Protective device and method for safely disconnecting a high-voltage network in the event of a vehicle collision
The protective device architecture in vehicles addresses the risk of accidental high-voltage system activation after an accident by using a vehicle control unit with ASIL logic to store accident events and prevent system startup, ensuring safety through effective shutdown and prevention mechanisms.
Patent Information
- Application Number
- DE102023211539
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-20
- Publication Date
- 2025-05-22
AI Technical Summary
Existing high-voltage systems in vehicles, particularly electric and hybrid vehicles, lack effective mechanisms to prevent accidental activation after an accident event, which can lead to electrical shocks and safety risks.
A protective device architecture that includes a vehicle control unit storing accident events with safety integrity logic (ASIL), preventing the high-voltage system from being started up, and utilizing bus systems (CAN 1 and CAN 2) and pulse width modulation to ensure safe shutdown and startup prevention.
The solution effectively prevents the high-voltage system from being accidentally activated after an accident, ensuring the safety of occupants and rescue workers by using ASIL-relevant safety integrity functions and flexible cable harness designs.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Technical field
[0001] The invention relates to a protective device for preventing activation of a high-voltage system, in particular a vehicle high-voltage system. Furthermore, the invention relates to a method for preventing activation of a high-voltage system comprising a protective device. State of the art
[0002] DE 10 2009 051 293 A1 discloses a circuit arrangement for disconnecting a voltage source from an electrical system of a vehicle, in particular a motor vehicle, wherein the electrical system comprises a first voltage system with a first voltage source and a second voltage system with a second voltage source. The device has the following features: a switching device for disconnecting the first voltage source from the first electrical system, wherein the switching device is switchable via a control current from the second electrical system such that, upon supply of the control current, the switching device disconnects the first voltage source from the first electrical system; a first control unit, via which a request for triggering a safety function can be detected; a second control unit, which is connected to the first control unit via at least one data bus; the second control unit is connected to the second control unit via at least one data bus;via which a request for triggering a safety function can be detected, a second control unit which is connected to the first control unit via at least one data bus and via which the supply of the control current to the switching device can be controlled, so that during operation of the circuit arrangement the first control unit issues a predetermined control command to the at least one data bus upon detection of the request and the second control unit interrupts the supply of the control current to the switching device in response to the predetermined control command.
[0003] CN 208232851 U discloses a battery monitoring system. The battery monitoring system includes a power input interface, a BMS (Battery Management System), a VCU (Vehicle Control Unit), an airbag control unit, a high-voltage load, a high-voltage interface module, and a gateway. The airbag control unit includes a crash sensor and a communication unit, and the communication unit is connected to the BMS. The BMS includes a high-voltage interlock circuit and a high-voltage relay. In the event of an impact, the airbag control unit transmits the impact signal directly to the BMS, which controls the high-voltage relay to interrupt the connection. The BMS also controls the high-voltage load through the high-voltage interlock circuit to achieve safety protection. Disclosure of the invention
[0004] According to the invention, a protective device for preventing activation of a high-voltage system, in particular a vehicle high-voltage system, is proposed, wherein the protective device comprises a body control unit, an airbag control unit, a braking system, a pulse width modulation, a central control unit, a cabling device, at least a first bus system CAN1, a second bus system CAN2 and a start-stop button or an ignition lock, an ignition communication path and a vehicle control unit, wherein a vehicle control unit stores an accident event and prevents the high-voltage system from starting up when the vehicle control unit is reactivated, wherein the protective device has a specific protective device architecture that operates according to a defined logic.
[0005] A high-voltage system, in particular a high-voltage system of a vehicle, is, in the sense of the protective device according to the invention, an electrical system that provides and manages energy for a vehicle drive.
[0006] For the purposes of the present protective device, the activation of a high-voltage system in a vehicle, in particular in an electric vehicle or a hybrid vehicle, is to be understood as the process by which the high-voltage system is put into the operating state.
[0007] A protective device architecture in the sense of the invention refers to a structure and / or a design of the protective device.
