Triple redundancy fail-safe system for a steering system and steering system

The triple fail-safe redundancy system for steer-by-wire steering systems addresses the lack of redundancy by using a primary ECU, a backup ECU, and a domain controller as a secondary backup, ensuring continuous operation and enhanced safety after a fault.

DE102018124499B4Active Publication Date: 2025-06-05STEERING SOLUTIONS IP HOLDING CORP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
DE102018124499
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2017-10-04
Filing Date
2018-10-04
Publication Date
2025-06-05
Estimated Expiration
2038-10-04

AI Technical Summary

Technical Problem

Existing steer-by-wire steering systems lack sufficient redundancy to ensure continuous operation in case of a single point fault, which can lead to reduced vehicle safety and limited driving duration or distance after a fault occurs.

Method used

A triple fail-safe redundancy system is introduced, featuring a control module with a primary ECU, a backup ECU, and a domain controller that operates as a secondary backup. In the event of a fault, the backup ECU takes over and notifies the domain controller to initialize as a backup, providing an additional redundancy layer.

Benefits of technology

The system ensures continued operation of the steering system beyond the typical fault limits, enhancing vehicle safety by allowing the vehicle to be driven longer or farther after a fault, and enabling emergency maneuvers if further faults occur.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Triple redundancy fail-safe system for a steering system (12), the system comprising: a control module that includes: a first electrical control unit (ECU) configured to operate as a primary ECU to send an engine command to an engine to produce torque; a second ECU configured to operate as a backup for the first ECU; and in response to an error in the first ECU: send a notification to a domain controller (510) about the error; and to work as the primary ECU; and wherein the domain controller (510) is configured to operate as a backup for the second ECU in response to receiving the notification of the failure.
Need to check novelty before this filing date? Find Prior Art

