Function-oriented electronics architecture
The control device with smart actuators and computing platforms addresses the rigidity and complexity of existing vehicle architectures by enabling centralized fault management and compensatory measures, enhancing flexibility and safety.
Patent Information
- Application Number
- DE102019132428
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2019-11-29
- Publication Date
- 2026-02-12
- Estimated Expiration
- 2039-11-29
AI Technical Summary
Existing vehicle electrical/electronic architectures are rigid, complex, and inflexible, requiring each control unit to manage vehicle configuration and fault display, leading to potential misidentification of functional failures and increased complexity with sensory and actuator units.
A control device with smart actuators and functional modules on high-performance computing platforms, allowing centralized fault detection and management, enabling actuators to react independently to faults and coordinate compensatory measures across the electromechanical system.
This approach enhances vehicle flexibility and fault management by enabling centralized decision-making and compensatory actions, improving functional safety and simplifying updates and variant management.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The present invention relates to a function-oriented electronics architecture, in particular for a vehicle.
[0002] The electrical / electronic architecture (E / E) refers to the internal integration of electrical and electronic components in a motor vehicle, which, in general, are designed to provide optimal energy management. This encompasses the functions of energy storage, energy supply, and energy recuperation. E / E systems are used in both gasoline-powered and electric vehicles. They are responsible, for example, for supplying and controlling driver assistance and safety systems (e.g., ESP) as well as the components of the infotainment system with their corresponding electronic control units.
[0003] In today's common architectures, functionalities are located on the respective control units. This means that every end device, such as an electronic, electromechanical, or mechanical component, is controlled by a corresponding control unit, so the functionality of the end device is ultimately determined by the control unit. This architectural design allows vehicle / powertrain variability and fault management to be implemented on the respective control units. Within this architecture, each control unit sends specific information (e.g., engine speed, drive mode, gear selected) as well as specific warning / information messages (e.g., red or yellow warning symbol) via the vehicle's internal communication network (e.g., FlexRay or CAN). This information is sent to the instrument cluster and can be displayed there. Currently, 62 messages and 110 signals are defined for warning / information messages alone.
[0004] A growing disadvantage of this architecture is that each control unit must be aware of the vehicle configuration in order to request compensatory measures, for example, when a function failure is detected. Mapping vehicle variance at the control unit level is not only complex and time-consuming, but also results in a relatively rigid architecture with regard to updates and expandability. Furthermore, in principle, every control unit is capable of triggering a fault display on the instrument cluster, provided this is predefined in the corresponding control unit. Thus, it is possible that, for example, a function of the electromechanical system might be displayed as faulty or defective, even though it could potentially be provided by other components within the electromechanical system through compensatory measures.Furthermore, the ever-increasing number of sensory and actuator units in modern vehicles poses increasingly greater problems for this approach.
[0005] German patent application DE 10 2017 201 702 A1 discloses an actuator control unit for a motor vehicle for controlling actuators. The actuator control unit comprises a number of driver output stages, each driver output stage configured to control an actuator, and a receiver unit for receiving control signals from a central engine control unit of the motor vehicle. The actuator control unit has a first power supply connection for connecting to a first voltage source and a second power supply connection for connecting to a second voltage source, the voltages provided by the first and second voltage sources being different. A first number of first driver output stages are coupled to the first power supply connection to control their associated actuator, which is an actuator of a first operating voltage class.A second set of second driver output stages is coupled to the second power supply connection to control its associated actuator, which is an actuator of a second operating voltage class.
[0006] Publication DE 100 52 570 A1 discloses a system for controlling operational processes, in particular in a vehicle, wherein the system for controlling the operational processes contains program modules and the program modules themselves and / or the program modules in their entirety are divided into a hardware-dependent and a hardware-independent part, wherein the hardware-dependent part and the hardware-independent part exchange physical quantities.
