Method and device for verifying a triggering decision for triggering a safety device for a vehicle, method and device for triggering a safety device for a vehicle, sensor device for a vehicle and safety system for a vehicle
By integrating verification calculations within the sensor's electronic circuitry, the method addresses inefficiencies in existing vehicle safety systems, reducing space, communication, and energy consumption while enhancing flexibility and reliability in trigger decision verification.
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- ROBERT BOSCH GMBH
- Filing Date
- 2016-02-29
- Publication Date
- 2026-04-23
AI Technical Summary
Existing vehicle safety systems face challenges in efficiently verifying trigger decisions for safety devices due to the complexity of microprocessors and separate verification devices, leading to increased space requirements, communication bandwidth, and power consumption, as well as potential component errors causing unintended triggering.
Integrating verification calculations within the sensor's electronic circuitry, eliminating separate microprocessors and complex application-specific integrated circuits, and using a simplified electronic circuit in the control unit to reduce space, complexity, and energy consumption while enhancing flexibility and reliability in trigger decision verification.
This approach reduces space requirements, communication overhead, and energy consumption while improving flexibility in verification design, ensuring accurate differentiation between plausible accident scenarios and preventing unintended triggering decisions.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
State of the art
[0001] The invention relates to a device or a method according to the preamble of the independent claims. The present invention also relates to a computer program.
[0002] In particular, an airbag control unit for a vehicle may have a dual-path system architecture for verifying fire decisions or triggering decisions.
[0003] DE 10 2011 077 486 B3 describes a device and a method for triggering an occupant protection device. DE 10 2008 043 475 A1 relates to a method for controlling a safety device using a gyroscope, wherein a trigger signal for the safety device is to be determined, and wherein a plausibility check device with sensors may also be integrated. DE 10 2010 005 914 A1 relates to a sensor unit for a motor vehicle control system for safety functions or protective devices, wherein the sensor unit has internal fault monitoring, and wherein code information is transmitted from the sensor unit via a separate signal, by means of which corresponding functions can be validated and activated in a control unit.DE 10 2007 058 071 A1 relates to a method and a device for verifying the plausibility of an evaluation of safety-relevant signals for a motor vehicle by control units, wherein the plausibility calculation is performed on a different control unit than the evaluation, and wherein the plausibility unit can be provided in the sensor control unit or in the sensor measuring unit itself. DE 10 2006 049 121 B3 relates to an accident detection device with redundantly arranged acceleration sensors, wherein a signal evaluation unit connected to both acceleration sensors for checking the plausibility of their output signals simultaneously serves to determine the severity of the accident. DE 10 2006 018 028 A1 relates to a method and a device for controlling personal protective equipment, wherein an evaluation circuit is provided as a microcontroller in a control unit, to which external sensors are connected.DE 60 2004 005 420 T2 relates to vehicle occupant restraint systems and more specifically to a system and a method for determining whether a restraint system should be triggered. Disclosure of the invention
[0004] Against this background, the approach presented here introduces a method, a device that uses this method, and finally a corresponding computer program according to the main claims. Advantageous further developments and improvements of the device specified in the independent claim are possible through the measures listed in the dependent claims.
[0005] According to embodiments of the present invention, in particular, the verification of a trigger decision or fire decision of, for example, a microprocessor or other electronic circuit in a control unit for triggering a vehicle safety device can be performed by a microprocessor or other electronic circuit of at least one sensor involved in the trigger decision. In other words, the verification of a trigger decision of a control unit for a vehicle safety device can be implemented by an electrical circuit of at least one sensor relevant to the trigger decision. Such a sensor can include an electronic circuit for verification.
[0006] Advantageously, according to embodiments of the present invention, a dedicated verification device, such as a microprocessor or the like, arranged separately from a control unit for a safety device and a sensor, can be eliminated, and a simplified electronic circuit, for example an application-specific integrated circuit (ASIC) or the like, can be provided in the control unit. In other words, an additional microprocessor outside the sensor and the control unit, and additionally or alternatively a complex application-specific integrated circuit in the control unit, can be eliminated. This allows for a reduction in area, communication bandwidth, and power consumption, as well as the provision of a more compact and cost-effective control unit.By integrating verification into the sensor's electronic circuitry, the control unit can significantly reduce space requirements, software complexity, and energy consumption. Eliminating a separate verification device can also reduce space requirements, increase flexibility in evaluation logic, and lower communication overhead. By performing verification calculations within the sensor's electronic circuitry, greater flexibility in verification design can be achieved, enabling improved differentiation between plausible accident scenarios and borderline situations that do not result in an accident. This reliably prevents potential component errors, such as those in a microprocessor, from leading to unintended triggering decisions.