Description

BACKGROUNDThis application relates generally to steer-by-wire steering systems and, more particularly, to providing triple fail-safe redundancy to electronic control units (ECUs) operating the steering system in the vehicle.The increasing dependence on automatic driving assistance systems (ADAS) has led to one or more controllers of different subsystems in a vehicle communicating with one another. For example, communication allows communication between subsystems and, in turn, allows one subsystem to automatically respond to actions of other subsystems.Moreover, increasing demands on vehicle safety are driving system redundancy to achieve higher levels of safety. Redundancy is achieved by including a backup component (or a second component or backup component) that is to take over operations if a primary (or first) component has a fault. The redundant component(s) typically take over the load of the operation of the EPS system for a limited time.Accordingly, it is desirable to have robust communication between controllers.DE 10 2015 110 958 A1 discloses a system which comprises a first and a second fail-safe device. Here, each of the fail-safe devices includes a processor and a memory. The memory stores instructions executable by the processor for performing detecting an error and / or providing a transmission regarding an error. The system further includes an arbitration bus connecting the first and second fail-safe devices. The communication regarding the fault may be provided by a first one of the first and second fail-safe devices to a second one of the first and second fail-safe devices. Further prior art is known from U.S. Pat. No. 2018 / 0 099 694 A1, U.S. Pat. No. 2003 / 0 098 197 A1, U.S. Pat. No. 6,548,969 B2 and U.S. Pat. No. 6,394,218 B1.SUMMARYIt is an object of the invention to provide an improved fail-safe triple redundant system for a steering system and an improved steering system.To achieve the object, a system having the features of claim 1 and a steering system having the features of claim 10 are provided. Advantageous embodiments of the invention can be taken from the dependent claims, the description and the drawings.According to one or more embodiments, a triple fail-safe redundancy system for a steering system is described. An example system includes a control module. The control module includes a first electrical control unit (ECU) that operates as a primary ECU to send an engine command to an engine to generate torque. The control module further includes a second ECU that operates as a backup for the first ECU. In response to a failure at the first ECU, the second ECU sends a notification of the failure to a domain controller and operates as a primary ECU. The system further includes the domain controller that operates as a backup to the second ECU in response to receiving the notification of the fault.One or more embodiments of a steering system are also described herein. An example of a steering system includes a control module. The control module includes a first electrical control unit (ECU) that operates as a primary ECU to send an engine command to an engine to generate torque. The control module further includes a second ECU that operates as a backup for the first ECU. In response to a failure at the first ECU, the second ECU sends a notification of the failure to a domain controller and operates as a primary ECU. The second ECU further initializes the domain controller to operate as a backup to the second ECU in response to receiving the notification of the fault.Further described herein are one or more embodiments of a control system in a steering system. The control system includes a first electrical control unit (ECU) operating as a primary ECU of the control system, the primary ECU sending an engine command to an engine to generate torque. The control system further includes a second ECU that operates as a backup for the first ECU. Working as a backup includes monitoring the first ECU for a fault. In response to detecting the fault at the first ECU, the second ECU operates as the primary ECU of the control system and initiates a domain controller to operate as the backup ECU.These and other advantages and features will become more apparent from the following description taken in conjunction with the drawings.BRIEF DESCRIPTION OF THE DRAWINGSThe subject matter which is considered to be the invention is set forth in detail and is specifically claimed in the claims at the end of the specification. The foregoing and other features and advantages of the invention will become apparent from the following detailed description when taken in conjunction with the accompanying drawings, in which: FIG. 1 illustrates a vehicle with a steering system according to one or more embodiments. FIG. 2 illustrates a block diagram of the vehicle 10 equipped with an SBW steering system 12 according to one or more embodiments. FIG. 3 illustrates an example redundant microcontroller unit (MCU) system according to one or more embodiments. FIG. 4 illustrates an example of a fully redundant system, according to one or more embodiments. FIG. 5 illustrates a block diagram for an example system providing an additional redundancy layer, according to one or more embodiments. FIG. 6 illustrates a communication system according to one or more embodiments. FIG. 7 illustrates an example flow diagram for a method for enabling additional redundancy layers for a steering system, according to one or more embodiments.DETAILED DESCRIPTIONAs used herein, the terms module and submodule refer to one or more processing circuits, such as an application specific integrated circuit (ASIC), an electronic circuit, a processor (shared, dedicated, or group) and memory that executes one or more software or firmware programs, a combinational logic circuit, and / or other suitable components that provide the described functionality. As can be seen, the submodules described below can be combined and / or further divided.Referring now to the figures, in which the invention will be described with reference to specific embodiments, without limiting the same, an exemplary embodiment of a vehicle 10 including a steering system 12 is illustrated in FIG. 1. In various embodiments, the steering system 12 includes a steering wheel 14 coupled to a steering shaft system 16 that includes a steering column, an intermediate shaft, and the required joints. In an exemplary embodiment, the steering system 12 is an EPS system further including a steering assist unit 18 coupled to the steering shaft system 16 of the steering system 12 and to tie rods 20, 22 of the vehicle 10. Alternatively, the steering assist unit 18 may connect the upper part of the steering shaft system 16 to the lower part of this system. The steering assist unit 18 includes, for example, a steering mechanism including a rack and a gear (not shown) that may be coupled to a steering actuator motor 19 and a transmission via the steering shaft system 16. During