between RWA-M and RWA-S is interrupted, the system makes a decision based on the vehicle speed: when the vehicle speed is ≤20kph, RWA-M and RWA-S are controlled simultaneously to maintain redundancy; when the vehicle speed is >20kph, RWA-M is switched to unilateral control to ensure safety.
[0034] When any controller, drive unit, or winding fails, the normally functioning controller, after completing fault isolation, switches from handling 50% of the output to handling 100% of the output torque, independently driving the remaining available motor windings or actuators to maintain functional continuity.
[0035] If a single-sided failure occurs in the lower steering unit, leaving only a single actuator motor to operate independently, the system enters a degraded operation mode, limiting the maximum value of the steering output torque to accommodate the motor's capacity, and simultaneously outputting a fault alarm signal to the chassis domain controller.
[0036] The triggering conditions for redundant links cover a variety of operating conditions, such as main link communication interruption, controller disconnection / reset / crash, abnormal sensor signal, master-slave output deviation exceeding the threshold, abnormal feedback from the execution unit, and internal diagnostic failure. This ensures that fault identification, isolation, control transfer, and output reconstruction can be performed under any triggering condition. When the rated function cannot be maintained, it smoothly transitions to the degraded mode, ensuring that the system still has basic controllable operation capability under fault conditions.
[0037] In addition, the consistency verification mechanism between the master and slave controllers runs continuously. The slave controller performs real-time cross-verification of the output results of the master controller. When the deviation exceeds the preset threshold, the fault location and handling process is triggered immediately, which further improves the robustness and security of the system.
[0038] Example 2 Based on Example 1, this example elaborates on the specific implementation of the steer-by-wire safety architecture for commercial vehicles. This architecture meets the stringent requirements of commercial vehicles for high real-time performance and high reliability through a communication network design that decouples internal and external controls and a multi-controller closed-loop redundancy strategy.
[0039] The hardware components of this architecture include a road sensor motor, a steering wheel angle and torque sensor, an up-turn master controller (SWA-M), an up-turn slave controller (SWA-S), a down-turn master controller (RWA-M), a down-turn slave controller (RWA-S), an internal control bus group, an external control bus, and a chassis domain controller.
[0040] In terms of communication architecture, this embodiment adopts a deep decoupling design between internal and external control. The upward steering master controller and the upward steering slave controller constitute the upward steering unit, which is responsible for collecting driver input information and realizing road feel simulation; the downward steering master controller and the downward steering slave controller constitute the downward steering unit, which is responsible for driving the steering actuator to complete the steering action.
[0041] The internal control network is constructed from four independent CAN FD buses, forming a closed-loop communication topology for the four controllers, such as... Figure 2 As shown, the specific connection relationships are as follows: the upstream main controller (SWA-M) and the downstream main controller (RWA-M) are connected through the internal control CAN FD1 bus, and the upstream slave controller (SWA-S) and the downstream slave controller (RWA-S) are connected through the internal control CAN FD2 bus. These two buses mainly undertake the transmission of key instructions and feedback data across units. At the same time, the upstream main controller (SWA-M) and the upstream slave controller (SWA-S) are connected through the internal control CAN FD3 bus, and the downstream main controller (RWA-M) and the downstream slave controller (RWA-S) are connected through the internal control CAN FD4 bus. These two buses are mainly used for status synchronization and data interaction within the same unit.
[0042] The internal control CAN FD bus is configured with an arbitration segment rate of 500 kbps and a data segment rate of 2 Mbps, with a maximum data length of 16 bytes per frame. It is specifically used to carry internal critical control messages that are extremely sensitive to time delays, such as the actual and target currents of the road sensor motor, steering wheel angle and torque signals, down-turn actuator sensor signals, target angle and steering wheel angle signals, actual and target currents of the actuator motor, and actuator torque and angle signals.
[0043] The external control network uses a CAN / J1939 bus. The upstream master controller, upstream slave controller, downstream master controller, and downstream slave controller are all connected to this bus and interact with the chassis domain controller. The external control network carries vehicle speed signals, yaw rate signals, lateral acceleration signals, sensor data, and fault information, among other vehicle-wide interaction messages. By separating critical internal control messages from external vehicle-wide interaction messages at the physical link level, this architecture effectively reduces the bus load rate, prevents critical messages from being blocked by non-critical messages, and significantly improves communication real-time performance.