[0007] One object of the present invention can be seen as providing an improved architecture, particularly for a vehicle, which overcomes the aforementioned disadvantages.
[0008] The problem is solved by means of a control device for an electromechanical system and by means of a corresponding control method according to the independent claims. Advantageous embodiments are described in the dependent claims.
[0009] According to the invention, a control device for an electromechanical system is provided with at least one group of actuators, each of which can be coupled to a mechanical, electromechanical, or electronic unit (or, according to further embodiments, is actually coupled) and is configured to control the operation of this mechanical unit. Within the scope of this description, an actuator may include a control unit, which, however, does not have a controlling / regulating module as is the case with conventional control units, but is configured to receive control commands from an external instance. The actuator or the control unit of the control device according to the invention may, for example, essentially comprise an actuation unit and a fault monitoring unit.The actuator of the control device according to the invention can, for example, correspond to a smart actuator, which is characterized in that it is able to detect certain faults in the mechanical or electromechanical unit it controls and react to them independently, for example by initiating an immediate measure that can prevent further damage to the controlled and, in this case, faulty mechanical unit. This is particularly relevant in the case of time-critical and / or serious faults. The smart actuator can thus ensure functional safety. The at least one group of actuators can also include sensors.
[0010] The control device according to the invention further comprises at least one group of functional modules, which are implemented on a computing platform, for example, on a high-performance computing platform (HCP). The group of functional modules can be associated with the group of actuators in the sense that the group of functional modules defines and controls the functions of the associated actuators. The group of functional modules includes, firstly, a plurality of control modules, wherein each actuator is assigned a control module and is communicatively coupled to it. A control module can, for example, be configured as a PLC (programmable logic controller). The group of functional modules further comprises a coordinating module, which is communicatively coupled to the plurality of control modules from the same group of functional modules.The coordinating module is configured to: i) receive error messages from each control module regarding the operating status of the associated mechanical unit and / or actuator; and ii) detect a malfunction (of the electromechanical system) based on the received error messages and then counteract the detected malfunction by modifying the operation of at least one of the actuators in the group. Since the control modules report fault states of the actuators in the at least one group to the coordinating module, the countermeasure for a detected malfunction can be taken into account considering the current overall state of the part of the electromechanical system containing the group of actuators. This allows for the initiation of an optimal compensatory measure.
[0011] With regard to the interaction between actuator and control module, it may be provided in particular that an actuator is configured to adjust a state parameter of the mechanical unit based on a signal received from the corresponding control module, and that each control module is configured to transmit a setpoint to the corresponding actuator and to receive an actual value from the corresponding actuator.
[0012] According to further embodiments of the control device, the coordinating module can also be configured to output an error information signal depending on the detected malfunction and / or the countermeasure taken. Advantageously, the coordinating module represents a central collection point for the functional limitations present in the associated group of actuators and, if applicable, in the associated group of function modules. The output of the error information signal can be preceded by a prior check to determine whether the detected malfunction can be compensated for by a workaround. It is possible, for example, that the classification of the degree or severity of a malfunction according to an error message from a control module is greater / more serious than the classification of the degree or severity of a malfunction based on a control module's error message.the severity of this malfunction from the perspective of the coordinating module, because the coordinating module has all relevant information about the state of the electromechanical system and may be able to compensate for the malfunction by taking countermeasures.
[0013] According to further embodiments, the control device can also include an output device which is controlled by a control module of a second group of function modules. The second group of function modules can be structured analogously to the first group of function modules. In particular, the second group of function modules can be implemented on a further computing platform, for example, on a second HCP. In the case of a vehicle, the output device can be an instrument cluster.
[0014] According to further embodiments of the control device, the at least one group of function modules can be communicatively coupled with the second group of function modules. In other words, this means that a communicative connection exists between the computing platform on which the at least one group of function modules is implemented and the other computing platform on which the second group of function modules is implemented. The corresponding communication bus used for this purpose can be different from the communication bus used for communication between the control modules and their associated actuators. In the latter case, FlexRay or CAN is typically used, while Ethernet can advantageously be used for the data connection between the computing platforms.
