System for detecting, isolating, and mitigating specific external sensor-based faults in a serial bus for low-voltage serial communication networks
The system addresses the challenge of accurately diagnosing faults in low voltage serial communication networks by employing a decision tree approach and data modeling to analyze bus voltage data, thereby improving diagnostic accuracy and reducing false results.
Patent Information
- Application Number
- DE102018122766
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2017-09-18
- Filing Date
- 2018-09-17
- Publication Date
- 2025-06-26
- Estimated Expiration
- 2038-09-17
AI Technical Summary
Existing systems for diagnosing faults in low voltage serial communication networks, such as CAN buses, face challenges in accurately detecting and isolating sensor-based faults due to potential miscalibration or circuit faults, leading to false positive or false negative results.
A system utilizing a decision tree approach, combined with data filtering, segmentation, and statistical modeling, to detect and isolate sensor errors and host ECU errors by analyzing bus voltage data patterns, and recalibrating the voltage sensor to mitigate recoverable faults.
The system improves diagnostic accuracy by effectively distinguishing between recoverable and unrecoverable faults, reducing false results and enhancing the reliability of network diagnostic and prediction algorithms.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
The present invention relates to a system according to the preamble of claim 1, as substantially disclosed in DE 11 2017 004 873 T5.INITIATIONComplex systems include a wide variety of interconnected and / or independent subsystems, each subsystem being controlled via a respective electronic control module. The various control modules communicate with each other and a host controller / electronic control unit (host ECU) via a serial communication bus. For example, in a vehicle, a low voltage differential controller area network (CAN) bus is used for this purpose. From time to time, certain faults may occur in one or more of the control modules and / or a voltage sensor used to monitor the bus voltage. Such errors may result in degraded system functionality if improperly diagnosed and maintained.Certain low voltage bus faults may be detected by the host ECU using a method of signal monitoring and timeout monitoring. Signal errors can be reported as loss of communication, e.g., loss of a transmitted data message. Other bus errors may be detected by comparing data from the voltage sensor to a calibrated threshold. The control modules can be electrically connected in parallel, so that the different control modules together share a bus voltage, i.e. the same voltage is applied to the different connected control units. If the measurement values of the voltage sensor appear abnormal, problems may occur in accurate fault detection. In such cases, it may be unclear whether the sensor readings are due to a faulty sensor or an actual fault in the communication network.SUMMARYDisclosed herein is a system for detecting, isolating, and mitigating certain sensor-based faults in a serial bus for low voltage serial communication networks that include multiple connected control modules, such as, but not limited to, a controller area network (CAN) bus of a vehicle. A voltage sensor measures a voltage level on the network bus. Such a voltage sensor, which may be external or internal to a host electronic control unit (ECU), may be miscalibrated, or certain sensor faults may be registered due to circuit faults, such as open or short circuit faults, reference voltage faults, or host ECU ground faults. Therefore, the dependence on the measured voltage in a network diagnostic and prognosis method may result in false positive or false negative results. The present invention is intended to provide improved diagnostic functionality that avoids such inaccurate test results using a decision tree approach as set forth herein.Using the disclosed system, various sensor errors or host ECU errors are detected and isolated using expected / normal bus voltage data patterns. Techniques for data filtering, data segmentation, and statistical modeling are also developed to mitigate recoverable types of errors, such as caused by sensor calibration errors, improper host ECU grounding, and the like. The disclosed approach is used in conjunction with existing network diagnostic and prediction algorithms and is directed to improving overall accuracy.Specifically, according to the invention, a system is presented which is distinguished by the features of claim 1.For an optional differential bus, such as a CAN bus, the output data includes both high-side and low-side measurements, e.g., 2.5-3.5V DC (high-side) and 1.5-2.5V DC (low-side) for the example CAN bus. The host ECU, which in some embodiments may include the voltage sensor and the ADC, is connected to the control modules via the communication bus and configured to detect a recoverable fault using a pattern in the bus voltage data when the voltage data is abnormal relative to a calibrated or expected voltage range. The host ECU also re-calibrates the tension sensor to mitigate the recoverable fault.A method for detecting, isolating, and mitigating a bus