operation, as a vehicle operator turns the steering wheel 14, the steering actuator motor 19 assists in moving the tie rods 20, 22, which in turn move steering axles 24, 26, respectively, coupled to road wheels 28, 30, respectively, of the vehicle 10.As shown in FIG. 1, the vehicle 10 further includes various sensors 31, 32, 33 that detect and measure observable conditions of the steering system 12 and / or the vehicle 10. The sensors 31, 32, 33 generate sensor signals based on the observable conditions. In one example, the sensor 31 is a torque sensor that detects a driver input steering wheel torque (HWT) applied to the steering wheel 14 by the driver of the vehicle 10. The torque sensor generates a driver torque signal based thereon. In another example, the sensor 32 is a motor angle and speed sensor that senses a rotational angle and speed of the steering actuator motor 19. In yet another example, the sensor 32 is a steering wheel position sensor that detects a position of the steering wheel 14. The sensor 33 generates a steering wheel position signal based thereon.A control module 40 receives the one or more sensor signals input from the sensors 31, 32, 33 and may receive other inputs, such as a vehicle speed signal 34. The control module 40 generates a command signal for controlling the steering actuator motor 19 of the steering system 12 based on one or more of the inputs and further based on the steering control systems and methods of the present disclosure. The steering control systems and methods of the present disclosure apply signal conditioning and perform friction classification to determine a surface friction level 42 as a control signal that can be used to control aspects of the steering system 12 by the steering assist unit 18. The surface friction level 42 may also be sent as a warning to an ABS 44 and / or an ESC system 46 indicating a change in surface friction that may be further classified as central slip (i.e., at a lower steering wheel angle) or eccentric slip (i.e., at a higher steering wheel angle), as described in more detail herein.Communication with the ABS 44, the ESC system 46, and other systems (not shown) may be via, for example, a controller area network (CAN) bus or other vehicle network known in the art to exchange signals such as the vehicle speed signal 34. In one or more examples, hardware constraints and the diversity of communication channels drive communication links between microcontrollers to use different protocols, such as, but not limited to, CAN, Serial Communications Interface (SCI), or Multi-Processor Link Interface (MLI). Each protocol may satisfy a portion of the security aspects of data processing, but does not inherently ensure that all security aspects are covered.Moreover, in one or more examples, the steering system 12 may be a steer-by-wire (SBW) steering system that does not include a mechanical connection between the steering wheel 14 and the road wheels 28, 30 that has been replaced with sensors, actuators, and electronics. For example, in a conventional steering system that includes a steering wheel, a steering column, a steering assist system with rack and pinion, and tie rods, the driver rotates the steering wheel, which causes the road wheels of the vehicle to turn / turn through the various mechanical components. In the steer-by-wire system, a number of the mechanical components between the steering wheel and the road wheels of the vehicle are replaced by a sensor on the steering wheel and both sensors and actuators on the road wheels, and the rotation of the steering wheel is measured by the sensor. This rotation measurement is processed by the electronics to generate command signals for the actuators to turn the road wheels. Feedback to the driver in the form of steering torque to represent the feel of driving is provided by torque and rotational servo actuators with software that provide a simulation of driving conditions for the driver.FIG. 2 illustrates a block diagram of the vehicle 10 equipped with an SBW steering system 12 according to one or more embodiments. The steering system 12 may be an autonomous or semi-autonomous vehicle 100 with a steer-by-wire system. It should be appreciated that the steer-by-wire steering system 12 illustrated and described may be used in an autonomous or semi-autonomous vehicle or in a more conventional vehicle. The torque feedback system 100 provides a low cost torque feedback system for the steer-by-wire vehicle 10 that includes the controller 40. Although not required, the controller 40 may also be associated with an autonomous or semi-autonomous vehicle that uses an advanced driver assistance system ("ADAS") 27, thereby converting a conventional steer-by-wire vehicle to an autonomous or semi-autonomous vehicle. The ADAS system 27 may use a navigation system that allows the vehicle 10 and its passengers to travel from door to door, where the operator does not need to steer the vehicle 10 at all. When the ADAS system 27 is activated, the steering wheel 14 is not needed to control the vehicle 10, such that rotation of the steering wheel 14 during the autonomous driving mode is not required.The steer-by-wire vehicle 10 does not include a mechanical connection between the steering wheel 14 and a steering gear 180, such as an electric power steering gear, operatively coupled to a plurality of road wheels 28, 30. However, the steering wheel 14 and the steering gear 180 are electrically coupled. The guidance of the vehicle 10 is performed using the steering gear 180, with an input shaft being rotated by an actuator 120, such as a servo actuator. In one or more examples that include the ADAS system 27, in a non-active mode of the ADAS system 27, the actuator 120 receives an electronic communication signal of the driver's rotation of the steering wheel 14.The ADAS system 27 is activated when an autonomous vehicle driving state is desired, thereby disabling directional control of the road wheels 28, 30 by the steering wheel 14. The driver may switch between the autonomous vehicle driving state and a non-autonomous vehicle driving state.The non-autonomous vehicle driving state (non-active mode of the ADAS system 27 when the ADAS system 27 is included) includes a driver controlling the steering wheel 14 to control the direction of the vehicle 10. As mentioned above, in a non-active mode of the ADAS system 27, the actuator 120 receives an electronic communication signal of the driver's rotation of the steering wheel 14. However, due to the lack of mechanical connection between the steering wheel 14 and the road wheels 28, 30, the driver is not provided with a feel for the road without torque feedback. In one or more examples, the torque system 100 may include a servo actuator coupled to the steering column 16 and the steering wheel 14 to simulate the driver's driving feel for the road. The torque system 100 may apply tactile feedback in the form of torque to the steering wheel 14 and is coupled to the steering wheel 14 and / or the steering column 16. It should be appreciated that in one or more examples, the torque feedback system 100 may provide tactile feedback using any other components instead of another servo actuator coupled to the steering column 16 and the steering wheel 14 to provide tactile feedback in the form of torque to the steering wheel 14 to simulate the driver's feel for the road.Aspects of the embodiments described herein may be performed by any suitable control system and / or processing device, such as the control module 26. In one embodiment, the control module 26 is an autonomous driving system or a portion thereof. The control module 40 may be an ECU. The vehicle 10 includes additional ECUs. The control module 40 receives information from the other ECUs, such as the vehicle speed signal 34, the sensor information, and various other information. As already described, there are several communication methods designed for communication between microcontrollers, among which the protocols SCI, CAN and MLI are known. Each protocol may satisfy a portion of the security aspects of data processing, but does not inherently ensure that all security aspects are covered.In one or more examples, the control module 40 is an ECU operating with a real-time operating system (RTOS). It should be appreciated that while an ECU-powered steering system 12 is illustrated herein, the technical solutions described herein are applicable in various other environments, such as other ECUs that operate other components of the vehicle 10, such as an engine, exhaust system, tire pressure monitoring system, infotainment system, etc. Increasing vehicle safety requirements drive system redundancy to achieve higher safety levels. The redundancy is typically achieved by the distribution of the control system up to redundant microcontrollers.FIG. 3 illustrates an example redundant microcontroller unit (MCU) system according to one or more embodiments. The depicted MCU system 200 is depicted in a context of the vehicle 10, where communication with / from the MCU architecture 200 is via one or more controller area network (CAN) buses. Furthermore, two microcontrollers are employed in the illustrated MCU architecture 200 to provide redundancy. It should be appreciated that in other implementations, the MCU system 200 may include additional microcontrollers. The MCUs of the MCU system 200 are internally connected via communication between microcontrollers (IMCs) to exchange information such as status information with each other.In the illustrated example, upon failure of the CAN communication, the MCU-2 220 acts as a backup to the MCU-1 210 and vice versa. Accordingly, other nodes connected via the CAN bus continue to receive information from the MCU architecture 200 (i.e., data availability to the other nodes is assured). Typically, the MCU having a CAN communication on a particular bus is referred to as a source MCU, and the MCU providing a backup for the CAN communication is referred to as a backup MCU. A source MCU of one bus will act as a backup ECU for the other bus.For example, in FIG. 2, consider a first case where MCU-1 210 is the source MCU having communication over CAN bus-1 215 and MCU-2 220 is the backup MCU for the communication it receives over CAN bus-2 225. In another case, MCU-2 220 is the source MCU having communication over CAN bus-2 225, and MCU-1 210 is the backup MCU for the communication received over CAN bus-1 215. The CAN bus-1 215 and the CAN bus-2 225 are connected to respective public CAN buses, the public CAN bus-1 217 and the public CAN bus-2 227.The CAN communication may be stopped due to a failure, for example, a problem with a CAN transceiver, turning off an MCU, resetting an MCU due to a failure, an interrupt in the CAN bus line locally at the MCU, a short circuit in a CAN bus line locally at the MCU, application-specific deactivation of the CAN communication, and the like. It should be appreciated that the above examples are a few and that CAN communication may be interrupted by other errors. The backup MCU sends CAN messages upon failure of the other primary MCU.Moreover, typical steering systems for implementing a fully redundant system similarly include, among other redundant components 2, redundant position sensing sensors, redundant semiconductor driver circuits for motor operation, redundant windings of a motor, and a redundant battery supply.FIG. 4 illustrates an example of a fully redundant system according to one or more embodiments. As shown, two ECUs 200A and 200B operate using respective motor position sensors 210A and 210B, which in turn monitor the position of motors 220A and 220B, respectively. The motors 220A and 220B generate torque that is used as an assist torque to maneuver the vehicle 10 and / or as a feedback torque to provide feedback to the driver. In such a system 300, in the event of a single point fault in one of the components, the faulty component is shut down. The remaining operational components take over the load of the steering control.In such scenarios, after such a fault, the steering system 12 may be operated for a limited time because the system is now operating without redundancy. For example, the boundary may be set based on a time period since the detection of the fault and / or a number of kilometers traveled since the detection of the fault. Such restrictions may present discomfort to the driver / passengers of the vehicle 10. Further, in one or more examples, stopping operation of the vehicle in the preconfigured boundary may not be possible in practice, e.g., under conditions where the repair time is long, and the like. Accordingly, a technical challenge is to provide another redundancy layer when a fault condition is detected in a redundant system, such as steering system 12.The technical solutions described herein address, among other things, such a technical challenge that would be presented to the skilled reader to provide an additional redundancy layer that allows a driver / passengers of a vehicle to complete a trip after a single point fault has occurred in a system that is to be operated fully redundantly, such as the steering system.In one or more examples, the technical solutions described herein use additional domain ECUs located in the vehicle 10 and operating under L3 to SAE 2016. In one or more examples, the technical solutions enable a vehicle manufacturer, operator, service personnel, or other users to configure which ECU of the vehicle 10, such as a chassis domain controller, an ADAS motion controller, or other vehicle subsystem, is to be used as an additional redundancy layer in the event of a single point fault in the steering system 12."Domain controllers" are controllers in the vehicle 10 that house and integrate modules from different vendors. For example, a domain controller, such as through sensor fusion, may integrate software modules developed by a number of different manufacturers to perform functions such as lane assist, park pilot, cruise