[0007] A procedure for verifying a triggering decision to activate a safety device for a vehicle is presented, the procedure comprising the following steps: Reading a sensor signal from at least one detection element of a sensor device of the vehicle, wherein the sensor signal represents a physical measurement quantity to be taken into account in the triggering decision; Performing a check of the sensor signal for the presence of a trigger event using an electronic circuit of the sensor device, wherein the electronic circuit and the sensing element form an integrated assembly; and Determining verification information using a result of the verification for output to an output interface of the sensor device.
[0008] This method can be implemented, for example, in software or hardware, or in a hybrid form of both, such as in a control unit or device. The vehicle can be a motor vehicle. The safety device can include means for personal protection, occupant protection, or the like, for example, at least one airbag. The sensor device can include at least one accelerometer, yaw rate sensor, or the like as a detection element. The physical quantity measured can represent acceleration, yaw rate, or the like. The triggering event can be characterized by a characteristic signal level.The electronic circuit and the sensing element of the sensor device can be arranged on a common printed circuit board or separator board, arranged within a common housing, potted together, and additionally or alternatively hard-wired together.
[0009] According to one embodiment, the verification information determined in the determination step can be a verification bit. Thus, the verification information can have either the value one or the value zero. Such an embodiment offers the advantage that the communication bandwidth required to transmit the verification information can be reduced.
[0010] In particular, the verification information determined in the determination step can be configured to lock or unlock the release mechanisms of the safety device. Such an embodiment offers the advantage that it reliably enables the safety device to be triggered when a triggering event occurs and reliably prevents it from triggering when no such event occurs.
[0011] The verification step can also be performed using at least one test parameter representing a threshold value, a holding time, and additionally or alternatively a filter characteristic. In particular, a filter characteristic can represent at least one corner frequency that differs from a frequency at the output interface of the sensor device. Such an embodiment offers the advantage that sensor signals can be subjected to precise and versatile verification to enable reliable verification.
[0012] Furthermore, during the execution step, at least one test parameter for verification can be set depending on application information representing a type of triggering event. The type of triggering event can, for example, be characterized by at least one typical acceleration property. In particular, the type of triggering event can exhibit acceleration along at least one typical axis. Such an embodiment offers the advantage that different use cases, accident scenarios, or the like can be taken into account, thus extending the protective function of the safety device.
[0013] According to one embodiment, during the verification process, the sensor signal can be filtered, a threshold comparison can be performed on the sensor signal, and a counter can be incremented or decremented depending on the threshold comparison. The counter can represent the result of the verification. The sensor signal can be filtered, in particular, using a low-pass filter. Such an embodiment offers the advantage of enabling an accurate and reliable evaluation of the sensor signal to ensure secure verification.
[0014] A method for triggering a safety device for a vehicle is also presented, the method comprising the following steps: Generating a trigger request based on at least one sensor signal from at least one sensor device of the vehicle; and Making a trigger decision to trigger the safety device depending on the trigger request and the verification information provided according to an embodiment of the aforementioned method for verification.
[0015] This method can be implemented, for example, in software or hardware, or in a hybrid form of both, such as in a control unit or device. The triggering method can be carried out in conjunction with an embodiment of the verification method described above. In the generation step, at least one sensor signal can be evaluated. The triggering decision can be represented by a trigger signal that can be made available for output to the safety device.
[0016] Furthermore, a sensor device for a vehicle is presented, wherein the sensor device has the following features: at least one detection element for capturing a physical measurement quantity to be taken into account in a triggering decision for triggering a safety device for the vehicle; an electronic circuit configured to perform steps of an embodiment of the foregoing verification method; and an output interface designed to output the sensor signal and verification information.
[0017] In conjunction with or using the sensor device, an embodiment of the aforementioned verification method can be implemented. The output interface can be configured to output the sensor signal in unprocessed form and the verification information.