fault in a low voltage serial network having a host ECU in communication with or connected to the control modules as mentioned above is also described. The method includes measuring the bus voltage using the voltage sensor, wherein the bus voltage is common / equal for the host ECU and the control modules. The method also includes converting the measured bus voltage to bus voltage data indicative of the measured bus voltage and comparing the bus voltage data to a calibrated voltage range to detect the bus fault. In addition, the host ECU isolates the detected bus fault using a data pattern in the bus voltage data as a recoverable fault occurring when the bus voltage data is outside the calibrated voltage range. Thereafter, the method includes re-calibrating, via the host ECU, the voltage sensor to mitigate the detected recoverable type fault.The above features and advantages, as well as other features and advantages of the present invention, will become more apparent from the following detailed description of the embodiment(s) and best mode(s) for carrying out the described disclosures with reference to the accompanying drawings and appended claims.BRIEF DESCRIPTION OF THE DRAWINGSFIG. 1 is a schematic illustration of a system in the form of an example vehicle having a controller area network (CAN) bus connecting a plurality of control modules to a host electronic control unit (ECU), the host ECU configured to perform a method for detecting, isolating, and mitigating recoverable types of bus faults as set forth herein. FIG. 2 is a flow diagram describing a method for detecting, isolating, and mitigating bus errors on the communication bus of FIG. 1, as set forth herein. FIG. 3 is a flow diagram illustrating an exemplary embodiment for performing a data filtering and average extraction sub-process as part of the method of FIG. 2. FIG. 4 is a flow diagram showing an exemplary embodiment for performing an outlier removal and recalibration sub-process as part of the method of FIG. 2.DETAILED DESCRIPTIONReferring to the drawings, wherein like reference numerals refer to like components throughout the several views, an example system is schematically illustrated in FIG. 1 as a vehicle 11. The vehicle 11 or other superordinate system in other embodiments includes a low-voltage communication bus 50, such as a controller area network (CAN) bus, through which a plurality of application specific control modules 10, 20, and 30 are connected to a host electronic control unit (ECU) 40. The control modules 10, 20 and 30 are respectively labeled C1, C2 and C3. While three control modules 10, 20 and 30 are shown for simplified illustration, fewer or additional control modules may be used on the communication bus 50 within the scope of the invention.The host ECU 40 is configured to execute computer readable instructions representing a method 100 for diagnosing, isolating, and mitigating certain types of faults on the communication bus 50 using available network data including a measured bus voltage (arrow V 50) from a voltage sensor 59. The host ECU 40 may be an off-board diagnostic tool, i.e., located outside the vehicle 11, and used to measure the bus voltage through a vehicle port (not shown). While the voltage sensor 59 is shown separate from the host ECU 40 for clarity of illustration, the voltage sensor 59 and an analog-to-digital converter (ADC) may be integral with or part of the circuit of the host ECU 40. For this purpose, patterns in measured and output bus voltage data from the voltage sensor 59 and ADC are used. An exemplary embodiment of the method 100 is described in more detail below with reference to FIGS. 2-4. While a differential CAN bus with high-side and low-side voltage data is described below for illustrative purposes, the present invention is not limited to vehicle embodiments in general or CAN applications in particular, but rather is applicable to systems of various types using low-voltage data communication between multiple electronic controllers via serial communication bus 50.As will be appreciated by those skilled in the art, the CAN bus protocol allows connected controllers and devices to communicate with each other with low voltage data signals in the vehicle 11. The CAN bus protocol uses a two-wire balanced signaling scheme as defined in ISO-11898-2, which specifies a two-wire differential in which a number of nodes are bounded by the electrical bus load. The two cores of a CAN bus are identified as CAN high side (CAN H) and CAN low side (CAN L). In an exemplary CAN embodiment, the characteristic impedance of communication bus 50 is 120 Ω and the common mode voltage is in the range of -2 V DC on CAN L to +7 V DC on CAN H. The CAN L- voltage is typically in the range of 1.5-2.5 V DC, while CAN H- voltage ranges are in the range of 2.5-3.5 V DC. Each node is able to send and receive messages, but not simultaneously. Each received message contains a bit identifier representing the priority of the message, i.e. an 11-bit identifier (CAN 2.0A) or an extended 29-bit identifier (CAN 2.0B).The CAN protocol specifies two logical states, i.e., recessive and dominant. A differential voltage is used to represent the recessive and dominant states (i.e., bits). In the recessive state (logic state=1), the differential