[0015] According to further embodiments of the control device, the control module controlling the output device can be configured to output error information via the output device based on the error information signal. The error information can be used to inform the user of the electromechanical system about its functional limitations and / or to initiate a maintenance measure. Since the error information signal is generated based on an overall assessment of the electromechanical system, particularly on the basis of error messages transmitted by control modules, it can inform the user (for example, the driver of a vehicle) which function(s) in the electromechanical system is / are actually not present because the malfunction of the component providing these function(s) cannot be remedied by means of alternative measures.Countermeasures that could be initiated by the coordinating module can be compensated for.
[0016] According to further embodiments of the control device, each actuator can have a fault monitoring unit which, in the event of an operational fault (malfunction) in the mechanical unit, is configured to transmit a corresponding fault signal to the associated control module. By transmitting the fault signal, the control module is provided with information about functional limitations of the associated mechanical system or actuator. The fieldbus existing between these units can be used to transmit the fault signal from the actuator to the associated control module (e.g., using the CAN or FlexRay protocol).
[0017] According to further embodiments, the control device can also include a diagnostic event module, which is communicatively coupled to the coordinating module and has a fault memory, and a function suppression module, which is communicatively coupled to the coordinating module and is configured to prevent the execution of certain functions of the electromechanical system depending on the current state of the electromechanical system. In the case of a vehicle, the diagnostic event module can be the DEM (diagnostic error manager) and the function suppression module the FIM (function inhibit manager), which are basic software modules of the AUTOSAR reference architecture for ECU software in the automotive industry.Both the diagnostic event module and the function suppression module are controlled by the coordinating module, so that the documentation of all relevant information regarding malfunctions of the electromechanical system takes place at a central location and not individually within each control unit itself, as in the control unit-oriented, previously known E / E architecture.
[0018] According to further embodiments of the control device, the at least one group of function modules can also include an output module which is communicatively coupled to the coordinating module and is configured to receive the error information signal and to prioritize and / or coordinate the information to be output based on the error information signal. The output module can be configured to receive additional signals besides the received error information signal, process these signals together, and output a uniform signal from the perspective of the first group of function modules, which is transmitted to the second group of function modules via the fieldbus.The output signal can be used within the second group of function modules to output relevant information, particularly a warning message, about the operating status of the electromechanical system via the output device. The output module can generally be used to design the display.
[0019] According to further embodiments of the control device, the electromechanical system can be a platform for building an automobile. The first group of actuators and the first group of functional modules can be configured for monitoring and controlling the chassis and the powertrain. The platform can comprise several computing platforms (in particular, HCPs), with each computing platform implementing a group of functional modules that, together with the associated group of actuators or terminals, are responsible for other functional areas of the vehicle. For example, another group of control modules and actuators can be responsible for the human-machine interfaces in the passenger compartment and other services. Yet another group of control modules and actuators can be responsible for energy and charging processes and other services.In general, each group of control modules can be implemented on its own computing platform, with a broadband data connection provided between the computing platforms.
[0020] Within the first group of control modules in an automotive platform, the coordinating module can be a PTR manager (power train reduction manager). This manager collects all functional limitations of the actuator / sensor level components in the corresponding group and, as mentioned previously, makes decisions regarding compensatory measures and any resulting information to be displayed. Due to its location within the group of functional modules that oversees the actuator group, the PTR manager has access to all relevant information about the entire vehicle. All decisions are documented via a preferably existing interface to the DEM and / or FIM.The output module, which can be referred to as the PTUI (power train user interface), bundles the display requests from the powertrain, which are generated within the first group of function modules, and prioritizes and coordinates them. Communication between the output module and the output device, which is equivalent to communication between two different computing platforms, each implementing a group of different function modules, can take place via a fieldbus (e.g., Ethernet).