[0018] Furthermore, a safety system for a vehicle is presented, whereby the safety system has the following features: at least one embodiment of the aforementioned sensor device; at least one safety device; and a control unit configured to perform steps of an embodiment of the aforementioned method for triggering, wherein the control unit is capable of transmitting signals to or being connected to the at least one sensor device and the at least one safety device.
[0019] In conjunction with or using the safety system, an embodiment of the aforementioned method for verification and an embodiment of the aforementioned method for triggering can thus be implemented.
[0020] The approach presented here further creates a device designed to perform, control, and implement the steps of a variant of the method presented here in appropriate facilities. This embodiment of the invention in the form of a device also allows the problem underlying the invention to be solved quickly and efficiently.
[0021] For this purpose, the device may include at least one processing unit for processing signals or data, at least one storage unit for storing signals or data, at least one interface to a sensor or actuator for reading sensor signals from the sensor or for outputting data or control signals to the actuator, and / or at least one communication interface for reading or outputting data embedded in a communication protocol. The processing unit may, for example, be a signal processor, a microcontroller, or the like, and the storage unit may be flash memory, an EPROM, or a magnetic storage device.The communication interface can be configured to read or output data wirelessly and / or via wired connections, whereby a communication interface that can read or output wired data can, for example, read this data electrically or optically from or output it into a corresponding data transmission line.
[0022] In this context, a device can be understood as an electrical device that processes sensor signals and outputs control and / or data signals accordingly. The device may have an interface, which can be implemented in hardware and / or software. In the case of a hardware-based interface, the interfaces can, for example, be part of a so-called system ASIC, which incorporates various functions of the device. However, it is also possible that the interfaces are separate integrated circuits or consist at least partially of discrete components. In the case of a software-based interface, the interfaces can be software modules, which, for example, are located on a microcontroller alongside other software modules.
[0023] In an advantageous embodiment, the device controls the triggering of at least one safety device. For this purpose, the device can, for example, access sensor signals such as acceleration and motion signals. The control or triggering is effected via actuators such as gas generators of airbags and seatbelt pretensioners.
[0024] Also advantageous is a computer program product or computer program with program code that can be stored on a machine-readable carrier or storage medium such as a semiconductor memory, a hard disk memory or an optical memory and is used to carry out, implement and / or control the steps of the method according to one of the embodiments described above, in particular if the program product or program is executed on a computer or device.
[0025] Examples of the approach presented here are shown in the drawings and explained in more detail in the following description. It shows: Fig. 1 a schematic representation of a verification of a trigger decision by two microprocessors; Fig. 2 a schematic representation of a verification of a triggering decision by a calculation in an application-specific integrated circuit; Fig. 3 a schematic representation of a vehicle with a safety system according to an exemplary embodiment; Fig. 4 a schematic representation of a verification process for a trigger decision according to an exemplary embodiment; Fig. 5 a schematic representation of a security system according to an exemplary embodiment; Fig. 6 a schematic representation of a security system according to an exemplary embodiment; Fig. 7 a flowchart of a procedure for verification according to an exemplary embodiment; and Fig. 8 a flowchart of a procedure for triggering according to an exemplary embodiment.
[0026] In the following description of favorable embodiments, the same or similar reference symbols are used for the elements shown in the various figures and having a similar effect, without repeating these elements.
[0027] Fig. Figure 1 shows a schematic representation of a verification of a trigger decision by two microprocessors. In other words, it shows Fig. 1. A safety system 100 for a vehicle, in particular a motor vehicle. The safety system 100 is designed, for example, to make a triggering decision or ignition decision to trigger or ignite one or more airbags.
[0028] Of the security system, 100 are in Fig. 1 a sensor 110, a first microprocessor 120, a second microprocessor 130, a device 140 for unlocking or locking ignition means and an ignition device or triggering device 150 or device 150 for causing ignition or triggering.
[0029] Here, the first microprocessor 120, on the one hand, and the second microprocessor 130 and the device 140, on the other hand, are arranged in parallel between the sensor 110 and the device 150. The sensor 110 is connected to the first microprocessor 120 and to the second microprocessor 130 for signal transmission. The first microprocessor 120 is connected to the device 150 for signal transmission. The second microprocessor 130 is connected to the device 140 for signal transmission, and the device 140 is in turn connected to the device 150 for signal transmission.