[0044] Furthermore, the upstream and downstream slave controllers, as important components of the redundant link, together with the upstream and downstream master controllers, form a multi-controller closed-loop redundant communication architecture. Under normal operating conditions, the master controller in each module is responsible for collecting local sensor signals, executing control algorithm calculations, generating target control commands, and outputting control quantities to the execution unit; the slave controllers receive target information and status information sent by the master controllers, perform consistency verification on the control results of the master controllers, and simultaneously complete local operating status monitoring and redundancy standby.
[0045] Furthermore, in the road feel simulator module, the main controller and the slave controller drive the corresponding windings of the dual-winding motor respectively, each bearing 50% of the motor output torque; in the steering actuator module, the main controller and the slave controller drive the corresponding actuator motor respectively, each bearing 50% of the torque output, thus forming a master-slave cooperative dual-channel control structure.
[0046] When the system detects a fault, the master and slave controllers will perform tiered control switching based on the fault type, location, and scope of impact. If the fault occurs on the master controller side, the slave controller will take over control after confirming the failure of the master controller; if the fault occurs on the slave controller side, the master controller will continue to operate and disconnect the faulty channel. For the road sense simulator module, when any controller, drive unit, or winding fails, the normal controller will switch from 50% output to 100% output after completing fault isolation, independently driving the remaining available windings to maintain the continuity of the road sense function.
[0047] For the steering actuator module, in the event of a single-sided failure, the normal controller takes over the remaining actuators. However, considering that the maximum output capacity of a single actuator motor is insufficient to meet the steering torque requirements of the entire vehicle, the system will automatically switch from normal operation to degraded operation, limiting the system output capacity and sending a fault alarm signal to the chassis domain controller. The triggering conditions for redundant links cover a variety of operating conditions, including main control link communication interruption, controller disconnection / reset / crash, abnormal signals from critical sensors, master-slave output deviation exceeding the threshold, abnormal feedback from actuators, and internal diagnostic failures. This ensures that the system can prioritize fault identification, isolation, control transfer, and output reconstruction when an anomaly occurs.
[0048] To achieve accurate fault location, this embodiment introduces a fault location method based on heartbeat counting. This method cyclically sends heartbeat signals among the four controllers in the internal control network, specifically following three rules: When a node is working normally, the heartbeat signals it sends and receives from its neighboring nodes are both 1. When a node fails to receive a heartbeat signal of 1 sent to the preceding / following node three times in a row, it sends a heartbeat signal of 2 to the node in the opposite direction. When a node receives a heartbeat signal of n (n>1) from the preceding / following node, the node sends a heartbeat signal of n+1 to the node in the opposite direction.
[0049] Through this numerical increment propagation mechanism, fault information can be quickly transmitted to the entire network, enabling each node to locate the fault source in real time, whether it is located in a controller or a communication link, based on the received heartbeat value, thereby providing a basis for decision-making for subsequent coordinated switching.
[0050] Furthermore, the correspondence between heart rate signal values and SWA-M states is shown in Table 1:
[0051] Table 1. SWA-M Fault Location and State Decision Table Based on Heartbeat Count When faced with different fault or normal operating conditions, the uplink main controller (SWA-M) determines its own operating status (such as normal or full takeover) and locates the specific fault point based on the heartbeat signal values (i.e., the values in the heartbeat message) sent by its forward node (S_MC) and backward node (N_MC) and the current vehicle speed conditions.
[0052] Specifically, when the system is functioning normally and the vehicle speed is less than or equal to 20 kph, if the heartbeat signal values received by SWA-M before and after the initial heartbeat are 3 and 4 respectively, it indicates that there is no abnormality in network communication, and SWA-M remains in a normal state. However, once a communication abnormality occurs (such as S_MC becoming 4 or N_MC becoming 3), or a specific link is interrupted (such as N_MC becoming 2), SWA-M will immediately identify the fault and enter a full takeover state, beginning to take the lead in control.