[0008] An accident event, in particular a vehicle accident, within the meaning of the present invention is an accident that occurs, for example, during the operation or use of a vehicle and results in material damage to the vehicle or damage to the vehicle's functionality. This includes, for example, a collision, impact, malfunction, malfunction, or other unexpected event that affects the safety, integrity, or performance of the vehicle. For example, an accident event can significantly affect the high-voltage systems of a vehicle. This is particularly the case if the vehicle is an electric or hybrid vehicle.
[0009] A charging connector within the meaning of the invention is, for example, an electrical connector system for a vehicle for connecting the vehicle to an external power source for charging the vehicle battery. For example, an electric vehicle can be electrically coupled to the power source of a charging station via a connector system.
[0010] Reactivation of a high-voltage system within the meaning of the invention, preferably in connection with a vehicle, such as an electric or hybrid vehicle, is understood to mean a process in which the high-voltage system is returned to an operational state after being temporarily deactivated or shut down, for example, due to an accident. For example, reactivation of the vehicle control unit can occur via an ignition lock and / or a charging connector.
[0011] In an advantageous embodiment of the protective device proposed according to the invention for preventing activation of a high-voltage system, a vehicle control unit stores an accident event by means of a protective device architecture with a safety integrity.
[0012] A safety integrity level included in the protective device architecture within the meaning of the proposed invention can, for example, be an Automotive Safety Integrity Level (ASIL). ASIL is a concept used in the international standard ISO 26262 for the functional safety of electrical and electronic vehicle systems.
[0013] The vehicle control unit with a safety integrity architecture, such as ASIL, either stores a received accident event or detects faulty transmission channels to determine whether an accident event may have occurred. Upon such detection, the high-voltage system is shut down, preventing the high-voltage system from starting up in the long term. In addition, information from other CAN bus participants is used to determine whether the airbag control unit could transmit information about an accident event, and if in doubt, the high-voltage system is not started up. Furthermore, the high-voltage system can be re-enabled using a special workshop diagnostic tool, thus preventing improper tampering with safety-relevant functions of the high-voltage system.
[0014] Furthermore, a protective device architecture for preventing activation of a high-voltage system is preferably proposed, in which a protective device architecture stores an accident event in the vehicle control unit, comprising at least the following logic: a) a first if query as to whether an accident event report has occurred, which stores an accident event in a non-volatile memory via an airbag control unit via a first bus system CAN1 and a second bus system CAN2 and in the vehicle control unit and executes an accident event reaction; b) a second if query as to whether an accident event report has occurred, which reports an accident event from the airbag control unit via pulse width modulation, and stores an accident event in the non-volatile memory of the vehicle control unit and executes an accident event reaction; c) a third if-query to check whether there is no communication between the airbag control unit and the vehicle control unit via the first if-query and the second if-query and whether the ignition is switched on or a speed is greater than zero, whereby an accident event is stored in the non-volatile memory of the vehicle control unit and the high-voltage system is shut down. d) a fourth if query prevents the high-voltage system from starting up if an existing accident event is identified internally in the non-volatile memory.
[0015] The term “non-volatile memory” in the sense of the present invention refers to the storage of data or information, for example information regarding the occurrence of an accident event, in a data memory which stores the data indelibly after a loss of any power supply or after the system is switched off (switched off the system).
[0016] The first if query is a primary path that is executed if a wiring harness used for transmission from the airbag control unit to the vehicle control unit remains undamaged by the accident event. The second if query is the secondary path if the primary path on the first bus system CAN 1 or on the second bus system CAN 2 is damaged. The third if query also takes the ignition and speed into account to rule out incorrect detection of an accident event between the received accident signals and detected faulty transmission paths from the airbag control unit to the vehicle control unit. The vehicle control unit can use the ignition lock and the speed to determine whether the airbag control unit is operational.Furthermore, the ignition lock can be used to distinguish between driving and charging or pre-heating the battery, as the airbag control unit could be switched off during charging or conditioning. If the driver switches off the ignition lock while driving to deactivate the drive, the accident event must be reliably detected as long as the vehicle is still rolling, and the airbag control unit remains awake. This is achieved by taking speed into account, which is taken into account in both the body control unit and the vehicle control unit. The fourth if-state query prevents the high-voltage system from starting up if the first to third if-state queries previously detected an accident event and the vehicle control unit was switched off in the meantime.