[0030] The first microprocessor 120 and the second microprocessor 130 are configured to receive a sensor signal 115 from the sensor 110. The first microprocessor 120 is configured to process the sensor signal 115 and output an ignition request signal 125 to the device 150. The second microprocessor 130 is configured to process the sensor signal 115 and control the device 140 to cause the ignition means to be unlocked or locked. The device 140 is configured to output a release signal 145 to the device 150, depending on whether the ignition means are unlocked or locked.
[0031] Fig. Figure 2 shows a schematic representation of the verification of a trigger decision by a calculation in an application-specific integrated circuit. Fig. Figure 2 shows a security system 100, which corresponds to the one in Fig. The safety system shown in Figure 1 corresponds to the exception that an application-specific integrated circuit (ASIC) is provided instead of the second microprocessor.
[0032] With reference to Fig. 1 and Fig. 2. It should be noted that, in particular, an airbag control unit has a two-path system architecture for verifying deployment decisions. For this purpose, a deployment decision is made on the control unit's microprocessor, i.e., the first microprocessor 120, and verified by a second independent hardware instance, i.e., the second microprocessor 130 or the application-specific integrated circuit 230. The second hardware instance can be a second microprocessor 130, which computes the same or a similar algorithm as the first microprocessor 120. Alternatively, the second hardware instance can be the ASIC 230, on which an algorithm for verifying the deployment decision can be implemented. The airbag is only deployed if the decisions of the first microprocessor 120 and the second hardware instance 130 or 230 are positive.
[0033] Fig. Figure 3 shows a schematic representation of a vehicle 400 with a safety system 410 according to an exemplary embodiment. The vehicle 400 is a motor vehicle. According to the Fig. In the embodiment shown in Figure 3, the safety system 410 is designed as an airbag system.
[0034] The security system 410 indicates, according to the in Fig. Figure 3 shows an embodiment comprising a safety device 420, a control unit 430, and a sensor device 440. The sensor device 440 is connected to the control unit 430 in a signal-transmitting manner. The control unit 430 is also connected to the safety device 420 in a signal-transmitting manner.
[0035] The sensor device 440 exhibits, according to the in Fig. Figure 3 shows an embodiment comprising a detection element 442, an electronic circuit 444, and an output interface 446. At least the detection element 442 and the electronic circuit 444 are arranged on a common circuit board and / or in a common housing, or form an integrated assembly. The electronic circuit 444 is, for example, implemented as a microprocessor or an application-specific integrated circuit. The detection element 442 is connected to the electronic circuit 444 and to the output interface 446 for signal transmission. The electronic circuit 444 is also connected to the output interface 446 for signal transmission.
[0036] The sensing element 442 is configured to detect a physical measurement quantity for consideration in a triggering decision for the activation of the safety device 420. Furthermore, the sensing element 442 is configured to provide a sensor signal 450 representing the detected measurement quantity. The sensing element 442 is also configured to provide or output the sensor signal 450 to the electronic circuit 444 and the output interface 446. For example, the sensing element 442 is configured to detect acceleration and / or rotation rate.
[0037] The electronic circuit 444 is configured to generate verification information 455 using the sensor signal 450. In other words, the electronic circuit 444 is configured to verify a triggering decision for triggering the safety device 420.
[0038] The electronic circuit 444 comprises a reading device 462, a test device 464, and a determination device 466. The reading device 462 is configured to read the sensor signal 450 from the sensing element 442. The test device 464 is configured to check the sensor signal 450 for the presence of a trigger event. The trigger event can be characterized, for example, by a characteristic signal waveform of the sensor signal 450, such as an acceleration value exceeding a threshold. The determination device 466 is configured to determine the verification information 455 using the result of the check. The verification information 455 is, for example, a single bit or verification bit. The electronic circuit 444 is configured to output the verification information 455 to the output interface 446 of the sensor device 440.
[0039] Output interface 446 is configured to output the sensor signal 450 and the verification information 455. Output interface 446 is configured to receive the sensor signal 450 from the sensing element 442 and the verification information 455 from the electronic circuit 444. Specifically, output interfaces 446 and 40 are configured to output the sensor signal 450 and the verification information 455 to the control unit 430, or to make them available for output to the control unit 430.