voltage on CAN H and CAN L is lower than a minimum threshold. In the dominant state (logic state=0), the difference is higher than the minimum threshold. Bus data is transmitted as message packets commonly referred to as frames, each frame being separated from previous frames by a bit field referred to as a space frame. The space frame consists of at least three consecutive re-intensive bits. Thus, after receiving the consecutive re-intensive bits, the reception of a dominant bit from the host ECU 40 is regarded as a start of the next frame.In the particular configuration of FIG. 1, the control modules 10, 20, and 30 and the host ECU 40 are configured to receive or route data over the communication bus 50 as part of their normal function. To this end, each control module 10, 20, 30 and host ECU 40 is electrically connected to respective power and ground grids 60 and 70 (PG and GG, respectively). That is, each control module 10, 20, 30 and host ECU 40 send and receive bit messages over communication bus 50, such messages conforming to a predetermined message format and at message transmission rates that may occur at different times. Although not limited to a specific system or functional embodiment, the control module 10, 20, 30 may be variously embodied in an exemplary vehicle configuration such as an engine control module, a transmission control module, a body control module, a battery control module, etc.The communication bus 50 of FIG. 1 also includes a plurality of communication links, including a first communication link 51 between the control modules 10 and 20, a second communication link 53 between the control modules 20 and 30, and a third communication link 55 between the control module 30 and the host ECU 40. The power grid 60 may include a power supply (PS) 62, e.g., a battery, electrically connected to a first power bus (PB 1) 64 and a second power bus (PB 2) 66 to supply electrical power to the control modules 10, 20, and 30 and the host ECU 40.The power supply 62 of FIG. 1 may be connected to the first and second power buses 64 and 66 via power connections arranged in a series configuration with a power connection 69 connecting the first and second power buses 64 and 66. The first power bus 64 may be connected to the control modules 10 and 20 via power connections arranged in a star configuration, wherein the power connection 61 connects the first power bus 64 and the control module 10 together and a power connection 63 connects the first power bus 64 and the control module 20 together. The second power bus 66 may similarly be connected to the control modules 30 and 40 via power connections arranged in a star configuration, e.g., a power connection 65 connecting the second power bus 66 and the control module 30, and a power connection 67 connecting the second power bus 66 to the host ECU 40.The ground grid 70 includes a vehicle ground 72 connected to respective first and second ground buses 74 and 76 (GB 1, GB 2) to provide electrical ground to the control modules 10, 20, and 30 and the host ECU 40. That is, the vehicle ground 72 is connected to the first and second ground buses 74 and 76 via ground connections arranged in a series configuration, e.g., a ground connection 79 connecting the first and second ground buses 74 and 76. The first ground bus 74 is connected to the control modules 10 and 20 via ground connections arranged in a star configuration, wherein a ground connection 71 connects the first ground bus 74 and the control module 10 and a ground connection 73 connects the first ground bus 74 to the control module 20. The second ground bus 76 is connected to the control module 30 and the host ECU 40 via ground connections arranged in a star configuration, one ground connection 75 connecting the second ground bus 76 and the control module 30, and another ground connection 77 connecting the second ground bus 76 to the host ECU 40. Other topologies for communication, power, and ground distribution for the control modules 10, 20, and 30, the host ECU 40, and the communication bus 50 may be utilized with similar effect.The control modules 10, 20, and 30 and the host ECU 40 may be configured as various combinations of one or more processors, e.g., application specific integrated circuits (ASICs), electronic circuits, central processing units or microprocessors, and sufficient amounts and configurations of the associated memory, including read-only, programmable read-only, random access, optical, and magnetic memories. Host ECU 40 executes one or more software or firmware programs to perform the present method 100, an exemplary embodiment of which is shown in FIGS. 3-4 to provide the described functionality.As shown in FIG. 1, the control modules 10, 20, and 30 and the host ECU 40 are electrically arranged in parallel, and thus share a common bus voltage, i.e., the bus voltage is seen by the control modules 10, 20, and 30 and the host ECU 40. Thus, the voltage sensor 59 may be connected to the communication bus 50 and configured to measure and report the bus voltage (arrow V 50) to the host ECU 40, the bus voltage (arrow V 50) being comprised of the respective high-side and low-side CAN H- and CAN L- data mentioned above. Once the measured voltage has undergone digital conversion, the host ECU 40, depending