[0021] The control device described here can be used to build a further development of the previously known E / E architecture, which meets the requirements of a novel architecture, the E 3The invention fulfills the requirements of an end-to-end electronics architecture. In the control device according to the invention, a new functional level is created compared to the previously known E / E architecture. This new level comprises at least one group of functional modules, with each group of control modules being implemented on a computing platform, in particular a human-computer interface (HCP). For example, three, four, five, or more computing platforms can be provided to control the overall operation of the electromechanical system. The innovation compared to the previously known E / E architecture is that the functions usually located on control units are transferred to and executed on the computing platforms. In the case of the drive system as the subsystem of the vehicle to be controlled, the conventional control units can be largely replaced by smart actuators within the scope of the invention.Each smart actuator then operates by executing instructions based on a specification from the associated control module, which is implemented on the computing platform and is not, in particular, a component of the smart actuator itself. Time-critical functionalities, such as the shift sequence of a multi-speed dual-clutch transmission, or time-critical monitoring functions for fulfilling functional safety requirements according to the ISO 26262 standard, can still remain on the control units or smart actuators.
[0022] According to the E 3The architecture aims to avoid direct communication between control units, for example, between the transmission and engine. Instead, this communication is handled centrally via the computing platform. This is partly because relevant limitations of the overall vehicle, for which no information is available at the control unit level, can be directly considered and mitigated (capped), potentially affecting, for example, a shift sequence.
[0023] The control device according to the invention enables the porting of fault handling from the control units, or more generally from the control unit level, to the newly created, computationally powerful functional level, thereby achieving maximum availability of the powertrain. To make variant management (variant handling) manageable, a clear system context can preferably be established. The system context of a mechanical system to be controlled essentially consists of the control module, the actuator or control unit of the sensor-actuator level, and the mechanical system to be actuated. This generic system context enables the introduction of centralized fault management for the powertrain by the coordinating module, in this case the PTR manager. Furthermore, the management of all powertrain displays can preferably also be carried out centrally, for example, by the PTUI module located downstream of the PTR manager.
[0024] To better illustrate the functionality and, above all, the difference between the control device according to the invention and the prior art, a comparison to the human organism can be drawn. Here, the two hemispheres of the brain correspond to two exemplary computing platforms or two groups of control modules (the number of which can be larger as needed). For example, hands are actuated, corresponding to the (smart) actuator or the control unit. The individual fingers of the hands then correspond to mechanical units. Let us now consider the loss of a thumb as an exemplary failure scenario. In such a failure scenario, our hand (corresponding to the smart actuator) does not decide how a planned process can be carried out alternatively, such as inserting a thumbtack into a pinboard.Rather, the decision regarding which measure can be taken to solve the problem is made in the relevant hemisphere of the brain, depending on the situation, possibly with subsequent communication with the other hemisphere. For example, it might be decided that the planned procedure can still be carried out using the other hand, provided there are no "error messages." The brain also processes the severity of the injury or error and indicates whether, for example, a direct visit to the hospital is necessary, which in the case of a vehicle corresponds to a visit to a repair shop.
[0025] In principle, the present control device can be described as having a function-oriented architecture, in contrast to the control unit-oriented architecture known from the prior art.
[0026] According to the invention, a vehicle is also provided which has the control device disclosed herein.
[0027] Furthermore, a method for controlling an electromechanical system is provided, wherein the electromechanical system comprises at least one group of actuators, each of which can be coupled to a mechanical unit and is configured to control the operation of this mechanical unit, and at least one group of functional modules, which are preferably implemented on a computing platform, comprising: a plurality of control modules, wherein each actuator is assigned a control module and communicatively coupled to it, and a coordinating module, which is communicatively coupled to the plurality of control modules. The method includes: receiving error messages regarding the operation of the actuators and / or the mechanical units by the coordinating module, and detecting a malfunction based on the received error messages.and initiating countermeasures in the form of modifying the operation of at least one of the actuators in the group to counteract the identified malfunction. Basically, each of the control modules serves to regulate the operation of at least one associated actuator.