[0040] The control unit 430 is designed to trigger the safety device 420. The control unit 430 has, according to the [document / section], the following characteristics: Fig. Figure 3 shows an embodiment comprising a generator 432 and a decision unit 434. The generator 432 is configured to receive the sensor signal 450 from the sensor unit 440, more precisely from the output interface 446 of the sensor unit 440. Furthermore, the generator 432 is configured to generate a trigger request based on the sensor signal 450. The generator 432 is also configured to provide a request signal 433, which represents the trigger request. The decision unit 434 is configured to receive the request signal 433 from the generator 432 and the verification information 455 from the sensor unit 440. The decision unit 434 is also configured to make the trigger decision to activate the safety device 420 based on the request signal 433 and the verification information 455.
[0041] The control unit 430 is configured to output a trigger signal 435 to the safety device 420, depending on the trigger decision. Thus, the control unit 430 is configured to generate the trigger signal 435 using the sensor signal 450 and the verification information 455.
[0042] According to one embodiment, the safety device 420 further comprises release means 422 or ignition means 422. The verification information 455 can cause the release means 422 of the safety device 420 to lock or unlock. In this process, the release signal 435 can be received by the release means 422.
[0043] The control unit 430 and the safety device 420 can be designed as a single unit or integrated assembly according to one embodiment. According to other embodiments, the safety device 420 can also be another device for occupant protection, personal protection, or the like.
[0044] Fig. Figure 4 shows a schematic representation of a process 500 for verifying a trigger decision according to an exemplary embodiment. The process 500, or the verification, is carried out by the electronic circuitry of the sensor device. Fig. 3 or a similar electronic circuit is executable. In other words, it shows Fig. 4 a workflow 500 in an exemplary electronic circuit of the sensor device implemented as a microprocessor for verifying the trigger decision or ignition decision made in the control unit.
[0045] Block 501 initiates sequence 500. Block 502 performs signal filtering, specifically filtering of the sensor signal. A threshold comparison is then carried out in the subsequent block 503. A counter is processed in the following block 504, after which a verification bit is handled in the subsequent block 505. Finally, block 506 checks whether the verification bit has the value 1.
[0046] If the check in block 506 shows that the verification bit has the value 1, sequence 500 proceeds to block 507, where it is checked whether the sensor or sensor device is in a fault state. If the check in block 507 shows that the sensor device is not in a fault state, sequence 500 proceeds to block 508, where the verification bit is set at a sensor output or the output interface of the sensor device.
[0047] If the check in block 506 reveals that the verification bit does not have the value 1, sequence 500 proceeds to block 509, where the verification bit is cleared at the sensor output. Similarly, if the check in block 507 reveals that the sensor device is in a fault state, sequence 500 proceeds to block 509.
[0048] After block 508 or block 509, sequence 500 transitions to block 510, which represents the end of sequence 500.
[0049] In particular, it shows Fig. In other words, a process 500 for validating a fire decision, for example, for rollover detection, is described in the form of a program with several sub-functions. A first function, represented by block 502, includes a low-pass filter. A second function, represented by block 503, includes a threshold comparison of the low-pass filtered sensor signal. A third function, represented by block 504, includes a counter that is initialized to a maximum value each time the filtered sensor signal exceeds the threshold. If the threshold is not exceeded again, the counter is decremented. A fourth function, represented by block 505, sets the verification bit x to 1 at its output if the counter is greater than zero. This externally documents that the current situation is considered a plausible accident scenario.The fourth function sets the verification bit x to 0 at its output if the counter is zero. This signals externally that the situation cannot be a plausible accident. A fifth function, represented by blocks 506 and 507, evaluates the verification bit and the sensor status. If the verification bit is set and the sensor is not in a fault state, the verification bit is set at the sensor output, as represented by block 508. If the verification bit is not set, or if the sensor is in a fault state but the verification bit is set, the verification bit is not set at the sensor output, as represented by block 509. Alternatively, a different fault handling strategy can be implemented.
[0050] Fig. Figure 5 shows a schematic representation of a safety system 410 according to an exemplary embodiment. In other words, it shows Fig. 5. In particular, examples of releases or trigger decisions for various accident detection functions. The safety system 410 is the one described in Fig. The security system shown is similar to the one in the 3.