control, and the like. Sensor fusion is the combining of sensory data or data originating from different sources, so that the resulting information has less uncertainty than when these sources are used individually. For example, the domain controller may receive sensory data, such as measurements and / or control signals from sensors such as a front camera, an all-round vision system, a radar, a laser, an ultrasonic nano radar, and the like. The domain controller may use sensor fusion using such input data to perform one or more of the functions described above.The technical solutions described herein enable the domain controller of the vehicle 10 to be used to provide an additional redundancy layer, in the example above, a triple redundancy triggered upon a single point fault in one of the components of the steering system 12.FIG. 5 illustrates a block diagram for an example system providing an additional redundancy layer, according to one or more embodiments. In the illustrated system 400, an SBW steering system is illustrated that includes a first controller, a road wheel actuator controller 300A, that is used to operate the road wheel actuator in a full redundancy mode. The steering system further includes and a second controller, a steering wheel actuator controller 300B, used to operate the steering wheel actuator in a full redundancy mode.The controllers 300A and 300B are all interconnected via a high speed communication bus 505, for example a high speed serial communication bus. In one or more examples, the high-speed communication bus 505 may be a gigabit Ethernet bus, a high-speed CAN bus, or another such communication bus.In one or more examples, the information included on the communication bus 505 includes a desired steering position as provided by the steering wheel actuator controller 300B and an actual position as provided by the road wheel actuator controller 300A. In fault free operation, a primary ECU receives various input signals from the redundant ECUs within the road wheel actuator controller 300A and generates the output torque command to cause the road wheel actuator to maneuver the road wheel 28, 30. Similarly, a primary ECU from the redundant ECUs within the smooth operation steering wheel actuator controller 300B receives various input signals and generates the output torque command to cause the steering wheel actuator to generate a feedback torque on the steering wheel 14. In the fault-free mode, a domain controller 510 of the vehicle 10 is inactive with respect to steering system operation and does not perform any of the operations associated with generating assist torque and / or feedback torque using the road wheel actuator and / or the steering wheel actuator, respectively.In the event of a failure, such as a single point failure, in the road wheel actuator controller 300A, a backup ECU among the redundant ECUs within the road wheel actuator controller 300A assumes operation of the road wheel actuator. Also, in the event of a failure in the steering wheel actuator controller 300B, a backup ECU out of the redundant ECUs within the steering wheel actuator controller 300B performs the operation of the steering wheel actuator.To overcome the technical challenge of providing an additional redundancy layer in response to a fault in one of the components in the steering system 12, the system 400 further enables the domain controller 510 to provide a third redundancy layer in this case. In one or more examples, the domain controller 510 houses a steering system model 515 (e.g., a bicycle model) that is provided with information from additional vehicle sensors 520, such as measurement signals for yaw, road wheel speeds, etc. The steering system model 515 is an operating model for the steering system 12 preconfigured in the domain controller 510. The steering system model 515 varies depending on the model of the steering system 12 used in the vehicle 10. In other words, the steering system model 515 simulates the operation of the steering system 12.The domain controller 510 receives status information and other input data from the one or more sensors and / or MCUs of the road wheel actuator controller 300A and / or the steering wheel actuator controller 300B via the communication bus 505. Further, the domain controller 510 sends control commands to the road wheel actuator and / or the steering wheel actuator of the steering system 12. the domain controller 510 may send / receive data and / or control commands to and from additional vehicle actuators 530, for example, to / from a brake system in the vehicle 10. the domain controller 510 uses the high speed communication bus 505 to communicate with the backup ECU from the road wheel actuator controller 300A and / or the steering wheel actuator controller 300B to ensure redundancy in the event of the single point fault in the primary ECU of the controllers.Thus, the domain controller 510 is not active in controlling the steering system 12 when the road wheel actuator controller 300A and the steering wheel actuator controller 300B are operating in the fault-free mode. Once a fault is detected in one or more of these controllers (300A / B), the controller(s) indicates / indicate to the domain controller 510 that a single point fault has occurred and that a backup ECU of the controller(s) has taken over the operation of the corresponding controller(s). The domain controller 510 initiates the steering system model 515 and begins to operate as a secondary backup of the ECU that the controller has adopted. Since the operating ECU now operates redundantly, the steering system 12 can therefore be operated beyond the limits which have to be set without the additional redundancy.If a further fault occurs, the steering system 12 can be put out of operation according to the predefined limit values, such as a limited duration or a limited number of kilometers. Alternatively or additionally, in the event of the additional fault, the domain controller 510 performs an emergency maneuver for a safe stop, e.g., by actuating additional actuators such as the brakes or rear steering actuators. The emergency maneuver may include additional actions such as starting emergency lights, providing notifications to the driver, service technician, manufacturer, or other third party. Alternatively or additionally, if an additional domain controller is present in the vehicle, the additional fault may trigger the additional domain controller to operate as a redundant ECU.FIG. 6 illustrates an example of a communication system 500 in a vehicle. The system 500 may be one of the ECUs or controllers or such a device described herein that communicates over an in-vehicle network 465, such as using the CAN, SCI, MLI protocols. The system 500 includes hardware such as electronic circuits.The system 500 includes, among other things, a processor 405, a memory 410 coupled to a memory controller 415, and one or more input devices 445 and / or output devices 440, such as peripherals