[0053] In addition, when the vehicle speed is greater than 20 kph, if the heartbeat signal combination received by SWA-M is (4)(2), the system will determine that a relatively serious communication interruption has occurred. At this time, in order to prevent danger during high-speed driving, SWA-M will also quickly enter the full takeover mode.
[0054] Furthermore, this embodiment defines the control allocation and execution logic of the system under different hardware failure scenarios. Its core design concept is to adopt differentiated fault-tolerant strategies based on the specific location of the failure (upward or downward unit), thereby maximizing the vehicle's handling capability while ensuring safety, as shown in Table 2:
[0055] Table 2 Safety Control Strategies for Commercial Vehicle Steer-by-Wire Systems In response to a failure of the uplink unit (SWA), the strategy focuses on master-slave switching to ensure that the source of control commands is unique and correct.
[0056] When the upstream main controller (SWA-M) fails (failure point ⑤), the system immediately activates the highest priority redundant takeover mechanism, switching to the upstream slave controller (SWA-S) to fully take over control authority. The downstream unit (RWA-M / S) then unconditionally follows the instructions issued by the new main controller, thereby achieving seamless connection of control flow.
[0057] When the fault manifests as an interruption in internal communication between SWA-M and SWA-S (failure point ③), or an anomaly occurs in SWA-S and its related links (failure point ⑥), the system strategy tends to maintain the status quo, continue to have SWA-M take the lead in control and cut off the communication on the faulty side, so as to avoid command conflicts caused by the loss of connection between the master and slave controllers and ensure the stability and uniqueness of control.
[0058] For fault handling of the RWA (Remote WA) unit, a speed-based degraded operation logic is introduced to address the risk of execution layer failure.
[0059] When the communication link between the master and slave controllers is interrupted (failure point ④), the system implements drastically different safety strategies based on vehicle speed: at low speeds below 20 kph, both RWA-M and RWA-S are allowed to maintain control simultaneously, utilizing the output of both motors to maintain maximum steering assist performance; while at high speeds above 20 kph, to avoid safety risks caused by asynchronous control of both motors due to communication interruption, the system forcibly switches to RWA-M single-side control to ensure absolute uniformity of steering commands. If a controller hardware failure occurs (failure point ⑦ or ⑧), the system directly performs physical isolation, with the healthy single-side controller independently undertaking the steering execution task.
[0060] Table 3 defines the core behavior patterns of the uplink master controller when facing different failures. Under normal communication interruption (failure point ④(1)), the system is fine, and SWA-M maintains normal status and the original control strategy. However, once a serious fault affecting master-slave coordination occurs (such as ②, ③, ④(2), ⑥, ⑧), SWA-M will enter a full takeover state. At this time, it will not only take full control of the road feel simulator, but also provide 100% maximum assistance to the road feel motor to actively compensate for the possible lack of control in the system. If a fault occurs that causes the master controller to be completely paralyzed (such as ①, ⑤, ⑦), SWA-M will enter a failure state and stop working, completely transferring the system's control.
[0061]
[0062] Table 3 Fault Response and State Transition Table for Uplink Main Controller (SWA-M) Among them, failure point ④(1) corresponds to the low-speed operation scenario with a vehicle speed ≤20kph: at this time, the vehicle steering resistance is large, and the tolerance for the control synchronization deviation of the dual-side actuator motors is high under low-speed conditions. The system maintains the simultaneous output of control torque of RWA-M and RWA-S, and coordinates the output of the dual-side motors through the redundant links of the other internal control bus, so as to maximize the retention of steering assist performance under the premise of ensuring the consistency of steering commands.
[0063] Failure point ④(2) corresponds to the high-speed operation scenario with a vehicle speed >20kph: When driving at high speed, if the control of the two motors is not synchronized, it is easy to cause high-risk problems such as vehicle deviation and steering jamming. Therefore, the system is forced to switch to the RWA-M single-side control mode to ensure the uniqueness of the steering command and prioritize the stability of high-speed driving. At the same time, the system will limit the maximum value of the steering output torque to match the upper limit of the single motor output and output a fault alarm signal to the chassis domain controller.