[0051] The 410 security system is in Fig. 5 a first sensor device 440 with an electronic circuit 444, a second sensor device 640 with an electronic circuit 444, a third sensor device 670, sensor signals 450, verification bits 455, the generator device 432 in the form of a microcontroller (µC), the request signal 433 or an ignition request, an application-specific integrated circuit 636, a device 638 for unlocking or locking the triggering means or ignition means, a release signal 655 and the decision device 434 for deciding on the ignition are shown.
[0052] The first sensor device 440 is assigned a rollover detection function or is designed to detect a rollover of the vehicle. According to the [reference to be added], the first sensor device 440 has... Fig. In the embodiment shown in Figure 5, three detection elements are provided: a first accelerometer for acceleration along a Y-axis (aY), a second accelerometer for acceleration along a Z-axis (aZ), and a gyroscope for rotation about an X-axis (ωX).
[0053] The second sensor unit 640 is assigned to an ESP application (ESP = Electronic Stability Program). The second sensor unit 640 has three detection elements: a first accelerometer for acceleration along the X-axis (aX), a second accelerometer for acceleration along the Y-axis (aY), and a yaw rate sensor for rotation about the Z-axis (ωZ).
[0054] The third sensor unit 670 is designed to detect an impact of the vehicle at the front, side and / or rear. The second sensor unit 640 has two detection elements: a first accelerometer for acceleration along the X-axis (aX) and a second accelerometer for acceleration along the Y-axis (aY).
[0055] The generator 432, or microcontroller 432, is configured to receive the sensor signals 450 from the first sensor 440, the second sensor 640, and the third sensor 670. The application-specific integrated circuit 636 is configured to receive the verification bits 455 from the first sensor 440 and the second sensor 640. The application-specific integrated circuit 636 is connected to the device 638 for signal transmission. The device 638 is configured to output the release signal 655 to the decision unit 434 when the release means or ignition means of the safety device are unlocked. The decision unit 434 is configured to receive the request signal 433 and the release signal 655 and, if necessary, to trigger the safety device, for example, to induce the deployment of an airbag.
[0056] In other words, it should be noted that the rollover detection sensors, such as the first sensor unit 440, or the sensors for the ESP application, such as the second sensor unit 640, each have their own microprocessor 444 and, for example, three sensing elements or detection elements. The first sensor unit 140 has two accelerometers in the lateral and vertical directions of the vehicle, as well as a yaw rate element for detecting rotations around the longitudinal axis. The second sensor unit 640 has two accelerometers in the longitudinal and lateral directions of the vehicle, as well as a yaw rate element for detecting yaw movements. The verification bit 455 is evaluated in the control unit by the application-specific integrated circuit 636. As long as the verification bit 455 is set to 1, the ignition devices are unlocked by hardware. A firing decision can then be made via the control unit's microcontroller 432.If the verification bit is zero, the ignition system is locked. A firing decision via the control unit's 432 microcontroller is not possible. This ensures a hardware-based dual-path airbag ignition system.
[0057] Fig. Figure 6 shows a schematic representation of a safety system 410 according to an exemplary embodiment. The safety system 410 is related to the safety system from Fig. 3 or Fig. 5 similarly. Here, the safety system 410 is suitable for reacting to a rollover detection, with a verification calculation taking place in the sensor device 440. The sensor device 440 is, for example, designed as a roll rate sensor. Furthermore, the sensor device 440 is configured to verify a trigger decision in the event of a vehicle rollover.
[0058] The 410 security system is in Fig. Figure 6 shows the sensor device 440 with the detection element 442, which is configured to detect a rotation rate Ωx, and with the electronic circuit 444 in the form of a microcontroller, wherein the electronic circuit 444 comprises a filter device 761, a threshold comparison device 763 and a hold timer 765, the verification bit 455, the generator device 432 or the microcontroller 432 and the decision device 434 with an adding device 782 for combining the verification bit 455 and a request signal from the generator device 432 and with a triggering device 784. The decision device 434 can also be referred to as a system ASIC.
[0059] The verification can be executed as a program in the electronic circuit 444 of the sensor device 440 and documented at the output interface as verification bit 455. This verification image 455 can be evaluated via a communication interface, such as PSI, SPI or CAN, by a hardware component in the control unit that is independent of the microprocessor 432 of the control unit, i.e., the system ASIC, in order to lock or unlock the ignition means.
[0060] According to one embodiment, verification with different parameters can be applied to a longitudinal acceleration channel of an ESP sensor to verify a fire decision in the event of a frontal or rear impact. According to another embodiment, verification with different parameters can be applied to a lateral acceleration channel to verify a fire decision in the event of a side impact.