[0017] In a further possible embodiment of the protective device architecture proposed according to the invention, the vehicle control unit stores information about a received accident event and / or detects, due to a faulty transmission channel or faulty transmission channels, whether an accident event has occurred and stores this information.
[0018] This has the advantage that the vehicle control unit stores the accident event. When the vehicle control unit is reactivated, it prevents the high-voltage system from being switched on. This eliminates the need for a low-voltage pyroelectric fuse, for example.
[0019] In an advantageous embodiment of the protective device architecture proposed according to the invention, each If query of the protective device architecture as well as the storage in the non-volatile memory, the shutdown of the high-voltage system and the prevention of the startup of the high-voltage system has a logic that includes an ASIL-relevant safety integrity function.
[0020] In an advantageous embodiment of the protective device architecture according to the invention, a high-voltage system is only released for startup after repair in a workshop.
[0021] In a further advantageous embodiment of the protective device architecture according to the invention, the startup of a high-voltage system is enabled by a vehicle-specific workshop diagnostic device in which the accident event is deleted or unlocked within a vehicle control unit.
[0022] According to the invention, a method for preventing activation of a high-voltage system comprising a protective device is proposed, which method comprises at least the following steps: - Request to activate the high-voltage system, - Checking by a vehicle control unit before activating a high-voltage system whether the control unit receives messages from one or more bus systems, - Shutdown of a high-voltage system and - Preventing a high voltage system from starting up.
[0023] According to the invention, a request to activate the high-voltage system can be made, for example, via a start-stop button or an ignition lock. Alternatively, the request can also be made via a charging plug.
[0024] In a further advantageous embodiment of the method proposed according to the invention, an ASIL safety integrity function in the vehicle control unit is activated each time a high-voltage system is started up.
[0025] In addition to the previously described logic that stores the accident event, the protective device architecture contains another procedure that should be implemented in a safety integrity check such as ASIL, which is activated in the vehicle control unit each time the high-voltage system is powered up. In this case, before the high-voltage system is switched on, the vehicle control unit first checks whether it is receiving bus system messages from another bus system participant in the airbag control unit network, the first bus system CAN1, such as the brake system. This checks whether a transmission from the central control unit to the vehicle control unit on the second bus system CAN2 is possible, since the brake system, unlike the airbag control unit, is also active during charging or battery conditioning.This takes into account the case where a stationary vehicle (for example at an intersection) with an active ignition lock has suffered an accident in which both the second bus system CAN2, the pulse width modulation and the information from the ignition lock were interrupted. Advantages of the invention
[0026] In the protective device proposed according to the invention, a low-voltage pyro-fuse and a high-voltage pyro-fuse are preferably omitted, which represents a cost advantage in vehicle manufacture and in repair after an accident.
[0027] In the protective device according to the invention, it is advantageously proposed that the airbag control unit be inactive during charging or when the high-voltage battery needs to be conditioned. This reduces the demands on the service life of the airbag control unit.
[0028] According to the invention, the vehicle control unit advantageously either stores an accident event that has occurred using safety integrity logic (ASIL) or detects whether an accident event may have occurred based on faulty transmission channels. Upon such detection, the high-voltage system is shut down and a startup of the high-voltage system is prevented in the long term, thereby advantageously avoiding electric shock and thus protecting rescue personnel and passengers.
[0029] The protective device according to the invention achieves flexibility in the wiring harness design as well as independence of the low-voltage wiring harness design from the performance of impact tests and the expected impact deformations of the vehicle.
[0030] In addition, the high-voltage system can be advantageously reactivated using a special workshop diagnostic tool, preventing improper or unauthorized activation of the safety-relevant high-voltage system. Short description of the drawings
[0031] Embodiments of the invention are explained in more detail with reference to the drawings and the following description.
[0032] They show: Fig. 1 a schematic representation of a protective device, Fig. 2 a schematic representation of a method for preventing activation of a high-voltage system and Fig. 3 a schematic representation of a protective device architecture. Embodiments of the invention
[0033] In the following description of the embodiments of the invention, identical or similar elements are designated by the same reference numerals, whereby a repeated description of these elements is omitted in individual cases. The figures only schematically illustrate the subject matter of the invention.
