Method and device for operating a vehicle
By determining the actual service life and health state of vehicle steering components, the method extends their use with guaranteed safety, addressing premature replacements and improving reliability.
Patent Information
- Application Number
- DE102023211421
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-11-16
- Publication Date
- 2025-07-31
- Estimated Expiration
- 2043-11-16
AI Technical Summary
Existing vehicle systems initiate safety measures based on predetermined service life, regardless of the actual condition of components, potentially leading to unnecessary component replacements and reduced operational reliability.
A method and device for determining the actual service life and health state of steering system components, allowing continued operation if certain criteria are met, and initiating safety measures only when necessary, thereby extending the service life with guaranteed operational safety.
Enables prolonged use of vehicle components with ensured operational safety by avoiding unnecessary replacements and enhancing reliability through condition-based safety measures.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
The invention relates to methods and devices for operating a vehicle.Nowadays, vehicles, in particular automobiles, systems or components, are specified for a predetermined service life (service life). If the actual life or useful life of a component exceeds this specified life, a life-dependent safety measure is initiated. For example, a vehicle driver is requested to replace the component by generating a corresponding output signal.This takes place independently of whether wear up to a relevant damage limit of a component has actually also occurred. Thus, a situation may occur in which the service-life-dependent safety measure is initiated despite a component that is still functional to the desired extent.Furthermore, redundant systems in the vehicle, in particular redundant steering systems, are known. This redundancy may be required, particularly in the case of a steer-by-wire steering system.Known from the prior art is US 2023 / 0097944 A1, which describes a method in which a vehicle cannot be accelerated after a speed reduction by a braking intervention of a vehicle driver if a fault has been detected in a steer-by-wire steering system. This document describes various scenarios of such speed regulation.Furthermore, U.S. Pat. No. 10,752,282 B2 is known, which describes a control system in a steering system. The control system includes a first electrical control unit which operates as a primary control unit of the control system and sends an engine control signal to the engine to generate a drive torque. The control system includes a second control unit that serves as a backup for the first control unit. The operation as a backup includes monitoring the first control unit for a malfunction.Furthermore, U.S. Pat. No. 11,605,252 B2 is known, which describes systems and methods for predictive detection of vehicle faults based on diagnostic fault codes. The document describes a method comprising determining a probability of a vehicle fault based on one or more diagnostic fault codes, wherein the probability of the fault is indicated to a vehicle driver if the probability exceeds a threshold value.Furthermore, US 2022 / 0 263 849 A1 is known, which describes abnormality detection in a vehicle network.DE 102017 117 327 A1 discloses a steering system of a vehicle and, in particular, methods and systems for monitoring vehicle steering systems in order to determine the integrity of the steering system.DE 10 2021 200 428 A1 discloses a steering system for a motor vehicle, comprising at least one electromechanical actuator operatively connected to a steerable wheel for steering, said electromechanical actuator having a sensor device which is designed to record at least one load value correlated with the load of the actuator and is connected to a control unit which is at least designed to process the load value.DE 10 2010 033 066 A1 discloses a method for detecting external impacts in vehicle steering systems which have a rotatable steering spindle and a servomotor for generating an auxiliary steering torque.DE 103 369 A1 discloses a method for controlling at least one mechanical actuating device and an electronic control system for controlling at least one mechanical actuating device.The technical problem arises of providing methods and apparatuses for operating a vehicle that allow for prolonged use of components in a steering system of the vehicle, thereby enabling operation of the vehicle with ensured operational safety. Furthermore, the technical problem arises of increasing operational reliability of the vehicle.The solution of the technical problems is achieved by the subject matters having the features of the independent claims. Further advantageous embodiments of the invention are given by the dependent claims.A method for operating a vehicle according to a first alternative, in particular a motor vehicle, is proposed. The method can also be a method for operating a subsystem of the vehicle, in particular a steering system of the vehicle. Preferably, the vehicle is a motor vehicle or an automobile. However, the method can also serve for operating a vehicle different therefrom. Here, an actual service life and, as an estimated variable, a degree of damage or a state of health of at least one component of a steering system of the vehicle are determined. The steering system of the vehicle may include components, in particular mechanical, electrical and / or electronic components, in order to influence vehicle guidance, in particular by a vehicle driver. However, it is also conceivable that a driver assistance system influences the vehicle guidance via the steering system.In steerable wheel vehicles, the steering system may include components to manipulate wheels of the vehicle to a position where the vehicle is then guided along a predetermined trajectory. In automobiles, this can be done, in particular, by setting a steering angle. Alternatively, the steering system may allow other components of the vehicle that are part of a steering system, such as components for adjusting a rudder in aircraft.A steering system may be an electromechanical or hydraulic steering system, in particular an electric power steering system. A steering system can also be a so-called steer-by-wire steering system. Further, a steering system may be a front axle or a rear axle steering system. Such a steering system may comprise an electromechanical or a hydraulic