or controllers, communicatively coupled via a local I / O controller 435. These devices 440 and 445 may include, for example, battery sensors, position sensors (altimeters, accelerometer, GPS), display / identification lights, and the like. Input devices such as a conventional keyboard 450 and a mouse 455 may be coupled to the I / O controller 435. The I / O controller 435 may be, for example, one or more buses or other wired or wireless connections as are known in the art. The I / O controller 435 may include additional elements omitted for simplicity, such as controllers, buffers (caches), drivers, repeaters, and receivers to enable communication.I / O devices 440, 445 may further include devices communicating both inputs and outputs, for example, disk storage, a network interface card (NIC), or a modulator / demodulator (for accessing other files, devices, systems, or network), a radio frequency (RF) or other transmitter / receiver, a telephony interface, a bridge, a router, and the like.The processor 405 is a hardware device for executing hardware instructions or software, particularly those stored in the memory 410. Processor 405 may be a custom or commercially available processor, a central processing unit (CPU), an auxiliary processor among multiple processors associated with system 500, a semiconductor-based microprocessor (in the form of a microchip or chipset), a macroprocessor, or other device for executing instructions. Processor 405 includes a cache 470, which may include, among other things, an instruction cache to accelerate fetch of executable instructions, a data cache to accelerate fetch and store data, and a translation lookaside buffer (TLB) to accelerate translation from virtual to physical addresses for both executable instructions and data. Cache 470 may be organized as a hierarchy of multiple levels of cache (L 1, L 2, etc.).The memory 410 may include one or more volatile memory elements (e.g., random access memory, RAM such as DRAM, SRAM, SDRAM), and nonvolatile memory elements (e.g., ROM, erasable programmable read-only memory (EPROM), electronically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), tape, compact disc read-only memory (CD-ROM), disk, floppy disk, cartridge, cassette, or the like). Moreover, the memory 410 may include electronic, magnetic, optical, or other types of storage media. It should be appreciated that the memory 410 may have a distributed architecture in which various components are located remotely from each other but may be accessed by the processor 405.The instructions in memory 410 may include one or more separate programs, each of which comprises an ordered listing of executable instructions for implementing logical functions. In the example of FIG. 4, the instructions in memory 410 include a suitable operating system (OS) 411. Operating system 411 may essentially control the execution of other computer programs and provides scheduling, input-output control, file and data management, memory management, communication control, and related services. In one or more examples, the OS 411 is a real-time operating system (RTOS).Additional data, including, for example, instructions for processor 405 or other retrievable information, may be stored in mass storage 420, which may be a mass storage device such as a hard disk or solid state drive. The instructions stored in memory 410 or mass storage 420 may include those that enable the processor to perform one or more aspects of the systems and methods described herein.The system 500 may further include a display controller 425 coupled to a user interface or display 430. In some embodiments, the display 430 may be an LCD screen. In further embodiments, the display 430 may include a plurality of LED status lights. In some embodiments, system 500 may further include a network interface 460 for coupling to a network 465. The network 465 may be an IP-based network for communication between the system 500 and an external server, client, and the like, over a broadband connection. In one embodiment, network 465 may be a satellite network. Network 465 sends and receives data between system 500 and external systems. In some embodiments, network 465 may be a managed IP network managed by a service provider. The network 465 may be implemented wirelessly, for example, using wireless protocols and technologies such as WiFi, WiMax, satellite, or others. The network 465 may also be a packet switched network, such as a local area network, a wide area network, a metropolitan area network, the Internet, or other similar type of networking environment. The network 465 may be a fixed wireless network, a wireless local area network (LAN), a wireless wide area network (WAN), a personal area network (PAN), a virtual private network (VPN), an in-vehicle network, an intranet, or other suitable network system, and may include equipment for receiving and transmitting signals. The network may use one or more protocols such as CAN, SCI, MLI, and the like.FIG. 7 illustrates an example flow diagram for a method for enabling additional redundancy layers for a steering system, according to one or more embodiments. The method includes operating an actuator in the steering system 12 using a control system including a primary ECU and a backup ECU, the primary ECU performing the control operations for the actuator, as illustrated at 610. The actuator may be either the steering wheel actuator or the road wheel actuator. The method further includes detecting whether a single point fault has occurred, as shown at 620. The single point fault is detected when one of the actuator control systems has a fault in operation. Until such a fault, the operation of the actuators in the steering system 12 continues.In response to detecting the fault, it is determined whether the primary ECU or the secondary ECU from the control system has the fault, as shown at 630. It is thus determined which of the two ECUs from the control system is faulty. If the primary ECU is faulty, the method includes switching control operations in the control system, as shown at 640.In one or more examples, the backup ECU detects the fault at the primary ECU by comparing a first road wheel position calculated by the primary ECU corresponding to a steering wheel position with a second road wheel position calculated by the backup ECU corresponding to the same steering wheel position. When the difference in resulting road wheel positions exceeds a predetermined threshold and when the sensors and other components of the backup ECU do not indicate signs of failure, the backup ECU determines that the primary ECU is faulty. The primary ECU similarly determines that the backup ECU has a failure. Alternatively or additionally, communication between microcontrollers between the ECUs allows the ECUs to mutually inform about a fault, e.g., if the fault is due to a failed component, e.g., a position sensor.Switching the control operations includes disabling the path of the primary ECU in the control