[0034] Fig. Figure 1 shows a schematic representation of a protective device 100, wherein the protective device 100 is shown as a block diagram. The protective device 100 has a start-stop button or an ignition lock 101. A body control unit 102 is connected to the start-stop button or the ignition lock 101, followed by an airbag control unit 104. Furthermore, Fig. 1 shows that the body control unit 102 is connected to a vehicle control unit 110 via a wiring system 112, the airbag control unit 104 and the braking system 106 are connected to the first bus system CAN1 114 via a central control unit 108, and to the vehicle control unit 110 via a wiring system 112 to the second bus system CAN2 118. In addition, the airbag control unit 104 is directly connected to the vehicle control unit 110 via a pulse width modulation 116 via a wiring system 112. Furthermore, the body control unit 102 forwards the ignition key information to the vehicle control unit 110 via an ignition communication path 120 via a wiring system 112.
[0035] In Fig. 2 shows a method 200 for preventing activation of a high-voltage system. In a first step, a request 202 is made to activate the high-voltage system. In a second step, a check 204 is performed to determine whether the high-voltage system is receiving messages from a bus participant on the first bus system CAN1 114. This bus participant (unlike the airbag control unit 104) is active in all vehicle states. In the third step, the high-voltage system is shut down (208). In the final step, a startup of the high-voltage system is prevented 212.
[0036] Fig.3 shows a schematic representation of a protective device architecture 300. The protective device architecture 300 is represented by a process sequence, wherein the first block is a starting point 300.2 of the protective device architecture 300. The starting point 300.2 is followed by a first if query 302 and a second if query 304. The first if query 302 queries whether an accident event was reported by an airbag control unit 104 via a first bus system CAN1 114 and a second bus system CAN2 118. An accident event is then stored in a non-volatile memory 310 in the vehicle control unit 110, and the high-voltage system is shut down 208. The second if query 304 queries whether an accident event message has occurred, which reports an accident event from the airbag control unit 104 via a pulse width modulation 116.An accident event is then stored in a non-volatile memory 310 in the vehicle control unit 110, and the high-voltage system is shut down 208. The third if query 306 queries whether communication between the airbag control unit 104 and the vehicle control unit 110 via the communication path of the second bus system CAN2 118 or the first bus system 114 or the pulse width modulation 116 is not possible and the ignition is switched on or a speed greater than zero is present. An accident event is then stored in the non-volatile memory 310 of the vehicle control unit 110, and the high-voltage system is shut down 208. After the first three if queries 302, 304, and 306, a fourth if query 308 prevents 212 the high-voltage system from being powered up.
[0037] For example, a second if-query 304 may be triggered if a first if-query 302 has already occurred or if the primary path of a first if-query 302 is corrupted. The corruption of the primary path may be caused, for example, by a malfunction of the first bus system CAN1 114 and / or the second bus system CAN2 118.
[0038] The third if query 306 additionally considers the ignition communication path 120 and the speed to rule out incorrect detection of an accident event, distinguishing between the received accident signals and a detected faulty transmission path from the airbag control unit 104 to the vehicle control unit 110. Based on the information from the start / stop button or the ignition lock 101 and the speed, the vehicle control unit 110 detects whether the airbag control unit 104 is operational. The information from the start / stop button or the ignition lock 101 can be used, for example, to distinguish between the driving and charging or battery conditioning operating modes, since the airbag control unit 104 is switched off during charging or battery conditioning.If a driver deactivates the start / stop button or the ignition lock 101 while driving to shut off the engine, the accident event must still be reliably detected while the vehicle is still rolling, and the airbag control unit 104 remains awake. This occurs taking into account the speed, which is taken into account in both the body control unit 102 and the vehicle control unit 110.
[0039] If the fourth if query 308 detects a message about an accident event in the non-volatile memory 310, this prevents a high-voltage system, for example, of a vehicle from being started up. The high-voltage system can only be unlocked by a specialist in a workshop after repair or maintenance. For example, unlocking by workshop personnel using a vehicle-specific workshop diagnostic device within the vehicle control unit 110 can delete or unlock the accident event. For this purpose, the address of the non-volatile memory 310 is specifically accessed. This is a deliberate unlocking of the crash event, which must not be performed using a freely available tester and the command to delete the global error memory. This prevents, for example, an unqualified user from unlocking the system even though the high-voltage system is not yet safe.In a figurative sense, this corresponds to replacing the low-voltage or high-voltage pyro-fuse, which is also only described in the workshop instructions.