[0028] It is understood that the features mentioned above and those to be explained below can be used not only in the combinations specified, but also in other combinations or on their own, without leaving the scope of the present invention.
[0029] Further advantages and embodiments of the invention will become apparent from the description and the accompanying drawings. Fig. Figure 1 shows an exemplary structure of an E / E architecture. Fig. Figure 2 shows an exemplary structure of the architecture according to the present invention. Fig. Figure 3 shows another exemplary structure of the architecture according to the present invention.
[0030] In Fig. Figure 1 illustrates an exemplary setup of a typical E / E architecture.
[0031] A first conventional control unit (or actuator) 1 and a second conventional control unit (or actuator) 2 are shown. Both control units 1 and 2 have the same basic structure. The first control unit 1 has a control unit 10, an actuation unit 11, a fault handling unit 12, and a fault monitoring unit 13. The fault handling unit 12 can include a DIM and / or an FIM. The second control unit 2 also has a control unit 20, an actuation unit 21, a fault handling unit 22, and a fault monitoring unit 23. The fault handling unit 22 can include a DIM and / or an FIM. The first control unit 1 is coupled to and controls a first mechanical system 15, for example, a parking lock. Likewise, the second control unit 2 is coupled to a second mechanical system 25, for example an electric parking brake, and also controls it.Reference numeral 3 denotes a generic reference, which may, for example, correspond to a symbol on the instrument cluster or to an emitted tone.
[0032] In the event of a fault in a mechanical system 15, 25 during the in Fig. In the architecture outlined in 1, which is detected by the corresponding fault monitoring unit 13,23, each control unit 1,2 can transmit a corresponding fault message to the instrument cluster, which usually leads directly to the output of the generic message.
[0033] In Fig. Figure 2 illustrates an exemplary architecture according to the present invention. As shown, the control device according to the invention is based on a new system level, which is arranged between the generic instruction, for example, between the device responsible for outputting the instruction 3, and the control units 1, 2. The new system level represents a computing platform 4 on which, in the example shown, four function modules are implemented. The function modules arranged on the computing platform 4 simultaneously form the at least one group of function modules that is assigned to the at least one group of actuators, which comprises the two control units 1, 2. The function modules comprise a first control module 10, which is responsible for operating the first control unit 1, and a second control module 20, which is responsible for operating the second control unit 2.The functional modules also include a coordinating module 41 and an error handling module 42, whose functions have already been described previously. As in the case of . Fig. In the embodiment shown in Figure 1, each control unit 1, 2 controls a corresponding mechanical system 15, 25.
[0034] The difference to the one in Fig. 1. Illustrating a previously known E / E architecture consists, firstly, in the fact that parts of the functional units from the actuators 1, 2 in the Fig. 2 illustrated control device according to the invention have been moved to the computing platform 4, namely the control units 10, 20 and the error handling units 12, 22, the latter being in Fig. 2 on the computing platform 4 have been combined into a central error handling module 42. Therefore, the two control units 1, 2 in Fig. 2. The components are adapted such that they each only have the actuation unit 11, 21 and the fault monitoring unit 13, 23. Furthermore, a new central module is provided, the coordinating module 41, which collects all reported functional limitations (represented by the arrows between the control units 1, 2 and the coordinating module 41) of the components of the actuator / sensor level and decides on compensatory measures to be taken and, in particular, on information to be displayed.