drive device.A steering system can in particular comprise the following mechanical components:steering handle, such as a steering wheel, for example,steering gear, such as a worm gear, for example,- steering column,steering shaft,- steering rack,mechanical connecting means such as screws,valve of a hydraulic power steering system,pump of a hydraulic power steering system,fluid lines of a hydraulic power steering system,driving means of an electromechanical power steering system, such as an electric motor,- torsion bar,and further mechanical components known to the skilled person.A steering system may include the following electrical or electronic components:control device, which can be designed as a computing device and can comprise at least one microcontroller or integrated circuit,steering angle sensor,steering wheel angle sensor,torque sensor,steering shaft position sensor,- steering rack position sensor,electrical contact elements, such as plugs, for example,electrical components, such as electrical switching units, such as MOSFETs or IGBTs,capacitors,- inductances,electrical lines,and further electrical or electronic components known to the skilled person.The actual lifetime may denote the time difference between a current time and the time of the first startup of the component or the vehicle. The actual service life can thus be a measure of the (operating) age of the component. The time of the first startup (or another reference time valid for the lifetime determination) may be predetermined. This can be stored in a memory device in a retrievable manner, for example. The current time can be determinable, for example retrievable by a server device. The vehicle or the component can also provide information at the current point in time, for example by a correspondingly designed device for determining the current point in time.The degree of damage represents a state and a functionality of the component, in particular on the basis of a predetermined scale or evaluation system. For example, such an evaluation system may comprise a classification into the degrees of damage "A", "B",..., "F", wherein e.g. "A" stands for no damage and "F" stands for severe damage. It is of course also possible to use a numerical value for the representation which lies, for example, between a minimum value, e.g. 0, and a maximum value, e.g. 1, wherein the minimum or maximum value represents no damage and the respectively remaining maximum or minimum value represents a severe damage. The degree of damage can be component-specific.The state of health, which may also be referred to as state of health (SOH), denotes in a further alternative of the invention a measure of the component in terms of functionality, performance and / or safety. Analogously to the degree of damage, the state of health can be determined according to a scale or evaluation system, wherein different scale- or evaluation system-specific values represent different states of health. Analogously to the details regarding the degree of damage, a numerical value can be used for the representation, which lies, for example, between a minimum value, e.g. 0, and a maximum value, e.g. 1, wherein the minimum or maximum value represents a maximally healthy state and the respectively remaining maximum or minimum value represents a minimally healthy state. The state of health can also be component-specific.In contrast to the level of damage explained, the state of health generally and as explained above relates to a functionality, performance and / or safety of a component. It describes how good or poor a component can fulfil its intended function and whether it operates safely and efficiently. A good health condition normally means that a component is in an acceptable state, while a poor health condition indicates problems with the component. The degree of damage, on the other hand, refers to a degree of wear, damage and / or deterioration of the component. It describes how much the component is already damaged or worn out. In other words, the state of health is a measure of the general state and the performance of a component. According to the further alternative of the invention, the degree of damage denotes a measure for the already occurring wear or damage of a component. It is thus conceivable that a component is in a good state of health but nevertheless has a certain degree of damage.The degree of damage or the state of health can be determined here by at least one computing device of the steering system. For this purpose, at least one input variable can be evaluated, for example a variable detected with the aid of a sensor. Such input variables detected with sensor assistance can be, for example:a temperature of the component,a power or energy consumption of the component,a dynamic variable associated with the component, such as a position, a speed or an acceleration,a pressure,a setpoint variable for controlling / regulating a component, such as a setpoint voltage, a setpoint current, a setpoint torque,an actual variable of the component, such as an actual voltage, an actual current, an actual torque,a command or manipulated variable for a component,a controlled variable of a component,and further variables known to the skilled person, which are component-specific or specific for the operation of the component.In a further embodiment of the further alternative of the invention, a setpoint auxiliary torque of a drive device of the steering system and a generated actual auxiliary torque are determined and compared in a steering system, wherein the degree of damage or the state of health of the drive device and / or of the regulating or control device of the drive device can be determined from a difference of these variables.In a further embodiment of the further alternative of the invention, an actual auxiliary torque and a change in a steering rack position are detected, wherein the degree of damage or the state of health of the steering gear can be determined as a function of these variables.In a further embodiment of the further alternative of the invention, a path or angular range of a movable component, for example of the steering rack or of a worm wheel, which path or angular range has already been covered since startup is determined, wherein the degree of damage or the state of health of the steering rack or of the worm wheel or of the steering gear can be determined as a function of the distance covered, for example as a function of a predetermined assignment.The degree of damage or state of health can be determined by evaluating a count variable, wherein a value of the