on the received bus voltage (arrow V 50) or more specifically on the corresponding data, executes the method 100 using a processor (P) and an associated memory (M), thereby detecting and isolating certain faults, such as a store-in-range fault, detecting and isolating open-circuit or short-circuit faults and ground faults, and finally performing a corresponding control action to mitigate the faults, e.g. by transmitting control signals (arrow CC O) and / or registering suitable diagnostic codes that trigger a repair if necessary.The host ECU 40 finally determines the measured voltage (arrow V 50) as a quantized digital value. An analog-to-digital conversion process may be performed on a raw analog signal via an analog-to-digital converter (ADC), which, like voltage sensor 59, may be located in host ECU 40 to measure a digital sensor measurement as the measured bus voltage (arrow V 50). This may include high-side and low-side voltage data, i.e., when bus 50 is a differential bus, and which is negotiated by host ECU 40 in executing the remainder of method 100, as described below. Thereafter, the host ECU 40 receives the bus voltage data, compares the received bus voltage data with a calibrated voltage threshold to detect a fault on the bus 50. The host ECU 40 then isolates the detected error, i.e., identifies the error as a specific type of error, particularly a correctable sensor error. This is accomplished using a data pattern in the bus voltage data when the bus voltage data is outside the calibrated voltage range. As a control measure, the host ECU 40 may thereafter calibrate the voltage sensor to mitigate the detected faulty sensor fault.ERROR MODELLINGIn a logical formulation, the variable x represents an actual bus voltage on the communication bus 50, y represents the sensor reading from the voltage sensor 59, and w represents a zero average low level of voltage measurement noise. Thus, for a healthy voltage sensor 59, y=x+w. Certain categories of bus errors can be determined from this mathematical relationship, including: I. Store-at-fault: y=ax+b+w, a=0 or a→0 (i.e., y is constant) II. Out-of-range: y reaches a saturation limit, e.g., 5V of DC. III. Recoverable sensor: y = ax + b + w, ! (a = 1 AND b = 0) where a and b are a scaling factor and a bias value, respectively. For recoverable types of bus errors, a and / or b are not accurate if the initial calibration of the voltage sensor 59 is incorrect. Thus, one corrective measure is that the calibrations may be modified by or using the host ECU 40 or offline, as will be disclosed later herein with particular reference to FIG. 4.ERROR SIGNATURESFor the fault type I mentioned above, i.e. for a fault of the type Jerk-in-Fault, possible causes include an electrical short circuit in a sensor circuit with which the voltage sensor 59 generates the bus voltage (V50rzcut in a protection diode arranged within such a circuit. Alternatively, the resistance in an ADC circuit used to perform the above-mentioned ADC conversion may be too small, or there may be a software calibration error. A typical fault signature for fault type I is that all control modules on communication bus 50, e.g., control modules 10, 20, and 30 of FIG. 1, actively send and receive messages, and this variance in the reported data from voltage sensor 59 remains low.For fault type II, i.e. out-of-range faults, possible causes include the actual bus voltage, i.e. x in the above modeled formulation is out of range, or that the sensor circuit is shorted to power or ground, i.e. x is constant and out of range. Alternatively, the ADC reference voltage may decrease, indicating that the actual bus voltage x saturates the ADC, or there may be a sensor ground fault, as indicated by a shift from x out of range. Fault signatures for fault type II may include all control modules being active and having more than N 1 data points in [0,δ] | |V HH or V LH being within (V 50- δ, V 50] with V HH as the dominant means for provided CAN H- data, V LH as the recessive means for CAN L- data, and voltage sensor 59 having an effective measurement range defined as [0+δ, V 50- δ], with δ>0.For fault type III, i.e., recoverable fault types, this may be caused by the ADC reference voltage changing such that a≠1in the formulation y'=ax+b+w Similarly, recoverable faults may be caused by a false software calibration or a ground offset at the electrical ground of voltage sensor 59, i.e., a≠1AND / OR b #0. This condition also allows calibration as a control measure as set forth below. In this fault, all control modules are active and two extracted data means are different from normal levels, as described below.SENSOR FAULT DETECTIONReferring to FIG. 2, after the vehicle 11 starts (*) with the block 101 and initializes the communication bus 50 of FIG. 1, e.g., in response to a key-on event or ignition event, the method 100 then proceeds to block 102 where the host ECU 40 receives the measured bus voltage (arrow V 50) from the voltage sensor 59 with the associated CAN H- and CAN L- data.Blocks 102- 124 finally determine whether the voltage sensor 59 of FIG. 1 is functioning properly / normally, with a diagnostic that recovery from a particular fault, e.g., by software calibration, is possible or impossible. Depending on whether the