[0035] Fig. Figure 3 shows a further exemplary structure of the architecture according to the present invention, which is based on the basic structure made up of Fig. Figure 2 is based on the diagram. A first computing platform 4 and a second computing platform 5 are shown. Within the first computing platform 4, the control module 10 responsible for the first control unit 1 is provided, as well as the coordinating module 41, the fault handling module 42, and an output module 43, whose functions have already been described. Although only one control unit 1 is shown, further control units can, of course, be provided, each coupled with a corresponding control module. The function modules within the second computing platform 5 are not explicitly shown but can be assumed to be analogous to the function modules within the first computing platform 4. The second computing platform 5 is coupled to an instrument cluster 51, which is controlled by a corresponding control module, for example, to output visual and / or audible information.
[0036] The following describes how the in Fig. The architecture shown in Figure 3 is explained. In an exemplary scenario, the mechanical unit 15 can correspond to a parking lock, with the first computing platform 4 then being responsible for the overall control of the drive train. The in Fig. The three arrows shown represent communication between the respective elements / components, with single and double arrows indicating the direction of communication. Communication can, for example, correspond to the transmission of a signal or a sequence of signals.
[0037] The mechanical unit 15 is controlled by the actuating unit 11 based on an external instruction, for example, a driver request to engage the parking lock, which is transmitted to the control module 10 via a first communication 61. In accordance with the external instruction, the control module 10 transmits a target value to the actuating unit 11 via a third communication 63. The actuating unit 11 controls the mechanical system 15 accordingly and reports the current state to the control module 10 via a fourth communication 64. The control module 10 reports the status regarding the execution of the received external instruction via a second communication 62.
[0038] If a fault occurs in the mechanical unit 15, it is detected by the fault monitoring unit 13 and transmitted to the associated control module 10 via a fifth communication 65. Upon receiving a fault message, the control module 10 transmits a fault message to the coordinating module 41 via a sixth communication 66. The coordinating module 41, which contains all relevant information about the entire vehicle, coordinates with other units via a seventh communication 67 regarding a possible compensatory measure to address the fault. Simultaneously, relevant information regarding the fault and the resulting decision is documented in the fault handling module 42 via an eighth communication 68. The coordinating module 41 also determines which information should be displayed on the output device 51.For this purpose, an error information signal is first transmitted to the output module 43 via a ninth communication 69. The error information signal can, for example, contain information about the severity of the existing fault (e.g., error level 1 - driving possible without restriction; error level 2 - driving possible with restrictions; error level 2a - driving possible with restrictions, output of additional information; error level 3 - driving not possible, no power transmission; error level 4 - driving not possible, obstruction). The output module 43 bundles the display requests of the group of function modules and the associated group of actuators, and performs a corresponding prioritization if, for example, a display field can show several error messages, and more than one is present.The information to be displayed is transmitted by means of a tenth communication 70 from the output module 43 to the second computing platform 5, for example to the display device 51 by means of an eleventh communication 71, which originates from the associated control unit (in . Fig. 3 not explicitly shown).
[0039] For time-critical error messages, a direct time-critical communication path is provided between the control unit 1 and the coordinating module 41. Using this communication path, a time-critical monitoring function can be implemented via a twelfth communication 72 to fulfill the functional safety requirements of ISO standard 26262. This allows time-critical errors to be output directly, without having to go through the associated control module 10.
[0040] Reference numeral 44 indicates the elements that embody the aforementioned advantageous system context – the mechanical unit 15, the associated control unit 11, and the associated control module 10. The control module 10 controls and monitors (regulates) the associated control unit 1 and reports functional limitations to the coordinating module 41. The clear system context simplifies the development of variants.
[0041] In a variation on the representation in Fig. Instead of the ninth communication 69 between the coordinating module 41 and the output module 43, an equivalent communication can take place between the fault handling module 42 and the output module 43. In other words, the fault handling module 42 can be configured to transmit a fault information signal to the output module 43 based on the information from the coordinating module 41 for documenting the existing malfunction, the compensatory measure taken, and any information output to the driver.