count variable can be determined, in particular incremented, as a function of the input variable. Thus, for example, it is conceivable that the count variable is incremented with each change in position. Here, a value of the increment may be proportional to the value of the position change. The count variable can also be incremented if the input variable changes to a value in a predetermined value range.Generally, methods and input variables for determining the degree of damage or the state of health of components of a steering system are known to the person skilled in the art.The input variable can be detected with sensor assistance or determined mathematically from a variable detected with sensor assistance.Further, the actual lifetime is compared with a specified lifetime of the component. The specified lifetime may be a predetermined lifetime. This can be stored in a retrievable manner, for example in a server device or a storage device of the vehicle. The specified lifetime may be, for example, a lifetime specified by the manufacturer of the component. The specified service life can be a predetermined service life until the assumed occurrence of a functional capability of the component that is no longer desired.Furthermore, at least one continued operation criterion for the component is evaluated as a function of the estimated variable. If the continued operation criterion is fulfilled, it can be assumed that the continued operation of this component and thus of the vehicle is ensured in a safe manner. If the continued operation criterion is not fulfilled, it can be assumed that the continued operation of the component or of the vehicle is possible in a manner that is undesirably impaired compared to the ideal state of the component.The continued operation criterion can likewise be evaluated by the computing device of the steering system, a further computing device of the steering system or a computing device different therefrom.The continued operation criterion cannot be fulfilled if the degree of damage or the state of health is higher or lower than a predetermined measure. The measure can be selected in such a way that, for example, a relatively higher or lower damage rate or state of health represents an in particular undesirably impaired functionality of the component. An impaired functionality may be a functionality that deviates from the setpoint functionality in the undamaged state. The continued operation criterion can be fulfilled if the degree of damage or the state of health is less than or greater than or equal to the predetermined measure(s), wherein a relatively lower or higher damage wheel or state of health represents a desired functionality of the component. An impaired functionality may be a functionality that deviates from the setpoint functionality in the undamaged state. In order to determine whether the continued operation criterion is fulfilled, a comparison of the estimated variable with a predetermined threshold value can be made, for example.Furthermore, a service life-dependent safety measure is initiated if the actual service life is greater than the specified service life and the continued operation criterion is not fulfilled. The lifetime-dependent safety measure is not initiated if the actual lifetime is greater than the specified lifetime and the continued operation criterion is fulfilled.Examples of lifetime-dependent safety measures that are initiated if the actual lifetime is greater than the specified lifetime and the continued operation criterion is not fulfilled are, for example.restricting the vehicle speed to speeds in a predetermined (safe) range, in other words restricting a maximum permissible vehicle speed to a predetermined value which is in particular lower than the maximum speed permissible in the fault-free state of the vehicle,generating a request for the shutdown of the vehicle or initiating measures for the shutdown, for example initiating a so-called limp-aid maneuver,the request for a service station stay or the setting of a vehicle state which permits further operation, for example for travel into a service station, with predetermined operating parameters,generating a warning signal and / or a request for component replacement or component maintenance for a vehicle driver or vehicle occupant, preferably in an optical or acoustic manner,generating a request for component exchange,and further lifetime-dependent safety measures known to the person skilled in the art. This advantageously results in the service life of a vehicle being able to be extended beyond the specified service life of a component with a guaranteed operational reliability, namely if the continued operating criterion is fulfilled for this component even after the specified service life has elapsed. Thus, until now, a safety measure has been initiated in the vehicle when the specified service life has elapsed, independently of the actual degree of damage or state of health of the component, that is to say also in cases in which the component could continue to be operated with a predetermined operating safety. In other words, the permissible service life of a component in the vehicle is therefore changed, which advantageously enables a longer use of the component. Thus, an unnecessary component exchange can be avoided.It is possible that the evaluation of the continued operation criterion takes place only when the actual service life is greater than the specified service life or when these service lives are equal.It is of course conceivable that, in addition, the continued operation criterion is already evaluated in a state in which the actual service life is less than the specified service life, and the service life-dependent safety measure is initiated if the continued operation criterion is not fulfilled.A method for operating a vehicle according to the further alternative is further proposed, wherein the explained degree of damage or the explained state of health of at least one component of the steering system is determined as an estimated variable in each case by at least two mutually different computing devices of the steering system. With regard to the degree of damage and the state of health, reference is made to the explanations given above.The computing devices can each be designed as a microcontroller or integrated circuit or comprise at least one(s) such(s). The computing devices are preferably components of a control unit, which can be a control unit of the steering system, and are furthermore preferably arranged in a common housing. However, it is also possible for the computing