voltage sensor 59 is functioning normally, then various combinations of hardware and software based diagnostics and prediction are performed in blocks 134- 138 described below.The block 102 includes measuring the bus voltage (arrow V 50) using the voltage sensor 59, and reporting the measured voltage to the host ECU 40 as high-side and low-side CAN H- and CAN L- data. The method 100 then proceeds to block 104.Next, at block 104, the host ECU 40 determines whether all control modules on the communication bus 50 are active, e.g., the control units 10, 20, and 30 and the host ECU 40 of FIG. 1. the block 104 may include monitoring message traffic on the communication bus 50 and verifying that the control modules 10, 20, and 30 and the host ECU 40 are actively communicating by sending and receiving messages. Block 104 may also include overwashing bus data onto error frames. The method 100 continues to block 106 when all control modules are active, and alternatively to block 132 when all control modules are not active.Block 106 includes determining whether the measured voltage data received at block 102 is normal with respect to calibrated / expected voltage ranges. If so, the method 100 returns to block 102. The method 100 instead continues to block 110 if the voltage data is not within normal ranges.The block 110 includes determining whether the measured voltage data indicates an unrecoverable type of sensor fault, such as a store-at-fault or out-of-range fault. Such types of errors may be indicated when all control modules are active whenever the data variance from voltage sensor 59 is zero or very low ("Store-at-Fault"), or when more than a calibrated number of data points fall within a calibrated range of CAN H and CAN L. The method 100 continues to block 128 if the fault is of an unremoved type that indicates a sensor hardware fault. A diagnostic code may be recorded in the memory (M) of the host ECU 40 at this time. Otherwise, the method 100 continues to block 112 if the measured voltage data indicates a recoverable fault type.In block 112, the recoverable fault types host ECU 40 filters and processes the reported voltage data, i.e., the CAN H and CAN L- data in the CAN bus example of FIG. 1. Block 112 may also include filtering out signal noise or performing other filtering operations. A non-limiting exemplary embodiment for implementing the block 112 is illustrated in FIG. 3 and described below. The method 100 proceeds to block 114 using the filtered voltage data.The block 114 includes determining, via the host ECU 40, whether the filtered voltage data is sufficiently informative. The block 114 may include comparing the filtered voltage data, e.g., the extracted two averages, to a corresponding threshold to determine whether the extracted averages are too close to each other or whether an extracted average is zero. The method 100 proceeds to block 126 if the voltage data is not sufficiently informative, and alternatively to block 116.At block 116, the method 100 uses the filtered data from block 112 and a recorded decision tree to determine whether an "ECU mass offset fault", i.e., a high resistance on the electrical ground of the host ECU 40, is present at a node other than the node at which the voltage sensor 59 is located. That is, there may be two different types of ground faults: an offset ground in which a ground path to a given controller or ECU has a voltage drop but not enough to affect the on state of the controller / ECU, and a ground free ground in which the ground path has a sufficient voltage drop to interrupt the power supply to the controller / ECU. In the second case, a stalling of the vehicle 11 may result depending on the control(s) / ECU(s) affected by the fault.Example ground faults may be caused by wire harness and connection faults with respect to the host ECU 40.For example, block 116 may include reading the CAN H- and CAN L- data and finding an average voltage of a dominant bit within a given data frame of a message. The voltages may then be compared to predefined thresholds to detect and isolate the ECU ground fault. The average recessive voltage is 2.5 V DC and the dominant voltage is 3.5 V DC for CAN H(1,5 V DC for CAN L), when ground is normal. However, if one or more of the control modules have a ground that is offset, the transmitted voltage for such control modules will tend to be pulled high. CAN H and CAN L are pulled high when the control module concerned sends frame data and during the inter-frame range between data transmissions. Thus, detection of such a response is a way to detect the ECU ground fault offset. The method 100 continues to block 128 when the ECU ground offset fault is detected. The method 100 alternatively proceeds to block 118 if the recoverable fault is not an ECU ground offset fault.At block 118, the method 100 uses the filtered voltage data of block 112 to determine whether the recoverable fault is an out-of-range fault. The method 100 continues to block 128 when this type of fault is detected. The method 100 alternatively proceeds to block 120 if the recoverable fault is not an out-of-range fault.Block 120 includes determining whether the filtered voltage data of block 112 indicates an ECU ground offset combined with a recoverable sensor fault. Again, if all