[0042] Communication between control unit 1 and the first computing platform 4, or the function modules implemented therein, can take place, for example, via FlexRay or CAN. In the Fig.In the example shown, further control units can be provided, for example, for controlling components from the engine and transmission areas, which are communicatively coupled to the function modules of the first computing platform 4, analogous to the first control unit 1. Communication between the first computing platform 4 (e.g., first HCP) and the second computing platform 5 (e.g., second HCP) can be handled via a different fieldbus, for example, Ethernet. For communication between the output device 51 and the second computing platform 5, CAN FD (CAN with Flexible Data Rate) or LVDS (low voltage differential signaling) can be used.
[0043] Particularly when using the control device according to the invention in a vehicle, where a computing platform is responsible for controlling the powertrain, maximum powertrain availability in the event of a fault can be achieved by initiating countermeasures based on the overall system state. Thus, all possible backup strategies are feasible and manageable. Furthermore, the display of error messages can be subjected to plausibility checks or verification. For example, if the parking lock could not be engaged five times and the use of the electronic parking brake was requested instead, a corresponding warning message can only then be displayed to the driver.
[0044] A further advantage of the control device according to the invention is that it simplifies variant management across brands and model series. By locating the coordinating module (in particular the PTR manager) in the HCP, all relevant vehicle variants can be represented without significant effort. This is further facilitated by centralizing the processing of all drive restrictions in a single module.
[0045] A further advantage of the control device according to the invention is that updating the action strategy is relatively easy, even across different model series or brands. For example, new backup strategies (e.g., compensating for a fault in the automated manual transmission using existing electric motors) can be specifically introduced or adapted.
Claims
[1] Control device for a platform for the construction of an automobile, comprising: at least one group of actuators, of which one actuator can be coupled to a mechanical and / or hydraulic unit and is configured to control the operation of this mechanical unit; comprising at least one group of separate functional modules implemented on at least one computing platform: a plurality of control modules, wherein each actuator is assigned a control module and communicatively coupled to it, so that the operation of each actuator is carried out by executing instructions based on a specification of the associated control module; a coordinating module that is communicatively coupled with the majority of control modules from at least one group and is set up: i) to receive error messages from each control module regarding the operating status of the associated mechanical unit and / or actuator; and ii) to identify a malfunction based on the received error messages and then to counteract the identified malfunction by means of a countermeasure in the form of a modification of the operation of at least one of the actuators from the at least one group; iii) depending on the identified dysfunction and / or the measures taken Countermeasure: issue an error information signal; wherein at least one group of function modules further comprises an output module which is communicatively coupled to and configured with the coordinating module: a) to receive the fault information signal and to prioritize and coordinate the information to be output based on the fault information signal; and b) to receive further signals and process them together and output a uniform output signal from the perspective of the first group of function modules, which is transmitted to a second group of function modules via a fieldbus. [2] Control device according to claim 1, further comprising: an output device which is controlled by a control module of the second group of function modules. [3] Control device according to claim 2, wherein the at least one group of functional modules is communicatively coupled with the second group of functional modules. [4] Control device according to claim 3, wherein the control module controlling the output device is configured to output error information on the basis of the error information signal by means of the output device. [5] Control device according to one of claims 1 to 4, wherein each actuator has a fault monitoring unit which, in the event of an operating fault of the mechanical unit, is configured to transmit a corresponding fault signal or information about functional limitation to the associated control module. [6] Control device according to any one of claims 1 to 5, wherein the at least one group of functional modules further comprises: a diagnostic event module that is communicatively linked to the coordinating module and has an error memory; and A function suppression module, which is communicatively coupled with the coordinating module and is configured to prevent the execution of certain functions of the electromechanical system depending on the current state of the electromechanical system. [7] Vehicle comprising the control device according to any one of claims 1 to 6.
Citation Information
Patent Citations
System for controlling and monitoring vehicle-operating processes inserts variable program conditions with variable program modules and / or the same program modules with different content.
DE10052570A1
actuator control unit for a motor vehicle for controlling actuators
DE102017201702A1