devices to be part of different control units of the vehicle, if appropriate arranged in housings which are different from one another. The computing devices can be connected by data or signals, e.g. via a vehicle communication system such as a bus system or via a communication interface such as an inter-micro communication interface.The computing devices enable control of the operation of the steering system in a redundant manner. The computing devices can be, in particular, control devices for generating control signals for the operation of the steering system, in particular for the operation of a drive device of the steering system. In this case, it is possible for a first computing device to serve as the main computing device and the at least one further computing device to serve as the backup computing device, wherein in a fault-free state of the main computing device this main computing device generates the control signals. In an error-free state of this main computing device, the backup computing device can generate the control signals or take over the generation of the control command. It is conceivable that the two computing devices are arranged on a common printed circuit board. It is also possible for both computing devices to generate control signals for power amplification units (output stages) which are different from one another, in particular redundant. It is also possible that both computing devices can generate control signals for operating a drive device of the steering system, for example a 6-phase electric motor.Furthermore, at least one plausibility criterion is evaluated as a function of the at least two estimation variables. The plausibility criterion can be evaluated by the main computing device or the backup computing device. Thus, the plausibility criterion can be fulfilled, for example, when the estimated variables do not deviate from one another or do not deviate from one another by more than a predetermined amount. The plausibility criterion cannot be fulfilled if the two estimated variables deviate from one another by more than a predetermined amount.Furthermore, at least one plausibility-dependent safety measure is initiated if the at least one plausibility criterion is not fulfilled. The plausibility-dependent safety measure can be a lifetime-dependent safety measure, wherein exemplary lifetime-dependent safety measures have been explained above. However, this is not obligatory. In addition to the lifetime-dependent safety measures already explained above, such a plausibility-dependent safety measure can be:accepting the generation of control signals by a computing device other than the one which previously generates the control signals, i.e. in particular by the backup computing device,preventing the acceptance of the generation of control signals from being performed by a computing device other than the one which previously generates the control signals, i.e. in particular by the backup computing device,disabling the steering system.and further safety measures known to the skilled person.It is also possible that at least one continued operation criterion is evaluated as a function of at least one of the at least two estimation variables and-as explained above-at least one service life-dependent safety measure is initiated if the at least one continued operation criterion is not fulfilled, wherein the evaluation or the initiation only occurs if the at least one plausibility criterion is fulfilled.If the at least one plausibility criterion is not fulfilled, then at least one of the computing devices can carry out a self-diagnosis for detecting a fault-free self-operating state or a foreign diagnosis for detecting a fault-free operating state of the remaining computing device. If, for example, the main computing device detects a fault-free operating state by a self-diagnosis and / or the backup computing device detects the fault-free operating state of the main computing device in a foreign diagnosis, then the operation as a main computing device can be continued. If the main computing device detects an incorrect operating state by the self-diagnosis and / or if the backup computing device detects the incorrect operating state of the main computing device in a foreign diagnosis, the operation of the main computing device can be ended in order to generate control signals. In this case, the backup computing device can be operated as a main computing device, in particular if it has detected a fault-free operating state of its own in a self-diagnosis and / or if the main computing device has detected the fault-free operating state of the backup computing device in a foreign diagnosis. The plausibility check advantageously results in increased operational reliability during operation of the vehicle, since it can be assumed when the plausibility criterion is not fulfilled that the estimated variable has not been reliably determined accurately and therefore the methods based on the estimated variable are also not carried out with the desired reliability.In a further embodiment, the estimated variable is determined as a function of at least one variable detected with the aid of a sensor. This and corresponding advantages have already been explained above. The determination can be made here, for example, on a model basis, on a characteristic curve basis or on an assignment basis. Of course, other ways of determination are also possible. A quantity detected with the aid of a sensor can be an input quantity for a method for determining the estimated quantity. Alternatively, it is conceivable that an input variable for such a method is determined from the variable detected with the aid of a sensor, for example by calculation steps. This advantageously results in a reliable determination of a current value of the estimated variable and thus also in a guarantee of operational reliability at the current point in time.In a further embodiment, the estimated variables are determined by the different computing devices in the same way. Alternatively, the estimated variables are determined by the different computing devices in different ways. For example, the estimated variables can be determined by the same computing rules or in each case by computing rules which differ from one another. The estimated variables can also be determined as a function of the same input variables or as a function of input variables which differ from one another.If estimated variables are determined in the same way, in particular by the same computing rules and on the basis of the same input variables, a simple implementation of the