[0061] Fig. Figure 7 shows a flowchart of a verification method 800 according to an exemplary embodiment. The method 800 can be carried out to verify a triggering decision for activating a safety device for a vehicle. The verification method 800 is used in conjunction with the method described in Fig. 3, Fig. 5 or Fig. 6 shown or a similar security system and / or one shown Fig. 3, Fig. 5 or Fig. 6 shown or a similar sensor device. Method 800 is also applicable for verification in connection with the process from Fig. 4 to consider.
[0062] Verification procedure 800 includes step 810 of reading a sensor signal from at least one sensing element of a sensor device in the vehicle. Here, the sensor signal represents a physical measurement quantity to be considered in the trigger decision. In a subsequent execution step 820, verification procedure 800 uses an electronic circuit of the sensor device to check the sensor signal for the presence of a trigger event. The electronic circuit and the sensing element form an integrated assembly. In a subsequent determination step 830, verification information is determined for output to an output interface of the sensor device using a result of the check performed in execution step 820.
[0063] According to one embodiment, the verification information determined in step 830 of the Determination process is a verification bit and / or configured to cause locking or unlocking of release devices of the safety device. Additionally or alternatively, according to one embodiment, in step 820 of the Execution process, the verification is performed using at least one test parameter representing a threshold value, a holding time, and / or a filter parameter. Optionally, according to one embodiment, at least one test parameter for the verification is also set in step 820 of the Execution process, depending on application information. The application information represents a type of release event.According to one embodiment, in step 820 of the verification process, the sensor signal is filtered, a threshold comparison is performed on the sensor signal, and a counter is incremented or decremented depending on the threshold comparison. The counter represents the result of the verification performed in step 820.
[0064] Fig. Figure 8 shows a flowchart of a method 900 for triggering according to an exemplary embodiment. The method 900 can be implemented to trigger a safety device for a vehicle. The method 900 for triggering is used in conjunction with the [missing information]. Fig. 3, Fig. 5 or Fig. 6 shown or a similar security system can be executed. The procedure 900 for triggering is also applicable in conjunction with the verification procedure from Fig. 7 executable.
[0065] The triggering procedure 900 includes a step 910 for generating a trigger request based on at least one sensor signal from at least one sensor device of the vehicle. In a subsequent step 920, the procedure 900 makes a trigger decision to activate the safety device based on the trigger request and the verification information, wherein the verification information is obtained by executing the verification procedure. Fig. 7 is or will be provided.
[0066] With reference to the Fig.In summary, and in other words, sections 4 to 9 state that airbag sensors, such as sensor devices 440 and 640, can, for example, have their own microprocessor 444 or electronic circuit 444 and a programming interface. An evaluation logic for verifying the fire decision can be implemented by using the electronic circuit 444 in a sensor device 440 or 640. This can include preprocessing the sensor signals 450 to obtain a physical useful signal. Possible processes for this include window integrals or filters with different corner frequencies than those at the sensor output. Furthermore, this can include calculating an evaluation algorithm with flexible thresholds for different applications. Finally, it can include implementing an application-specific holding mechanism 765 to enable a fire decision within a defined or predefined time interval.For example, rollover detection may have different requirements for the holding mechanism 765 than frontal impact detection. When the sensor device 440 has verified a situation, this is made available at the output interface 446 of the sensor device 440 using the verification information 455. This allows, in particular, a reduction in communication bandwidth compared to system architectures in which the sensor signals, which are at least 10 bits wide, must be made available to a second hardware instance.
[0067] If an embodiment includes an “and / or” connection between a first feature and a second feature, this is to be read as meaning that the embodiment according to one embodiment has both the first feature and the second feature, and according to another embodiment either only the first feature or only the second feature.