system, as shown at 642. Further, the backup ECU is made from the control system to the primary ECU of the control system to perform one or more of the control operations of the control system, as illustrated at 644.Alternatively, if the backup ECU of the control system has the fault, the method includes disabling the path of the backup ECU in the control system, as shown at 645.The method further includes initializing and using the domain controller 510 as a new backup ECU of the control system, as shown at 650. The domain controller 510, which is external to the steering system 12, thus enables redundancy to be provided to the controlling ECU of the control system, i.e., the ECU now functioning as the primary ECU.Using the domain controller 510 as a backup ECU includes initializing the steering system model 515 on the domain controller 510, as shown at 652. The steering system model 515 is a preconfigured simulation model for the steering system 12 of the vehicle 10. the steering system model 515 is programmed to calculate estimates of torque commands, such as the assist torque and / or the feedback torque, that the actuators of the steering system 12 generate based on one or more sensor measurements. In one or more examples, the domain controller 510 receives the sensor measurements from the primary ECU from the control system. Alternatively or additionally, the domain controller 510 uses sensor measurements from one or more different sources, such as sensors to which the domain controller 510 is associated. Thus, the domain controller with steering system model 515 generates a torque command for operations of the steering system, as illustrated at 654.The steering system 12 is thus operated with the primary ECU from the control system and domain controller 510 as a backup ECU until another single point fault occurs in the control system, as illustrated at 660 and 670. The domain controller 510 thus provides an additional redundancy layer in the event of an ECU fault in the steering system 12.The domain controller 510 detects the further fault at the primary ECU by comparing a first road wheel position as calculated by the primary ECU corresponding to a steering wheel position and a second road wheel position as calculated by the domain controller 510 corresponding to a predicted steering wheel position and a corresponding predicted road wheel position. In one or more examples, the domain controller 510 calculates the predicted road wheel position based on other sensor data that the domain controller receives from sensors external to the steering system 12, such as sensors from a brake system, wheel assembly system, and the like.In addition, the domain controller, which functions as a backup controller, initiates an emergency maneuver in response to an additional fault, i.e., the control system's operational control has a fault, as illustrated at 680.The emergency maneuver may include stopping the vehicle 10, for example, by automatically sending brake commands to an actuator of the braking system of the vehicle 10 or to any other actuators in the vehicle 10. In one or more examples, the driver is allowed to operate the vehicle 10 for a limited time or distance before the vehicle 10 comes to an automatic stop.The technical solutions thus improve redundancy in control systems of the steering system by providing an additional redundancy layer with the domain controller located outside the steering system as a backup ECU in the event of a single point fault in the control system. The improvement enables a vehicle driver to drive the vehicle longer or farther than in the case where the single point fault causes the vehicle to stop.The present technical solutions may be a system, method and / or computer program product at any possible level of technical detail of integration. The computer program product may include one or more computer readable storage media having computer readable program instructions embodied therein to cause a processor to perform aspects of the present technical solutions.Aspects of the present technical solutions are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems) and computer program products according to embodiments of the technical solutions. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, may be implemented by computer readable program instructions.The flowchart and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present technical solutions. In this context, each block in the flowchart or block diagrams may represent a module, segment, or portion of the instructions that includes one or more executable instructions for implementing the specified logical function(s). In some alternative implementations, the functions indicated in the blocks may occur out of the order indicated in the figures. For example, two blocks shown in succession may be executed substantially simultaneously, or the blocks may sometimes be executed in the reverse order depending on the functionality. It is also noted that each block of the block diagrams and / or flowchart illustration, and combinations of blocks in the block diagrams and / or flowchart illustration, may be implemented by special purpose hardware-based systems that perform the specified functions or acts, or perform combinations of special purpose hardware and computer instructions.It is also to be appreciated that any module, unit, component, server, computer, terminal device, or device exemplified herein and executing instructions may include, or otherwise have access to, computer readable media such as storage media, computer storage media, or data storage devices (removable and / or non-removable) such as magnetic disks, optical disks, or tapes. Computer storage media may include volatile and non-volatile, removable and non-removable media implemented in a method or technology for storing information, such as computer readable instructions, data structures, program modules, or other data. Such computer storage media may be part of the apparatus or accessible or connectable thereto. Any application or module described herein may be implemented using computer readable / executable instructions that may be stored or otherwise maintained on these computer readable media.While the technical solutions have been described in detail in connection with only a limited number of embodiments, it should be readily understood that the technical solutions are not limited to these disclosed embodiments. Rather, the technical solutions may be modified to include any number of variations, changes, substitutions, or equivalent arrangements not heretofore described, but which are commensurate with the spirit and scope of the technical solutions. In addition, although various embodiments of the technical solutions have been described, it is understood that aspects of the technical solutions may include only some of the described embodiments. Accordingly, the technical solutions are not to be considered as limited by the above description.