method advantageously results. If the estimated variables are determined in different ways, in particular by calculation rules that differ from one another and / or on the basis of input variables that differ from one another, a high reliability results in the determination of the estimated variables, in particular if the at least one plausibility criterion is fulfilled.In a further embodiment, the evaluation of the plausibility criterion is carried out by a computing device which generates a control signal for a drive device of the steering system in the fault-free state of the steering system. This may be the main computing device. This advantageously results in the computing device responsible for generating the control signal being able to validate directly whether such a control signal is generated while observing the plausibility criterion, without additional data transmission processes to other devices being necessary for the validation. In particular, the main computing device can immediately abort or change or prevent the generation of a control signal if it is detected that the plausibility criterion is not (any longer) fulfilled.In an alternative embodiment, the evaluation of the plausibility criterion is carried out by a computing device which, in the fault-free state of the steering system, does not generate a control signal for a drive device of the steering system. This can be, in particular, the explained backup computing device. This advantageously results in a distribution of calculation loads to the various calculation devices, in particular the main calculation device is not additionally loaded by the evaluation of the plausibility criterion. In such a scenario, if the non-satisfaction of the plausibility criterion is detected, a corresponding signal representing the non-satisfaction may be transmitted to the main computing device. The main computing device can then initiate corresponding measures, in particular abort or change or prevent the generation of a control signal.In a further embodiment, information is transmitted between the computing devices via an inter-micro interface for evaluating the plausibility criterion. This advantageously results in the simplest possible and quick-over-time evaluation of the plausibility criterion. In particular, e.g. the first computing device can transmit information such as e.g. the estimated variable to the further computing device or vice versa. As explained above, a result of the evaluation of the plausibility criterion can also be transmitted to the respective other computing device. InIn a further embodiment, a resulting estimated variable is determined as a function of the estimated variables. Furthermore, at least one continued operation criterion is evaluated as a function of the resulting estimated variable, wherein at least one continued operation-specific safety measure is initiated if the at least one continued operation criterion is not fulfilled. As the resulting estimated variable, for example, an average value, in particular a weighted average value, of the two estimated variables can be determined. The safety measure specific to continued operation can correspond to one of the above-explained lifetime-dependent and / or plausibility-dependent safety measures, but can also be different therefrom. In particular, in the case of a non-fulfilment, information can be generated for a vehicle driver or other vehicle occupants, informing them about the non-fulfilment. This advantageously results in a higher accuracy and reliability in the determination of the estimated variable and thus in an increased operational reliability.In a further embodiment, a confidence factor is assigned to an estimated variable, wherein the confidence factor represents a measure of the fulfillment of the plausibility criterion. In particular, such a confidence factor can be assigned to a resulting estimate variable. The trust factor may form a measure of safety integrity (ASIL).However, it is also possible that, in particular for evaluating a continued operation criterion, only the estimated variable determined by the first or the further computing device is used, wherein the confidence factor is then assigned to this estimated variable. Furthermore, the continued operation criterion and / or the initiation of the continued operation-specific safety measure can take place as a function of the confidence factor. For example, the confidence factor may correlate with the degree of compliance. In this case, a high confidence factor indicates that the plausibility criterion is fulfilled to a high degree.It is possible, for example, that for an estimated variable having a first value, to which a comparatively lower confidence factor is assigned, the continued operation criterion is not fulfilled, while it is fulfilled for an estimated variable having the first value, to which a higher confidence factor is assigned.This advantageously results in a further improvement in the operational safety during operation of the vehicle.Furthermore, a device for operating a vehicle is proposed, wherein the device comprises at least one computing device. An actual service life and, as an estimated variable, a degree of damage or a state of health of at least one component of the steering system can be determined or is determined by the computing device. Furthermore, the actual service life is compared with a specified service life of the component and at least one continued operation criterion is evaluated as a function of the estimated variable. This can likewise be effected by the computing device.Furthermore, a service life-dependent safety measure is initiated if the actual service life is greater than the specified service life and the continued operation criterion is not fulfilled, wherein the service life-dependent safety measure is not initiated if the actual service life is greater than the specified service life and the continued operation criterion is fulfilled. The apparatus is thus configured to perform a method of operating a vehicle according to any of the embodiments described in this disclosure. This device thus advantageously enables such a method to be carried out.A vehicle having such a device is also described.Furthermore, a device for operating a vehicle is proposed, wherein the device comprises a first and at least one further computing device, wherein the further computing device is different from the first computing device. Furthermore, as an estimated variable, a degree of damage or a state of health of at least one component of a steering system of the vehicle is