Claims
[1] Sensor device (440, 640) for a vehicle (400), wherein the sensor device (440, 640) has the following features: at least one detection element (442) for detecting a physical measurement quantity for consideration in a triggering decision for triggering a safety device (420) for the vehicle (400); an electronic circuit (444) configured to verify the triggering decision to trigger the safety device (420), wherein the electronic circuit (444) and the sensing element (442) form an integrated assembly, the electronic circuit (444) having the following features: a reading device (462) for reading a sensor signal (450) from the at least one detection element (442), wherein the sensor signal (450) represents the physical measured quantity to be taken into account in the triggering decision; A test device (464) for performing a check of the sensor signal (450) for the presence of a trigger event, wherein the test device (464) is configured to filter the sensor signal (450), to perform a threshold comparison on the sensor signal (450), and, depending on the threshold comparison, to increment or decrement a counter, wherein the counter represents the result of the check, wherein the counter is initialized to a maximum value each time the filtered sensor signal (450) crosses the threshold, and the counter is counted down unless the threshold is crossed again; and a determination device (466) for determining verification information (455) using a result of the verification for output to an output interface (446) of the sensor device (440, 640), wherein the verification information (455) is a verification bit, the verification bit being set to 1 if the counter is greater than zero, thereby documenting that the current situation is considered a plausible accident situation, and the verification bit being set to 0 if the counter is zero, thereby signaling that the situation cannot be a plausible accident; and the output interface (446) which is configured to output the sensor signal (450) and the verification information (455) to a control unit (430) which is configured to trigger the safety device (420). [2] Sensor device (440, 640) according to claim 1, wherein the verification information (455) is configured to cause locking or unlocking of release means (422) of the safety device (420). [3] Sensor device (440, 640) according to one of the preceding claims, wherein the test device (464) is configured to perform the verification using at least one test parameter representing a threshold value, a holding time and / or a filter characteristic. [4] Sensor device (440, 640) according to one of the preceding claims, wherein the test device (464) is configured to set at least one test parameter for verification depending on application information that represents a type of trigger event. [5] Method (800) for verifying a triggering decision to trigger a safety device (410) for a vehicle (400), wherein the method (800) comprises the following steps: Reading (810) a sensor signal (450) from at least one detection element (442) of a sensor device (440, 640) of the vehicle (400), wherein the sensor signal (450) represents a physical measurement quantity to be taken into account in the triggering decision; Performing (820) a check of the sensor signal (450) for the presence of a triggering event using an electronic circuit (444) of the sensor device (440, 640), wherein the electronic circuit (444) and the sensing element (442) form an integrated assembly; and Determining (830) verification information (455) using a result of the verification for output to an output interface (446) of the sensor device (440, 640). [6] Method (900) for triggering a safety device (420) for a vehicle (400), wherein the method (900) comprises the following steps: Generating (910) a trigger request (433) depending on at least one sensor signal (450) from at least one sensor device (440, 640, 670) of the vehicle (400); and Making (920) a trigger decision to trigger the safety device (420) depending on the trigger request (433) and on the verification information (455) provided according to the method (800) for verification according to claim 5. [7] Safety system (410) for a vehicle (400), wherein the safety system (410) has the following features: at least one sensor device (440, 640) according to one of claims 1 to 4; at least one safety device (420); and a control unit (430) configured to perform steps of the method (900) for triggering according to claim 6, wherein the control unit (430) is capable of transmitting signals to or being connected to the at least one sensor device (440, 640) and the at least one safety device (420). [8] Device (444; 430) configured to perform steps of the method (800; 900) according to one of claims 5 or 6 in corresponding units (462, 464, 466; 432, 434). [9] Computer program configured to perform the method (800; 900) according to one of claims 5 or 6. [10] Machine-readable storage medium on which the computer program according to claim 9 is stored.
Citation Information
Patent Citations
Passenger protection unit e.g. airbag, controlling device, for vehicle, has micro controller comparing signals from impact sensors with respective threshold values, and controlling passenger protection unit depending on comparison
DE102006018028A1
Collision e.g. front collision, detection device for motor vehicle, has hardware components that respond to signal sequence of evaluation unit and deactivates occupant restraint system during sequence absence and enforces resetting of unit
DE102006049121B3
Method and device for verifying the plausibility of an evaluation of safety-relevant signals for a motor vehicle
DE102007058071A1
Airbags i.e. side airbags, controlling method for motor vehicle i.e. car, involves detecting sensor signals, determining acceleration variable and rotation rate variable, and controlling side airbags depending on determined variables
DE102008043475A1
Sensing unit e.g. acceleration sensor, for use in control apparatus for controlling occupant protection system of car, has terminal transmitting signal, where unit transmits another signal in temporal manner, during fault free operation
DE102010005914A1