[0064] Table 4 illustrates the complementary and backup logic of the up-to-down controller. Similar to SWA-M, it maintains its normal strategy under normal circumstances (failure point ④(1)). Its core value lies in its role as a backup redundancy: when the main controller link fails (failure points ①, ⑤, ⑦), SWA-S will quickly take over and enter a full takeover state, providing 100% assistance to ensure that steering assistance is not interrupted. Conversely, when SWA-S itself or its down-to-down execution link has problems (failure points ②, ③, ④(2), ⑥, ⑧) that prevent it from participating in control, it will degenerate into a failure state and stop working, leaving the stage to the main controller or other healthy modules.
[0065]
[0066] Table 4 Fault Response and State Transition Table for Uplink Main Controller (SWA-S) Table 5 specifies the hierarchical response mechanism of the downstream master actuator. In most communication interference scenarios (failure points ③, ④, ⑧, ②, ⑥), the RWA-M maintains its normal control strategy. When it loses contact with the slave controller but the upstream link is normal (failure points ①, ⑤), the RWA-M switches to a receive-and-forward control signal state, receiving instructions from the RWA-S and acting as a relay station for sensor data. It only stops working when its own hardware is completely damaged (failure point ⑦), at which point the system relies entirely on the RWA-S for unilateral control.
[0067]
[0068] Table 5. Fault Response and Status Transition Table for Downlink Main Controller (RWA-M) Table 6 clarifies the auxiliary and backup roles of the downstream actuator. Under normal circumstances (failure points ③, ④(1), ⑦, ①, ⑤), RWA-S is in a normal controlled state. When its communication with the main controller is interrupted but the upstream link is intact (failure points ②, ⑥), RWA-S also enters the receiving and forwarding control signal state, receives the instructions of RWA-M and feeds back the signal, forming a reverse relay link. Specifically, the failure conditions of RWA-S are more extensive. In addition to its own failure (failure point ⑧), when the main link communication at the execution level is interrupted (failure point ④(2)) causing it to be unable to cooperate with the host, it will also enter a failure state. At this time, RWA-M will independently complete all execution tasks.
[0069]
[0070] Table 6. Fault Response and State Transition Table for Downlink Main Controller (RWA-S) Although this embodiment preferably uses the CAN FD bus for the internal control network and the CAN / J1939 bus for the external control network, those skilled in the art will understand that other vehicle-mounted buses with high bandwidth and strong real-time performance can also be used for the internal control network, and other chassis domain communication networks can be used for the external control network depending on the vehicle platform, as long as they meet the requirements of compatibility with the vehicle controller. Furthermore, the four-controller closed-loop communication structure can be expanded into a closed-loop redundant structure with more nodes, but the closed-loop communication relationship used for fault propagation and fault location must be retained.
[0071] In summary, this invention provides a steer-by-wire safety system and its control method for commercial vehicles, which can improve communication real-time performance, system fault tolerance, and fault location efficiency.
[0072] It should be noted that, depending on the implementation needs, the various steps / components described in this application can be broken down into more steps / components, or two or more steps / components or parts of the operation of steps / components can be combined into new steps / components to achieve the purpose of this invention.
[0073] The order of the steps in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0074] It should be understood that those skilled in the art can make improvements or modifications based on the above description, and all such improvements and modifications should fall within the protection scope of the appended claims.
Claims
1. A safety system for steer-by-wire function in commercial vehicles, characterized in that, This includes an up-turn unit, a down-turn unit, an internal control communication network, an external control communication network, and a chassis domain controller; The up-turn unit includes a redundant up-turn master controller and an up-turn slave controller, and the down-turn unit includes a redundant down-turn master controller and a down-turn slave controller; the master controller and the slave controller cooperate to execute control commands under normal operating conditions and take over from each other under fault conditions. The internal control communication network consists of multiple independent high-speed vehicle buses, used to carry internal key control messages between the upper and lower turning units; the internal key control messages include driver input signals, target turning angle commands, and actuator feedback signals. The external control communication network adopts a communication bus compatible with the vehicle chassis domain protocol to carry vehicle interaction messages between the steer-by-wire safety system and the chassis domain controller; the vehicle interaction messages include vehicle dynamic status parameters and system fault information. The internal control communication network connects the up-to-up main controller, the up-to-up slave controller, the down-to-down main controller, and the down-to-down slave controller.