determined in each case by the at least two mutually different computing devices of the steering system, wherein at least one plausibility criterion is evaluated as a function of the at least two estimated variables. Furthermore, at least one safety measure is initiated if the at least one plausibility criterion is not fulfilled. The apparatus is thus configured to perform a method of operating a vehicle according to any of the embodiments described in this disclosure. This device thus advantageously enables such a method to be carried out.A vehicle having such a device is also described.The invention is explained in more detail on the basis of exemplary embodiments. The figures show: FIG. 1 shows a schematic flow diagram of a method according to the invention, FIG. 2 shows a schematic flow diagram of a method according to the invention in a further embodiment, FIG. 3 shows a schematic flow diagram of a method according to the invention in a further embodiment, FIG. 4 shows a schematic flow diagram of a method according to the invention in a further embodiment, FIG. 5 shows a schematic block diagram of a device according to the invention, FIG. 6 shows a schematic time profile of an error rate of a component, and FIG. 7 shows a schematic block diagram of a device according to the invention.In the following, the same reference numerals denote elements having the same or similar technical features.FIG. 1 shows a schematic flow diagram of a method according to the invention for operating a vehicle. In a step S_TL, an actual service life of at least one component of a steering system of the vehicle is determined. This actual lifetime TL (see also FIG. 6 ) may correspond to a number of operating hours since the startup of the component, for example.In a step S_VL, the actual lifetime TL is then compared with a predetermined specified lifetime SL of the component. The specified lifetime SL can be called up for this purpose from an external system, for example a storage device.If the actual lifetime TL is less than the specified lifetime SL, the process returns to step S_TL to determine the actual lifetime TL. If the actual lifetime is greater than or equal to the specified lifetime SL, a degree of damage or a state of health of the component is determined as the estimated variable in a step S_SG. As a function of this estimation variable SG, it is evaluated in a step S_WK whether a further operation criterion, which is specific to the component in particular, is fulfilled. If the continued operation criterion is not fulfilled, a safety measure, for example one of the service life-dependent safety measures explained above, is initiated. If, however, the continued operation criterion is fulfilled, the service life-dependent safety measure is not initiated and the method can return to step V_TL of determining the actual service life TL, for example.FIG. 2 shows a schematic flow diagram of a method according to the invention in a further embodiment. Here, a first computing device 3 a(see e.g. FIG. 5 ) and a further computing device 3 beach perform a step S_SWa, S_SWb for determining an estimated variable SGa, SGb, wherein a degree of damage or a state of health of the same component of a steering system is determined as the estimated variable. The computing devices 3 a, 3 bare computing devices 3 a, 3 bof the steering system that are different from one another. FIG. 2 shows that a first estimated variable SGa is determined with the first computing device and a further estimated variable SGb is determined with the further computing device, these being respectively component-specific estimated variables SGa, SGb. In a step S_P, a plausibility criterion is evaluated as a function of the two estimation variables SGa, SGb. The plausibility criterion can be fulfilled in particular if the estimated variables SGa, SGb do not deviate from one another or do not deviate from one another by more than a predetermined amount. If the at least one plausibility criterion is not fulfilled, a plausibility-specific safety measure can be initiated. For example, an alert may be output to a vehicle operator.FIG. 3 shows a schematic flow diagram of a method according to the invention in a further embodiment. In this case, the determination steps S_SGa, S_SGb and the step S_K for evaluating the plausibility criterion correspond to the steps illustrated in FIG. 2, and reference is made to the explanations relating thereto.If the plausibility criterion is fulfilled, then in a step S_SRr a resulting estimated variable SGr can be determined as a function of the two estimated variables SGa, SGb, for example as an average value or weighted average value.In a step S_WK, at least one continued operation criterion is evaluated as a function of the resulting estimated variable SGr, wherein at least one continued operation-specific safety measure SM is initiated if the continued operation criterion is not fulfilled. If the continued operation criterion is fulfilled, the method can return again to steps S_SWa, S_SWb for determining the estimation variables SGa, SGb.The continued operation criterion can be fulfilled if the estimated variable is higher or lower than a predetermined measure. The measure can be selected in such a way that, for example, a comparatively higher or lower estimation variable represents an in particular undesirably impaired operational safety of the vehicle. An impaired operational safety can be an operational safety that deviates from a setpoint operational safety in the undamaged state of the vehicle. The continued operation criterion may not be fulfilled if the estimated variable is less than or higher than the predetermined measure or equal to the predetermined measure, wherein a comparatively lower or higher estimated variable represents a desired operational reliability. In order to determine whether the continued operation criterion is fulfilled, a comparison of the estimated variable with a predetermined threshold value can be made, for example.FIG. 4 shows a schematic flow diagram of a method according to the invention in a further embodiment. In this case, steps S_SWa, S_SWb for determining the estimated variables SGa, SGb and step S_K for evaluating the plausibility criterion correspond to the steps illustrated in FIG. 2, and reference is made to the explanations relating thereto.If the plausibility criterion is fulfilled, a step S_VF can be carried out to determine a confidence factor VF which is assigned to the first estimated variable SGa, the second estimated variable SGb or a resulting estimated variable SGr. In a step S_WK, a