controllers on the communication bus 50 are active, the block 120 may find more than two clusters of bus voltage data and not enough data points available at a normal bus voltage level, i.e., relative to a calibrated number of data points. The method 100 continues to block 128 when such a combination is detected. The method 100 alternatively proceeds to block 122 if the fault is not a combined ECU ground offset and not a recoverable sensor fault.Block 122, achieved in response to a negative decision at block 120, includes determining whether the filtered voltage data from block 112 indicates a recoverable sensor fault. The signature for such an error may be active, with all controllers, such that two extracted averages deviate from normal data levels. The method 100 continues to block 128 when a recoverable sensor fault combination is detected. The method 100 alternatively continues to block 124 if the recoverable sensor fault is not detected.At block 124, the host ECU 40 determines from the previous steps whether the voltage sensor 59 of FIG. 1 is operating normally. If so, the method 100 continues to block 128. Otherwise, the method 100 continues to block 126.Block 126, reached from block 114 if the data from the voltage sensor 59 is not informative, or block 124, if a decision is made that the voltage sensor 59 is not functioning normally, includes registering a diagnostic code indicative of an unknown sensor status. The method 100 then proceeds to block 128.Block 128 includes repeating blocks 102- 126 for a calibrated number of times to enable a possibility to eliminate transient errors. The method 100 then proceeds to block 130.Next, at block 130, the host ECU 40 removes outliers in the bus data and re-calibrates the voltage sensor 59. An example implementation of block 130 is illustrated in FIG. 4 and described below. The method 100 then proceeds to block 131.Block 131 includes terminating the diagnostic and prognostic portions of the method 100 and then proceeding to block 132.ECU NETWORK DIAGNOSIS AND PROGNOSISThe remainder of the method 100, i.e., blocks 132- 138, relates to resident diagnostic algorithms of the communication bus 50 as a whole, including network faults and ground faults of the host ECU 40. Thus, block 132 includes checking if the voltage sensor 59 of FIG. 1 is operating normally / as expected, effectively confirming the decision made in block 124, which evaluation is performed in blocks 102- 124, as set forth above. The method 100 continues to block 134 whenever the results of block 132 indicate a normally functioning voltage sensor 59. The method 100 proceeds directly to block 136 if the sensor is not operating normally or as expected.At blocks 134 and 136, host ECU 40 initiates diagnostics and predictions of the hardware and software of bus 50, and then proceeds to block 138. Blocks 134 and 136 are executed when the voltage sensor 59 is considered normal, i.e., hardware and software based algorithms may be used as the data may be trusted by the voltage sensor 59. Block 134 relates to existing algorithms based on bus voltage (CAN H, CAN L) to diagnose the bus 50. Block 136 performs a diagnostic using processing of bus messages and thus does not rely on the bus voltage (arrow V 50) from voltage sensor 59 of FIG. 1. Thus, block 136 is executed without execution of block 134 if the voltage sensor 59 is considered abnormal, i.e., the hardware of the voltage sensor 59 cannot reliably provide data suitable for the diagnosis, and thus, software-based diagnostics and predictions are used as an alternative.At block 138, the host ECU 40 merges the results of the diagnostics from blocks 134 and 136 and then proceeds to block 140. Block 138 may include merging the results of blocks 134 and 136 if block 132 confirms that voltage sensor 59 is normal, or bypassing block 134 if voltage sensor 59 is not normal.Block 140 includes recording the results of block 138, e.g., as a diagnostic code or corresponding diagnostic result indicating the end of a control loop of method 100. The method 100 then returns to block 102.FIG. 3 illustrates an example embodiment of a sub-method 112A for implementing the block 112 of the method 100 shown in FIG. 2. Generally, the CAN H- and CAN L- data are segmented based on the measured voltage level, after which segments containing noise are discarded. The mean of the remaining lowest data segments are the estimated recessive CAN H- and dominant CAN L- levels. Using CAN H- CAN L- data synchronization, the data whose average is the estimated recessive CAN L- level (dominant CAN H- level) can then be identified and filtered.For example, block 201 may include receiving the high-side / low-side (CAN H CAN L) data and then proceed to block 203 where host ECU 40 segments the data evenly between a maximum and a minimum of the data. CAN H- data is typically between 2.5-3.5 V DC and CANL data is typically between 1.5-2.5 V DC. Sub-method 112A continues to block 205 when the data has been segmented.Block 205 includes counting the number of data points in each of the segments and then, at block 207, removing data from a segment if the number of data points in the segment is below a calibrated noise threshold. The sub-method 112A then continues to block 209.At block 209, the sub-method 112A