2. The commercial vehicle steer-by-wire safety system according to claim 1, characterized in that, The internal control communication network specifically includes four independent internal control CAN FD buses. Two of these buses connect the upstream master controller and the downstream master controller, and the upstream slave controller and the downstream slave controller, respectively, for the transmission of critical control messages across units. The other two buses connect the upstream master controller and the upstream slave controller, and the downstream master controller and the downstream slave controller, respectively, for status synchronization and data interaction within the same unit.
3. The commercial vehicle steer-by-wire safety system according to claim 1, characterized in that, The system has a fault location mechanism based on heartbeat counting, which includes: each controller sends a first preset value of heartbeat signal to adjacent nodes when working normally; when any controller fails to receive a normal heartbeat signal from an adjacent node multiple times in a row, it sends a second preset value of fault indication heartbeat signal to the node in the opposite direction; the node that subsequently receives an abnormal heartbeat signal updates the heartbeat signal value according to a preset incrementing rule and propagates it to its reverse node until each node in the system identifies the location of the fault source based on the received heartbeat value.
4. The commercial vehicle steer-by-wire safety system according to claim 1, characterized in that, The multiple independent high-speed vehicle buses all adopt the CAN FD protocol, with an arbitration segment rate of ≥500kbps and a data segment rate of ≥2Mbps.
5. The commercial vehicle steer-by-wire safety system according to claim 3, characterized in that, Under normal operating conditions, the main controller and slave controller of the upper rotation unit jointly drive the dual windings of the road feel motor, each bearing 50% of the rated output torque; the main controller and slave controller of the lower rotation unit jointly drive the steering actuator motor, each bearing 50% of the rated output torque.
6. The commercial vehicle steer-by-wire safety system according to claim 5, characterized in that, When the fault location mechanism identifies a fault in any controller, drive unit, or winding, the system performs output reconfiguration: after completing fault isolation, the normally functioning controller takes over all output torque on the faulty side and independently drives the remaining available motor windings or actuator motor.
7. The commercial vehicle steer-by-wire safety system according to claim 6, characterized in that, When a single-sided fault occurs in the steering unit, causing a single actuator motor to operate independently, the system enters a degraded operation mode, limiting the maximum value of the steering output torque and outputting a fault alarm signal to the chassis domain controller.
8. The commercial vehicle steer-by-wire safety system according to claim 1, characterized in that, The external control communication network adopts the CAN bus or J1939 bus protocol.
9. The commercial vehicle steer-by-wire safety system according to claim 3, characterized in that, A consistency verification mechanism is also configured between the master controller and the slave controller. The slave controller receives the target control commands and status information sent by the master controller in real time and performs cross-verification on the output results of the master controller. When the deviation exceeds a preset threshold, the fault location mechanism is triggered.
10. A control method for the steer-by-wire safety system for commercial vehicles as described in claim 1, characterized in that, include: Under normal operating conditions, the internal control communication network transmits internal key control messages containing driver input signals, target steering angle commands, and actuator feedback signals between the up-turn main controller, up-turn slave controller, down-turn main controller, and down-turn slave controller, and controls the main controller and slave controller in the up-turn unit and down-turn unit to coordinately execute control commands. The external control communication network uses a communication bus compatible with the vehicle chassis domain protocol to transmit vehicle interaction messages containing vehicle dynamic status parameters and system fault information between the steer-by-wire safety system and the chassis domain controller. Fault monitoring is based on a heartbeat counting mechanism, which locates fault nodes or fault links by periodically exchanging heartbeat signals between controllers in the internal control communication network. Based on the located fault, a redundant control strategy is triggered, and the normally functioning controller takes over control through the redundant link and performs output reconfiguration.