continued operation criterion can then be evaluated as a function of the confidence factor VF and the estimation variable SGa, SGb, SGr which is assigned to this confidence factor VF. Furthermore, at least one continued operation-specific safety measure SM is initiated if the continued operation criterion is not fulfilled. If the continued operation criterion is fulfilled, the method can return again to steps S_SWa, S_SWb for determining the estimation variables SGa, SGb.FIG. 5 shows a schematic block diagram of an apparatus 1 according to the invention. the apparatus can comprise a control unit 2, wherein the control unit 2 can in turn comprise a first computing device 3 aand a further computing device 3 b. These may be arranged on different printed circuit boards within a housing of the control unit 2. The control device SG can be a control device of a steering system of the vehicle and generate, for example, control signals CS for operating a drive device 4 of the steering system. Such a signal CS can be, for example, a setpoint phase current for such a drive device 4.Schematically shown are input variables E 1, E 2,..., En of the control unit 2, which can also be input variables of the computing devices 3 a, 3 bin each case. Such input variables can be input variables E 1, E 2,..., En detected with sensor assistance or can be determined as a function of variables detected with sensor assistance. Exemplary input variables have been explained above.Schematically depicted are steps S_SGa, S_SGb for determining estimation variables SGa, SGb (see FIG. 2 ). FIG. 5 shows that the estimated variable SGb determined by the further computing device 3 bis transmitted to the first computing device 3 avia an inter-microcommunication interface 5. This can then carry out the step S_P for evaluating the plausibility criterion. Depending on a result of the evaluation, the first computing device 3 acan then determine a control signal CS in a step S_CS for generating this control signal CS. If the plausibility criterion is not fulfilled, the control signal CS can be, for example, a signal for initiating a safety measure SM. If the plausibility criterion is fulfilled, the control signal CS can represent, for example, a setpoint phase current for the drive device 4.It is possible that the two estimation variables SGa, SGb shown in FIG. 5 are determined by the two computing devices 3 a, 3 bin the same or in different ways.For the embodiment shown in FIG. 5, it can be assumed that the first computing device 3 aconstitutes a main computing device of the control unit 2 or of the steering system, wherein this main computing device generates the control signal CS for the drive device 4 of the steering system in the fault-free state of the steering system. The further computing device 3 bconstitutes a backup computing device which can take over the generation of the control signal CS for the drive device 4 in a non-fault-free state of the steering system, in particular in a non-fault-free state of the first computing device 3 a. In the fault-free state of the steering system, in particular of the first computing device 3 a, however, the further computing device 3 bdoes not generate a control signal CS for the drive device.In the embodiment shown in FIG. 5, the plausibility criterion is evaluated by the first computing device 3 a, i.e. the main computing device. However, it is of course conceivable that the plausibility criterion is also evaluated by the further computing device 3 b, for which purpose in particular the estimation variable SGa determined by the first computing device 3 ais transmitted to the further computing device 3 b, for example via the interface 5 shown. A result of the evaluation can then in turn be transmitted to the first computing device 3 a, for example likewise via the interface 5 shown.FIG. 6 shows a schematic time profile of an error rate FR of a component. A time axis t and an error rate axis FR are shown here. Further illustrated is a predetermined specified lifetime SL of the component. It can be assumed that the failure rate FR of the component until the lapse of this specified lifetime SL does not exceed a first predetermined failure rate FR1. A solid line represents a previously assumed error rate profile, wherein it is assumed that the error rate FR of the component increases after the specified lifetime SL has elapsed. However, this assumption does not necessarily reflect the real conditions. For example, it is possible that even for an actual lifetime TL that is larger than the specified lifetime SL, the actual failure rate FR of the component does not exceed the first predetermined failure rate FR 1. Therefore, according to the invention, it is proposed, for situations in which the actual service life TL is greater than or equal to the specified service life SL, to evaluate a continued operation criterion for the component as a function of a degree of damage or a state of health of this component, wherein the operation of the component can be continued if the continued operation criterion is fulfilled.FIG. 7 shows a schematic block diagram of a device according to the invention for operating a vehicle in a further embodiment. The apparatus 1 comprises a computing device 3 which can determine an actual service life TL and compare it with a specified service life SL of a component of a steering system of the vehicle. The computing device 3 can likewise determine an estimated variable SG and evaluate a continued operation criterion as a function of this estimated variable SG. Furthermore, the computing device 3 can generate a control signal CS, wherein a lifetime-dependent safety measure SM can be initiated by this control signal and this control signal CS is generated if the actual lifetime TL is greater than the specified lifetime SL and the continued operation criterion is not fulfilled.List of reference characters1 Device 2 Control device 3, 3 a, 3 bCalculator 4 Drive device 5 Interface E 1, E 2,..., EnInput variables S_TL Step for determining the actual service life SL Specified service life TL Actual service life S_VL Step for comparing the service lives S_VL Step for determining an estimated variable S_WK Step for evaluating a continued operation criterion SM Safety measure S_VLa, S_VLb Step for determining estimated variables SGa, SGb estimation variables S_P step for evaluating a plausibility criterion S_SGr step for determining a resulting estimation variable SGr resulting estimation variable S_VF step for determining a confidence factor FR error rate FR1 predetermined error rate t time CS control signal