Claims

A triple redundancy fail-safe system for a steering system (12), the system comprising: a control module comprising: a first electrical control unit (ECU) configured to operate as a primary ECU to send a motor command to a motor to generate torque; a second ECU configured to operate as a backup for the first ECU; and in response to a fault at the first ECU: send a notification to a domain controller (510) of the fault; and operate as a primary ECU; and wherein the domain controller (510) is configured to operate as a backup for the second ECU in response to receiving the notification of the fault.The system of claim 1, wherein the domain controller (510) is external to the steering system (12).The system of claim 1, wherein the domain controller (510) houses a steering system model (515) to calculate an estimated torque command when operating as a backup ECU.The system of claim 1, wherein the second ECU detects the fault at the first ECU by comparing a first road wheel position calculated by the first ECU corresponding to a steering wheel position and a second road wheel position calculated by the second ECU corresponding to the steering wheel position.The system of claim 1, wherein the domain controller (510) detects the fault at the primary ECU by comparing a first road wheel position calculated by the primary ECU corresponding to a steering wheel position and a second road wheel position calculated by the domain controller (510) corresponding to a predicted steering wheel position and a corresponding predicted road wheel position.The system of claim 5, wherein the domain controller (510) initiates an emergency maneuver to stop operation of the steering system (12) in response to the fault at the primary ECU.The system of claim 1, wherein the control module controls a steering wheel actuator of the steering system (12) to generate a feedback torque.The system of claim 1, wherein the control module controls a road wheel actuator of the steering system (12) to generate an assist torque.The system of claim 1, wherein the first ECU is further configured to send a notification to the domain controller (510) of the fault in response to a fault at the second ECU, wherein the domain controller (510) is initialized to operate as a backup to the first ECU in response to receiving the notification of the fault.A steering system (12) comprising: a control module comprising: a first electrical control unit (ECU) configured to operate as a primary ECU of the control module, the primary ECU sending a motor command to a motor to generate torque; a second ECU configured to operate as a backup for the first ECU, the operation as a backup comprising: monitoring the first ECU for a fault; responsive to detecting the fault at the first ECU: operating as a primary ECU of the control module; and initializing a domain controller (510) to operate as a backup ECU.The steering system (12) of claim 10, wherein the domain controller (510) is external to the steering system (12).The steering system (12) of claim 10, wherein the first ECU is configured to send a notification to the domain controller (510) of the fault in response to a fault at the second ECU, wherein the domain controller (510) is initialized to operate as a backup to the first ECU in response to receiving the notification of the fault.The steering system (12) of claim 10, wherein the second ECU detects the fault at the first ECU by comparing a first road wheel position calculated by the first ECU corresponding to a steering wheel position and a second road wheel position calculated by the second ECU corresponding to the steering wheel position.The steering system (12) of claim 10, wherein the domain controller (510) detects the fault at the primary ECU by comparing a first road wheel position calculated by the primary ECU corresponding to a steering wheel position and a second road wheel position calculated by the domain controller (510) corresponding to a predicted steering wheel position and a corresponding predicted road wheel position.The steering system (12) of claim 10, wherein the domain controller (510) initiates an emergency maneuver to stop operation of the steering system (12) in response to the fault at the primary ECU.

Citation Information

Patent Citations

  • failure management in a vehicle

    DE102015110958A1

  • Electrical steering for vehicle, with triple redundancy

    US20030098197A1

  • Redundant steering controls for automated driving

    US20180099694A1

  • Steering system for a vehicle

    US6394218B1

  • Redundant steer-by-wire system

    US6548969B2