then determines whether the blocks 203- 207 have been repeated a calibrated number of times, for example twice, and if so, the sub-method 112A proceeds to block 211. If not, sub-method 112A returns to block 203.Block 211 includes identifying a segment in the logic of host ECU 40 when the number of data points exceeds a threshold. If adjacent segments have more data points than the cluster threshold, the segments may be combined. The sub-method 112A then continues to block 213.At block 213, the host ECU 40 determines whether the CAN H- and CAN L- data are synchronized, i.e., collected at the same time, and proceeds to block 215, if so. The sub-method 112A instead proceeds to block 225 if the CAN H- and CAN L- data are not synchronized.Block 215 includes determining whether data in the lower three segments is closer to dominant data and the total number of data points is less than the bus idle percentage. If so, the sub-method 112A continues to block 217. Otherwise, sub-method 112A continues to block 219.At block 217, the host ECU 40 reduces the average extraction threshold by 50% and then proceeds to block 219.At block 219, the host ECU 40 finds the lowest voltage segment whose number of data points exceed / are less than an average extraction threshold. These segments are characterized in logic as a recessive CAN H- and a dominant CAN L- segment. In other words, the lowest voltage corresponds to the recessive bit of the CAN H- data or the dominant bit of the CAN L- data. The sub-method 112A continues to block 221.The block 221 includes calculating the average of the CAN H- recess as an estimated CAN H- recessive voltage and calculating the average of the CAN L- recessive segment as an estimated CAN L- recessive voltage. Corresponding mean data may be calculated for the dominant CAN H- data. The sub-method 112A then continues to block 223.Block 223 includes filtering the bus data from block 221, e.g., by removing outliers from the recessive CAN L and then recalculating the values of block 221 before proceeding to block 225.At block 225, the maximum and minimum of the filtered data are determined and the mean of these data is calculated, i.e., as estimated dominant CAN H- voltage or recessive CAN L- voltage depending on the value to be calculated. The average of data below this level is the CAN H- recessive voltage (or dominant CAN L- voltage). Sub-process 112A is complete.FIG. 4 illustrates an exemplary embodiment of a sub-method 130A for implementing the block 130 of the method 100 shown in FIG. 2. In this embodiment, given an array of estimated CAN H- and CAN L- levels of independent data sets, the Thompson-Tau test can be used to remove outliers, if any. The filtered array of estimated CAN H- and CAN L- planes is then averaged and the average is then used for recalibration of the sensor.Specifically, block 301 includes inputting two arrays of estimated dominant and recessive raw averages, without calibration, for the CAN H- data prior to proceeding to block 303.Block 303 includes, for CAN H- data from block 301, calculating the mean and standard deviation before proceeding to block 305.At block 305, sub-method 130A includes determining an outlier rejection region using the Thompson-Tau test. If a data point is outside the rejection range, host ECU 40 removes it as an outlier and continues to block 307.At block 307, the host ECU 40 determines whether the outlier in the last loop and the dominant CAN H- array have more than a predetermined number of elements, e.g., three elements. If so, block 303 is repeated. The sub-method 130A alternatively proceeds to block 309.Block 309 includes averaging the remaining array as a final estimated dominant CAN H- voltage. The same procedure may be followed to derive the CAN H- recessive voltage before proceeding to block 311.At block 311, the host ECU 40 repeats the above process to derive the final estimated dominant and recessive voltages for CAN L- data and then proceeds to block 313.At block 313, the host ECU 40 estimates a current equivalent scaling factor (a) and bias voltage (b) as follows: where V REC and V DOM are the raw recessive and dominant voltages calculated from the sensor data using the methods described above, and NORM REC and NORMb DOM are the respective normal (theoretical) recessive and dominant voltages. All four values are for CAN H- or CAN L- data, i.e., the CAN H- and CAN L- data are not mixed. Thus, to determine recalibration parameters for the scaling factor (a) and bias voltage (b) for the CAN H- channel, data from the CAN H- channel having a normal value of 2.5 to 3.5V DC is used. For CAN L the sensor data is used for CAN L with a normal value of 1.5-2.5 V DC.Using the method 100 set forth above, therefore, a physical model-based approach for detecting, isolating, and remedying certain types of voltage sensor faults in a low voltage serial communication bus architecture is enabled, including, but not limited to, the CAN bus illustrated in FIG. 1. The method 100 is implemented passively using available bus voltage data without additional required hardware. Use of the method 100 is thus intended to ensure the accuracy of existing network diagnostic and prediction algorithms with the aim of reducing false positive or negative results from such algorithms.