Claims
Method for operating a vehicle, wherein an actual service life (TL) and, as an estimated variable, a degree of damage or a state of health of at least one component of a steering system of the vehicle are determined, wherein the actual service life (TL) is compared with a specified service life (SL) of the component and, as a function of the estimated variable, at least one continued operation criterion is evaluated, wherein a service life-dependent safety measure (SM) is initiated if the actual service life (TL) is greater than the specified service life (SL) and the continued operation criterion is not fulfilled, wherein the service life-dependent safety measure (SM) is not initiated if the actual service life (TL) is greater than the specified service life (SL) and the continued operation criterion is fulfilled.Method for operating a vehicle, wherein as an estimated variable (SGa, SGb) a degree of damage or a state of health of at least one component of a steering system is determined in each case by at least two computing devices (3a, 3b) of the steering system which differ from one another, wherein the degree of damage is a measure for already occurring wear or damage and the state of health is a measure with respect to functionality, performance and / or safety of the at least one component, wherein at least one plausibility criterion is evaluated as a function of the at least two estimated variables (SGa, SGb), wherein at least one safety measure (SM) is initiated if the at least one plausibility criterion is not fulfilled.Method according to Claim 2, characterized in that the estimated variable (SGa, SGb) is determined as a function of at least one variable detected with sensor assistance, and / or in that the estimated variables (SGa, SGb) are determined in the same or in different ways by the different computing devices (3a, 3b), and / or in that, for the evaluation of the plausibility criterion, information is transmitted between the computing devices (3a, 3b) via an inter-micro interface (5).Method according to one of Claims 2 to 3, characterized in that the evaluation of the plausibility criterion is carried out by a computing device (3a), which generates a control signal for a drive device of the steering system in the fault-free state of the steering system, or in that the evaluation of the plausibility criterion is carried out by a computing device (3b), which does not generate a control signal for an actuator of the steering system in the fault-free state of the steering system.Method according to one of Claims 2 to 4, characterized in that a setpoint auxiliary torque of a drive device of the steering system and a generated actual auxiliary torque are determined and compared, wherein the degree of damage or the state of health of a drive device (4) and / or of the regulating or control device (SG) of the drive device (4) is determined from a difference between these variables.Method according to one of Claims 2 to 5, characterized in that an actual auxiliary torque and a change in a steering rack position are detected, wherein the degree of damage or the state of health of a steering gear is determined as a function of these variables.Method according to one of Claims 2 to 6, characterized in that a path or angular range of a steering rack or of a worm wheel which has already been covered since start-up is determined, wherein the degree of damage or the state of health of the steering rack or of the worm wheel is determined as a function of the path covered.Method according to one of Claims 2 to 7, characterized in that a resulting estimated variable (SGr) is determined as a function of the estimated variables (SGa, SGb), and at least one continued operation criterion is evaluated as a function of the resulting estimated variable (SGr), at least one safety measure (SM) being initiated if the at least one continued operation criterion is not fulfilled.Method according to one of Claims 2 to 8, characterized in that a confidence factor (VF) is assigned to an estimated variable (SGa, SGb, SGr), the confidence factor (VF) representing a measure of fulfilment of the plausibility criterion.Device for operating a vehicle, wherein the device (1) comprises at least one computing device (3), wherein an actual service life (TL) and, as an estimated variable, a degree of damage or a state of health of at least one component of the steering system are determined by the computing device (3), wherein the actual service life (TL) is compared with a specified service life (SL) of the component and at least one continued operation criterion is evaluated as a function of the estimated variable, wherein a service life-dependent safety measure (SM) is initiated if the actual service life (TL) is greater than the specified service life (SL) and the continued operation criterion is not fulfilled, wherein the service life-dependent safety measure (SM) is not initiated, if the actual service life (TL) is greater than the specified service life (SL) and the continued operation criterion is fulfilled.Device for operating a vehicle, wherein the device comprises a first and at least one further computing device (3a, 3b), wherein the further computing device (3b) is different from the first computing device (3a), wherein as an estimated variable (SGa, SGb) a degree of damage or a state of health of at least one component of a steering system of the vehicle is determined in each case by the at least two computing devices (3a, 3b) of the steering system which are different from one another, wherein the degree of damage is a measure for already occurring wear or damage and the state of health is a measure with respect to functionality, performance and / or safety of the at least one component, wherein at least one plausibility criterion is evaluated as a function of the at least two estimated variables (SGa, SGb), wherein at least one safety measure (SM) is initiated if the at least one plausibility criterion is not fulfilled.
Citation Information
Patent Citations
Methods for detecting external shocks in vehicle steering systems
DE102010033066A1
procedures and systems for checking the integrity of steering systems
DE102017117327A1
Electromechanical steering system for a motor vehicle and method for operating a steering system for a motor vehicle
DE102021200428A1
Control method for at least a mechanical actuator, especially a mechanical actuator in a steer by wire system, whereby a control signal is generated based on analysis of an operation work flow
DE10340369A1
Triple redundancy failsafe for steering systems
US10752282B2