[0040] The invention is not limited to the embodiments described here and the aspects highlighted therein. Rather, numerous modifications are possible within the scope of the claims, which are within the scope of expert practice. QUOTES CONTAINED IN THE DESCRIPTION
[0000] This list of documents submitted by the applicant was generated automatically and is included solely for the convenience of the reader. This list is not part of the German patent or utility model application. The DPMA assumes no liability for any errors or omissions. Cited patent literature
[0000] DE 10 2009 051 293 A1
[0002] CN 208232851 U
[0003] Cited non-patent literature
[0000] ISO 26262
[0012]
Claims
[1] A protective device (100) for preventing activation of a high-voltage system, in particular a vehicle high-voltage system, wherein the protective device (100) comprises a body control unit (102), an airbag control unit (104), a braking system (106), a pulse width modulation unit (116), a central control unit (108), a cabling device (112), at least a first bus system CAN1 (114), a second bus system CAN2 (116), a start-stop button or an ignition lock (101), an ignition communication path (120), and a vehicle control unit (110), wherein the vehicle control unit (110) stores an accident event and, upon reactivation of the vehicle control unit (110), prevents the high-voltage system from starting up, wherein the protective device (100) has a specific protective device architecture (300) that operates according to a defined logic. [2] A protection device (100) for preventing activation of a high-voltage system according to claim 1, wherein a vehicle control unit (110) stores an accident event by means of a protection device architecture (300) with a safety integrity. [3] Protection device architecture (300) which stores an accident event in a non-volatile memory (310) in the vehicle control unit (110), comprising at least the following logic: a) a first if query (302) as to whether an accident event report has occurred, which stores an accident event in a non-volatile memory (310) via an airbag control unit (104) via a first bus system CAN1 (114) and a second bus system CAN2 (118) and in the vehicle control unit (110) and executes an accident event reaction; b) a second if query (304) as to whether an accident event report has occurred, which reports an accident event from the airbag control unit (104) via a pulse width modulation (116) and stores an accident event in the non-volatile memory (310) in the vehicle control unit (110) and executes an accident event reaction; c) a third if-query (306) as to whether there is communication between the airbag control unit (110) and the vehicle control unit (110) via the first if-query (302) or the second if-query (304) and whether an ignition is switched on or a speed is greater than zero, wherein an accident event is stored in the non-volatile memory (310) of the vehicle control unit (110) and the high-voltage system shuts down (208). d) a fourth if query (308) prevents the high-voltage system (212) from starting up if an existing accident event is identified internally in the non-volatile memory (310) [4] Protection device architecture (100) according to claim 3, wherein the vehicle control unit (110) stores information about a received accident event and / or detects whether an accident event has occurred due to a faulty transmission channel or faulty transmission channels and stores this information. [5] The protection device architecture (300) according to claims 3 to 4, wherein each if query (302, 304, 306, 308) of the protection device architecture (300) as well as the storage in the non-volatile memory (310) for shutting down the high-voltage system (208) and preventing the startup of the high-voltage system (212) comprises logic that includes an ASIL-relevant safety integrity function. [6] Protection device architecture (300) according to claims 3 to 5, in which a high-voltage system is only released for startup after repair in a workshop. [7] Protection device architecture (300) according to claims 3 to 6, wherein the startup of a high-voltage system is enabled by a vehicle-specific workshop diagnostic device in which the accident event is deleted or unlocked within a vehicle control unit (110). [8] Method (200) for preventing activation of a high-voltage system comprising a protective device (100) according to one of the preceding claims, which comprises at least the following steps: - Request (202) to activate the high-voltage system, - checking (204) by a vehicle control unit (110) before activating a high-voltage system whether the high-voltage system receives messages from one or more bus systems (114, 118), - Shutdown (208) of a high-voltage system and - Preventing (212) a high voltage system from starting up. [9] The method (200) of claim 8, wherein an ASIL safety integrity function in the vehicle control unit (110) is activated each time a high voltage system is started up.
Citation Information
Patent Citations
CN000115257387A
Device, vehicle, method and computer program for deactivating high-voltage components of a vehicle
DE102012018338A1