Claims
A system (11) comprising: a plurality of control modules (10, 20, 30); a low voltage serial communication bus (50) having a bus voltage; a voltage sensor (59) configured to measure the bus voltage; and a host electronic control unit (ECU) (40) in communication with the voltage sensor (59) and the control modules (10, 20, 30) via the communication bus (50), wherein the host ECU (40) is configured to: convert the measured bus voltage from the voltage sensor (59) via an analog-to-digital converter into bus voltage data; compare the bus voltage data to a calibrated voltage range to detect a bus fault; isolating the detected bus fault using a data pattern in the bus voltage data as a recoverable fault occurring when the bus voltage data is outside the calibrated voltage range; and re-calibrating the voltage sensor (59) to mitigate the detected recoverable fault; characterized in that the host ECU (40) is further configured to detect a "store-at-fault" type unrecoverable fault using the data pattern including determining whether the control modules (10, 20, 30) send and receive messages on the communication bus (50) and a deviation in the bus voltage data is less than a threshold variance and subsequently recording a diagnostic code indicating the "store-at-fault" type fault in the memory of the host ECU (40); and / or the host ECU (40) is further configured to detect an unremoved out-of-range fault type using the data pattern, including determining whether the control modules (10, 20, 30) send and receive messages on the bus and more than a predetermined number of data points of the bus voltage data are outside a calibrated range of an average of the high-side data, and subsequently recording a diagnostic code indicating the out-of-range fault in memory of the host ECU (40).The system (11) of claim 1, wherein the host ECU (40) is configured to re-calibrate the voltage sensor (59) by adjusting one or both of a scaling factor and / or a bias value.The system (11) of claim 1, wherein the system (11) is a vehicle (11), the communication bus (50) is a controller area network bus, and the bus data includes high-side data in a range of 2.5-3.5V DC and low-side data in a range of 1.5-2.5V DC.The system (11) of claim 4, wherein the host ECU (40) is configured to execute a software-based prediction and diagnostic method of the network without using the bus voltage data in response to the store-at-fault type.The system (11) of claim 1, wherein the host ECU (40) is configured to execute a software-based prediction and diagnostic procedure of the network without using the bus voltage data in response to the out-of-range fault type.The system (11) of claim 1, wherein the host ECU (40) is further configured to detect the presence of a ground offset error including calculating an average of a dominant bit within a given data frame of a series of bus messages and comparing the calculated average to a predefined threshold.The system (11) of claim 1, wherein the host ECU (40) is further configured to detect the presence of a ground offset fault combined with the recoverable fault by detecting a plurality of clusters of the bus voltage data and an insufficient number of data points of the bus voltage data at a normal bus voltage level and to remove outliers in the bus data before the voltage sensor (59) is re-calibrated.The system (11) of claim 7, wherein the host ECU (40) is configured to remove the outliers by uniformly segmenting the bus voltage data between a maximum and a minimum of the bus voltage data, count the number of data points in each segment, and remove the bus voltage data from a given segment if the number of data points in the given segment is below a calibrated noise threshold.
Citation Information
Patent Citations
SAFETY SYSTEM FOR ELECTRONIC EQUIPMENT
DE112017004873T5